Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
QTmGYKK6SL.exe

Overview

General Information

Sample name:QTmGYKK6SL.exe
renamed because original name is a hash value
Original sample name:190e4ed7759276e78d16398673996b2b.exe
Analysis ID:1483438
MD5:190e4ed7759276e78d16398673996b2b
SHA1:ce5bb936ab809356d5b0bc29b6be2e0d07d3dc0a
SHA256:d4e965deaaaa9d84359fbce89a2cb1966bca6bf525df8bbfb1ad9ed08df1daad
Tags:64exetrojan
Infos:

Detection

Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain
Detected unpacking (creates a PE file in dynamic memory)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
AI detected suspicious sample
Connects to many ports of the same IP (likely port scanning)
Contains functionality to hide user accounts
Found Tor onion address
Machine Learning detection for dropped file
Sigma detected: Execution from Suspicious Folder
Sigma detected: Suspicious New Service Creation
Sigma detected: Suspicious Program Location with Network Connections
AV process strings found (often used to terminate AV products)
Binary contains a suspicious time stamp
Checks if the current process is being debugged
Connects to several IPs in different countries
Contains functionality to create new users
Contains functionality to dynamically determine API calls
Contains functionality to enumerate network shares
Contains functionality to enumerate running services
Contains functionality to execute programs as a different user
Contains functionality to launch a process as a different user
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query network adapater information
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Deletes files inside the Windows folder
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Drops files with a non-matching file extension (content does not match file extension)
Enables debug privileges
Enables security privileges
Found dropped PE file which has not been started or loaded
Found evasive API chain (date check)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
May sleep (evasive loops) to hinder dynamic analysis
One or more processes crash
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries keyboard layouts
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Uses cacls to modify the permissions of files
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • QTmGYKK6SL.exe (PID: 6792 cmdline: "C:\Users\user\Desktop\QTmGYKK6SL.exe" MD5: 190E4ED7759276E78D16398673996B2B)
  • QTmGYKK6SL.exe (PID: 6544 cmdline: C:\Users\user\Desktop\QTmGYKK6SL.exe MD5: 190E4ED7759276E78D16398673996B2B)
    • o0c2ddmlg7qrbu2xkviy.exe (PID: 5844 cmdline: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exe MD5: 1455F96A3552BFFCBD01FB90A2A4447B)
      • sc.exe (PID: 5000 cmdline: sc.exe stop RDP-Controller MD5: 3FB5CF71F7E7EB49790CB0E663434D80)
        • conhost.exe (PID: 6312 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • sc.exe (PID: 4628 cmdline: sc.exe create RDP-Controller binpath= C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe type= own start= auto error= ignore MD5: 3FB5CF71F7E7EB49790CB0E663434D80)
        • conhost.exe (PID: 3052 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • sc.exe (PID: 932 cmdline: sc.exe failure RDP-Controller reset= 1 actions= restart/10000 MD5: 3FB5CF71F7E7EB49790CB0E663434D80)
        • conhost.exe (PID: 2088 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • sc.exe (PID: 6648 cmdline: sc.exe start RDP-Controller MD5: 3FB5CF71F7E7EB49790CB0E663434D80)
        • conhost.exe (PID: 6016 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • icacls.exe (PID: 3668 cmdline: icacls.exe C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\ /setowner *S-1-5-18 MD5: 48C87E3B3003A2413D6399EA77707F5D)
        • conhost.exe (PID: 1620 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • icacls.exe (PID: 2724 cmdline: icacls.exe C:\Users\Public /restore C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\ZsL2hKzmRChz.acl MD5: 48C87E3B3003A2413D6399EA77707F5D)
        • conhost.exe (PID: 5956 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • main.exe (PID: 3164 cmdline: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe MD5: CFCBC15615FFC698507D32C0A7D21134)
    • WerFault.exe (PID: 2300 cmdline: C:\Windows\system32\WerFault.exe -u -p 3164 -s 1156 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0)
  • svchost.exe (PID: 792 cmdline: C:\Windows\System32\svchost.exe -k LocalService -p -s LicenseManager MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • svchost.exe (PID: 2708 cmdline: C:\Windows\System32\svchost.exe -k WerSvcGroup MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
    • WerFault.exe (PID: 1804 cmdline: C:\Windows\system32\WerFault.exe -pss -s 432 -p 3164 -ip 3164 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0)
  • main.exe (PID: 3672 cmdline: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe MD5: CFCBC15615FFC698507D32C0A7D21134)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: Process startedAuthor: Florian Roth (Nextron Systems), Tim Shelton: Data: Command: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe, CommandLine: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe, CommandLine|base64offset|contains: , Image: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe, NewProcessName: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe, OriginalFileName: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 1804, ProcessCommandLine: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe, ProcessId: 3164, ProcessName: main.exe
Source: Process startedAuthor: Nasreddine Bencherchali (Nextron Systems): Data: Command: sc.exe create RDP-Controller binpath= C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe type= own start= auto error= ignore, CommandLine: sc.exe create RDP-Controller binpath= C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe type= own start= auto error= ignore, CommandLine|base64offset|contains: r, Image: C:\Windows\System32\sc.exe, NewProcessName: C:\Windows\System32\sc.exe, OriginalFileName: C:\Windows\System32\sc.exe, ParentCommandLine: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exe, ParentImage: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exe, ParentProcessId: 5844, ParentProcessName: o0c2ddmlg7qrbu2xkviy.exe, ProcessCommandLine: sc.exe create RDP-Controller binpath= C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe type= own start= auto error= ignore, ProcessId: 4628, ProcessName: sc.exe
Source: Network ConnectionAuthor: Florian Roth (Nextron Systems), Tim Shelton: Data: DestinationIp: 119.13.124.67, DestinationIsIpv6: false, DestinationPort: 29762, EventID: 3, Image: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe, Initiated: true, ProcessId: 3164, Protocol: tcp, SourceIp: 192.168.2.4, SourceIsIpv6: false, SourcePort: 63482
Source: Process startedAuthor: Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community: Data: Command: sc.exe create RDP-Controller binpath= C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe type= own start= auto error= ignore, CommandLine: sc.exe create RDP-Controller binpath= C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe type= own start= auto error= ignore, CommandLine|base64offset|contains: r, Image: C:\Windows\System32\sc.exe, NewProcessName: C:\Windows\System32\sc.exe, OriginalFileName: C:\Windows\System32\sc.exe, ParentCommandLine: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exe, ParentImage: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exe, ParentProcessId: 5844, ParentProcessName: o0c2ddmlg7qrbu2xkviy.exe, ProcessCommandLine: sc.exe create RDP-Controller binpath= C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe type= own start= auto error= ignore, ProcessId: 4628, ProcessName: sc.exe
Source: Process startedAuthor: vburov: Data: Command: C:\Windows\System32\svchost.exe -k LocalService -p -s LicenseManager, CommandLine: C:\Windows\System32\svchost.exe -k LocalService -p -s LicenseManager, CommandLine|base64offset|contains: , Image: C:\Windows\System32\svchost.exe, NewProcessName: C:\Windows\System32\svchost.exe, OriginalFileName: C:\Windows\System32\svchost.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 620, ProcessCommandLine: C:\Windows\System32\svchost.exe -k LocalService -p -s LicenseManager, ProcessId: 792, ProcessName: svchost.exe
No Snort rule has matched
Timestamp:2024-07-27T13:43:00.851979+0200
SID:2022930
Source Port:443
Destination Port:63481
Protocol:TCP
Classtype:A Network Trojan was detected
Timestamp:2024-07-27T13:42:22.481435+0200
SID:2022930
Source Port:443
Destination Port:49731
Protocol:TCP
Classtype:A Network Trojan was detected

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://banana.incognet.io/Avira URL Cloud: Label: malware
Source: https://reseed2.i2p.net/Virustotal: Detection: 5%Perma Link
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeReversingLabs: Detection: 21%
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeVirustotal: Detection: 22%Perma Link
Source: QTmGYKK6SL.exeVirustotal: Detection: 25%Perma Link
Source: QTmGYKK6SL.exeReversingLabs: Detection: 23%
Source: Submited SampleIntegrated Neural Analysis Model: Matched 99.2% probability
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeJoe Sandbox ML: detected

Compliance

barindex
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeUnpacked PE file: 0.2.QTmGYKK6SL.exe.3420000.2.unpack
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeFile created: C:\Users\user\AppData\Local\Temp\installer.logJump to behavior
Source: Binary string: RfxVmt.pdb source: QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, main.exe, 0000000E.00000003.1913857527.000002BAD3A5A000.00000004.00000020.00020000.00000000.sdmp, JcfQdL0z.14.dr
Source: Binary string: RfxVmt.pdbGCTL source: QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, main.exe, 0000000E.00000003.1913857527.000002BAD3A5A000.00000004.00000020.00020000.00000000.sdmp, JcfQdL0z.14.dr
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE10246DAF NetApiBufferFree,NetUserEnum,GetProcessHeap,HeapAlloc,memcpy,GetProcessHeap,HeapFree,14_2_00007FFE10246DAF
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE10246DF3 LocalAlloc,wcsncpy,LookupAccountNameW,GetLastError,GetLastError,LocalAlloc,LookupAccountNameW,LocalFree,GetLastError,ConvertSidToStringSidA,GetLastError,wcslen,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,NetApiBufferFree,NetUserEnum,GetProcessHeap,HeapAlloc,memcpy,GetProcessHeap,HeapFree,14_2_00007FFE10246DF3
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE11716DF3 LocalAlloc,wcsncpy,LookupAccountNameW,GetLastError,GetLastError,LocalAlloc,LookupAccountNameW,LocalFree,GetLastError,ConvertSidToStringSidA,GetLastError,wcslen,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,NetApiBufferFree,NetUserEnum,GetProcessHeap,HeapAlloc,memcpy,GetProcessHeap,HeapFree,24_2_00007FFE11716DF3
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE11716DAF NetApiBufferFree,NetUserEnum,GetProcessHeap,HeapAlloc,memcpy,GetProcessHeap,HeapFree,24_2_00007FFE11716DAF
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FF7BACD47F3 FindNextFileA,_mbscpy,FindFirstFileA,GetLastError,GetLastError,FindClose,14_2_00007FF7BACD47F3
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE1024A0D3 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,14_2_00007FFE1024A0D3
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE11501883 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,14_2_00007FFE11501883
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE11EC5BF3 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,14_2_00007FFE11EC5BF3
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE126D5253 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,14_2_00007FFE126D5253
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE13222FE3 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,14_2_00007FFE13222FE3
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE1A455803 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,14_2_00007FFE1A455803
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE1171A0D3 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,24_2_00007FFE1171A0D3
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE11741883 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,24_2_00007FFE11741883
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE11775BF3 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,24_2_00007FFE11775BF3
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE11EC5253 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,24_2_00007FFE11EC5253
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE126D2FE3 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,24_2_00007FFE126D2FE3
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE13205803 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,24_2_00007FFE13205803

Networking

barindex
Source: global trafficTCP traffic: 45.8.98.78 ports 19063,0,1,3,6,9
Source: global trafficTCP traffic: 204.8.84.94 ports 20578,0,2,5,7,8
Source: global trafficTCP traffic: 68.148.96.106 ports 12385,1,2,3,5,8
Source: global trafficTCP traffic: 82.165.57.155 ports 27813,1,2,3,7,8
Source: global trafficTCP traffic: 24.177.113.51 ports 1,2,4,5,6,15624
Source: global trafficTCP traffic: 73.62.1.179 ports 17850,0,1,5,7,8
Source: global trafficTCP traffic: 186.28.6.171 ports 15230,0,1,2,3,5
Source: QTmGYKK6SL.exe, 00000001.00000003.1843557253.0000000004466000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://reseed2.i2p.net/,https://reseed.diva.exchange/,https://reseed-fr.i2pd.xyz/,https://reseed.memcpy.io/,https://reseed.onion.im/,https://i2pseed.creativecowpat.net:8443/,https://reseed.i2pgit.org/,https://banana.incognet.io/,https://reseed-pl.i2pd.xyz/,https://www2.mk16.de/,https://i2p.ghativega.in/,https://i2p.novg.net/
Source: QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003A2F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://reseed2.i2p.net/,https://reseed.diva.exchange/,https://reseed-fr.i2pd.xyz/,https://reseed.memcpy.io/,https://reseed.onion.im/,https://i2pseed.creativecowpat.net:8443/,https://reseed.i2pgit.org/,https://banana.incognet.io/,https://reseed-pl.i2pd.xyz/,https://www2.mk16.de/,https://i2p.ghativega.in/,https://i2p.novg.net/
Source: o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmpString found in binary or memory: https://reseed2.i2p.net/,https://reseed.diva.exchange/,https://reseed-fr.i2pd.xyz/,https://reseed.memcpy.io/,https://reseed.onion.im/,https://i2pseed.creativecowpat.net:8443/,https://reseed.i2pgit.org/,https://banana.incognet.io/,https://reseed-pl.i2pd.xyz/,https://www2.mk16.de/,https://i2p.ghativega.in/,https://i2p.novg.net/
Source: main.exeString found in binary or memory: https://reseed2.i2p.net/,https://reseed.diva.exchange/,https://reseed-fr.i2pd.xyz/,https://reseed.memcpy.io/,https://reseed.onion.im/,https://i2pseed.creativecowpat.net:8443/,https://reseed.i2pgit.org/,https://banana.incognet.io/,https://reseed-pl.i2pd.xyz/,ht
Source: main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://reseed2.i2p.net/,https://reseed.diva.exchange/,https://reseed-fr.i2pd.xyz/,https://reseed.memcpy.io/,https://reseed.onion.im/,https://i2pseed.creativecowpat.net:8443/,https://reseed.i2pgit.org/,https://banana.incognet.io/,https://reseed-pl.i2pd.xyz/,https://www2.mk16.de/,https://i2p.ghativega.in/,https://i2p.novg.net/
Source: main.exe, 0000000E.00000002.2481168941.000002BAD4B5D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://reseed2.i2p.net/,https://reseed.diva.exchange/,https://reseed-fr.i2pd.xyz/,https://reseed.memcpy.io/,https://reseed.onion.im/,https://i2pseed.creativecowpat.net:8443/,https://reseed.i2pgit.org/,https://banana.incognet.io/,https://reseed-pl.i2pd.xyz/,https://www2.mk16.de/,https://i2p.ghativega.in/,https://i2p.novg.net/
Source: main.exe, 0000000E.00000002.2482562172.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmpString found in binary or memory: https://reseed2.i2p.net/,https://reseed.diva.exchange/,https://reseed-fr.i2pd.xyz/,https://reseed.memcpy.io/,https://reseed.onion.im/,https://i2pseed.creativecowpat.net:8443/,https://reseed.i2pgit.org/,https://banana.incognet.io/,https://reseed-pl.i2pd.xyz/,https://www2.mk16.de/,https://i2p.ghativega.in/,https://i2p.novg.net/
Source: main.exeString found in binary or memory: https://reseed2.i2p.net/,https://reseed.diva.exchange/,https://reseed-fr.i2pd.xyz/,https://reseed.memcpy.io/,https://reseed.onion.im/,https://i2pseed.creativecowpat.net:8443/,https://reseed.i2pgit.org/,https://banana.incognet.io/,https://reseed-pl.i2pd.xyz/,ht
Source: main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmpString found in binary or memory: https://reseed2.i2p.net/,https://reseed.diva.exchange/,https://reseed-fr.i2pd.xyz/,https://reseed.memcpy.io/,https://reseed.onion.im/,https://i2pseed.creativecowpat.net:8443/,https://reseed.i2pgit.org/,https://banana.incognet.io/,https://reseed-pl.i2pd.xyz/,https://www2.mk16.de/,https://i2p.ghativega.in/,https://i2p.novg.net/
Source: main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://reseed2.i2p.net/,https://reseed.diva.exchange/,https://reseed-fr.i2pd.xyz/,https://reseed.memcpy.io/,https://reseed.onion.im/,https://i2pseed.creativecowpat.net:8443/,https://reseed.i2pgit.org/,https://banana.incognet.io/,https://reseed-pl.i2pd.xyz/,https://www2.mk16.de/,https://i2p.ghativega.in/,https://i2p.novg.net/
Source: update.pkg.3.drString found in binary or memory: https://reseed2.i2p.net/,https://reseed.diva.exchange/,https://reseed-fr.i2pd.xyz/,https://reseed.memcpy.io/,https://reseed.onion.im/,https://i2pseed.creativecowpat.net:8443/,https://reseed.i2pgit.org/,https://banana.incognet.io/,https://reseed-pl.i2pd.xyz/,https://www2.mk16.de/,https://i2p.ghativega.in/,https://i2p.novg.net/
Source: unknownNetwork traffic detected: IP country count 16
Source: global trafficTCP traffic: 192.168.2.4:49730 -> 91.92.250.213:1110
Source: global trafficTCP traffic: 192.168.2.4:63482 -> 119.13.124.67:29762
Source: global trafficTCP traffic: 192.168.2.4:63483 -> 91.224.234.189:50444
Source: global trafficTCP traffic: 192.168.2.4:63484 -> 74.80.57.188:24372
Source: global trafficTCP traffic: 192.168.2.4:63485 -> 45.8.98.78:19063
Source: global trafficTCP traffic: 192.168.2.4:63486 -> 67.166.47.100:15536
Source: global trafficTCP traffic: 192.168.2.4:63487 -> 5.64.137.68:11737
Source: global trafficTCP traffic: 192.168.2.4:63488 -> 186.28.6.171:15230
Source: global trafficTCP traffic: 192.168.2.4:63489 -> 99.252.52.199:17541
Source: global trafficTCP traffic: 192.168.2.4:63490 -> 204.8.84.94:20578
Source: global trafficTCP traffic: 192.168.2.4:63491 -> 68.148.96.106:12385
Source: global trafficTCP traffic: 192.168.2.4:63492 -> 24.177.113.51:15624
Source: global trafficTCP traffic: 192.168.2.4:63504 -> 184.185.247.130:9859
Source: global trafficTCP traffic: 192.168.2.4:63506 -> 91.149.237.69:26412
Source: global trafficTCP traffic: 192.168.2.4:63509 -> 81.6.45.56:33834
Source: global trafficTCP traffic: 192.168.2.4:63510 -> 73.62.1.179:17850
Source: global trafficTCP traffic: 192.168.2.4:63511 -> 70.18.38.5:28737
Source: global trafficTCP traffic: 192.168.2.4:63512 -> 82.165.57.155:27813
Source: global trafficTCP traffic: 192.168.2.4:63514 -> 73.38.186.219:20033
Source: global trafficUDP traffic: 192.168.2.4:9421 -> 45.89.55.34:19318
Source: global trafficUDP traffic: 192.168.2.4:9421 -> 216.9.179.60:25750
Source: global trafficUDP traffic: 192.168.2.4:9421 -> 86.5.235.24:18771
Source: global trafficUDP traffic: 192.168.2.4:9421 -> 51.15.242.96:18384
Source: global trafficUDP traffic: 192.168.2.4:9421 -> 79.228.26.155:18701
Source: global trafficUDP traffic: 192.168.2.4:9421 -> 220.240.88.104:20056
Source: global trafficUDP traffic: 192.168.2.4:9421 -> 46.151.24.133:21987
Source: global trafficUDP traffic: 192.168.2.4:9421 -> 91.194.11.174:19248
Source: global trafficUDP traffic: 192.168.2.4:9421 -> 139.59.159.178:44567
Source: global trafficUDP traffic: 192.168.2.4:9421 -> 77.238.224.125:26317
Source: global trafficUDP traffic: 192.168.2.4:9421 -> 194.87.219.156:19047
Source: global trafficUDP traffic: 192.168.2.4:9421 -> 93.95.229.134:25799
Source: global trafficUDP traffic: 192.168.2.4:9421 -> 217.76.54.24:22773
Source: global trafficUDP traffic: 192.168.2.4:9421 -> 2.177.225.52:16459
Source: global trafficUDP traffic: 192.168.2.4:10253 -> 173.230.128.232:26930
Source: global trafficUDP traffic: 192.168.2.4:10253 -> 23.241.223.162:23154
Source: global trafficUDP traffic: 192.168.2.4:10253 -> 94.103.188.190:28803
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: unknownTCP traffic detected without corresponding DNS query: 91.92.250.213
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE10245F3A recv,WSAGetLastError,14_2_00007FFE10245F3A
Source: QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, main.exe, 0000000E.00000003.1915940712.000002BAD4B91000.00000004.00000020.00020000.00000000.sdmp, main.exe, 0000000E.00000003.1916098850.000002BAD4B97000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000018.00000003.2586491287.00000156D4C77000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000018.00000003.2586378729.00000156D4C71000.00000004.00000020.00020000.00000000.sdmp, xuutMjJX.14.dr, update.pkg.3.drString found in binary or memory: http://127.0.0.1:8118
Source: main.exe, 0000000E.00000003.1915940712.000002BAD4B91000.00000004.00000020.00020000.00000000.sdmp, main.exe, 0000000E.00000003.1916098850.000002BAD4B97000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://127.0.0.1:8118C
Source: QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, xuutMjJX.14.dr, update.pkg.3.drString found in binary or memory: http://identiguy.i2p/hosts.txt
Source: update.pkg.3.drString found in binary or memory: http://reg.i2p/hosts.txt
Source: main.exe, 0000000E.00000002.2481168941.000002BAD4B5D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://reg.i2p/hosts.txt8x
Source: main.exe, 00000018.00000002.2933918140.00000156D4C9E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://reg.i2p/hosts.txtV
Source: main.exe, 0000000E.00000002.2481168941.000002BAD4B5D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://reg.i2p/hosts.txtXn
Source: QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, xuutMjJX.14.dr, update.pkg.3.drString found in binary or memory: http://rus.i2p/hosts.txt
Source: update.pkg.3.drString found in binary or memory: http://shx5vqsw7usdaunyzr2qmes2fq37oumybpudrd4jjj4e4vk4uusa.b32.i2p/hosts.txt
Source: main.exe, 0000000E.00000002.2481168941.000002BAD4B5D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://shx5vqsw7usdaunyzr2qmes2fq37oumybpudrd4jjj4e4vk4uusa.b32.i2p/hosts.txtf
Source: main.exe, 0000000E.00000002.2481168941.000002BAD4B5D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://shx5vqsw7usdaunyzr2qmes2fq37oumybpudrd4jjj4e4vk4uusa.b32.i2p/hosts.txtxyz/
Source: QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, xuutMjJX.14.dr, update.pkg.3.drString found in binary or memory: http://stats.i2p/cgi-bin/newhosts.txt
Source: Amcache.hve.22.drString found in binary or memory: http://upx.sf.net
Source: main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drString found in binary or memory: https://banana.incognet.io/
Source: main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drString found in binary or memory: https://i2p.ghativega.in/
Source: QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, xuutMjJX.14.dr, update.pkg.3.drString found in binary or memory: https://i2p.mooo.com/netDb/
Source: main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drString found in binary or memory: https://i2p.novg.net/
Source: QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, xuutMjJX.14.dr, update.pkg.3.drString found in binary or memory: https://i2pd.readthedocs.io/en/latest/user-guide/configuration/
Source: main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drString found in binary or memory: https://i2pseed.creativecowpat.net:8443/
Source: QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, xuutMjJX.14.dr, update.pkg.3.drString found in binary or memory: https://legit-website.com/i2pseeds.su3
Source: QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, xuutMjJX.14.dr, update.pkg.3.drString found in binary or memory: https://netdb.i2p2.no/
Source: main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drString found in binary or memory: https://reseed-fr.i2pd.xyz/
Source: main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drString found in binary or memory: https://reseed-pl.i2pd.xyz/
Source: main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drString found in binary or memory: https://reseed.diva.exchange/
Source: QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, xuutMjJX.14.dr, update.pkg.3.drString found in binary or memory: https://reseed.i2p-projekt.de/
Source: main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drString found in binary or memory: https://reseed.i2pgit.org/
Source: main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drString found in binary or memory: https://reseed.memcpy.io/
Source: main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drString found in binary or memory: https://reseed.onion.im/
Source: main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drString found in binary or memory: https://reseed2.i2p.net/
Source: QTmGYKK6SL.exe, 00000001.00000003.1843557253.0000000004466000.00000004.00000020.00020000.00000000.sdmp, QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003A2F000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, main.exe, 0000000E.00000002.2481168941.000002BAD4B5D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 0000000E.00000002.2482562172.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drString found in binary or memory: https://www2.mk16.de/
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE1150F0FE strlen,strcat,strlen,strlen,strlen,strcat,strlen,strlen,strlen,strcat,LogonUserA,GetLastError,CreateProcessAsUserA,GetLastError,CloseHandle,CreateProcessA,GetLastError,14_2_00007FFE1150F0FE
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile deleted: C:\Windows\Temp\gJinHgIGJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeCode function: 0_2_033A7B920_2_033A7B92
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeCode function: 0_2_033B6BCE0_2_033B6BCE
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeCode function: 0_2_033A49620_2_033A4962
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeCode function: 0_2_033AC95A0_2_033AC95A
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeCode function: 0_2_033A59560_2_033A5956
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeCode function: 0_2_033A98AA0_2_033A98AA
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeCode function: 0_2_033B4F9A0_2_033B4F9A
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeCode function: 0_2_033A5EE60_2_033A5EE6
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeCode function: 0_2_033BCCD20_2_033BCCD2
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FF7BACDC49014_2_00007FF7BACDC490
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE102508D014_2_00007FFE102508D0
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE1151252014_2_00007FFE11512520
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE11ECEFB014_2_00007FFE11ECEFB0
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE126DEAF014_2_00007FFE126DEAF0
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE1322904C14_2_00007FFE1322904C
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE13228F5E14_2_00007FFE13228F5E
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE13228E1614_2_00007FFE13228E16
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE132304B014_2_00007FFE132304B0
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE13228D2B14_2_00007FFE13228D2B
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE1A45CB6014_2_00007FFE1A45CB60
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE117208D024_2_00007FFE117208D0
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE1175252024_2_00007FFE11752520
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE1177EFB024_2_00007FFE1177EFB0
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE11ECEAF024_2_00007FFE11ECEAF0
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE126D904C24_2_00007FFE126D904C
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE126D8F5E24_2_00007FFE126D8F5E
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE126E04B024_2_00007FFE126E04B0
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE126D8D2B24_2_00007FFE126D8D2B
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE126D8E1624_2_00007FFE126D8E16
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE1320CB6024_2_00007FFE1320CB60
Source: Joe Sandbox ViewDropped File: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\cnccli.dll 9BC6EDD286F4DCD83E57B541BC99038F7E902DE943A6FD528BA485DF1187FFA8
Source: Joe Sandbox ViewDropped File: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\dwlmgr.dll 1DA31243257B0EBC79BA57CA98E6A3A1996CC4E2641E96098561CDCB1FA3EE46
Source: Joe Sandbox ViewDropped File: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\evtsrv.dll 2B5DC45E89700D4B991ADDED1AA097641D60932B7BBE2C12FC8536B9D46F15A6
Source: Joe Sandbox ViewDropped File: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\libi2p.dll 154C3DCA584BB1F78C7AE7688D70998F2B62BED8884267E3FCF150BFEFE2C9D8
Source: C:\Windows\System32\icacls.exeProcess token adjusted: SecurityJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: String function: 00007FFE117140D2 appears 473 times
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: String function: 00007FFE132277A2 appears 388 times
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: String function: 00007FFE1150C852 appears 526 times
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: String function: 00007FFE11EC9DC2 appears 405 times
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: String function: 00007FF7BACD2EF2 appears 314 times
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: String function: 00007FFE102440D2 appears 473 times
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: String function: 00007FFE11779DC2 appears 405 times
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: String function: 00007FFE1A4520C2 appears 356 times
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: String function: 00007FFE132020C2 appears 356 times
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: String function: 00007FFE126D1352 appears 398 times
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: String function: 00007FFE11EC1352 appears 398 times
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: String function: 00007FFE126D77A2 appears 388 times
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: String function: 00007FFE1174C852 appears 526 times
Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -pss -s 432 -p 3164 -ip 3164
Source: prgmgr.dll.14.drStatic PE information: Number of sections : 11 > 10
Source: TMCsWjkD.14.drStatic PE information: Number of sections : 11 > 10
Source: libi2p.dll.14.drStatic PE information: Number of sections : 11 > 10
Source: WQZiUkLe.14.drStatic PE information: Number of sections : 11 > 10
Source: 78a0MAty.14.drStatic PE information: Number of sections : 11 > 10
Source: termsrv32.dll.14.drStatic PE information: Number of sections : 11 > 10
Source: rJnwiXXd.14.drStatic PE information: Number of sections : 11 > 10
Source: samctl.dll.14.drStatic PE information: Number of sections : 11 > 10
Source: to1wcXFh.14.drStatic PE information: Number of sections : 11 > 10
Source: rdpctl.dll.14.drStatic PE information: Number of sections : 11 > 10
Source: QTmGYKK6SL.exeStatic PE information: Number of sections : 11 > 10
Source: gJinHgIG.14.drStatic PE information: Number of sections : 11 > 10
Source: M3Cw7G9m.14.drStatic PE information: Number of sections : 11 > 10
Source: dwlmgr.dll.14.drStatic PE information: Number of sections : 11 > 10
Source: evtsrv.dll.14.drStatic PE information: Number of sections : 11 > 10
Source: cnccli.dll.14.drStatic PE information: Number of sections : 11 > 10
Source: ViiRS0bs.14.drStatic PE information: Number of sections : 11 > 10
Source: QTmGYKK6SL.exe, 00000000.00000002.1702392786.0000000002C63000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenameCOMCTL32.DLL.MUIj% vs QTmGYKK6SL.exe
Source: QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamerfxvmt.dllj% vs QTmGYKK6SL.exe
Source: QTmGYKK6SL.exe, 00000001.00000002.2933702042.0000000002CE3000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenameCOMCTL32.DLL.MUIj% vs QTmGYKK6SL.exe
Source: classification engineClassification label: mal100.troj.evad.winEXE@32/51@0/37
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FF7BACD2029 FindResourceA,LoadResource,GetLastError,GetLastError,GetLastError,GetLastError,14_2_00007FF7BACD2029
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FF7BACD1DBC strcmp,strcmp,StartServiceCtrlDispatcherA,_read,GetLastError,14_2_00007FF7BACD1DBC
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FF7BACD1DBC strcmp,strcmp,StartServiceCtrlDispatcherA,_read,GetLastError,14_2_00007FF7BACD1DBC
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeFile created: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}Jump to behavior
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6016:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1620:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2088:120:WilError_03
Source: C:\Windows\System32\WerFault.exeMutant created: \BaseNamedObjects\Local\SM0:1804:120:WilError_03
Source: C:\Windows\System32\WerFault.exeMutant created: \BaseNamedObjects\Local\WERReportingForProcess3164
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5956:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3052:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6312:120:WilError_03
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeFile created: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeJump to behavior
Source: QTmGYKK6SL.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeKey opened: HKEY_USERS.DEFAULT\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeKey opened: HKEY_USERS.DEFAULT\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile read: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\config.iniJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: QTmGYKK6SL.exeVirustotal: Detection: 25%
Source: QTmGYKK6SL.exeReversingLabs: Detection: 23%
Source: main.exeString found in binary or memory: C:/msys64/mingw64/include/boost/asio/ip/impl/address.ipp
Source: main.exeString found in binary or memory: C:/msys64/mingw64/include/boost/asio/ip/impl/address_v4.ipp
Source: main.exeString found in binary or memory: C:/msys64/mingw64/include/boost/asio/ip/impl/address_v6.ipp
Source: main.exeString found in binary or memory: C:/msys64/mingw64/include/boost/asio/ip/impl/address.ipp
Source: main.exeString found in binary or memory: C:/msys64/mingw64/include/boost/asio/ip/impl/address_v4.ipp
Source: main.exeString found in binary or memory: C:/msys64/mingw64/include/boost/asio/ip/impl/address_v6.ipp
Source: QTmGYKK6SL.exeString found in binary or memory: NATS-SEFI-ADD
Source: QTmGYKK6SL.exeString found in binary or memory: NATS-DANO-ADD
Source: QTmGYKK6SL.exeString found in binary or memory: JIS_C6229-1984-b-add
Source: QTmGYKK6SL.exeString found in binary or memory: jp-ocr-b-add
Source: QTmGYKK6SL.exeString found in binary or memory: JIS_C6229-1984-hand-add
Source: QTmGYKK6SL.exeString found in binary or memory: jp-ocr-hand-add
Source: QTmGYKK6SL.exeString found in binary or memory: ISO_6937-2-add
Source: unknownProcess created: C:\Users\user\Desktop\QTmGYKK6SL.exe "C:\Users\user\Desktop\QTmGYKK6SL.exe"
Source: unknownProcess created: C:\Users\user\Desktop\QTmGYKK6SL.exe C:\Users\user\Desktop\QTmGYKK6SL.exe
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeProcess created: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exe C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exe
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeProcess created: C:\Windows\System32\sc.exe sc.exe stop RDP-Controller
Source: C:\Windows\System32\sc.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeProcess created: C:\Windows\System32\sc.exe sc.exe create RDP-Controller binpath= C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe type= own start= auto error= ignore
Source: C:\Windows\System32\sc.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeProcess created: C:\Windows\System32\sc.exe sc.exe failure RDP-Controller reset= 1 actions= restart/10000
Source: C:\Windows\System32\sc.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeProcess created: C:\Windows\System32\sc.exe sc.exe start RDP-Controller
Source: C:\Windows\System32\sc.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknownProcess created: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeProcess created: C:\Windows\System32\icacls.exe icacls.exe C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\ /setowner *S-1-5-18
Source: C:\Windows\System32\icacls.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeProcess created: C:\Windows\System32\icacls.exe icacls.exe C:\Users\Public /restore C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\ZsL2hKzmRChz.acl
Source: C:\Windows\System32\icacls.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k LocalService -p -s LicenseManager
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k WerSvcGroup
Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -pss -s 432 -p 3164 -ip 3164
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 3164 -s 1156
Source: unknownProcess created: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeProcess created: C:\Users\user\Desktop\QTmGYKK6SL.exe C:\Users\user\Desktop\QTmGYKK6SL.exeJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeProcess created: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exe C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeJump to behavior
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeProcess created: C:\Windows\System32\sc.exe sc.exe stop RDP-ControllerJump to behavior
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeProcess created: C:\Windows\System32\sc.exe sc.exe create RDP-Controller binpath= C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe type= own start= auto error= ignoreJump to behavior
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeProcess created: C:\Windows\System32\sc.exe sc.exe failure RDP-Controller reset= 1 actions= restart/10000Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeProcess created: C:\Windows\System32\sc.exe sc.exe start RDP-ControllerJump to behavior
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeProcess created: C:\Windows\System32\icacls.exe icacls.exe C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\ /setowner *S-1-5-18Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeProcess created: C:\Windows\System32\icacls.exe icacls.exe C:\Users\Public /restore C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\ZsL2hKzmRChz.aclJump to behavior
Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -pss -s 432 -p 3164 -ip 3164Jump to behavior
Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 3164 -s 1156Jump to behavior
Source: C:\Windows\System32\WerFault.exeProcess created: unknown unknownJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: winmm.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: d3d9.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: wtsapi32.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: winsta.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: winmm.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: d3d9.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: wtsapi32.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: winsta.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: wsock32.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: samcli.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: libi2p.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: wsock32.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: samlib.dllJump to behavior
Source: C:\Windows\System32\icacls.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\icacls.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: licensemanagersvc.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: licensemanager.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: clipc.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: wersvc.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: windowsperformancerecordercontrol.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: weretw.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: xmllite.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: wer.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: faultrep.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: dbghelp.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: dbgcore.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: wer.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: wsock32.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: samcli.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: libi2p.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: wsock32.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeSection loaded: samlib.dllJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile written: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\termsrv32.iniJump to behavior
Source: QTmGYKK6SL.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
Source: QTmGYKK6SL.exeStatic file information: File size 12016128 > 1048576
Source: QTmGYKK6SL.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x8bc200
Source: QTmGYKK6SL.exeStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0x10e400
Source: Binary string: RfxVmt.pdb source: QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, main.exe, 0000000E.00000003.1913857527.000002BAD3A5A000.00000004.00000020.00020000.00000000.sdmp, JcfQdL0z.14.dr
Source: Binary string: RfxVmt.pdbGCTL source: QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, main.exe, 0000000E.00000003.1913857527.000002BAD3A5A000.00000004.00000020.00020000.00000000.sdmp, JcfQdL0z.14.dr

Data Obfuscation

barindex
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeUnpacked PE file: 0.2.QTmGYKK6SL.exe.3420000.2.unpack
Source: rfxvmt.dll.14.drStatic PE information: 0xE004CD23 [Sat Feb 5 03:04:03 2089 UTC]
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FF7BACDDECE GetModuleHandleW,GetProcAddress,GetProcAddress,LoadLibraryW,GetProcAddress,14_2_00007FF7BACDDECE
Source: QTmGYKK6SL.exeStatic PE information: section name: .didata
Source: o0c2ddmlg7qrbu2xkviy.exe.1.drStatic PE information: section name: .xdata
Source: main.exe.3.drStatic PE information: section name: .xdata
Source: libi2p.dll.14.drStatic PE information: section name: .xdata
Source: evtsrv.dll.14.drStatic PE information: section name: .xdata
Source: cnccli.dll.14.drStatic PE information: section name: .xdata
Source: termsrv32.dll.14.drStatic PE information: section name: .xdata
Source: rdpctl.dll.14.drStatic PE information: section name: .xdata
Source: samctl.dll.14.drStatic PE information: section name: .xdata
Source: prgmgr.dll.14.drStatic PE information: section name: .xdata
Source: dwlmgr.dll.14.drStatic PE information: section name: .xdata
Source: to1wcXFh.14.drStatic PE information: section name: .xdata
Source: ViiRS0bs.14.drStatic PE information: section name: .xdata
Source: WQZiUkLe.14.drStatic PE information: section name: .xdata
Source: gJinHgIG.14.drStatic PE information: section name: .xdata
Source: TMCsWjkD.14.drStatic PE information: section name: .xdata
Source: rJnwiXXd.14.drStatic PE information: section name: .xdata
Source: M3Cw7G9m.14.drStatic PE information: section name: .xdata
Source: 78a0MAty.14.drStatic PE information: section name: .xdata
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeCode function: 0_2_033A6575 push esi; ret 0_2_033A6577
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE115179B3 push qword ptr [00007FFE47517884h]; retf 14_2_00007FFE115179B9
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE115179BB push qword ptr [00007FFE4751788Ch]; retf 14_2_00007FFE115179C1
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE115179FF push qword ptr [00007FFE475178D0h]; retf 14_2_00007FFE11517A05
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE11517A07 push qword ptr [00007FFE475178D8h]; retf 14_2_00007FFE11517A0D
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE11517A0F push qword ptr [00007FFE475178E0h]; retf 14_2_00007FFE11517A15
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE11517A17 push qword ptr [00007FFE185178E8h]; retf 14_2_00007FFE11517A1D
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE115179E7 push qword ptr [00007FFE475178B8h]; retf 14_2_00007FFE115179ED
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE115179EF push qword ptr [00007FFE475178C0h]; retf 14_2_00007FFE115179F5
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE115179F7 push qword ptr [00007FFE475178C8h]; retf 14_2_00007FFE115179FD
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE115179C3 push qword ptr [00007FFE47517894h]; retf 14_2_00007FFE115179C9
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE115179CB push qword ptr [00007FFE4751789Ch]; retf 14_2_00007FFE115179D1
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE115179D3 push qword ptr [00007FFE475178A4h]; retf 14_2_00007FFE115179D9
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE115172B8 push rsp; ret 14_2_00007FFE115172B9
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE115172BC push rsp; ret 14_2_00007FFE115172BD
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE1151726F push qword ptr [rsi]; ret 14_2_00007FFE11517275
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE1151727C push rsp; ret 14_2_00007FFE1151727D
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE115172E0 push rsp; ret 14_2_00007FFE115172E1
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE115172E4 push rsp; ret 14_2_00007FFE115172E5
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE115172E8 push rsp; ret 14_2_00007FFE115172E9
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE115172C4 push rsp; ret 14_2_00007FFE115172C5
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE115172CC push rsp; ret 14_2_00007FFE115172CD
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE115172D0 push rsp; ret 14_2_00007FFE115172D1
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE115172D4 push rsp; ret 14_2_00007FFE115172D5
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE115172D8 push rsp; ret 14_2_00007FFE115172D9
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE115172DC push rsp; ret 14_2_00007FFE115172DD
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE132315D7 push rsp; retf 0000h14_2_00007FFE132315D8
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE117579C3 push qword ptr [00007FFE47757894h]; retf 24_2_00007FFE117579C9
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE117579CB push qword ptr [00007FFE4775789Ch]; retf 24_2_00007FFE117579D1
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE117579D3 push qword ptr [00007FFE477578A4h]; retf 24_2_00007FFE117579D9
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE117579E7 push qword ptr [00007FFE477578B8h]; retf 24_2_00007FFE117579ED
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE1024875B strlen,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,strlen,strlen,GetProcessHeap,HeapAlloc,strlen,NetUserAdd,CreateProfile,14_2_00007FFE1024875B
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\ViiRS0bsJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\evtsrv.dllJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\gJinHgIGJump to dropped file
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeFile created: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\to1wcXFhJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\78a0MAtyJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\prgmgr.dllJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\rdpctl.dllJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\termsrv32.dllJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\WQZiUkLeJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\rfxvmt.dllJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\samctl.dllJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\cnccli.dllJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\rJnwiXXdJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\M3Cw7G9mJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeFile created: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\dwlmgr.dllJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\libi2p.dllJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\JcfQdL0zJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\TMCsWjkDJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\ViiRS0bsJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\gJinHgIGJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\to1wcXFhJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\78a0MAtyJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\WQZiUkLeJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\rJnwiXXdJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\M3Cw7G9mJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\JcfQdL0zJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\TMCsWjkDJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\to1wcXFhJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\ViiRS0bsJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\WQZiUkLeJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\gJinHgIGJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\JcfQdL0zJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\TMCsWjkDJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\rJnwiXXdJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\M3Cw7G9mJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeFile created: C:\Windows\Temp\78a0MAtyJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeFile created: C:\Users\user\AppData\Local\Temp\installer.logJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FF7BACD1DBC strcmp,strcmp,StartServiceCtrlDispatcherA,_read,GetLastError,14_2_00007FF7BACD1DBC
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeProcess created: C:\Windows\System32\sc.exe sc.exe stop RDP-Controller

Hooking and other Techniques for Hiding and Protection

barindex
Source: QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
Source: QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserListsam_user_test_special_accountsam_user_set_special_account(is_set == 0) || (is_set == 1)SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts[E] (%s) -> Failed(s_sid=%s,is_set=%d,err=%08x)
Source: o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmpString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
Source: o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmpString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserListsam_user_test_special_accountsam_user_set_special_account(is_set == 0) || (is_set == 1)SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts[E] (%s) -> Failed(s_sid=%s,is_set=%d,err=%08x)
Source: main.exeString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
Source: main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
Source: main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserListsam_user_test_special_accountsam_user_set_special_account(is_set == 0) || (is_set == 1)SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts[E] (%s) -> Failed(s_sid=%s,is_set=%d,err=%08x)
Source: main.exe, 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
Source: main.exe, 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserListsam_user_test_special_accountsam_user_set_special_account(is_set == 0) || (is_set == 1)SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts[E] (%s) -> Failed(s_sid=%s,is_set=%d,err=%08x)
Source: main.exe, 0000000E.00000003.1914709125.000002BAD3A5A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
Source: main.exe, 0000000E.00000003.1914709125.000002BAD3A5A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserListsam_user_test_special_accountsam_user_set_special_account(is_set == 0) || (is_set == 1)SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts[E] (%s) -> Failed(s_sid=%s,is_set=%d,err=%08x)
Source: main.exeString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
Source: main.exe, 00000018.00000002.2935871980.00007FFE11724000.00000002.00000001.01000000.0000000E.sdmpString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
Source: main.exe, 00000018.00000002.2935871980.00007FFE11724000.00000002.00000001.01000000.0000000E.sdmpString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserListsam_user_test_special_accountsam_user_set_special_account(is_set == 0) || (is_set == 1)SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts[E] (%s) -> Failed(s_sid=%s,is_set=%d,err=%08x)
Source: samctl.dll.14.drString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
Source: samctl.dll.14.drString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserListsam_user_test_special_accountsam_user_set_special_account(is_set == 0) || (is_set == 1)SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts[E] (%s) -> Failed(s_sid=%s,is_set=%d,err=%08x)
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeProcess created: C:\Windows\System32\icacls.exe icacls.exe C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\ /setowner *S-1-5-18
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: GetLastError,EnumServicesStatusExA,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,strlen,strlen,GetProcessHeap,HeapAlloc,strcpy,14_2_00007FFE11507694
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: GetLastError,EnumServicesStatusExA,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,strlen,strlen,GetProcessHeap,HeapAlloc,strcpy,24_2_00007FFE11747694
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: GetProcessHeap,HeapAlloc,GetAdaptersInfo,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetAdaptersInfo,14_2_00007FFE102460C8
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: GetProcessHeap,HeapAlloc,GetAdaptersInfo,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetAdaptersInfo,14_2_00007FFE1150B648
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: GetProcessHeap,HeapAlloc,GetAdaptersInfo,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetAdaptersInfo,14_2_00007FFE11EC2738
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: GetProcessHeap,HeapAlloc,GetAdaptersInfo,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetAdaptersInfo,14_2_00007FFE126D4978
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: GetProcessHeap,HeapAlloc,GetAdaptersInfo,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetAdaptersInfo,14_2_00007FFE13221D98
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: GetProcessHeap,HeapAlloc,GetAdaptersInfo,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetAdaptersInfo,14_2_00007FFE1A4530A8
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: GetProcessHeap,HeapAlloc,GetAdaptersInfo,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetAdaptersInfo,24_2_00007FFE117160C8
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: GetProcessHeap,HeapAlloc,GetAdaptersInfo,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetAdaptersInfo,24_2_00007FFE1174B648
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: GetProcessHeap,HeapAlloc,GetAdaptersInfo,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetAdaptersInfo,24_2_00007FFE11772738
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: GetProcessHeap,HeapAlloc,GetAdaptersInfo,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetAdaptersInfo,24_2_00007FFE11EC4978
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: GetProcessHeap,HeapAlloc,GetAdaptersInfo,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetAdaptersInfo,24_2_00007FFE126D1D98
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: GetProcessHeap,HeapAlloc,GetAdaptersInfo,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetAdaptersInfo,24_2_00007FFE132030A8
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeDropped PE file which has not been started: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\evtsrv.dllJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeDropped PE file which has not been started: C:\Windows\Temp\ViiRS0bsJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeDropped PE file which has not been started: C:\Windows\Temp\gJinHgIGJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeDropped PE file which has not been started: C:\Windows\Temp\to1wcXFhJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeDropped PE file which has not been started: C:\Windows\Temp\78a0MAtyJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeDropped PE file which has not been started: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\prgmgr.dllJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeDropped PE file which has not been started: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\rdpctl.dllJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeDropped PE file which has not been started: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\termsrv32.dllJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeDropped PE file which has not been started: C:\Windows\Temp\WQZiUkLeJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeDropped PE file which has not been started: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\rfxvmt.dllJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeDropped PE file which has not been started: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\samctl.dllJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeDropped PE file which has not been started: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\cnccli.dllJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeDropped PE file which has not been started: C:\Windows\Temp\rJnwiXXdJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeDropped PE file which has not been started: C:\Windows\Temp\M3Cw7G9mJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeDropped PE file which has not been started: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\dwlmgr.dllJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeDropped PE file which has not been started: C:\Windows\Temp\JcfQdL0zJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeDropped PE file which has not been started: C:\Windows\Temp\TMCsWjkDJump to dropped file
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeEvasive API call chain: GetSystemTimeAsFileTime,DecisionNodesgraph_14-60416
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeAPI coverage: 9.6 %
Source: C:\Users\user\Desktop\QTmGYKK6SL.exe TID: 3288Thread sleep count: 195 > 30Jump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exe TID: 3288Thread sleep time: -11700000s >= -30000sJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe TID: 6808Thread sleep count: 63 > 30Jump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe TID: 6808Thread sleep time: -31500s >= -30000sJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe TID: 5756Thread sleep count: 63 > 30Jump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe TID: 5756Thread sleep time: -31500s >= -30000sJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe TID: 4136Thread sleep count: 56 > 30Jump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe TID: 8Thread sleep time: -30000s >= -30000sJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe TID: 5644Thread sleep count: 32 > 30Jump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe TID: 5448Thread sleep count: 31 > 30Jump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070809Jump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04070809Jump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070809Jump to behavior
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04070809Jump to behavior
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeLast function: Thread delayed
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeLast function: Thread delayed
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeLast function: Thread delayed
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FF7BACD47F3 FindNextFileA,_mbscpy,FindFirstFileA,GetLastError,GetLastError,FindClose,14_2_00007FF7BACD47F3
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE1024A0D3 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,14_2_00007FFE1024A0D3
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE11501883 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,14_2_00007FFE11501883
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE11EC5BF3 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,14_2_00007FFE11EC5BF3
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE126D5253 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,14_2_00007FFE126D5253
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE13222FE3 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,14_2_00007FFE13222FE3
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE1A455803 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,14_2_00007FFE1A455803
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE1171A0D3 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,24_2_00007FFE1171A0D3
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE11741883 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,24_2_00007FFE11741883
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE11775BF3 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,24_2_00007FFE11775BF3
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE11EC5253 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,24_2_00007FFE11EC5253
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE126D2FE3 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,24_2_00007FFE126D2FE3
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE13205803 FindNextFileA,strcpy,FindFirstFileA,GetLastError,GetLastError,FindClose,24_2_00007FFE13205803
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeThread delayed: delay time: 60000Jump to behavior
Source: Amcache.hve.22.drBinary or memory string: VMware
Source: Amcache.hve.22.drBinary or memory string: VMware Virtual USB Mouse
Source: Amcache.hve.22.drBinary or memory string: vmci.syshbin
Source: Amcache.hve.22.drBinary or memory string: VMware, Inc.
Source: Amcache.hve.22.drBinary or memory string: VMware20,1hbin@
Source: Amcache.hve.22.drBinary or memory string: c:\windows\system32\driverstore\filerepository\vmci.inf_amd64_68ed49469341f563
Source: Amcache.hve.22.drBinary or memory string: Ascsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000
Source: Amcache.hve.22.drBinary or memory string: .Z$c:/windows/system32/drivers/vmci.sys
Source: Amcache.hve.22.drBinary or memory string: :scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000
Source: Amcache.hve.22.drBinary or memory string: pci\ven_15ad&dev_0740&subsys_074015ad,pci\ven_15ad&dev_0740,root\vmwvmcihostdev
Source: Amcache.hve.22.drBinary or memory string: c:/windows/system32/drivers/vmci.sys
Source: Amcache.hve.22.drBinary or memory string: scsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000
Source: QTmGYKK6SL.exe, 00000001.00000002.2933221271.00000000010E8000.00000004.00000020.00020000.00000000.sdmp, main.exe, 0000000E.00000003.1915621130.000002BAD3A61000.00000004.00000020.00020000.00000000.sdmp, main.exe, 0000000E.00000002.2480258672.000002BAD3A53000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: main.exe, 00000018.00000002.2933664807.00000156D4527000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllGG
Source: o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000002.1970305392.0000023071658000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllMM
Source: Amcache.hve.22.drBinary or memory string: vmci.sys
Source: Amcache.hve.22.drBinary or memory string: VMware-56 4d 43 71 48 15 3d ed-ae e6 c7 5a ec d9 3b f0
Source: Amcache.hve.22.drBinary or memory string: vmci.syshbin`
Source: Amcache.hve.22.drBinary or memory string: \driver\vmci,\driver\pci
Source: Amcache.hve.22.drBinary or memory string: scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000
Source: Amcache.hve.22.drBinary or memory string: VMware20,1
Source: Amcache.hve.22.drBinary or memory string: Microsoft Hyper-V Generation Counter
Source: Amcache.hve.22.drBinary or memory string: NECVMWar VMware SATA CD00
Source: Amcache.hve.22.drBinary or memory string: VMware Virtual disk SCSI Disk Device
Source: Amcache.hve.22.drBinary or memory string: scsi\cdromnecvmwarvmware_sata_cd001.00,scsi\cdromnecvmwarvmware_sata_cd00,scsi\cdromnecvmwar,scsi\necvmwarvmware_sata_cd001,necvmwarvmware_sata_cd001,gencdrom
Source: Amcache.hve.22.drBinary or memory string: scsi\diskvmware__virtual_disk____2.0_,scsi\diskvmware__virtual_disk____,scsi\diskvmware__,scsi\vmware__virtual_disk____2,vmware__virtual_disk____2,gendisk
Source: Amcache.hve.22.drBinary or memory string: Microsoft Hyper-V Virtualization Infrastructure Driver
Source: Amcache.hve.22.drBinary or memory string: VMware PCI VMCI Bus Device
Source: Amcache.hve.22.drBinary or memory string: VMware VMCI Bus Device
Source: Amcache.hve.22.drBinary or memory string: VMware Virtual RAM
Source: Amcache.hve.22.drBinary or memory string: BiosVendor:VMware, Inc.,BiosVersion:VMW201.00V.20829224.B64.2211211842,BiosReleaseDate:11/21/2022,BiosMajorRelease:0xff,BiosMinorRelease:0xff,SystemManufacturer:VMware, Inc.,SystemProduct:VMware20,1,SystemFamily:,SystemSKUNumber:,BaseboardManufacturer:,BaseboardProduct:,BaseboardVersion:,EnclosureType:0x1
Source: Amcache.hve.22.drBinary or memory string: vmci.inf_amd64_68ed49469341f563
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeAPI call chain: ExitProcess graph end nodegraph_14-57593
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeProcess queried: DebugPortJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeProcess queried: DebugPortJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FF7BACDDECE GetModuleHandleW,GetProcAddress,GetProcAddress,LoadLibraryW,GetProcAddress,14_2_00007FF7BACDDECE
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FF7BACD3452 GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,strncpy,strncpy,strncpy,14_2_00007FF7BACD3452
Source: C:\Users\user\Desktop\QTmGYKK6SL.exeProcess token adjusted: DebugJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FF7BACD1131 Sleep,Sleep,_amsg_exit,_initterm,_initterm,SetUnhandledExceptionFilter,_malloc_dbg,strlen,_malloc_dbg,_cexit,14_2_00007FF7BACD1131
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE1150F0FE strlen,strcat,strlen,strlen,strlen,strcat,strlen,strlen,strlen,strcat,LogonUserA,GetLastError,CreateProcessAsUserA,GetLastError,CloseHandle,CreateProcessA,GetLastError,14_2_00007FFE1150F0FE
Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -pss -s 432 -p 3164 -ip 3164Jump to behavior
Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 3164 -s 1156Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FF7BACD8235 GetSystemTimeAsFileTime,14_2_00007FF7BACD8235
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE10246DF3 LocalAlloc,wcsncpy,LookupAccountNameW,GetLastError,GetLastError,LocalAlloc,LookupAccountNameW,LocalFree,GetLastError,ConvertSidToStringSidA,GetLastError,wcslen,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,NetApiBufferFree,NetUserEnum,GetProcessHeap,HeapAlloc,memcpy,GetProcessHeap,HeapFree,14_2_00007FFE10246DF3
Source: C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
Source: Amcache.hve.22.drBinary or memory string: c:\programdata\microsoft\windows defender\platform\4.18.23080.2006-0\msmpeng.exe
Source: Amcache.hve.22.drBinary or memory string: msmpeng.exe
Source: Amcache.hve.22.drBinary or memory string: c:\program files\windows defender\msmpeng.exe
Source: Amcache.hve.22.drBinary or memory string: MsMpEng.exe
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE1024592A socket,htonl,htons,bind,listen,WSAGetLastError,WSAGetLastError,WSAGetLastError,14_2_00007FFE1024592A
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE1150AEAA socket,htonl,htons,bind,listen,WSAGetLastError,WSAGetLastError,WSAGetLastError,14_2_00007FFE1150AEAA
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE11EC1F9A socket,htonl,htons,bind,listen,WSAGetLastError,WSAGetLastError,WSAGetLastError,14_2_00007FFE11EC1F9A
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE126D41DA socket,htonl,htons,bind,listen,WSAGetLastError,WSAGetLastError,WSAGetLastError,14_2_00007FFE126D41DA
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE132215FA socket,htonl,htons,bind,listen,WSAGetLastError,WSAGetLastError,WSAGetLastError,14_2_00007FFE132215FA
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE1A45290A socket,htonl,htons,bind,listen,WSAGetLastError,WSAGetLastError,WSAGetLastError,14_2_00007FFE1A45290A
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE1A45A751 bind,14_2_00007FFE1A45A751
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE1A46B820 listen,htons,recv,select,14_2_00007FFE1A46B820
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 14_2_00007FFE1A46B7E8 bind,14_2_00007FFE1A46B7E8
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE1171592A socket,htonl,htons,bind,listen,WSAGetLastError,WSAGetLastError,WSAGetLastError,24_2_00007FFE1171592A
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE1174AEAA socket,htonl,htons,bind,listen,WSAGetLastError,WSAGetLastError,WSAGetLastError,24_2_00007FFE1174AEAA
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE11771F9A socket,htonl,htons,bind,listen,WSAGetLastError,WSAGetLastError,WSAGetLastError,24_2_00007FFE11771F9A
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE11EC41DA socket,htonl,htons,bind,listen,WSAGetLastError,WSAGetLastError,WSAGetLastError,24_2_00007FFE11EC41DA
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE126D15FA socket,htonl,htons,bind,listen,WSAGetLastError,WSAGetLastError,WSAGetLastError,24_2_00007FFE126D15FA
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE1320290A socket,htonl,htons,bind,listen,WSAGetLastError,WSAGetLastError,WSAGetLastError,24_2_00007FFE1320290A
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE1320A751 bind,24_2_00007FFE1320A751
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE1321B7E8 bind,24_2_00007FFE1321B7E8
Source: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exeCode function: 24_2_00007FFE1321B820 listen,htons,recv,select,24_2_00007FFE1321B820
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure2
Valid Accounts
2
Native API
1
DLL Side-Loading
1
DLL Side-Loading
1
Deobfuscate/Decode Files or Information
OS Credential Dumping1
System Time Discovery
Remote Services1
Archive Collected Data
1
Ingress Tool Transfer
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault Accounts2
Command and Scripting Interpreter
1
Create Account
2
Valid Accounts
2
Obfuscated Files or Information
LSASS Memory1
Account Discovery
Remote Desktop ProtocolData from Removable Media1
Encrypted Channel
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain Accounts3
Service Execution
2
Valid Accounts
2
Access Token Manipulation
1
Software Packing
Security Account Manager1
System Service Discovery
SMB/Windows Admin SharesData from Network Shared Drive1
Non-Standard Port
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCron4
Windows Service
4
Windows Service
1
Timestomp
NTDS3
File and Directory Discovery
Distributed Component Object ModelInput Capture1
Proxy
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchd1
Services File Permissions Weakness
11
Process Injection
1
DLL Side-Loading
LSA Secrets23
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC Scripts1
Services File Permissions Weakness
1
File Deletion
Cached Domain Credentials1
Network Share Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items21
Masquerading
DCSync131
Security Software Discovery
Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job2
Valid Accounts
Proc Filesystem1
Process Discovery
Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt2
Access Token Manipulation
/etc/passwd and /etc/shadow21
Virtualization/Sandbox Evasion
Direct Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCron21
Virtualization/Sandbox Evasion
Network Sniffing1
System Owner/User Discovery
Shared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement
Network Security AppliancesDomainsCompromise Software Dependencies and Development ToolsAppleScriptLaunchdLaunchd11
Process Injection
Input Capture1
System Network Configuration Discovery
Software Deployment ToolsRemote Data StagingMail ProtocolsExfiltration Over Unencrypted Non-C2 ProtocolFirmware Corruption
Gather Victim Org InformationDNS ServerCompromise Software Supply ChainWindows Command ShellScheduled TaskScheduled Task1
Hidden Users
KeyloggingProcess DiscoveryTaint Shared ContentScreen CaptureDNSExfiltration Over Physical MediumResource Hijacking
Determine Physical LocationsVirtual Private ServerCompromise Hardware Supply ChainUnix ShellSystemd TimersSystemd Timers1
Services File Permissions Weakness
GUI Input CapturePermission Groups DiscoveryReplication Through Removable MediaEmail CollectionProxyExfiltration over USBNetwork Denial of Service
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1483438 Sample: QTmGYKK6SL.exe Startdate: 27/07/2024 Architecture: WINDOWS Score: 100 75 Multi AV Scanner detection for domain / URL 2->75 77 Antivirus detection for URL or domain 2->77 79 Multi AV Scanner detection for submitted file 2->79 81 7 other signatures 2->81 8 main.exe 156 2->8         started        13 QTmGYKK6SL.exe 1 2->13         started        15 main.exe 2 2->15         started        17 3 other processes 2->17 process3 dnsIp4 61 68.148.96.106 SHAWCA Canada 8->61 63 82.165.57.155 ONEANDONE-ASBrauerstrasse48DE Germany 8->63 71 29 other IPs or domains 8->71 51 C:\Windows\Temp\to1wcXFh, PE32+ 8->51 dropped 53 C:\Windows\Temp\rJnwiXXd, PE32+ 8->53 dropped 55 C:\Windows\Temp\gJinHgIG, PE32+ 8->55 dropped 59 15 other files (13 malicious) 8->59 dropped 91 Contains functionality to hide user accounts 8->91 93 Found Tor onion address 8->93 19 WerFault.exe 19 16 8->19         started        65 91.92.250.213, 1110, 49730 THEZONEBG Bulgaria 13->65 57 C:\Users\user\...\o0c2ddmlg7qrbu2xkviy.exe, PE32+ 13->57 dropped 22 o0c2ddmlg7qrbu2xkviy.exe 10 13->22         started        67 23.241.223.162 TWC-20001-PACWESTUS United States 15->67 69 94.103.188.190 RATELE-ASRU Russian Federation 15->69 73 3 other IPs or domains 15->73 95 Detected unpacking (creates a PE file in dynamic memory) 17->95 25 WerFault.exe 2 17->25         started        file5 signatures6 process7 file8 47 C:\ProgramData\Microsoft\...\Report.wer, Unicode 19->47 dropped 49 C:\Users\Public\...\main.exe, PE32+ 22->49 dropped 83 Multi AV Scanner detection for dropped file 22->83 85 Contains functionality to hide user accounts 22->85 87 Machine Learning detection for dropped file 22->87 89 Found Tor onion address 22->89 27 icacls.exe 1 22->27         started        29 icacls.exe 1 22->29         started        31 sc.exe 1 22->31         started        33 3 other processes 22->33 signatures9 process10 process11 35 conhost.exe 27->35         started        37 conhost.exe 29->37         started        39 conhost.exe 31->39         started        41 conhost.exe 33->41         started        43 conhost.exe 33->43         started        45 conhost.exe 33->45         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
QTmGYKK6SL.exe25%VirustotalBrowse
QTmGYKK6SL.exe24%ReversingLabs
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exe100%Joe Sandbox ML
C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\libi2p.dll0%ReversingLabs
C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\libi2p.dll0%VirustotalBrowse
C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\rfxvmt.dll0%ReversingLabs
C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\rfxvmt.dll0%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exe21%ReversingLabsWin64.Trojan.Barys
C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exe23%VirustotalBrowse
C:\Windows\Temp\JcfQdL0z0%ReversingLabs
C:\Windows\Temp\to1wcXFh0%ReversingLabs
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://upx.sf.net0%URL Reputationsafe
https://i2pseed.creativecowpat.net:8443/0%Avira URL Cloudsafe
https://reseed-fr.i2pd.xyz/0%Avira URL Cloudsafe
http://reg.i2p/hosts.txt8x0%Avira URL Cloudsafe
https://i2p.novg.net/0%Avira URL Cloudsafe
https://reseed.i2p-projekt.de/0%Avira URL Cloudsafe
http://shx5vqsw7usdaunyzr2qmes2fq37oumybpudrd4jjj4e4vk4uusa.b32.i2p/hosts.txtf0%Avira URL Cloudsafe
https://netdb.i2p2.no/0%Avira URL Cloudsafe
https://reseed.memcpy.io/0%Avira URL Cloudsafe
https://reseed-fr.i2pd.xyz/4%VirustotalBrowse
https://reseed.i2p-projekt.de/4%VirustotalBrowse
https://i2p.ghativega.in/0%Avira URL Cloudsafe
https://netdb.i2p2.no/0%VirustotalBrowse
https://reseed.i2pgit.org/0%Avira URL Cloudsafe
https://www2.mk16.de/0%Avira URL Cloudsafe
http://reg.i2p/hosts.txt0%Avira URL Cloudsafe
https://i2p.ghativega.in/0%VirustotalBrowse
https://reseed-pl.i2pd.xyz/0%Avira URL Cloudsafe
http://shx5vqsw7usdaunyzr2qmes2fq37oumybpudrd4jjj4e4vk4uusa.b32.i2p/hosts.txtxyz/0%Avira URL Cloudsafe
https://reseed.memcpy.io/0%VirustotalBrowse
https://i2pseed.creativecowpat.net:8443/0%VirustotalBrowse
http://stats.i2p/cgi-bin/newhosts.txt0%Avira URL Cloudsafe
http://127.0.0.1:81180%Avira URL Cloudsafe
http://identiguy.i2p/hosts.txt0%Avira URL Cloudsafe
https://i2p.novg.net/1%VirustotalBrowse
http://127.0.0.1:81180%VirustotalBrowse
https://reseed-pl.i2pd.xyz/0%VirustotalBrowse
https://reseed.diva.exchange/0%Avira URL Cloudsafe
https://reseed.i2pgit.org/2%VirustotalBrowse
http://127.0.0.1:8118C0%Avira URL Cloudsafe
https://legit-website.com/i2pseeds.su30%Avira URL Cloudsafe
https://reseed.onion.im/0%Avira URL Cloudsafe
https://i2p.mooo.com/netDb/0%Avira URL Cloudsafe
https://reseed.diva.exchange/2%VirustotalBrowse
https://i2pd.readthedocs.io/en/latest/user-guide/configuration/0%Avira URL Cloudsafe
https://reseed2.i2p.net/0%Avira URL Cloudsafe
https://legit-website.com/i2pseeds.su30%VirustotalBrowse
https://www2.mk16.de/0%VirustotalBrowse
http://reg.i2p/hosts.txtV0%Avira URL Cloudsafe
https://banana.incognet.io/100%Avira URL Cloudmalware
http://reg.i2p/hosts.txtXn0%Avira URL Cloudsafe
http://rus.i2p/hosts.txt0%Avira URL Cloudsafe
https://reseed.onion.im/2%VirustotalBrowse
http://shx5vqsw7usdaunyzr2qmes2fq37oumybpudrd4jjj4e4vk4uusa.b32.i2p/hosts.txt0%Avira URL Cloudsafe
https://i2pd.readthedocs.io/en/latest/user-guide/configuration/0%VirustotalBrowse
https://reseed2.i2p.net/5%VirustotalBrowse
https://i2p.mooo.com/netDb/2%VirustotalBrowse
https://banana.incognet.io/4%VirustotalBrowse
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://reseed-fr.i2pd.xyz/main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drtrue
  • 4%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://i2pseed.creativecowpat.net:8443/main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drtrue
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://reseed.i2p-projekt.de/QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, xuutMjJX.14.dr, update.pkg.3.drfalse
  • 4%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
http://reg.i2p/hosts.txt8xmain.exe, 0000000E.00000002.2481168941.000002BAD4B5D000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://i2p.novg.net/main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drtrue
  • 1%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
http://shx5vqsw7usdaunyzr2qmes2fq37oumybpudrd4jjj4e4vk4uusa.b32.i2p/hosts.txtfmain.exe, 0000000E.00000002.2481168941.000002BAD4B5D000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://netdb.i2p2.no/QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, xuutMjJX.14.dr, update.pkg.3.drfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://reseed.memcpy.io/main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drtrue
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://i2p.ghativega.in/main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drtrue
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
http://upx.sf.netAmcache.hve.22.drfalse
  • URL Reputation: safe
unknown
https://reseed.i2pgit.org/main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drtrue
  • 2%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://www2.mk16.de/QTmGYKK6SL.exe, 00000001.00000003.1843557253.0000000004466000.00000004.00000020.00020000.00000000.sdmp, QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003A2F000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, main.exe, 0000000E.00000002.2481168941.000002BAD4B5D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 0000000E.00000002.2482562172.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drtrue
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
http://reg.i2p/hosts.txtupdate.pkg.3.drfalse
  • Avira URL Cloud: safe
unknown
https://reseed-pl.i2pd.xyz/main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drtrue
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
http://shx5vqsw7usdaunyzr2qmes2fq37oumybpudrd4jjj4e4vk4uusa.b32.i2p/hosts.txtxyz/main.exe, 0000000E.00000002.2481168941.000002BAD4B5D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://stats.i2p/cgi-bin/newhosts.txtQTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, xuutMjJX.14.dr, update.pkg.3.drfalse
  • Avira URL Cloud: safe
unknown
http://127.0.0.1:8118QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, main.exe, 0000000E.00000003.1915940712.000002BAD4B91000.00000004.00000020.00020000.00000000.sdmp, main.exe, 0000000E.00000003.1916098850.000002BAD4B97000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000018.00000003.2586491287.00000156D4C77000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000018.00000003.2586378729.00000156D4C71000.00000004.00000020.00020000.00000000.sdmp, xuutMjJX.14.dr, update.pkg.3.drfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
http://identiguy.i2p/hosts.txtQTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, xuutMjJX.14.dr, update.pkg.3.drfalse
  • Avira URL Cloud: safe
unknown
https://reseed.diva.exchange/main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drtrue
  • 2%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
http://127.0.0.1:8118Cmain.exe, 0000000E.00000003.1915940712.000002BAD4B91000.00000004.00000020.00020000.00000000.sdmp, main.exe, 0000000E.00000003.1916098850.000002BAD4B97000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://legit-website.com/i2pseeds.su3QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, xuutMjJX.14.dr, update.pkg.3.drfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://reseed.onion.im/main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drtrue
  • 2%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://i2p.mooo.com/netDb/QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, xuutMjJX.14.dr, update.pkg.3.drfalse
  • 2%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://i2pd.readthedocs.io/en/latest/user-guide/configuration/QTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, xuutMjJX.14.dr, update.pkg.3.drfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
https://reseed2.i2p.net/main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drtrue
  • 5%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
http://reg.i2p/hosts.txtVmain.exe, 00000018.00000002.2933918140.00000156D4C9E000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://banana.incognet.io/main.exe, main.exe, 00000018.00000002.2935551559.00007FFDFB7E4000.00000002.00000001.01000000.0000000A.sdmp, main.exe, 00000018.00000002.2933918140.00000156D4C3D000.00000004.00000020.00020000.00000000.sdmp, update.pkg.3.drtrue
  • 4%, Virustotal, Browse
  • Avira URL Cloud: malware
unknown
http://reg.i2p/hosts.txtXnmain.exe, 0000000E.00000002.2481168941.000002BAD4B5D000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://rus.i2p/hosts.txtQTmGYKK6SL.exe, 00000001.00000003.1854237313.0000000003B54000.00000004.00000020.00020000.00000000.sdmp, o0c2ddmlg7qrbu2xkviy.exe, 00000003.00000000.1866831901.00007FF66564E000.00000008.00000001.01000000.00000005.sdmp, main.exe, 0000000E.00000002.2480467750.000002BAD4726000.00000004.00000020.00020000.00000000.sdmp, xuutMjJX.14.dr, update.pkg.3.drfalse
  • Avira URL Cloud: safe
unknown
http://shx5vqsw7usdaunyzr2qmes2fq37oumybpudrd4jjj4e4vk4uusa.b32.i2p/hosts.txtupdate.pkg.3.drfalse
  • Avira URL Cloud: safe
unknown
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
184.185.247.130
unknownUnited States
22773ASN-CXA-ALL-CCI-22773-RDCUSfalse
216.9.179.60
unknownUnited States
17385ORBITELUSfalse
73.38.186.219
unknownUnited States
7922COMCAST-7922USfalse
217.76.54.24
unknownSweden
39597SVNET-SE-ASSverigeNetMedianetworkiHalmstadABSEfalse
45.8.98.78
unknownRussian Federation
395800GBTCLOUDUStrue
204.8.84.94
unknownUnited States
32641ARBINET-INTERNALUStrue
82.165.57.155
unknownGermany
8560ONEANDONE-ASBrauerstrasse48DEtrue
173.230.128.232
unknownUnited States
63949LINODE-APLinodeLLCUSfalse
51.15.242.96
unknownFrance
12876OnlineSASFRfalse
2.177.225.52
unknownIran (ISLAMIC Republic Of)
12880DCI-ASIRfalse
220.240.88.104
unknownAustralia
7545TPG-INTERNET-APTPGTelecomLimitedAUfalse
91.149.237.69
unknownPoland
41952MARTON-ASPLfalse
91.92.250.213
unknownBulgaria
34368THEZONEBGfalse
86.5.235.24
unknownUnited Kingdom
5089NTLGBfalse
81.6.45.56
unknownSwitzerland
13030INIT7CHfalse
74.80.57.188
unknownUnited States
25921LUS-FIBER-LCGUSfalse
94.103.188.190
unknownRussian Federation
197390RATELE-ASRUfalse
194.87.219.156
unknownRussian Federation
197695AS-REGRUfalse
91.194.11.174
unknownRussian Federation
42994HQservCommunicationSolutionsILfalse
79.228.26.155
unknownGermany
3320DTAGInternetserviceprovideroperationsDEfalse
67.166.47.100
unknownUnited States
7922COMCAST-7922USfalse
68.148.96.106
unknownCanada
6327SHAWCAtrue
23.241.223.162
unknownUnited States
20001TWC-20001-PACWESTUSfalse
70.18.38.5
unknownUnited States
701UUNETUSfalse
119.13.124.67
unknownAustralia
9723ISEEK-AS-APiseekCommunicationsPtyLtdAUtrue
5.64.137.68
unknownUnited Kingdom
5607BSKYB-BROADBAND-ASGBfalse
24.177.113.51
unknownUnited States
20115CHARTER-20115UStrue
139.59.159.178
unknownSingapore
14061DIGITALOCEAN-ASNUSfalse
45.89.55.34
unknownRussian Federation
44676VMAGE-ASRUfalse
91.224.234.189
unknownRussian Federation
56542PARKTELECOM-ASRUfalse
46.151.24.133
unknownRussian Federation
49608T4D_RU-ASRUfalse
73.62.1.179
unknownUnited States
7922COMCAST-7922UStrue
99.252.52.199
unknownCanada
812ROGERS-COMMUNICATIONSCAfalse
93.95.229.134
unknownIceland
44925THE-1984-ASISfalse
77.238.224.125
unknownRussian Federation
42429TELERU-ASRUfalse
186.28.6.171
unknownColombia
19429ETB-ColombiaCOtrue
IP
127.0.0.1
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1483438
Start date and time:2024-07-27 13:41:11 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 9m 21s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:25
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:QTmGYKK6SL.exe
renamed because original name is a hash value
Original Sample Name:190e4ed7759276e78d16398673996b2b.exe
Detection:MAL
Classification:mal100.troj.evad.winEXE@32/51@0/37
EGA Information:
  • Successful, ratio: 40%
HCA Information:Failed
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
  • Excluded IPs from analysis (whitelisted): 52.168.117.173
  • Excluded domains from analysis (whitelisted): onedsblobprdeus16.eastus.cloudapp.azure.com, ocsp.digicert.com, slscr.update.microsoft.com, login.live.com, blobcollector.events.data.trafficmanager.net, ctldl.windowsupdate.com, umwatson.events.data.microsoft.com, fe3cr.delivery.mp.microsoft.com
  • Execution Graph export aborted for target QTmGYKK6SL.exe, PID 6544 because there are no executed function
  • Execution Graph export aborted for target QTmGYKK6SL.exe, PID 6792 because there are no executed function
  • Execution Graph export aborted for target o0c2ddmlg7qrbu2xkviy.exe, PID 5844 because it is empty
  • Not all processes where analyzed, report is missing behavior information
  • Report size exceeded maximum capacity and may have missing behavior information.
  • Report size exceeded maximum capacity and may have missing disassembly code.
  • Report size exceeded maximum capacity and may have missing network information.
TimeTypeDescription
07:42:23API Interceptor195x Sleep call for process: QTmGYKK6SL.exe modified
07:42:59API Interceptor376x Sleep call for process: main.exe modified
07:43:23API Interceptor1x Sleep call for process: WerFault.exe modified
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
184.185.247.130file.exeGet hashmaliciousVidarBrowse
    91.92.250.213IRqsWvBBMc.exeGet hashmaliciousAmadey, VidarBrowse
      file.exeGet hashmaliciousVidarBrowse
        216.9.179.60file.exeGet hashmaliciousVidarBrowse
          81.6.45.56file.exeGet hashmaliciousVidarBrowse
            73.38.186.219file.exeGet hashmaliciousVidarBrowse
              45.8.98.78file.exeGet hashmaliciousVidarBrowse
                204.8.84.94file.exeGet hashmaliciousVidarBrowse
                  82.165.57.155file.exeGet hashmaliciousVidarBrowse
                    173.230.128.232file.exeGet hashmaliciousVidarBrowse
                      91.149.237.69file.exeGet hashmaliciousVidarBrowse
                        No context
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        ASN-CXA-ALL-CCI-22773-RDCUS93g0DCqh1e.elfGet hashmaliciousMiraiBrowse
                        • 68.227.186.53
                        xZ2Ha9PYPn.elfGet hashmaliciousMiraiBrowse
                        • 66.210.234.66
                        file.exeGet hashmaliciousVidarBrowse
                        • 184.185.247.130
                        mpsl.elfGet hashmaliciousMiraiBrowse
                        • 72.194.198.162
                        arm7.elfGet hashmaliciousMiraiBrowse
                        • 68.6.47.11
                        nX1oQE2we8.exeGet hashmaliciousCryptOne, QbotBrowse
                        • 72.209.191.27
                        LisectAVT_2403002C_89.exeGet hashmaliciousFormBookBrowse
                        • 98.167.121.228
                        94.156.8.9-skid.mips-2024-07-23T17_40_11.elfGet hashmaliciousMirai, MoobotBrowse
                        • 184.190.153.158
                        wAO7F8FbEz.elfGet hashmaliciousUnknownBrowse
                        • 68.96.185.235
                        0GJSC4Ua2K.elfGet hashmaliciousUnknownBrowse
                        • 174.79.178.111
                        SVNET-SE-ASSverigeNetMedianetworkiHalmstadABSERFQ24060084#U00b7pdf.exeGet hashmaliciousRemcos, GuLoaderBrowse
                        • 217.76.50.73
                        IT01879020517_uGIim_xml#U00b7pdf.exeGet hashmaliciousRemcosBrowse
                        • 217.76.50.73
                        Cp91KTtA1I.exeGet hashmaliciousRemcos, GuLoaderBrowse
                        • 217.76.50.73
                        I3AAOUFA1w.exeGet hashmaliciousRemcos, GuLoaderBrowse
                        • 217.76.50.73
                        Gsi3o47VVe.exeGet hashmaliciousRemcos, GuLoaderBrowse
                        • 217.76.50.73
                        fKPsJbn9jd.exeGet hashmaliciousRemcos, GuLoaderBrowse
                        • 217.76.50.73
                        pko_trans_details_20240710_105339#U00b7pdf.exeGet hashmaliciousRemcosBrowse
                        • 217.76.50.73
                        OD2J305312A-200805674H-2024090716pdf.exeGet hashmaliciousRemcos, GuLoaderBrowse
                        • 217.76.50.73
                        Vendor Data Requirements#U00b7pdf.exeGet hashmaliciousRemcosBrowse
                        • 217.76.50.73
                        Orange_doklad_CN0413278003_20240705_FR09831200076590#U00b7pdf.exeGet hashmaliciousRemcos, GuLoaderBrowse
                        • 217.76.50.73
                        COMCAST-7922US205.185.120.123-skid.sh4-2024-07-27T10_33_38.elfGet hashmaliciousMirai, MoobotBrowse
                        • 184.122.149.149
                        205.185.120.123-skid.m68k-2024-07-27T10_33_18.elfGet hashmaliciousMirai, MoobotBrowse
                        • 76.144.6.176
                        205.185.120.123-skid.arm7-2024-07-27T10_33_43.elfGet hashmaliciousMirai, MoobotBrowse
                        • 25.212.223.48
                        93g0DCqh1e.elfGet hashmaliciousMiraiBrowse
                        • 98.54.154.173
                        xZ2Ha9PYPn.elfGet hashmaliciousMiraiBrowse
                        • 25.6.129.49
                        AKPSrAWl2G.elfGet hashmaliciousMiraiBrowse
                        • 76.27.22.105
                        TRn7934M3A.elfGet hashmaliciousMiraiBrowse
                        • 75.67.106.141
                        rLog7rmU2e.elfGet hashmaliciousMiraiBrowse
                        • 76.122.78.50
                        WIwTo1UTMq.elfGet hashmaliciousMiraiBrowse
                        • 69.254.187.221
                        5oXS6HtbzC.elfGet hashmaliciousMiraiBrowse
                        • 73.174.55.28
                        ORBITELUSfile.exeGet hashmaliciousVidarBrowse
                        • 216.9.179.60
                        1CZlhmRsza.elfGet hashmaliciousMirai, MoobotBrowse
                        • 208.115.146.132
                        3LI2VAvf26.elfGet hashmaliciousUnknownBrowse
                        • 208.115.145.33
                        JoaD4Dp71E.elfGet hashmaliciousMiraiBrowse
                        • 208.115.145.97
                        VJy4TgKlVo.elfGet hashmaliciousMiraiBrowse
                        • 208.90.178.131
                        3LqyRhuLwv.elfGet hashmaliciousMiraiBrowse
                        • 208.115.145.97
                        skyljne.mpsl.elfGet hashmaliciousMiraiBrowse
                        • 208.90.178.146
                        pf8hBdVOlp.elfGet hashmaliciousMiraiBrowse
                        • 208.115.145.91
                        4E2ggD3VyS.elfGet hashmaliciousMiraiBrowse
                        • 208.90.178.178
                        botx.arm.elfGet hashmaliciousUnknownBrowse
                        • 208.115.146.130
                        No context
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\cnccli.dllfile.exeGet hashmaliciousVidarBrowse
                          C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\dwlmgr.dllfile.exeGet hashmaliciousVidarBrowse
                            C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\libi2p.dllfile.exeGet hashmaliciousVidarBrowse
                              C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\evtsrv.dllfile.exeGet hashmaliciousVidarBrowse
                                Process:C:\Windows\System32\WerFault.exe
                                File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                Category:dropped
                                Size (bytes):65536
                                Entropy (8bit):0.9540509635037503
                                Encrypted:false
                                SSDEEP:96:VeGFbBzcjsehMX71fwQXIDcQic6EcErcw3U3d+HbHg/opAnQzOqg7ThVMkQrIdUX:1pVcju0MAR436jtIzuiFFZ24lO8lu
                                MD5:9FCB1376DF5A2A43B47D9058C3E0887D
                                SHA1:D0FF9040623F66FAAB2B611E8ACDCC437D79A5ED
                                SHA-256:B266869B1D78CE6CC5FCBABED457875B6DACC82B376F97D3F686A47ABCB52595
                                SHA-512:D0F55137AE0A2D272BECA7509BDDC319F4C69457914F24D60D7AC81EB184121AB2203213CA3F6638B38CC13ECB26158AF60B1C42C177AC2907006900FC8D12C7
                                Malicious:true
                                Preview:..V.e.r.s.i.o.n.=.1.....E.v.e.n.t.T.y.p.e.=.A.P.P.C.R.A.S.H.....E.v.e.n.t.T.i.m.e.=.1.3.3.6.6.5.5.4.1.9.7.1.0.1.0.7.9.2.....R.e.p.o.r.t.T.y.p.e.=.2.....C.o.n.s.e.n.t.=.1.....U.p.l.o.a.d.T.i.m.e.=.1.3.3.6.6.5.5.4.1.9.7.6.4.7.9.4.6.9.....R.e.p.o.r.t.S.t.a.t.u.s.=.5.2.4.3.8.4.....R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.b.6.9.b.9.d.a.0.-.b.8.c.d.-.4.9.e.8.-.a.9.8.d.-.e.e.4.b.a.4.c.1.b.e.4.8.....I.n.t.e.g.r.a.t.o.r.R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.c.4.e.6.9.4.2.b.-.6.6.9.f.-.4.2.5.0.-.b.f.4.2.-.8.c.c.8.8.c.0.c.f.9.3.4.....W.o.w.6.4.H.o.s.t.=.3.4.4.0.4.....N.s.A.p.p.N.a.m.e.=.m.a.i.n...e.x.e.....A.p.p.S.e.s.s.i.o.n.G.u.i.d.=.0.0.0.0.0.c.5.c.-.0.0.0.0.-.0.0.1.4.-.4.0.7.2.-.c.e.0.d.1.a.e.0.d.a.0.1.....T.a.r.g.e.t.A.p.p.I.d.=.W.:.0.0.0.6.0.3.1.8.d.4.3.1.0.6.5.7.e.8.3.6.8.5.5.7.f.1.8.3.e.1.5.c.4.7.c.d.0.0.0.0.f.f.f.f.!.0.0.0.0.f.6.d.a.c.c.e.5.9.f.7.8.c.a.4.e.e.6.6.2.2.c.4.a.3.4.0.9.2.3.2.8.2.e.c.3.a.d.d.e.!.m.a.i.n...e.x.e.....T.a.r.g.e.t.A.p.p.V.e.r.=.1.9.7.0././.0.1././.0.1.:.0.0.:.0.0.:.0.0.!.1.a.
                                Process:C:\Windows\System32\WerFault.exe
                                File Type:Mini DuMP crash report, 15 streams, Sat Jul 27 11:43:17 2024, 0x1205a4 type
                                Category:dropped
                                Size (bytes):630612
                                Entropy (8bit):0.9954004505190842
                                Encrypted:false
                                SSDEEP:768:dF/CPw0uUm5s0TTg5PcONad6duMXdjJld1F:d0arZTTUUONaaXFJld1
                                MD5:CDFD86DA68A64C90E6B96CBA603552F8
                                SHA1:0E049F88F66F0074AAFDD513C640B4C7140AE365
                                SHA-256:CD77D9133794BEAE2A2FB4D968890A6EBCBDBF5144CC342FC83587735FEC10C6
                                SHA-512:52AE48824532A0840FD4082332BB7D83668E37F777776C4098E3D379BF8F8B709BE3730360B8DFFF311B61F102D9BC0BC7834AF7E9903A4E4336B32CE909742D
                                Malicious:false
                                Preview:MDMP..a..... .......U.f............$...........x...8.......................N...........`.......8...........T............-...q.......................!..............................................................................eJ......0"......Lw......................T.......\...".f.............................@..............,...E.a.s.t.e.r.n. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................E.a.s.t.e.r.n. .S.u.m.m.e.r. .T.i.m.e...............................................1.9.0.4.1...1...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6.......................................................................................................................................................................................................................................................................................................................................................................................................................................
                                Process:C:\Windows\System32\WerFault.exe
                                File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                Category:dropped
                                Size (bytes):6726
                                Entropy (8bit):3.7167613702482543
                                Encrypted:false
                                SSDEEP:96:RSIU6o7wVetb6MXBmkWYyZzW5aM4UB89bdxDDFfGKfm:R6l7wVeJ6MXBmNYycprB89bdxlfGKfm
                                MD5:8B12A6FF776235A776EA6A9CC661F42C
                                SHA1:327DB96CA43470FECFCC7CCCFBBDCC94CDCCCD4E
                                SHA-256:5F0A7335ADE207FCA3ED2140846F56D0FC8F26E92FDF6DD362E4FD16775C9A92
                                SHA-512:9578E2650A7F402BF25927B8811B503FF35A751F5984AC043735160C94B8801A57CC1CB89C1955DBC4E3171E2A038D27F00D4CF6A3EFBD55C26217D70BEE05A9
                                Malicious:false
                                Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.W.E.R.R.e.p.o.r.t.M.e.t.a.d.a.t.a.>.......<.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.........<.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.1.0...0.<./.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.........<.B.u.i.l.d.>.1.9.0.4.5.<./.B.u.i.l.d.>.........<.P.r.o.d.u.c.t.>.(.0.x.3.0.).:. .W.i.n.d.o.w.s. .1.0. .P.r.o.<./.P.r.o.d.u.c.t.>.........<.E.d.i.t.i.o.n.>.P.r.o.f.e.s.s.i.o.n.a.l.<./.E.d.i.t.i.o.n.>.........<.B.u.i.l.d.S.t.r.i.n.g.>.1.9.0.4.1...2.0.0.6...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6.<./.B.u.i.l.d.S.t.r.i.n.g.>.........<.R.e.v.i.s.i.o.n.>.2.0.0.6.<./.R.e.v.i.s.i.o.n.>.........<.F.l.a.v.o.r.>.M.u.l.t.i.p.r.o.c.e.s.s.o.r. .F.r.e.e.<./.F.l.a.v.o.r.>.........<.A.r.c.h.i.t.e.c.t.u.r.e.>.X.6.4.<./.A.r.c.h.i.t.e.c.t.u.r.e.>.........<.L.C.I.D.>.2.0.5.7.<./.L.C.I.D.>.......<./.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.......<.P.r.o.c.e.s.s.I.n.f.o.r.m.a.t.i.o.n.>.........<.P.i.d.>.3.1.6.4.<./.P.i.
                                Process:C:\Windows\System32\WerFault.exe
                                File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                Category:dropped
                                Size (bytes):4603
                                Entropy (8bit):4.411212185165714
                                Encrypted:false
                                SSDEEP:48:cvIwWl8zsQJg771I9vsWpW8VYSYm8M4JD2+SWF4yq85/pCR4X3l1d:uIjfWI7gF7VCJA/iOS3l1d
                                MD5:90DD9C71EE656B42D5A0489657EFC0A1
                                SHA1:436ADA40DD34BDCB762C233A4E9660F5FA25C6C1
                                SHA-256:D648CE73344BBB377510EA21EF64E6DF478BAAD028FDB2EAAA80C2DB59BF6941
                                SHA-512:ED92CA94C45B1AE4E3DEAC217946ED6221E6810F455DE2464F9A4824C3AD470B7916B5D6742A1375F4C0514AC9D7DE7D53995B459FF6799FCAE38256C2315B32
                                Malicious:false
                                Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?>..<req ver="2">.. <tlm>.. <src>.. <desc>.. <mach>.. <os>.. <arg nm="vermaj" val="10" />.. <arg nm="vermin" val="0" />.. <arg nm="verbld" val="19045" />.. <arg nm="vercsdbld" val="2006" />.. <arg nm="verqfe" val="2006" />.. <arg nm="csdbld" val="2006" />.. <arg nm="versp" val="0" />.. <arg nm="arch" val="9" />.. <arg nm="lcid" val="2057" />.. <arg nm="geoid" val="223" />.. <arg nm="sku" val="48" />.. <arg nm="domain" val="0" />.. <arg nm="prodsuite" val="256" />.. <arg nm="ntprodtype" val="1" />.. <arg nm="platid" val="2" />.. <arg nm="tmsi" val="429285" />.. <arg nm="osinsty" val="1" />.. <arg nm="iever" val="11.789.19041.0-11.0.1000" />.. <arg nm="portos" val="0" />.. <arg nm="ram" val="409
                                Process:C:\Windows\System32\svchost.exe
                                File Type:data
                                Category:dropped
                                Size (bytes):82020
                                Entropy (8bit):3.024582262277265
                                Encrypted:false
                                SSDEEP:1536:VL7SZZChl+Jh8D/9ai7zDpiQuK+swaURXtE:VL7SZZChl+Jh8D/9ai7zDpiQuK+swaUA
                                MD5:57BA76B5CF06F5B190A74EB9A981A2AA
                                SHA1:720F9BC819CEBCD5C54D383E866CDB80488B5614
                                SHA-256:D1E543672CBE8FD845DBD3B120DB9E9191B9176D14B01FE1917D9553D5CBC026
                                SHA-512:AAC900F3E1CBEAE93332DE684BA1BC4C74FFEFBBF666042AC8FD9D49924BFE2FD3D3C48F5E47B4CEA1EF8B2BAEDB9AFE62BDA62FF8ABD7C091025F5530485F64
                                Malicious:false
                                Preview:I.m.a.g.e.N.a.m.e.,.U.n.i.q.u.e.P.r.o.c.e.s.s.I.d.,.N.u.m.b.e.r.O.f.T.h.r.e.a.d.s.,.W.o.r.k.i.n.g.S.e.t.P.r.i.v.a.t.e.S.i.z.e.,.H.a.r.d.F.a.u.l.t.C.o.u.n.t.,.N.u.m.b.e.r.O.f.T.h.r.e.a.d.s.H.i.g.h.W.a.t.e.r.m.a.r.k.,.C.y.c.l.e.T.i.m.e.,.C.r.e.a.t.e.T.i.m.e.,.U.s.e.r.T.i.m.e.,.K.e.r.n.e.l.T.i.m.e.,.B.a.s.e.P.r.i.o.r.i.t.y.,.P.e.a.k.V.i.r.t.u.a.l.S.i.z.e.,.V.i.r.t.u.a.l.S.i.z.e.,.P.a.g.e.F.a.u.l.t.C.o.u.n.t.,.W.o.r.k.i.n.g.S.e.t.S.i.z.e.,.P.e.a.k.W.o.r.k.i.n.g.S.e.t.S.i.z.e.,.Q.u.o.t.a.P.e.a.k.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.Q.u.o.t.a.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.Q.u.o.t.a.P.e.a.k.N.o.n.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.Q.u.o.t.a.N.o.n.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.P.a.g.e.f.i.l.e.U.s.a.g.e.,.P.e.a.k.P.a.g.e.f.i.l.e.U.s.a.g.e.,.P.r.i.v.a.t.e.P.a.g.e.C.o.u.n.t.,.R.e.a.d.O.p.e.r.a.t.i.o.n.C.o.u.n.t.,.W.r.i.t.e.O.p.e.r.a.t.i.o.n.C.o.u.n.t.,.O.t.h.e.r.O.p.e.r.a.t.i.o.n.C.o.u.n.t.,.R.e.a.d.T.r.a.n.s.f.e.r.C.o.u.n.t.,.W.r.i.t.e.T.r.a.n.s.f.e.r.C.o.u.n.t.,.O.t.h.e.r.T.r.a.n.s.f.e.r.C.o.u.n.t.,.H.a.n.
                                Process:C:\Windows\System32\svchost.exe
                                File Type:data
                                Category:dropped
                                Size (bytes):13340
                                Entropy (8bit):2.685623798077692
                                Encrypted:false
                                SSDEEP:96:TiZYWTAavBQfYjEYjcW/H2YEZi5tHiPICFuwv5j3aH03MGnGIeW3:2ZDTzq/U7O1aH03MGnBeW3
                                MD5:11087BC1AA84F9B28BA56BFE1DAA0FE4
                                SHA1:1ADB9040F0308E8A926681B6239953167A3D910E
                                SHA-256:727F945812ECFC73326708E99A6858B5E737F09F11B60CAA0C56A1F883CD0A9B
                                SHA-512:6F2514F075E3CF9C033FBF38A27D4FEE04FBFB1522337AA9611E9D58BC099684E36095449D6CB9DD0E4795D3E1729E59D2BB62F0E25387B748BF7AC99673E37E
                                Malicious:false
                                Preview:B...T.i.m.e.r.R.e.s.o.l.u.t.i.o.n. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .1.5.6.2.5.0.....B...P.a.g.e.S.i.z.e. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .4.0.9.6.....B...N.u.m.b.e.r.O.f.P.h.y.s.i.c.a.l.P.a.g.e.s. . . . . . . . . . . . . . . . . . . . . . . . . . .1.0.4.8.3.3.3.....B...L.o.w.e.s.t.P.h.y.s.i.c.a.l.P.a.g.e.N.u.m.b.e.r. . . . . . . . . . . . . . . . . . . . . . . . . . . . . .2.....B...H.i.g.h.e.s.t.P.h.y.s.i.c.a.l.P.a.g.e.N.u.m.b.e.r. . . . . . . . . . . . . . . . . . . . . . .1.3.1.0.7.1.9.....B...A.l.l.o.c.a.t.i.o.n.G.r.a.n.u.l.a.r.i.t.y. . . . . . . . . . . . . . . . . . . . . . . . . . . . .6.5.5.3.6.....B...M.i.n.i.m.u.m.U.s.e.r.M.o.d.e.A.d.d.r.e.s.s. . . . . . . . . . . . . . . . . . . . . . . . . . . .6.5.5.3.6.....B...M.a.x.i.m.u.m.U.s.e.r.M.o.d.e.A.d.d.r.e.s.s. . . . . . . . . . . . . . . . . .1.4.0.7.3.7.4.8.8.2.8.9.7.9.1.....B...A.c.t.i.v.e.P.r.o.c.e.s.s.o.r.s.A.f.f.i.n.i.t.y.M.a.s.k. . . . . . .
                                Process:C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exe
                                File Type:data
                                Category:dropped
                                Size (bytes):456
                                Entropy (8bit):3.2341395630162877
                                Encrypted:false
                                SSDEEP:12:Ml8Pi7t8+d/fQfjfEWNfElsfghFfShFfgmSem4emzYWr:k8APd/oj8i8ls0FSFgID7r
                                MD5:40AB00517F4227F2C3C334F1D16B65B4
                                SHA1:F8D57AF017E2209B4FB24122647FD7F71B67C87C
                                SHA-256:4BAF4B78D05A28AF7DEE7DBBCE2B4EDF6053D9239C1756C932BE9F2FEEE4EF85
                                SHA-512:75D74306F043B864295F09A60C19A43494C226664733C99318989CE5C22CB9395BB407FB5C8C0268AD9184A79813304ED5FC943A6B53DB54F5F225CDA31650E3
                                Malicious:false
                                Preview:C.o.m.p.u.t.e.r...{.2.0.d.0.4.f.e.0.-.3.a.e.a.-.1.0.6.9.-.a.2.d.8.-.0.8.0.0.2.b.3.0.3.0.9.d.}.....D.:.A.I.(.D.;.;.F.A.;.;.;.B.U.).(.A.;.;.F.A.;.;.;.B.A.).(.A.;.O.I.C.I.I.D.;.F.A.;.;.;.B.A.).(.A.;.I.D.;.F.A.;.;.;.S.Y.).(.A.;.O.I.C.I.I.O.I.D.;.F.A.;.;.;.C.O.).(.A.;.O.I.C.I.I.O.I.D.;.F.A.;.;.;.S.Y.).(.A.;.O.I.C.I.I.D.;.0.x.1.3.0.1.f.f.;.;.;.I.U.).(.A.;.O.I.C.I.I.D.;.0.x.1.3.0.1.f.f.;.;.;.S.U.).(.A.;.O.I.C.I.I.D.;.0.x.1.3.0.1.f.f.;.;.;.S.-.1.-.5.-.3.).....
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                Category:dropped
                                Size (bytes):115200
                                Entropy (8bit):6.220309385007289
                                Encrypted:false
                                SSDEEP:1536:RQsjbnQsiAEVTEWeFENdEUD1/H6BELpsV4vN8qdnJNXq8Vc3:RQibZibeFENdppW54NdvXq6c3
                                MD5:E6CAC6ACD18D0BBAD9C2384B1DBEDE84
                                SHA1:63004A83FF18CCE911BC74D27C1A2B7BEA9CF4C3
                                SHA-256:9BC6EDD286F4DCD83E57B541BC99038F7E902DE943A6FD528BA485DF1187FFA8
                                SHA-512:43C745D49AB82809C24E5EE62E11406B12B695140117EB1012111EEA3B73F9B34B5ADE21A1DB3AA1FEAD982F266B05646A08A4813CBA2EA950C59A73AB069FB3
                                Malicious:true
                                Joe Sandbox View:
                                • Filename: file.exe, Detection: malicious, Browse
                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."...(............\........."h.............................P......Zq....`... .........................................^....................................@..l........................... ...(.......................h............................text...X...........................`..`.data........0......................@....rdata..@d...@...f...(..............@..@.pdata..............................@..@.xdata..............................@..@.bss.....................................edata..^...........................@..@.idata..............................@....CRT....X.... ......................@....tls.........0......................@....reloc..l....@......................@..B........................................................................................................................................................................
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:ASCII text, with CRLF line terminators
                                Category:dropped
                                Size (bytes):2847
                                Entropy (8bit):5.56218878604364
                                Encrypted:false
                                SSDEEP:48:CFdHW54yclDYcm9FL3vU4bcPPE4bcPPTM94bcPPZ4bcPPA4bcPP84bcPPcWIe18m:idH9NYJ9Vf3YPHYPTNYP6YPTYP/YPV3/
                                MD5:84DC05C9BB86705E04922F07504B4927
                                SHA1:DF1E54ED89D0DF43D3A53A0EB4F963CB9C3AE56A
                                SHA-256:700EA53FA8FD4A29D77CFF1C57FD4B456071AD083EC58873238DBB23644E8634
                                SHA-512:E874ABC5CDA0AFDC9D0B3D3DB5818597A4669FB410A6A0D83A98344FD70A2194309782D6F21C19D12BA84686C96EBC487122899F7DAD0C17B33EEB26CC976D3C
                                Malicious:false
                                Preview:[I] (debug_init) -> Log open success(flog_path=C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\cnccli.log)..[I] (debug_init) -> Done..[D] (ini_get_sec) -> Done(name=main)..[D] (ini_get_var) -> Done(sec=main,name=version,value=400004957b19a09d)..[I] (module_load) -> Done(name=ntdll.dll,ret=0x00007ffe22170000)..[D] (module_get_proc) -> Done(hnd=0x00007ffe22170000,name=RtlGetVersion,ret=0x00007ffe221ae520)..[I] (sys_init) -> GetWindowsDirectoryA done(sys_win_dir=C:\Windows)..[D] (registry_get_value) -> Done(root=0xffffffff80000002,key=SOFTWARE\Microsoft\Cryptography,param=MachineGuid)..[I] (sys_init) -> GetWindowsDirectoryA done(sys_mach_guid=9e146be9-c76a-4720-bcdb-53011b87bd06)..[I] (sys_init) -> GetVolumeInformationA done(vol=C:\,vol_sn=81f395a1)..[I] (sys_init) -> Done(sys_uid=c76a8f0881f395a1,sys_os_ver=10.0.19045.0.0)..[I] (net_init) -> Done..[I] (ebus_init) -> Done..[D] (ini_get_sec) -> Done(name=cnccli)..[D] (ini_get_var) -> Done(sec=cnccli,name=server_host,value=c
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:Generic INItialization configuration [cnccli]
                                Category:dropped
                                Size (bytes):214
                                Entropy (8bit):5.104102844508187
                                Encrypted:false
                                SSDEEP:6:1EVQLD4o8WnuJO+70X1YIzOD7kXpTRL9gWVUDeLn:Cjo8DJO+70X1YeC7kX9vgpKL
                                MD5:91D86E531FECE0D34AD78D947FC7331C
                                SHA1:52C9A7C16634637E9DB31A6CE63850DFB170B44D
                                SHA-256:A885C71096995389DF3015B194B9AD10AE24C4328F4322932D6455398B2FC653
                                SHA-512:1EE4ED0F8045670DBEE2C5C4F8100C362B84C1CCC1A2E7F4FD1E97EC057055F1A8DC75A0CE349CC01DBFFA2B18E7C7C2288845641358CA3A609B0E6FBD9F49B5
                                Malicious:false
                                Preview:[main]..version=400004957b19a09d..[cnccli]..server_host=c21a876e..server_port=41674..server_timeo=15000..i2p_try_num=10..i2p_sam3_timeo=15000..i2p_addr=2lyi6mgj6tn4eexl6gwnujwfycmq7dcus2x42petanvpwpjlqrhq.b32.i2p..
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                Category:dropped
                                Size (bytes):104448
                                Entropy (8bit):6.25639342609658
                                Encrypted:false
                                SSDEEP:1536:cTa6mu/WYUIdcVVKwU4k+EFfgvVFc2nx7ehX/DhZB34:cTa6mu5UIdc/KwzrGgw2x7ehX7hP34
                                MD5:7D37AB1E97BBC8593665FF365D8C96B7
                                SHA1:B42A6717F91A4C538A4979AB1F0A9CC58485061D
                                SHA-256:1DA31243257B0EBC79BA57CA98E6A3A1996CC4E2641E96098561CDCB1FA3EE46
                                SHA-512:60B3683FA7BCA42932E02AED4615E67264F31D6F85BEBCD3EA7187B9F7A9F79270341496432C07F7E9B10A3172AF22D636206FA5B89514A693405EC9D61F678D
                                Malicious:true
                                Joe Sandbox View:
                                • Filename: file.exe, Detection: malicious, Browse
                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."...(............\.........?..............................0.......'....`... .........................................^.......................$............ ..l............................v..(.......................`............................text...............................`..`.data...............................@....rdata...a... ...b..................@..@.pdata..$............h..............@..@.xdata..T............r..............@..@.bss.... ................................edata..^............|..............@..@.idata...............~..............@....CRT....X...........................@....tls................................@....reloc..l.... ......................@..B........................................................................................................................................................................
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:ASCII text, with CRLF line terminators
                                Category:dropped
                                Size (bytes):1021
                                Entropy (8bit):5.4436306974457125
                                Encrypted:false
                                SSDEEP:24:CFAGHS+5lGyclY7Gfy6BgT7cRE9FLxJDJt0ERbSXee:CFdHS+54yclDYcm9FL3vU7
                                MD5:8BD5B6F80F6407078329F58F97A25B42
                                SHA1:1349DE7A5C1235B3C6A2F2331641A31E37A2198C
                                SHA-256:B41054EEB3003F4983D2CBAE2448F38BD3CCB393B0AEF17C01AC19F556A20A94
                                SHA-512:EBDDB1BE707EC351CA7BE2A81456D09A9224296B0E37A79E89786FB003DF0C55FC6251E42EFF6388D7E51F33CDBB860D34203FF4D118B4A5D375E7182DC709A5
                                Malicious:false
                                Preview:[I] (debug_init) -> Log open success(flog_path=C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\dwlmgr.log)..[I] (debug_init) -> Done..[D] (ini_get_sec) -> Done(name=main)..[D] (ini_get_var) -> Done(sec=main,name=version,value=400004957b19a09d)..[I] (module_load) -> Done(name=ntdll.dll,ret=0x00007ffe22170000)..[D] (module_get_proc) -> Done(hnd=0x00007ffe22170000,name=RtlGetVersion,ret=0x00007ffe221ae520)..[I] (sys_init) -> GetWindowsDirectoryA done(sys_win_dir=C:\Windows)..[D] (registry_get_value) -> Done(root=0xffffffff80000002,key=SOFTWARE\Microsoft\Cryptography,param=MachineGuid)..[I] (sys_init) -> GetWindowsDirectoryA done(sys_mach_guid=9e146be9-c76a-4720-bcdb-53011b87bd06)..[I] (sys_init) -> GetVolumeInformationA done(vol=C:\,vol_sn=81f395a1)..[I] (sys_init) -> Done(sys_uid=c76a8f0881f395a1,sys_os_ver=10.0.19045.0.0)..[I] (net_init) -> Done..[I] (ebus_init) -> Done..[I] (ebus_subscribe) -> Done(handler=0x00007ffe11ecb0c0)..[I] (tcp_connect) -> Done(sock=0x1a0,host=7
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                Category:dropped
                                Size (bytes):92672
                                Entropy (8bit):6.241321016680509
                                Encrypted:false
                                SSDEEP:1536:uVq4VcOpVJ7Z4LB2gnUYQulkvJp0qn2goggVoOHDE:uVq4VcOph4LB2khdkYq2goggM
                                MD5:FB3BDB27D9C479148F3545ED99E65980
                                SHA1:A5860563DE81D8B74A1C842647E8F4AC7655842A
                                SHA-256:2B5DC45E89700D4B991ADDED1AA097641D60932B7BBE2C12FC8536B9D46F15A6
                                SHA-512:A26D4B169C4061FC7A2A5FEFAEB4AAE0E9A28211FA28F42B929EAAC3721DCBDD17A17ED6E77A79C17D93355CF85E4C46118E42D4F527ADF054AB1CC79C8B4D74
                                Malicious:true
                                Joe Sandbox View:
                                • Filename: file.exe, Detection: malicious, Browse
                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."...(.....f......\.........Io....................................W.....`... .........................................^....................`..................l............................J..(....................................................text...............................`..`.data...............................@....rdata...U.......V..................@..@.pdata.......`.......<..............@..@.xdata.......p.......F..............@..@.bss....`................................edata..^............P..............@..@.idata...............R..............@....CRT....X............d..............@....tls.................f..............@....reloc..l............h..............@..B........................................................................................................................................................................
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:ASCII text, with CRLF line terminators
                                Category:dropped
                                Size (bytes):7685
                                Entropy (8bit):5.3887730960177604
                                Encrypted:false
                                SSDEEP:48:CFdHs54yclDYcm9FL3vzBMrGtUEOYEdHE5QEMcEah8neYMAdtSn2EF:idHrNYJ9VfzBK5EFEJEiEvEy
                                MD5:B9C2B3A2DC6A87CDF6E30EBB6D4E5251
                                SHA1:DF4212C945A85D02738F6EC974602862D7E20EA3
                                SHA-256:088D2AE029308BE8AD8CE0AEA797F6D86CC5457D9C2F9516176B51E5C4F8789F
                                SHA-512:47832A15A50F073139A5F51B3F28E61160C6C0A14929D0BF495E824896B36108A7B8037FC702A49A633E5B43B7BD57C3107B6958AAC2C8DEEBA7B55507AFBD43
                                Malicious:false
                                Preview:[I] (debug_init) -> Log open success(flog_path=C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\evtsrv.log)..[I] (debug_init) -> Done..[D] (ini_get_sec) -> Done(name=main)..[D] (ini_get_var) -> Done(sec=main,name=version,value=400004957b19a09d)..[I] (module_load) -> Done(name=ntdll.dll,ret=0x00007ffe22170000)..[D] (module_get_proc) -> Done(hnd=0x00007ffe22170000,name=RtlGetVersion,ret=0x00007ffe221ae520)..[I] (sys_init) -> GetWindowsDirectoryA done(sys_win_dir=C:\Windows)..[D] (registry_get_value) -> Done(root=0xffffffff80000002,key=SOFTWARE\Microsoft\Cryptography,param=MachineGuid)..[I] (sys_init) -> GetWindowsDirectoryA done(sys_mach_guid=9e146be9-c76a-4720-bcdb-53011b87bd06)..[I] (sys_init) -> GetVolumeInformationA done(vol=C:\,vol_sn=81f395a1)..[I] (sys_init) -> Done(sys_uid=c76a8f0881f395a1,sys_os_ver=10.0.19045.0.0)..[I] (net_init) -> Done..[I] (server_init) -> CreateThread(routine_gc) done..[I] (server_init) -> CreateThread(routine_accept) done..[I] (server_init)
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:ASCII text, with CRLF line terminators
                                Category:dropped
                                Size (bytes):8812
                                Entropy (8bit):5.004039288486309
                                Encrypted:false
                                SSDEEP:192:b+FDwgDqM/VN8TWEMX4XpFsn/7BvvFQ6/C5:S3N8KX4pFsnS
                                MD5:1256DA672B8F39A275FE17E6C716F822
                                SHA1:B156C2186056CC5BFCA84549DD53F796936B2F6D
                                SHA-256:44DC1F938213E09A6EF6A64A9F14804530AE53F41E71813EFAF651D9516E246E
                                SHA-512:956D431C83ED0DD59D6F1F3101DCBCAD0C6BC1E06031141AAA236F7115A6CDAF95CCEA09E42CF1047D2205E8B37F87EA17BEBAABFB9C85B96D6FA12DE1C7F403
                                Malicious:false
                                Preview:## Configuration file for a typical i2pd user..## See https://i2pd.readthedocs.io/en/latest/user-guide/configuration/..## for more options you can use in this file.....## Lines that begin with "## " try to explain what's going on. Lines..## that begin with just "#" are disabled commands: you can enable them..## by removing the "#" symbol.....## Tunnels config file..## Default: ~/.i2pd/tunnels.conf or /var/lib/i2pd/tunnels.conf..# tunconf = /var/lib/i2pd/tunnels.conf....## Tunnels config files path..## Use that path to store separated tunnels in different config files...## Default: ~/.i2pd/tunnels.d or /var/lib/i2pd/tunnels.d..# tunnelsdir = /var/lib/i2pd/tunnels.d....## Path to certificates used for verifying .su3, families..## Default: ~/.i2pd/certificates or /var/lib/i2pd/certificates..# certsdir = /var/lib/i2pd/certificates....## Where to write pidfile (default: /run/i2pd.pid, not used in Windows)..# pidfile = /run/i2pd.pid....## Logging configuration section..## By default logs go
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:data
                                Category:dropped
                                Size (bytes):66138
                                Entropy (8bit):7.828263238514239
                                Encrypted:false
                                SSDEEP:1536:DcfdIJTAe0fhT4Fv/XkiO2ZgYd3218xs3svEykZd:aaTHl33O2u4XOsvQ
                                MD5:166C6727028BD4F428E411ED225117C6
                                SHA1:D08CB3E69EA6CF633349F990229E87CBA4BCD72A
                                SHA-256:63A0993B931DAD9DCCF08EA48A0D8E8BA94652EDA5BC84F787E640CDD0FC800A
                                SHA-512:90EDF532080C61E9FEE3B8C884E8894B8A52955410489BBCBA3A53AB7A2E291EC2D382A2CB1F5B304762207CBC1971F4A440281A5653257E7223CE171B3646A0
                                Malicious:false
                                Preview:I2Psu3..................................1721890600......reseed@cnc.netPK.........3.Xw.H.....a...;...routerInfo-6bL8xvKABpTmmQ-0qofqx9csy9SWPBPDE3hUrYsOrWo=.dat;t....C.>%.6.........Fh........E..e.<..Y..g{...k.W>6.|......3..~...F...Z..z..+.....I...;U.....X....>..........'..x.....X.B.....X2.Kly..-......L....3m%..+3...R-uC]..s#..}..mm.Y..JlY.,.....muR.C}R}C.*.+u..}.3.........+..#.K,L..J..|.+.m...l...9`.`...5b...XPl...l..=:I...~....E..>.!.....&..~.......i.&n%..e.X....\...i`.......o..[.V.....[Q..d..k..h..s#.C2.Y..iA.y.%.) q. +%I/;/.<.'5.858.......Z.I*(..$.............+..e.....Y.ZX..N.Z.......<g.~...-}.....f.E!.....G......Q[..e.;.....l....M...PK...........X.r......*...;...routerInfo-bfaXwwIiRX4zIAbSubKcynpxGzaHUWg7O6~I62TpPWI=.dat;.......f...$.f..._.>...9~.....-"{Z..Y...M(..*.)P.Z=......[.F....w...W.gF.B..Ys.[,..*..Oz.v......~V...v f`..xe..3.....8..1..d.....Z...........5c...yVi....i...srq.c^Z]FA...5KA~Q.-......5c...E@.A.yNT.y^QpIX`D..nEi`xe.....eZ.O.A.a.
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:data
                                Category:dropped
                                Size (bytes):512
                                Entropy (8bit):7.54503657449518
                                Encrypted:false
                                SSDEEP:6:LTv7HdsQGR0IKV39LmIlsNbJEwDf13Sj8pBeJ5/ufYSQurQBfw4NyvuqBOukTWRX:BsQR9x1lO2eN3lOWeu6wBv7kZT3AjGoB
                                MD5:46C0D6C7E1CDFD23468544ED40C2007B
                                SHA1:B8862DC7FE9D30CA3BBCF41ED462FD16C40F539D
                                SHA-256:347F36159022F246BA983EE0369DE2B658D75AB62B84CF5B931F6EB58C9AC8CA
                                SHA-512:40DA50FEFA6491D19A51662CDC2F52032C56548898B48654A13FE75698C8194E2FEC6C64D330B40AD6DA513349343E08622AE7ACCB63A0DF16FBD3061F7E1ADC
                                Malicious:false
                                Preview:......&..].....q...Wb|L...>.........b...?&...#.6.j..?4...R.Q.ZH..~.......~fs..`. 6.....BR.^@`....~.......i.p....H..._W..V$.m......X..{.i[3...q.1...U....l...)}..n.... JxM.u..(.!..u...i."l...Sl.&:.).de.R..].v..;.{*...b.v..&.....E;\...0TK...s.....:.z.!..4f.....t.b...$...f.....r....:..!...p..t.$....\.Tb..o.2.k.d....7r%..v+d.ZmEA.....Q...0....C....q.....M.4H....a...!je...........ct.dS...../.......O.&j..+..b.r.XR.B..[.@.X.iZ&....ko.B.YM2.....0..m..$..x.../.....T..3..$1W..1.5...8..
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:ASCII text, with CRLF line terminators
                                Category:dropped
                                Size (bytes):35948
                                Entropy (8bit):5.732819539542859
                                Encrypted:false
                                SSDEEP:768:Wm7qbLsUxWm6ABcbH6L00ZI7kX2MFu95eKbMmrqL6U+gsXnc1EZN8xso:xebL76AeH6L00ZI7y1FkeKbLOL6sz1E2
                                MD5:2B833954E244E54292022334B2ECBE32
                                SHA1:AC6052F7105B4BA10EC52A5C57A8E318CA164666
                                SHA-256:252BEE5FC4E082BC6C7DFD10E6B631EE1C1D6CE205B06B24CB53493CBBD56D19
                                SHA-512:D98AC5FA5EC4C422E88A33EF33DD8D349E900B58EE3DB505B511B38D321B83D3CDA6615C505EF95056646AA1C5D48F2C44501E9F6ED36D37625472A15A0FE485
                                Malicious:false
                                Preview:07:42:27@471/info - AESNI enabled..07:42:27@471/info - API: Starting NetDB..07:42:27@471/warn - Family: Can't load family certificates from C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\i2p\certificates\family..07:42:27@471/info - NetDb: 0 routers loaded (0 floodfils)..07:42:27@471/warn - Profiling: No profile yet for 6bL8xvKABpTmmQ-0qofqx9csy9SWPBPDE3hUrYsOrWo=..07:42:27@471/info - NetDb: RouterInfo added: 6bL8xvKABpTmmQ-0qofqx9csy9SWPBPDE3hUrYsOrWo=..07:42:27@471/info - NetDb: RouterInfo added: bfaXwwIiRX4zIAbSubKcynpxGzaHUWg7O6~I62TpPWI=..07:42:27@471/info - NetDb: RouterInfo added: DsvYfImUtDCJJtgrbBnvQrAkmeoDKe0r2x83Z2hjhDM=..07:42:27@471/warn - Profiling: No profile yet for E~S2QXf4oG3NCnl1gsCQbfzeFkaqevgyrjNf4Gn~raY=..07:42:27@471/info - NetDb: RouterInfo added: E~S2QXf4oG3NCnl1gsCQbfzeFkaqevgyrjNf4Gn~raY=..07:42:27@471/info - NetDb: RouterInfo added: Yly5nfw26VoRUHZZ4n9sI5UX4qoCFdMy2CVSZfOSXEM=..07:42:27@471/warn - Profiling: No profile yet for RGsysDsWkTToSgU
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:data
                                Category:dropped
                                Size (bytes):80
                                Entropy (8bit):6.04692809488736
                                Encrypted:false
                                SSDEEP:3:twkosSJqm4tfNSQmwIJNIvrGnUanyon:twhkdm/Qr0xntn
                                MD5:088FD090806D9F30F05D7DDF887B8461
                                SHA1:1D30EDE540B1586B0B43A0DF4D3550EFF19C2BDF
                                SHA-256:BBD6B1AF38CB7928732A7CFBAC014222A5A8DE5A1C845E213AACF2D7D42D13FA
                                SHA-512:C19ED74C85EA79576D57AAF8668FA7C618426BC465FCE3C893D77800008BA2CFA91620070E7C7B0043B3BCB27D1EF680EA7A723918ADBF9F9E2E64C2366ECFB7
                                Malicious:false
                                Preview:qU.q.JPZS.y....Z......#....6...9..(v..#.......J.........;..Ya..&..b4.4.}B...C
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:data
                                Category:dropped
                                Size (bytes):721
                                Entropy (8bit):6.555614565086438
                                Encrypted:false
                                SSDEEP:12:LX/s7/////////FqHxK8JAkkhHkf26oOBTasn:LX/s7/////////YHxEvBkFoO9asn
                                MD5:F9174E6B41A6A473158AC1F966914B27
                                SHA1:0D830BA98D7DE564AFC2F8F67BAEC7C4C61A7626
                                SHA-256:CFB88F9DE843929A22C655D25E222A29624714AB760176AA51081EA9CAEBE8D6
                                SHA-512:E196743204C120DB161469C645293F85C5EC8A675A41B7A17099A2395D271383A9E45C5AC987FA777D09198842167D46C432E2BDE6A67C24C18FD6D9B7280D07
                                Malicious:false
                                Preview:...*..t.....>.<...3...z.m...$G..I.:lo.d3M...#.r..@.....4.G..I.:lo.d3M...#.r..@.....4.G..I.:lo.d3M...#.r..@.....4.G..I.:lo.d3M...#.r..@.....4.G..I.:lo.d3M...#.r..@.....4.G..I.:lo.d3M...#.r..@.....4.G..I.:lo.d3M...#.r..@.....4.G..I.:lo.d3M...#.r..@.....4.G..I.:lo.d3M...#.r..@.....4.G..I.:lo.d3M...#.r..@.....4...h6.u$85zg.VBuy..zN..Z.~...<z.............Gu............NTCP2.@.caps=.4;.s=,cVW~cdVKUFpTDXn49-rcWh7P9b8ctCOGo5gYNoOlxzk=;.v=.2;..........SSU2.q.caps=.4;.i=,BKpOpplv9IdWJmss8ehKutgTbuqppS-EA4g8SXHlz-M=;.s=,0tVzlo-KxQNzHhjpDb3vgoLTBL2u2VM4YkeRvVBsbX4=;.v=.2;..,.caps=.LR;.netId=.2;.router.version=.0.9.60;3.hFy)N..jJ.o..C=CkGd..}.....<c..-.W.`Y.*...!l...$.BK.-m.Y.D..
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:data
                                Category:dropped
                                Size (bytes):455
                                Entropy (8bit):6.1261765648099615
                                Encrypted:false
                                SSDEEP:6:m6XAAd4UdSfTZXFZXFZXFZXFZXFZXFZXFZXFZXFZXnMr9aeISo+:LX/s7/////////QL
                                MD5:3AD796F50EBAAC900603CC60C06246F9
                                SHA1:9130FCF951C4DE74C7CA2D18C52EA533D6259921
                                SHA-256:40D236A1884062D7B72F9BA5547A46E8091F130646CFC1A0C0C46D927E7142DA
                                SHA-512:23C3F2F61DF73AC9189A994ACEAD8FE3EE00A53EFE8258931C0D724362A30FAA0343C9AAD410F8ED35DD99B96EAC76A5C9A3F0B21093191B0211C4C2AE58945E
                                Malicious:false
                                Preview:...*..t.....>.<...3...z.m...$G..I.:lo.d3M...#.r..@.....4.G..I.:lo.d3M...#.r..@.....4.G..I.:lo.d3M...#.r..@.....4.G..I.:lo.d3M...#.r..@.....4.G..I.:lo.d3M...#.r..@.....4.G..I.:lo.d3M...#.r..@.....4.G..I.:lo.d3M...#.r..@.....4.G..I.:lo.d3M...#.r..@.....4.G..I.:lo.d3M...#.r..@.....4.G..I.:lo.d3M...#.r..@.....4...h6.u$85zg.VBuy..zN..Z.~...<z............+2...,....'........4..;le6.)s.?!.\..F...I#hEhK....!};..
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:data
                                Category:dropped
                                Size (bytes):96
                                Entropy (8bit):6.256735677759421
                                Encrypted:false
                                SSDEEP:3:fUjW7uFKnPLdUm1C/gIvlGmNvFz6uDOa9v:ffuFKhUCC9lvFdOG
                                MD5:2E83436E40600D923E27A3FE7505BACF
                                SHA1:A6FE348694DB4FFF62E59D0FCC1F122E4DAF0B78
                                SHA-256:0FFFA8B889AE0034815A7EBA24709739C31D81AC6E7F62B5B1FA8FF6F98FABD4
                                SHA-512:0F5494E7238C3B11FE50006E651A8689322815D79AC78E36543A40455DCF31E96285DD9DD02840967D30F9652224BA536524E041F7AE4109E917E5C76445FAF6
                                Malicious:false
                                Preview:..s.....s...........S8bG..Plm~...i'..f.4.MI.h.T.,.@..;(..(..VM..N..o.V&k,..J...n./...<Iq...
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                Category:dropped
                                Size (bytes):9146880
                                Entropy (8bit):6.674746222402691
                                Encrypted:false
                                SSDEEP:196608:k1XYZ4Q+Kt8eiMFbO1CPwDvt3uF8f339CME:k1XgfieiMs1CPwDvt3uFe9CME
                                MD5:FE7ED803A7F672FAEE4587732B2C6E0F
                                SHA1:DF209D1B055044ABF4C0A6D4DE3EBFCD8D7784E1
                                SHA-256:154C3DCA584BB1F78C7AE7688D70998F2B62BED8884267E3FCF150BFEFE2C9D8
                                SHA-512:06E185F1689E7B5DFEF6625D99FF14DFCFF6C2203E9BE323FED3B6A9684C5179964969546D42F4639DB878903981BB15E0A8F62A1C5B2B0A47FA3496E05FDD3F
                                Malicious:true
                                Antivirus:
                                • Antivirus: ReversingLabs, Detection: 0%
                                • Antivirus: Virustotal, Detection: 0%, Browse
                                Joe Sandbox View:
                                • Filename: file.exe, Detection: malicious, Browse
                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...R.me..........."...).t]......R..0........................................P.......o....`... .......................................z..t... ...,............p..?...........p...............................`m.(....................*...............................text...(r]......t].................`..`.data.........]......x].............@....rdata.. >...@^..@....^.............@..@.pdata...?....p..@...^p.............@..@.xdata...t....t..v....t.............@..@.bss....`Q...@z..........................edata...t....z..v....z.............@..@.idata...,... ......................@....CRT....`....P......................@....tls.........`......................@....reloc.......p......................@..B........................................................................................................................................................................
                                Process:C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exe
                                File Type:PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
                                Category:dropped
                                Size (bytes):89088
                                Entropy (8bit):6.223370120951598
                                Encrypted:false
                                SSDEEP:1536:2IiMbJINPr6fRHJ4PuAyMonJqYcNtnOIkqGYtDtm3:JiMbJINP+fNJF/tJotOIpDtm
                                MD5:CFCBC15615FFC698507D32C0A7D21134
                                SHA1:F6DACCE59F78CA4EE6622C4A340923282EC3ADDE
                                SHA-256:A653F5DBEB0DDECBC16C70B0B8C9471ABB30C66032C2EE951DC36265F899D7D8
                                SHA-512:0AE08C2A2D56B976CBD748273A7AB8011F3EB82A22D58EBF44B73602FFA808E9A111A60AE250D441D11196522FD4C1AA6EC79193375EFFDC0207FFE7BBAB61DB
                                Malicious:true
                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......................(.....X.................@....................................x.....`... .................................................P............`..X...........................................`B..(....................................................text...h...........................`..`.data...............................@....rdata...P.......R..................@..@.pdata..X....`.......0..............@..@.xdata.......p.......:..............@..@.bss....P................................idata..P............D..............@....CRT....`............V..............@....tls.................X..............@....reloc...............Z..............@..B................................................................................................................................................................................................................
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:ASCII text, with CRLF line terminators
                                Category:dropped
                                Size (bytes):4672
                                Entropy (8bit):5.344035828155934
                                Encrypted:false
                                SSDEEP:96:idHwWYJ9VfyHzHH0Hf0HaSHvmHu5SHSGfipmHSm5SHLmHOn5SHHSHvmHX5SHpmHc:AziT6Tn0/06SOO5SkAz5Sic5SnSO35SV
                                MD5:71CF5ECF6CEF5D4BB72013249185FFE9
                                SHA1:2D4C3F9AC13559041648546C2F2576FDB6F3C9C1
                                SHA-256:CEB4CDD83D1266759AA781FC988FD6DC97C236C3CFC8555907E42C8BFBDA65B1
                                SHA-512:330F483FFB9649F2C3BFD05A288788433F8BCC9060185DCCCEFEB65D691B83196BC468AB060915CA3C4F57BF187F69C167EFB74DF5102756451BA8A0A9051A63
                                Malicious:false
                                Preview:[I] (debug_init) -> Log open success(flog_path=C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.log)..[I] (debug_init) -> Done..[I] (module_load) -> Done(name=ntdll.dll,ret=0x00007ffe22170000)..[D] (module_get_proc) -> Done(hnd=0x00007ffe22170000,name=RtlGetVersion,ret=0x00007ffe221ae520)..[I] (sys_init) -> GetWindowsDirectoryA done(sys_win_dir=C:\Windows)..[D] (registry_get_value) -> Done(root=0xffffffff80000002,key=SOFTWARE\Microsoft\Cryptography,param=MachineGuid)..[I] (sys_init) -> GetWindowsDirectoryA done(sys_mach_guid=9e146be9-c76a-4720-bcdb-53011b87bd06)..[I] (sys_init) -> GetVolumeInformationA done(vol=C:\,vol_sn=81f395a1)..[I] (sys_init) -> Done(sys_uid=c76a8f0881f395a1,sys_os_ver=10.0.19045.0.0)..[E] (package_install) -> Failed(pkg_path=C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\,tgt_path=C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\,err=00000003)..[I] (fs_file_read) -> Done(path=C:\Users\Public\Computer.{20d04fe0-3
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                Category:dropped
                                Size (bytes):105984
                                Entropy (8bit):6.293384667837124
                                Encrypted:false
                                SSDEEP:1536:ZPwYKFFHK6Qt+mPIg3aQtvv4+kWn+DnP8XprSCYA8CSs8qgu06wCYA8CSs8qgu08:lwf1KpFIg3hvIWmnP8XpD
                                MD5:B85FECC5E81D0CFBC3750C06E4A11412
                                SHA1:0F57603DB18BFE0A5EE50D618184E9ED4FCAFD7F
                                SHA-256:9FD76374C6E19923F99411D6F9BBF6614C94D81CD47630314C2AE21A94DF40A8
                                SHA-512:97D553317BB4D276E7F5F3C5808DCB8717319047512DEF6B96DA17D57248FFD5E374833A98F767F14BD8F3059DE464F7829D47C65D969BE868431FAAF6A61C1D
                                Malicious:true
                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."...(............\........................................@......bt....`... .........................................^.......................T............0..h...............................(.......................`............................text...............................`..`.data........ ......................@....rdata..Pc...0...d..................@..@.pdata..T............n..............@..@.xdata...............x..............@..@.bss....@................................edata..^...........................@..@.idata..............................@....CRT....X...........................@....tls......... ......................@....reloc..h....0......................@..B........................................................................................................................................................................
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:ASCII text, with CRLF line terminators
                                Category:dropped
                                Size (bytes):1167
                                Entropy (8bit):5.50821312859817
                                Encrypted:false
                                SSDEEP:24:CFAGHr5lGyclY7Gfy6BgT7cRE9FLxJDJt0ERpX3HeAOp:CFdHr54yclDYcm9FL3vNXeD
                                MD5:395FE061A21CC810082DBF7FA38C2A2D
                                SHA1:03BEFD760DD20181D39F8DD4AB636B5EE1892E9A
                                SHA-256:E82885A919E2AB24DABED793E0B747B1DD7BA0551AAD35259C5E31866FE80E09
                                SHA-512:593B2739CB930B1AFE537AA7C9E639FC0B79CF6025727634AD013B90E54D050B286B08736E008809283B1221E4CFAF20DF4A971D65F69FA771006393A7AFED70
                                Malicious:false
                                Preview:[I] (debug_init) -> Log open success(flog_path=C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\prgmgr.log)..[I] (debug_init) -> Done..[D] (ini_get_sec) -> Done(name=main)..[D] (ini_get_var) -> Done(sec=main,name=version,value=400004957b19a09d)..[I] (module_load) -> Done(name=ntdll.dll,ret=0x00007ffe22170000)..[D] (module_get_proc) -> Done(hnd=0x00007ffe22170000,name=RtlGetVersion,ret=0x00007ffe221ae520)..[I] (sys_init) -> GetWindowsDirectoryA done(sys_win_dir=C:\Windows)..[D] (registry_get_value) -> Done(root=0xffffffff80000002,key=SOFTWARE\Microsoft\Cryptography,param=MachineGuid)..[I] (sys_init) -> GetWindowsDirectoryA done(sys_mach_guid=9e146be9-c76a-4720-bcdb-53011b87bd06)..[I] (sys_init) -> GetVolumeInformationA done(vol=C:\,vol_sn=81f395a1)..[I] (sys_init) -> Done(sys_uid=c76a8f0881f395a1,sys_os_ver=10.0.19045.0.0)..[I] (net_init) -> Done..[I] (ebus_init) -> Done..[I] (ebus_subscribe) -> Done(handler=0x00007ffe11779d36)..[I] (tcp_connect) -> Done(sock=0x168,host=7
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                Category:dropped
                                Size (bytes):129024
                                Entropy (8bit):6.3129183036473915
                                Encrypted:false
                                SSDEEP:3072:7LZ2Dkkvacm5vSs9dHoLDS6o2zhoesVR8sZnv:/RLk9o2zk
                                MD5:FEF8651F5F797F30A37D7CD36BEA31AC
                                SHA1:8E85D22FB5247A69C1298D703D629DD46BC44C74
                                SHA-256:4083F67D11E7DF827BFF6C665B29F39FB197B4BA608D5C39ECFF46EA9A0B61F0
                                SHA-512:9C69D66690080A341C25EEB9E258FDE4DD4E94B80AF0085753E758378C1E1790FAEF48C7384AD5171C63BE156C68D0F207ECABF78D8AB5F367E04D5A34828851
                                Malicious:true
                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."...(.:..........\.........,.....................................~&....`... ...................................... ..^....0..D............................p..l...............................(...................p5...............................text...x9.......:..................`..`.data........P.......>..............@....rdata.......`.......@..............@..@.pdata..............................@..@.xdata..............................@..@.bss.....................................edata..^.... ......................@..@.idata..D....0......................@....CRT....X....P......................@....tls.........`......................@....reloc..l....p......................@..B........................................................................................................................................................................
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:ASCII text, with CRLF line terminators
                                Category:dropped
                                Size (bytes):1354
                                Entropy (8bit):5.503826806085153
                                Encrypted:false
                                SSDEEP:24:CFAGH75lGyclY7Gfy6BgT7cRE9FLxJDJt0dk1RDoyXegYcRAENmMeAOp:CFdH754yclDYcm9FL3vBycLMMeD
                                MD5:9863DDA07140FBEA82332DEECC99BBC8
                                SHA1:78E89D75BE3C7FA71F2DDD0C1EE7C496F445DA8F
                                SHA-256:603DD9ADC9A869CFBD3B3E3AD0AE8A674F4EC87CF0F09631F3834C2B7DC0755E
                                SHA-512:17C55D930BA1D7BC3C9510698612A56870DA08BC74C1ACB5CAC8599782871496DE80B74921D0C5F261DF63ADF106EBAA45074C19E2C7DEA8EC1AB8B3A441F153
                                Malicious:false
                                Preview:[I] (debug_init) -> Log open success(flog_path=C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\rdpctl.log)..[I] (debug_init) -> Done..[D] (ini_get_sec) -> Done(name=main)..[D] (ini_get_var) -> Done(sec=main,name=version,value=400004957b19a09d)..[I] (module_load) -> Done(name=ntdll.dll,ret=0x00007ffe22170000)..[D] (module_get_proc) -> Done(hnd=0x00007ffe22170000,name=RtlGetVersion,ret=0x00007ffe221ae520)..[I] (sys_init) -> GetWindowsDirectoryA done(sys_win_dir=C:\Windows)..[D] (registry_get_value) -> Done(root=0xffffffff80000002,key=SOFTWARE\Microsoft\Cryptography,param=MachineGuid)..[I] (sys_init) -> GetWindowsDirectoryA done(sys_mach_guid=9e146be9-c76a-4720-bcdb-53011b87bd06)..[I] (sys_init) -> GetVolumeInformationA done(vol=C:\,vol_sn=81f395a1)..[I] (sys_init) -> Done(sys_uid=c76a8f0881f395a1,sys_os_ver=10.0.19045.0.0)..[I] (scm_init) -> Done..[I] (net_init) -> Done..[I] (ebus_init) -> Done..[I] (proxy_init) -> Done..[I] (ebus_subscribe) -> Done(handler=0x00007ffe1174
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                Category:dropped
                                Size (bytes):37376
                                Entropy (8bit):5.7181012847214445
                                Encrypted:false
                                SSDEEP:768:2aS6Ir6sXJaE5I2IaK3knhQ0NknriB0dX5mkOpw:aDjDtKA0G0j5Opw
                                MD5:E3E4492E2C871F65B5CEA8F1A14164E2
                                SHA1:81D4AD81A92177C2116C5589609A9A08A5CCD0F2
                                SHA-256:32FF81BE7818FA7140817FA0BC856975AE9FCB324A081D0E0560D7B5B87EFB30
                                SHA-512:59DE035B230C9A4AD6A4EBF4BEFCD7798CCB38C7EDA9863BC651232DB22C7A4C2D5358D4D35551C2DD52F974A22EB160BAEE11F4751B9CA5BF4FB6334EC926C6
                                Malicious:false
                                Antivirus:
                                • Antivirus: ReversingLabs, Detection: 0%
                                • Antivirus: Virustotal, Detection: 0%, Browse
                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........qc..qc..qc......qc...`..qc...g..qc..qb..qc...b..qc...f..qc...c..qc...j..qc......qc...a..qc.Rich.qc.................PE..d...#............." .....Z...>.......]...............................................a....`A.........................................~..........@...............................\... x..T............................p...............q..P............................text....Y.......Z.................. ..`.rdata.......p.......^..............@..@.data...P............z..............@....pdata...............|..............@..@.rsrc...............................@..@.reloc..\...........................@..B........................................................................................................................................................................................................................................................
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                Category:dropped
                                Size (bytes):115712
                                Entropy (8bit):6.2749560583234105
                                Encrypted:false
                                SSDEEP:1536:9s2Ppklhc1NUWdaC/fHdHqTjhcqiBMAW4LFLvkgTzn6X8Y6ow6S:RIhc1NUWkC9qarBMILNz6X8Y6owz
                                MD5:D44FBD8760E79F5D950DB5BC6E86A398
                                SHA1:2175264673A9A5B7AF024D8E8F28879B1758ABC8
                                SHA-256:AD38977D88E19C24793C6AEE42B6389536B6879FAA50E2438350F140247A9DF2
                                SHA-512:9FD106939BF686D53676669755272CB59B2CCB7909BE27B40C7261988264E801CDC94503F3ED70B95CB0980C65153AA0CC66CA764C053846C4626FDE86E122E0
                                Malicious:true
                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."...(............\........................................P.......K....`... .........................................^....................................@..p...............................(...................X................................text...............................`..`.data........0......."..............@....rdata..pi...@...j...$..............@..@.pdata..............................@..@.xdata..............................@..@.bss.....................................edata..^...........................@..@.idata..............................@....CRT....X.... ......................@....tls.........0......................@....reloc..p....@......................@..B........................................................................................................................................................................
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:ASCII text, with CRLF line terminators
                                Category:dropped
                                Size (bytes):1926
                                Entropy (8bit):5.477443278024766
                                Encrypted:false
                                SSDEEP:48:CFdHr+54yclDYcm9FL3v6V//5ZR5+sR5HR5ikfP5OKXbeD:idHxNYJ9Vf6mD
                                MD5:0902968352608006AF4E59AD64C7AA17
                                SHA1:1B9501FE6D0197DDA5DF6BA8DBD88C79E04874CD
                                SHA-256:B574AFAC1B71A24313654134086F8574F26EBC8365F3BE18CCAFD181B4345F00
                                SHA-512:107F64D20F076F4576B0F0A31C6CA6C3052402E9DB8B74D6468BE8B3133BD4955897310B6E471E9CD60FA8F418F67090B4CFD470590AC150E7A5C51616A3C651
                                Malicious:false
                                Preview:[I] (debug_init) -> Log open success(flog_path=C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\samctl.log)..[I] (debug_init) -> Done..[D] (ini_get_sec) -> Done(name=main)..[D] (ini_get_var) -> Done(sec=main,name=version,value=400004957b19a09d)..[I] (module_load) -> Done(name=ntdll.dll,ret=0x00007ffe22170000)..[D] (module_get_proc) -> Done(hnd=0x00007ffe22170000,name=RtlGetVersion,ret=0x00007ffe221ae520)..[I] (sys_init) -> GetWindowsDirectoryA done(sys_win_dir=C:\Windows)..[D] (registry_get_value) -> Done(root=0xffffffff80000002,key=SOFTWARE\Microsoft\Cryptography,param=MachineGuid)..[I] (sys_init) -> GetWindowsDirectoryA done(sys_mach_guid=9e146be9-c76a-4720-bcdb-53011b87bd06)..[I] (sys_init) -> GetVolumeInformationA done(vol=C:\,vol_sn=81f395a1)..[I] (sys_init) -> Done(sys_uid=c76a8f0881f395a1,sys_os_ver=10.0.19045.0.0)..[I] (net_init) -> Done..[I] (sam_init) -> Done..[I] (ebus_init) -> Done..[I] (ebus_subscribe) -> Done(handler=0x00007ffe1171e21c)..[I] (tcp_connect) -
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                Category:dropped
                                Size (bytes):91136
                                Entropy (8bit):6.229599360032918
                                Encrypted:false
                                SSDEEP:1536:TP9ubSSddAQnoS8S1XsonSimrEozPyHzCnUbPICBL62:T1ubSSddAQoS8S1XsonGwW6CUbAC962
                                MD5:BF5D5BA471AB0266F991095FDCF74140
                                SHA1:42E890322966B7F2F9802C9E22269ED339C2969B
                                SHA-256:91DB57A2B77AC18B9605B08D7B926F9DC32C7E7D6F4047FBA0270A4403C288BB
                                SHA-512:B9F0113802C113F9FF5975989CC6CB9735CBE62D881E009FE853938604837996412332679C7EB7022B734401B2580D116566F7BA51CA62F787CF1D617B9EBC96
                                Malicious:true
                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."...(.....`......\...............................................B.....`... ..............................................................`..................d............................I..(......................h............................text...X...........................`..`.data...............................@....rdata.. T.......V..................@..@.pdata.......`.......8..............@..@.xdata..4....p.......B..............@..@.bss....@................................edata...............L..............@..@.idata...............N..............@....CRT....X............^..............@....tls.................`..............@....reloc..d............b..............@..B........................................................................................................................................................................
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:Generic INItialization configuration [SLPolicy]
                                Category:dropped
                                Size (bytes):435089
                                Entropy (8bit):5.449337416498263
                                Encrypted:false
                                SSDEEP:768:DUoDQVQpXQq4WDi9SUnpB8fbQnxJcy8RMFdKKb8x8Rr/d6gl/+f8jZ0ftlFn4p7V:TG6Gl33L+MOIiG4IvREWddadl/Fy/k8n
                                MD5:8CCA461A362EF864BDF35EDDE9F8E7A5
                                SHA1:83E7254EAA34C130EA56965E4CF46610AAF69C8F
                                SHA-256:785639D13771B021F191EC60E1C8E3E2EFEA164D2005F297A24559AEB0F58CCF
                                SHA-512:E01B175FAD5C6F718C9A504B49A516F270A93A277D8CCD11A41713CC337489FA0FBC3176B629A9A368A65D48CC31685F02DB6FDD486B91F31DF9F621E636817F
                                Malicious:false
                                Preview:; RDP Wrapper Library configuration..; Do not modify without special knowledge..; Edited by sebaxakerhtc....[Main]..Updated=2024-06-28..LogFile=\rdpwrap.txt..SLPolicyHookNT60=1..SLPolicyHookNT61=1....[SLPolicy]..TerminalServices-RemoteConnectionManager-AllowRemoteConnections=1..TerminalServices-RemoteConnectionManager-AllowMultipleSessions=1..TerminalServices-RemoteConnectionManager-AllowAppServerMode=1..TerminalServices-RemoteConnectionManager-AllowMultimon=1..TerminalServices-RemoteConnectionManager-MaxUserSessions=0..TerminalServices-RemoteConnectionManager-ce0ad219-4670-4988-98fb-89b14c2f072b-MaxSessions=0..TerminalServices-RemoteConnectionManager-45344fe7-00e6-4ac6-9f01-d01fd4ffadfb-MaxSessions=2..TerminalServices-RDP-7-Advanced-Compression-Allowed=1..TerminalServices-RemoteConnectionManager-45344fe7-00e6-4ac6-9f01-d01fd4ffadfb-LocalOnly=0..TerminalServices-RemoteConnectionManager-8dc86f1d-9969-4379-91c1-06fe1dc60575-MaxSessions=1000..TerminalServices-DeviceRedirection-Licenses-TS
                                Process:C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exe
                                File Type:data
                                Category:dropped
                                Size (bytes):10448885
                                Entropy (8bit):6.7084700728650555
                                Encrypted:false
                                SSDEEP:196608:D1XYZ4Q+Kt8eiMFbO1CPwDvt3uF8f339CMEv:D1XgfieiMs1CPwDvt3uFe9CMEv
                                MD5:B19DD73939F4D3249E87008653BFE5F5
                                SHA1:936A1DE5275E0EA2E4BC9BE7B724736B135B5BE4
                                SHA-256:7403BF80DA0910E3279FA603AE2D573B06F11D3D72585664965E593DAC92A0B6
                                SHA-512:103918920927C6E8BAC17293AB24E2E543B69FE3455E345FAA8A43C0B10F00827F4310552611EC349A1E3B6B02BEA8416A5DB52FB7A86A55D9E3D4DCF5FBF7F3
                                Malicious:false
                                Preview:.......cnccli.dll.MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."...(............\........."h.............................P......Zq....`... .........................................^....................................@..l........................... ...(.......................h............................text...X...........................`..`.data........0......................@....rdata..@d...@...f...(..............@..@.pdata..............................@..@.xdata..............................@..@.bss.....................................edata..^...........................@..@.idata..............................@....CRT....X.... ......................@....tls.........0......................@....reloc..l....@......................@..B.....................................................................................................................................................
                                Process:C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exe
                                File Type:ASCII text, with CRLF line terminators
                                Category:dropped
                                Size (bytes):3484
                                Entropy (8bit):5.491937416555677
                                Encrypted:false
                                SSDEEP:96:isYJ9VfDT0HU0Hn0H1Zt20H10H+kQHR3fPgRqY0HNVHyHH0HltHV2:DiTLT000H0Xt20V0TQxvPgRqY0tVSn0A
                                MD5:0EB6CEE38404B3E023D45F0DA45D6284
                                SHA1:46EC942239ADE21AFDE763C33BCA59DE6F2C2D52
                                SHA-256:223E00087E3C52617104CD2829A346952AC345EAB8080EE3190F0C1845995EF0
                                SHA-512:C593B32DA7284397244452C452841DCD20EAF35C013FB6A212D8AC75F5A600765054D2048112EDC736A5F1F4A5E00CEA7EDC3C03B7BDA824E6FBC28F3E69F1C8
                                Malicious:false
                                Preview:[I] (debug_init) -> Log open success(flog_path=C:\Users\user\AppData\Local\Temp\installer.log)..[I] (debug_init) -> Done..[I] (module_load) -> Done(name=ntdll.dll,ret=0x00007ffe22170000)..[D] (module_get_proc) -> Done(hnd=0x00007ffe22170000,name=RtlGetVersion,ret=0x00007ffe221ae520)..[I] (sys_init) -> GetWindowsDirectoryA done(sys_win_dir=C:\Windows)..[D] (registry_get_value) -> Done(root=0xffffffff80000002,key=SOFTWARE\Microsoft\Cryptography,param=MachineGuid)..[I] (sys_init) -> GetWindowsDirectoryA done(sys_mach_guid=9e146be9-c76a-4720-bcdb-53011b87bd06)..[I] (sys_init) -> GetVolumeInformationA done(vol=C:\,vol_sn=81f395a1)..[I] (sys_init) -> Done(sys_uid=c76a8f0881f395a1,sys_os_ver=10.0.19045.0.0)..[I] (net_init) -> Done..[I] (fs_path_expand) -> Done(path=%PUBLIC%,xpath=C:\Users\Public,xpath_sz=15)..[I] (fs_dir_create) -> Done(path=C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\,recursive=1)..[D] (fs_attr_get) -> Done(path=C:\Users\Public\Computer.{20d04fe0-3aea-10
                                Process:C:\Users\user\Desktop\QTmGYKK6SL.exe
                                File Type:PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
                                Category:dropped
                                Size (bytes):10636288
                                Entropy (8bit):6.704916902027684
                                Encrypted:false
                                SSDEEP:196608:F1XYZ4Q+Kt8eiMFbO1CPwDvt3uF8f339CME:F1XgfieiMs1CPwDvt3uFe9CME
                                MD5:1455F96A3552BFFCBD01FB90A2A4447B
                                SHA1:A0BEB097FB0F3FD1A83EF3D01BFF8706A40B32C1
                                SHA-256:CE82112E8B4476B65B09FCCD1CFF9F2F088FE4837C9129DE3D82CAEE138E6D7C
                                SHA-512:D2D8F7667CC44F136F34C30A8759C38AEE3FFBBDAFD1EB6329BF725F3C5CFCD1A0B2F64F9C12FEEE88680719CB4E3498BFC3D96927EF1F14CA6B4F1C79B52290
                                Malicious:true
                                Antivirus:
                                • Antivirus: Joe Sandbox ML, Detection: 100%
                                • Antivirus: ReversingLabs, Detection: 21%
                                • Antivirus: Virustotal, Detection: 23%, Browse
                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......................(.....H.................@.....................................@....`... ..............................................p...............0..d........................................... ...(....................u...............................text...............................`..`.data...P.........................@....rdata...^......`..................@..@.pdata..d....0......................@..@.xdata.......@.......&..............@..@.bss....P....P...........................idata.......p.......0..............@....CRT....`............F..............@....tls.................H..............@....reloc...............J..............@..B................................................................................................................................................................................................................
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                Category:dropped
                                Size (bytes):104448
                                Entropy (8bit):6.25639342609658
                                Encrypted:false
                                SSDEEP:1536:cTa6mu/WYUIdcVVKwU4k+EFfgvVFc2nx7ehX/DhZB34:cTa6mu5UIdc/KwzrGgw2x7ehX7hP34
                                MD5:7D37AB1E97BBC8593665FF365D8C96B7
                                SHA1:B42A6717F91A4C538A4979AB1F0A9CC58485061D
                                SHA-256:1DA31243257B0EBC79BA57CA98E6A3A1996CC4E2641E96098561CDCB1FA3EE46
                                SHA-512:60B3683FA7BCA42932E02AED4615E67264F31D6F85BEBCD3EA7187B9F7A9F79270341496432C07F7E9B10A3172AF22D636206FA5B89514A693405EC9D61F678D
                                Malicious:true
                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."...(............\.........?..............................0.......'....`... .........................................^.......................$............ ..l............................v..(.......................`............................text...............................`..`.data...............................@....rdata...a... ...b..................@..@.pdata..$............h..............@..@.xdata..T............r..............@..@.bss.... ................................edata..^............|..............@..@.idata...............~..............@....CRT....X...........................@....tls................................@....reloc..l.... ......................@..B........................................................................................................................................................................
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                Category:dropped
                                Size (bytes):37376
                                Entropy (8bit):5.7181012847214445
                                Encrypted:false
                                SSDEEP:768:2aS6Ir6sXJaE5I2IaK3knhQ0NknriB0dX5mkOpw:aDjDtKA0G0j5Opw
                                MD5:E3E4492E2C871F65B5CEA8F1A14164E2
                                SHA1:81D4AD81A92177C2116C5589609A9A08A5CCD0F2
                                SHA-256:32FF81BE7818FA7140817FA0BC856975AE9FCB324A081D0E0560D7B5B87EFB30
                                SHA-512:59DE035B230C9A4AD6A4EBF4BEFCD7798CCB38C7EDA9863BC651232DB22C7A4C2D5358D4D35551C2DD52F974A22EB160BAEE11F4751B9CA5BF4FB6334EC926C6
                                Malicious:false
                                Antivirus:
                                • Antivirus: ReversingLabs, Detection: 0%
                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........qc..qc..qc......qc...`..qc...g..qc..qb..qc...b..qc...f..qc...c..qc...j..qc......qc...a..qc.Rich.qc.................PE..d...#............." .....Z...>.......]...............................................a....`A.........................................~..........@...............................\... x..T............................p...............q..P............................text....Y.......Z.................. ..`.rdata.......p.......^..............@..@.data...P............z..............@....pdata...............|..............@..@.rsrc...............................@..@.reloc..\...........................@..B........................................................................................................................................................................................................................................................
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                Category:dropped
                                Size (bytes):105984
                                Entropy (8bit):6.293384667837124
                                Encrypted:false
                                SSDEEP:1536:ZPwYKFFHK6Qt+mPIg3aQtvv4+kWn+DnP8XprSCYA8CSs8qgu06wCYA8CSs8qgu08:lwf1KpFIg3hvIWmnP8XpD
                                MD5:B85FECC5E81D0CFBC3750C06E4A11412
                                SHA1:0F57603DB18BFE0A5EE50D618184E9ED4FCAFD7F
                                SHA-256:9FD76374C6E19923F99411D6F9BBF6614C94D81CD47630314C2AE21A94DF40A8
                                SHA-512:97D553317BB4D276E7F5F3C5808DCB8717319047512DEF6B96DA17D57248FFD5E374833A98F767F14BD8F3059DE464F7829D47C65D969BE868431FAAF6A61C1D
                                Malicious:true
                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."...(............\........................................@......bt....`... .........................................^.......................T............0..h...............................(.......................`............................text...............................`..`.data........ ......................@....rdata..Pc...0...d..................@..@.pdata..T............n..............@..@.xdata...............x..............@..@.bss....@................................edata..^...........................@..@.idata..............................@....CRT....X...........................@....tls......... ......................@....reloc..h....0......................@..B........................................................................................................................................................................
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:Generic INItialization configuration [SLPolicy]
                                Category:dropped
                                Size (bytes):435089
                                Entropy (8bit):5.449337416498263
                                Encrypted:false
                                SSDEEP:768:DUoDQVQpXQq4WDi9SUnpB8fbQnxJcy8RMFdKKb8x8Rr/d6gl/+f8jZ0ftlFn4p7V:TG6Gl33L+MOIiG4IvREWddadl/Fy/k8n
                                MD5:8CCA461A362EF864BDF35EDDE9F8E7A5
                                SHA1:83E7254EAA34C130EA56965E4CF46610AAF69C8F
                                SHA-256:785639D13771B021F191EC60E1C8E3E2EFEA164D2005F297A24559AEB0F58CCF
                                SHA-512:E01B175FAD5C6F718C9A504B49A516F270A93A277D8CCD11A41713CC337489FA0FBC3176B629A9A368A65D48CC31685F02DB6FDD486B91F31DF9F621E636817F
                                Malicious:false
                                Preview:; RDP Wrapper Library configuration..; Do not modify without special knowledge..; Edited by sebaxakerhtc....[Main]..Updated=2024-06-28..LogFile=\rdpwrap.txt..SLPolicyHookNT60=1..SLPolicyHookNT61=1....[SLPolicy]..TerminalServices-RemoteConnectionManager-AllowRemoteConnections=1..TerminalServices-RemoteConnectionManager-AllowMultipleSessions=1..TerminalServices-RemoteConnectionManager-AllowAppServerMode=1..TerminalServices-RemoteConnectionManager-AllowMultimon=1..TerminalServices-RemoteConnectionManager-MaxUserSessions=0..TerminalServices-RemoteConnectionManager-ce0ad219-4670-4988-98fb-89b14c2f072b-MaxSessions=0..TerminalServices-RemoteConnectionManager-45344fe7-00e6-4ac6-9f01-d01fd4ffadfb-MaxSessions=2..TerminalServices-RDP-7-Advanced-Compression-Allowed=1..TerminalServices-RemoteConnectionManager-45344fe7-00e6-4ac6-9f01-d01fd4ffadfb-LocalOnly=0..TerminalServices-RemoteConnectionManager-8dc86f1d-9969-4379-91c1-06fe1dc60575-MaxSessions=1000..TerminalServices-DeviceRedirection-Licenses-TS
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:data
                                Category:dropped
                                Size (bytes):66138
                                Entropy (8bit):7.828263238514239
                                Encrypted:false
                                SSDEEP:1536:DcfdIJTAe0fhT4Fv/XkiO2ZgYd3218xs3svEykZd:aaTHl33O2u4XOsvQ
                                MD5:166C6727028BD4F428E411ED225117C6
                                SHA1:D08CB3E69EA6CF633349F990229E87CBA4BCD72A
                                SHA-256:63A0993B931DAD9DCCF08EA48A0D8E8BA94652EDA5BC84F787E640CDD0FC800A
                                SHA-512:90EDF532080C61E9FEE3B8C884E8894B8A52955410489BBCBA3A53AB7A2E291EC2D382A2CB1F5B304762207CBC1971F4A440281A5653257E7223CE171B3646A0
                                Malicious:false
                                Preview:I2Psu3..................................1721890600......reseed@cnc.netPK.........3.Xw.H.....a...;...routerInfo-6bL8xvKABpTmmQ-0qofqx9csy9SWPBPDE3hUrYsOrWo=.dat;t....C.>%.6.........Fh........E..e.<..Y..g{...k.W>6.|......3..~...F...Z..z..+.....I...;U.....X....>..........'..x.....X.B.....X2.Kly..-......L....3m%..+3...R-uC]..s#..}..mm.Y..JlY.,.....muR.C}R}C.*.+u..}.3.........+..#.K,L..J..|.+.m...l...9`.`...5b...XPl...l..=:I...~....E..>.!.....&..~.......i.&n%..e.X....\...i`.......o..[.V.....[Q..d..k..h..s#.C2.Y..iA.y.%.) q. +%I/;/.<.'5.858.......Z.I*(..$.............+..e.....Y.ZX..N.Z.......<g.~...-}.....f.E!.....G......Q[..e.;.....l....M...PK...........X.r......*...;...routerInfo-bfaXwwIiRX4zIAbSubKcynpxGzaHUWg7O6~I62TpPWI=.dat;.......f...$.f..._.>...9~.....-"{Z..Y...M(..*.)P.Z=......[.F....w...W.gF.B..Ys.[,..*..Oz.v......~V...v f`..xe..3.....8..1..d.....Z...........5c...yVi....i...srq.c^Z]FA...5KA~Q.-......5c...E@.A.yNT.y^QpIX`D..nEi`xe.....eZ.O.A.a.
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                Category:dropped
                                Size (bytes):129024
                                Entropy (8bit):6.3129183036473915
                                Encrypted:false
                                SSDEEP:3072:7LZ2Dkkvacm5vSs9dHoLDS6o2zhoesVR8sZnv:/RLk9o2zk
                                MD5:FEF8651F5F797F30A37D7CD36BEA31AC
                                SHA1:8E85D22FB5247A69C1298D703D629DD46BC44C74
                                SHA-256:4083F67D11E7DF827BFF6C665B29F39FB197B4BA608D5C39ECFF46EA9A0B61F0
                                SHA-512:9C69D66690080A341C25EEB9E258FDE4DD4E94B80AF0085753E758378C1E1790FAEF48C7384AD5171C63BE156C68D0F207ECABF78D8AB5F367E04D5A34828851
                                Malicious:true
                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."...(.:..........\.........,.....................................~&....`... ...................................... ..^....0..D............................p..l...............................(...................p5...............................text...x9.......:..................`..`.data........P.......>..............@....rdata.......`.......@..............@..@.pdata..............................@..@.xdata..............................@..@.bss.....................................edata..^.... ......................@..@.idata..D....0......................@....CRT....X....P......................@....tls.........`......................@....reloc..l....p......................@..B........................................................................................................................................................................
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                Category:dropped
                                Size (bytes):92672
                                Entropy (8bit):6.241321016680509
                                Encrypted:false
                                SSDEEP:1536:uVq4VcOpVJ7Z4LB2gnUYQulkvJp0qn2goggVoOHDE:uVq4VcOph4LB2khdkYq2goggM
                                MD5:FB3BDB27D9C479148F3545ED99E65980
                                SHA1:A5860563DE81D8B74A1C842647E8F4AC7655842A
                                SHA-256:2B5DC45E89700D4B991ADDED1AA097641D60932B7BBE2C12FC8536B9D46F15A6
                                SHA-512:A26D4B169C4061FC7A2A5FEFAEB4AAE0E9A28211FA28F42B929EAAC3721DCBDD17A17ED6E77A79C17D93355CF85E4C46118E42D4F527ADF054AB1CC79C8B4D74
                                Malicious:true
                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."...(.....f......\.........Io....................................W.....`... .........................................^....................`..................l............................J..(....................................................text...............................`..`.data...............................@....rdata...U.......V..................@..@.pdata.......`.......<..............@..@.xdata.......p.......F..............@..@.bss....`................................edata..^............P..............@..@.idata...............R..............@....CRT....X............d..............@....tls.................f..............@....reloc..l............h..............@..B........................................................................................................................................................................
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                Category:dropped
                                Size (bytes):91136
                                Entropy (8bit):6.229599360032918
                                Encrypted:false
                                SSDEEP:1536:TP9ubSSddAQnoS8S1XsonSimrEozPyHzCnUbPICBL62:T1ubSSddAQoS8S1XsonGwW6CUbAC962
                                MD5:BF5D5BA471AB0266F991095FDCF74140
                                SHA1:42E890322966B7F2F9802C9E22269ED339C2969B
                                SHA-256:91DB57A2B77AC18B9605B08D7B926F9DC32C7E7D6F4047FBA0270A4403C288BB
                                SHA-512:B9F0113802C113F9FF5975989CC6CB9735CBE62D881E009FE853938604837996412332679C7EB7022B734401B2580D116566F7BA51CA62F787CF1D617B9EBC96
                                Malicious:true
                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."...(.....`......\...............................................B.....`... ..............................................................`..................d............................I..(......................h............................text...X...........................`..`.data...............................@....rdata.. T.......V..................@..@.pdata.......`.......8..............@..@.xdata..4....p.......B..............@..@.bss....@................................edata...............L..............@..@.idata...............N..............@....CRT....X............^..............@....tls.................`..............@....reloc..d............b..............@..B........................................................................................................................................................................
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:Generic INItialization configuration [cnccli]
                                Category:dropped
                                Size (bytes):214
                                Entropy (8bit):5.104102844508187
                                Encrypted:false
                                SSDEEP:6:1EVQLD4o8WnuJO+70X1YIzOD7kXpTRL9gWVUDeLn:Cjo8DJO+70X1YeC7kX9vgpKL
                                MD5:91D86E531FECE0D34AD78D947FC7331C
                                SHA1:52C9A7C16634637E9DB31A6CE63850DFB170B44D
                                SHA-256:A885C71096995389DF3015B194B9AD10AE24C4328F4322932D6455398B2FC653
                                SHA-512:1EE4ED0F8045670DBEE2C5C4F8100C362B84C1CCC1A2E7F4FD1E97EC057055F1A8DC75A0CE349CC01DBFFA2B18E7C7C2288845641358CA3A609B0E6FBD9F49B5
                                Malicious:false
                                Preview:[main]..version=400004957b19a09d..[cnccli]..server_host=c21a876e..server_port=41674..server_timeo=15000..i2p_try_num=10..i2p_sam3_timeo=15000..i2p_addr=2lyi6mgj6tn4eexl6gwnujwfycmq7dcus2x42petanvpwpjlqrhq.b32.i2p..
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                Category:dropped
                                Size (bytes):115200
                                Entropy (8bit):6.220309385007289
                                Encrypted:false
                                SSDEEP:1536:RQsjbnQsiAEVTEWeFENdEUD1/H6BELpsV4vN8qdnJNXq8Vc3:RQibZibeFENdppW54NdvXq6c3
                                MD5:E6CAC6ACD18D0BBAD9C2384B1DBEDE84
                                SHA1:63004A83FF18CCE911BC74D27C1A2B7BEA9CF4C3
                                SHA-256:9BC6EDD286F4DCD83E57B541BC99038F7E902DE943A6FD528BA485DF1187FFA8
                                SHA-512:43C745D49AB82809C24E5EE62E11406B12B695140117EB1012111EEA3B73F9B34B5ADE21A1DB3AA1FEAD982F266B05646A08A4813CBA2EA950C59A73AB069FB3
                                Malicious:true
                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."...(............\........."h.............................P......Zq....`... .........................................^....................................@..l........................... ...(.......................h............................text...X...........................`..`.data........0......................@....rdata..@d...@...f...(..............@..@.pdata..............................@..@.xdata..............................@..@.bss.....................................edata..^...........................@..@.idata..............................@....CRT....X.... ......................@....tls.........0......................@....reloc..l....@......................@..B........................................................................................................................................................................
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                Category:dropped
                                Size (bytes):115712
                                Entropy (8bit):6.2749560583234105
                                Encrypted:false
                                SSDEEP:1536:9s2Ppklhc1NUWdaC/fHdHqTjhcqiBMAW4LFLvkgTzn6X8Y6ow6S:RIhc1NUWkC9qarBMILNz6X8Y6owz
                                MD5:D44FBD8760E79F5D950DB5BC6E86A398
                                SHA1:2175264673A9A5B7AF024D8E8F28879B1758ABC8
                                SHA-256:AD38977D88E19C24793C6AEE42B6389536B6879FAA50E2438350F140247A9DF2
                                SHA-512:9FD106939BF686D53676669755272CB59B2CCB7909BE27B40C7261988264E801CDC94503F3ED70B95CB0980C65153AA0CC66CA764C053846C4626FDE86E122E0
                                Malicious:true
                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."...(............\........................................P.......K....`... .........................................^....................................@..p...............................(...................X................................text...............................`..`.data........0......."..............@....rdata..pi...@...j...$..............@..@.pdata..............................@..@.xdata..............................@..@.bss.....................................edata..^...........................@..@.idata..............................@....CRT....X.... ......................@....tls.........0......................@....reloc..p....@......................@..B........................................................................................................................................................................
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                Category:dropped
                                Size (bytes):9146880
                                Entropy (8bit):6.674746222402691
                                Encrypted:false
                                SSDEEP:196608:k1XYZ4Q+Kt8eiMFbO1CPwDvt3uF8f339CME:k1XgfieiMs1CPwDvt3uFe9CME
                                MD5:FE7ED803A7F672FAEE4587732B2C6E0F
                                SHA1:DF209D1B055044ABF4C0A6D4DE3EBFCD8D7784E1
                                SHA-256:154C3DCA584BB1F78C7AE7688D70998F2B62BED8884267E3FCF150BFEFE2C9D8
                                SHA-512:06E185F1689E7B5DFEF6625D99FF14DFCFF6C2203E9BE323FED3B6A9684C5179964969546D42F4639DB878903981BB15E0A8F62A1C5B2B0A47FA3496E05FDD3F
                                Malicious:true
                                Antivirus:
                                • Antivirus: ReversingLabs, Detection: 0%
                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...R.me..........."...).t]......R..0........................................P.......o....`... .......................................z..t... ...,............p..?...........p...............................`m.(....................*...............................text...(r]......t].................`..`.data.........]......x].............@....rdata.. >...@^..@....^.............@..@.pdata...?....p..@...^p.............@..@.xdata...t....t..v....t.............@..@.bss....`Q...@z..........................edata...t....z..v....z.............@..@.idata...,... ......................@....CRT....`....P......................@....tls.........`......................@....reloc.......p......................@..B........................................................................................................................................................................
                                Process:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                File Type:ASCII text, with CRLF line terminators
                                Category:dropped
                                Size (bytes):8812
                                Entropy (8bit):5.004039288486309
                                Encrypted:false
                                SSDEEP:192:b+FDwgDqM/VN8TWEMX4XpFsn/7BvvFQ6/C5:S3N8KX4pFsnS
                                MD5:1256DA672B8F39A275FE17E6C716F822
                                SHA1:B156C2186056CC5BFCA84549DD53F796936B2F6D
                                SHA-256:44DC1F938213E09A6EF6A64A9F14804530AE53F41E71813EFAF651D9516E246E
                                SHA-512:956D431C83ED0DD59D6F1F3101DCBCAD0C6BC1E06031141AAA236F7115A6CDAF95CCEA09E42CF1047D2205E8B37F87EA17BEBAABFB9C85B96D6FA12DE1C7F403
                                Malicious:false
                                Preview:## Configuration file for a typical i2pd user..## See https://i2pd.readthedocs.io/en/latest/user-guide/configuration/..## for more options you can use in this file.....## Lines that begin with "## " try to explain what's going on. Lines..## that begin with just "#" are disabled commands: you can enable them..## by removing the "#" symbol.....## Tunnels config file..## Default: ~/.i2pd/tunnels.conf or /var/lib/i2pd/tunnels.conf..# tunconf = /var/lib/i2pd/tunnels.conf....## Tunnels config files path..## Use that path to store separated tunnels in different config files...## Default: ~/.i2pd/tunnels.d or /var/lib/i2pd/tunnels.d..# tunnelsdir = /var/lib/i2pd/tunnels.d....## Path to certificates used for verifying .su3, families..## Default: ~/.i2pd/certificates or /var/lib/i2pd/certificates..# certsdir = /var/lib/i2pd/certificates....## Where to write pidfile (default: /run/i2pd.pid, not used in Windows)..# pidfile = /run/i2pd.pid....## Logging configuration section..## By default logs go
                                Process:C:\Windows\System32\WerFault.exe
                                File Type:MS Windows registry file, NT/2000 or above
                                Category:dropped
                                Size (bytes):1835008
                                Entropy (8bit):4.465588027990527
                                Encrypted:false
                                SSDEEP:6144:YIXfpi67eLPU9skLmb0b4IWSPKaJG8nAgejZMMhA2gX4WABl0uNXdwBCswSbh:NXD94IWlLZMM6YFHx+h
                                MD5:18A7F773AFC64BA71A3174DD874798D8
                                SHA1:05D1D7BBA6642DB7831DEEBCD7260D4D077D275F
                                SHA-256:64F1953CDEB5A5A7FB9E1FA675A1733EA6AD633D1B98C9FE424F6050BA78D604
                                SHA-512:0FC667BC1D50236A2BBA006688771A4B272DE71D79186E1CBFF7198A74F1B6B84E38C727A58B025CB2F1382C8A572DD0479C39FB8790AD912F2E709E0B926FBB
                                Malicious:false
                                Preview:regf6...6....\.Z.................... ...........\.A.p.p.C.o.m.p.a.t.\.P.r.o.g.r.a.m.s.\.A.m.c.a.c.h.e...h.v.e....c...b...#.......c...b...#...........c...b...#......rmtmj..+............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                File type:PE32+ executable (GUI) x86-64, for MS Windows
                                Entropy (8bit):6.075183250085094
                                TrID:
                                • Win64 Executable GUI (202006/5) 92.64%
                                • Win64 Executable (generic) (12005/4) 5.51%
                                • Generic Win/DOS Executable (2004/3) 0.92%
                                • DOS Executable Generic (2002/1) 0.92%
                                • VXD Driver (31/22) 0.01%
                                File name:QTmGYKK6SL.exe
                                File size:12'016'128 bytes
                                MD5:190e4ed7759276e78d16398673996b2b
                                SHA1:ce5bb936ab809356d5b0bc29b6be2e0d07d3dc0a
                                SHA256:d4e965deaaaa9d84359fbce89a2cb1966bca6bf525df8bbfb1ad9ed08df1daad
                                SHA512:99cf79aba0afc528341c3ef474ba4ab71e50faf497536e74f8d985c39e85d5e145fb86262bac3e95e4c7752c3c0294751d4a988c2f4fbe5bcfcd3c6d19ef9c70
                                SSDEEP:49152:h3FUhq8uEA5Cu+Ng9hxWpZdESPzNHk8aPu9ipJY0/CcjaChdReYEk8fSj+TBmkOv://CvGkk+8qc8On18iiDoA1PdxGdQI
                                TLSH:D0C64A6F76A58578C16EC23BC0A38F05E93370B90733C6E793A402685F669D35E7E624
                                File Content Preview:MZP.....................@...............................................!..L.!..This program must be run under Win64..$7.......................................................................................................................................
                                Icon Hash:0f3331383933070f
                                Entrypoint:0xcbd0a0
                                Entrypoint Section:.text
                                Digitally signed:false
                                Imagebase:0x400000
                                Subsystem:windows gui
                                Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                                DLL Characteristics:
                                Time Stamp:0x66A372C9 [Fri Jul 26 09:56:25 2024 UTC]
                                TLS Callbacks:
                                CLR (.Net) Version:
                                OS Version Major:5
                                OS Version Minor:2
                                File Version Major:5
                                File Version Minor:2
                                Subsystem Version Major:5
                                Subsystem Version Minor:2
                                Import Hash:1ed353d37eec2351405144927fa2357c
                                Instruction
                                push ebp
                                dec eax
                                sub esp, 20h
                                dec eax
                                mov ebp, esp
                                nop
                                dec eax
                                lea ecx, dword ptr [FFFE9808h]
                                call 00007F9363C586B0h
                                dec eax
                                mov eax, dword ptr [000B83FCh]
                                dec eax
                                mov ecx, dword ptr [eax]
                                call 00007F9363EF8731h
                                dec eax
                                mov eax, dword ptr [000B83EDh]
                                dec eax
                                mov ecx, dword ptr [eax]
                                mov dl, 01h
                                call 00007F9363EFB3E0h
                                dec eax
                                mov eax, dword ptr [000B83DCh]
                                dec eax
                                mov ecx, dword ptr [eax]
                                dec eax
                                mov edx, dword ptr [FFFE9132h]
                                dec esp
                                mov eax, dword ptr [000B89C3h]
                                call 00007F9363EF8733h
                                dec eax
                                mov eax, dword ptr [000B83BFh]
                                dec eax
                                mov ecx, dword ptr [eax]
                                call 00007F9363EF8944h
                                call 00007F9363C502EFh
                                jmp 00007F93644FD87Ah
                                nop
                                nop
                                call 00007F9363C504E6h
                                nop
                                dec eax
                                lea esp, dword ptr [ebp+20h]
                                pop ebp
                                ret
                                dec eax
                                nop
                                dec eax
                                lea eax, dword ptr [00000000h+eax]
                                dec eax
                                sub esp, 28h
                                call 00007F9363C4FA7Ch
                                dec eax
                                add esp, 28h
                                ret
                                int3
                                int3
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                NameVirtual AddressVirtual Size Is in Section
                                IMAGE_DIRECTORY_ENTRY_EXPORT0x9a60000x99.edata
                                IMAGE_DIRECTORY_ENTRY_IMPORT0x9960000x5022.idata
                                IMAGE_DIRECTORY_ENTRY_RESOURCE0xa8e0000x10e400.rsrc
                                IMAGE_DIRECTORY_ENTRY_EXCEPTION0xa210000x6c99c.pdata
                                IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                IMAGE_DIRECTORY_ENTRY_BASERELOC0x9a90000x77f9c.reloc
                                IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                IMAGE_DIRECTORY_ENTRY_TLS0x9a80000x28.rdata
                                IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                IMAGE_DIRECTORY_ENTRY_IAT0x9974e00x1300.idata
                                IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x99c0000x910c.didata
                                IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                .text0x10000x8bc1300x8bc200b3fe9a1ed1931d277bf4a4459132c6baunknownunknownunknownunknownIMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                .data0x8be0000xb7da80xb7e0017c3e6330ad28b0333381e0e682fcf1fFalse0.23081662134602313data4.9678713931139304IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                .bss0x9760000x1f12c0x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                .idata0x9960000x50220x5200b6c50884b06d185b3e0e5adccdbdc8ecFalse0.24213986280487804data4.309027972544423IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                .didata0x99c0000x910c0x920090ae02de82fa4c16bc78cc167eadf4eaFalse0.17069777397260275data3.932333073499333IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                .edata0x9a60000x990x200e2d71a5ffd4f3bef7d6ddffb2d86cc42False0.2578125data1.9097292504123948IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                .tls0x9a70000x1e40x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                .rdata0x9a80000x6d0x2003b865ba3ff3f216a3dd9f94558a7c19eFalse0.1953125data1.3848831201957763IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                .reloc0x9a90000x77f9c0x78000575f2261b16d059afc06f618f8d1775fFalse0.4357686360677083data6.422785322909365IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                .pdata0xa210000x6c99c0x6ca008f0acef375d8865e07fbe90ebaae5679False0.4971501006904488data6.496494357259558IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                .rsrc0xa8e0000x10e4000x10e400dfee6991e72429dbebfff72b7f828382False0.3487213445305273data6.450215863443641IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                NameRVASizeTypeLanguageCountryZLIB Complexity
                                RT_CURSOR0xa8ed580x134Targa image data - Map 64 x 65536 x 1 +32 "\001"EnglishUnited States0.38636363636363635
                                RT_CURSOR0xa8ee8c0x134dataEnglishUnited States0.4642857142857143
                                RT_CURSOR0xa8efc00x134dataEnglishUnited States0.4805194805194805
                                RT_CURSOR0xa8f0f40x134dataEnglishUnited States0.38311688311688313
                                RT_CURSOR0xa8f2280x134dataEnglishUnited States0.36038961038961037
                                RT_CURSOR0xa8f35c0x134dataEnglishUnited States0.4090909090909091
                                RT_CURSOR0xa8f4900x134Targa image data - RGB 64 x 65536 x 1 +32 "\001"EnglishUnited States0.4967532467532468
                                RT_ICON0xa8f5c40xaae7PNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0003199926858815
                                RT_ICON0xa9a0ac0x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0EnglishUnited States0.40778008298755186
                                RT_ICON0xa9c6540x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0EnglishUnited States0.5354127579737336
                                RT_ICON0xa9d6fc0x988Device independent bitmap graphic, 24 x 48 x 32, image size 0EnglishUnited States0.6524590163934426
                                RT_ICON0xa9e0840x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.7393617021276596
                                RT_STRING0xa9e4ec0x228data0.483695652173913
                                RT_STRING0xa9e7140x34cdata0.40165876777251186
                                RT_STRING0xa9ea600x390data0.3355263157894737
                                RT_STRING0xa9edf00x354data0.4307511737089202
                                RT_STRING0xa9f1440x438data0.40370370370370373
                                RT_STRING0xa9f57c0x3e4data0.3644578313253012
                                RT_STRING0xa9f9600x4e0data0.3141025641025641
                                RT_STRING0xa9fe400x290data0.4451219512195122
                                RT_STRING0xaa00d00x1f0data0.5262096774193549
                                RT_STRING0xaa02c00x1acdata0.5584112149532711
                                RT_STRING0xaa046c0x4ccdata0.3469055374592834
                                RT_STRING0xaa09380x594data0.36554621848739494
                                RT_STRING0xaa0ecc0x508data0.3641304347826087
                                RT_STRING0xaa13d40x398data0.28804347826086957
                                RT_STRING0xaa176c0x3a0data0.4267241379310345
                                RT_STRING0xaa1b0c0x1d8data0.5148305084745762
                                RT_STRING0xaa1ce40xccdata0.6666666666666666
                                RT_STRING0xaa1db00x1b8data0.5318181818181819
                                RT_STRING0xaa1f680x3e8data0.38
                                RT_STRING0xaa23500x3f0data0.3888888888888889
                                RT_STRING0xaa27400x3e4data0.36947791164658633
                                RT_STRING0xaa2b240x3d4data0.2826530612244898
                                RT_STRING0xaa2ef80x3e0data0.4183467741935484
                                RT_STRING0xaa32d80x434data0.3745353159851301
                                RT_STRING0xaa370c0x614data0.32005141388174807
                                RT_STRING0xaa3d200x448data0.3302919708029197
                                RT_STRING0xaa41680x34cdata0.3933649289099526
                                RT_STRING0xaa44b40x370data0.3568181818181818
                                RT_STRING0xaa48240x438data0.3907407407407407
                                RT_STRING0xaa4c5c0x17cdata0.4631578947368421
                                RT_STRING0xaa4dd80xccdata0.6225490196078431
                                RT_STRING0xaa4ea40x1d0data0.5344827586206896
                                RT_STRING0xaa50740x3dcdata0.3765182186234818
                                RT_STRING0xaa54500x3c0data0.35104166666666664
                                RT_STRING0xaa58100x314data0.38578680203045684
                                RT_STRING0xaa5b240x304data0.38212435233160624
                                RT_RCDATA0xaa5e280x627eJPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=6, datetime=2010:05:11 20:59:59], baseline, precision 8, 256x256, components 3EnglishUnited States0.9922265408106608
                                RT_RCDATA0xaac0a80x10data1.5
                                RT_RCDATA0xaac0b80x4d1f8raw G3 (Group 3) FAX, byte-paddedEnglishUnited States0.475767341150252
                                RT_RCDATA0xaf92b00x1054data0.4672248803827751
                                RT_RCDATA0xafa3040x2dataEnglishUnited States5.0
                                RT_RCDATA0xafa3080x151Delphi compiled form 'TForm1'0.7210682492581603
                                RT_RCDATA0xafa45c0x4c651dataEnglishUnited States0.17103795623703713
                                RT_RCDATA0xb46ab00x5580ddataEnglishUnited States0.2652239585861499
                                RT_GROUP_CURSOR0xb9c2c00x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.25
                                RT_GROUP_CURSOR0xb9c2d40x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.25
                                RT_GROUP_CURSOR0xb9c2e80x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                RT_GROUP_CURSOR0xb9c2fc0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                RT_GROUP_CURSOR0xb9c3100x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                RT_GROUP_CURSOR0xb9c3240x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                RT_GROUP_CURSOR0xb9c3380x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                                RT_GROUP_ICON0xb9c34c0x4cdataEnglishUnited States0.8026315789473685
                                DLLImport
                                oleaut32.dllSysFreeString, SysReAllocStringLen, SysAllocStringLen
                                advapi32.dllRegQueryValueExW, RegOpenKeyExW, RegCloseKey
                                user32.dllCharNextW, LoadStringW
                                kernel32.dllSleep, VirtualFree, VirtualAlloc, lstrlenW, VirtualQuery, QueryPerformanceCounter, GetTickCount, GetSystemInfo, GetVersion, CompareStringW, IsValidLocale, SetThreadLocale, GetSystemDefaultUILanguage, GetUserDefaultUILanguage, GetLocaleInfoW, WideCharToMultiByte, MultiByteToWideChar, GetACP, LoadLibraryExW, GetStartupInfoW, GetProcAddress, GetModuleHandleW, GetModuleFileNameW, GetCommandLineW, FindResourceW, FreeLibrary, GetLastError, UnhandledExceptionFilter, RtlUnwindEx, RtlUnwind, RaiseException, ExitProcess, ExitThread, SwitchToThread, GetCurrentThreadId, CreateThread, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, FindFirstFileW, FindClose, WriteFile, GetStdHandle, CloseHandle
                                kernel32.dllGetProcAddress, RaiseException, LoadLibraryA, GetLastError, TlsSetValue, TlsGetValue, LocalFree, LocalAlloc, GetModuleHandleW, FreeLibrary
                                user32.dllWINNLSEnableIME, SetClassLongPtrW, GetClassLongPtrW, SetWindowLongPtrW, GetWindowLongPtrW, CreateWindowExW, WindowFromPoint, WaitMessage, UpdateLayeredWindow, UpdateWindow, UnregisterClassW, UnhookWindowsHookEx, TranslateMessage, TranslateMDISysAccel, TrackPopupMenu, TrackMouseEvent, SystemParametersInfoW, ShowWindow, ShowScrollBar, ShowOwnedPopups, ShowCaret, SetWindowRgn, SetWindowsHookExW, SetWindowTextW, SetWindowPos, SetWindowPlacement, SetTimer, SetScrollRange, SetScrollPos, SetScrollInfo, SetRect, SetPropW, SetParent, SetMenuItemInfoW, SetMenu, SetForegroundWindow, SetFocus, SetCursorPos, SetCursor, SetClipboardData, SetCapture, SetActiveWindow, SendMessageTimeoutW, SendMessageA, SendMessageW, ScrollWindow, ScreenToClient, RemovePropW, RemoveMenu, ReleaseDC, ReleaseCapture, RegisterWindowMessageW, RegisterClipboardFormatW, RegisterClassW, RedrawWindow, PostQuitMessage, PostMessageW, PeekMessageA, PeekMessageW, OpenClipboard, MsgWaitForMultipleObjectsEx, MsgWaitForMultipleObjects, MessageBoxIndirectW, MessageBoxW, MessageBeep, MapWindowPoints, MapVirtualKeyW, LoadStringW, LoadKeyboardLayoutW, LoadIconW, LoadCursorW, LoadBitmapW, KillTimer, IsZoomed, IsWindowVisible, IsWindowUnicode, IsWindowEnabled, IsWindow, IsIconic, IsDialogMessageA, IsDialogMessageW, IsChild, InvalidateRect, InsertMenuItemW, InsertMenuW, HideCaret, GetWindowThreadProcessId, GetWindowTextLengthW, GetWindowTextW, GetWindowRect, GetWindowPlacement, GetWindowDC, GetUpdateRgn, GetUpdateRect, GetTopWindow, GetSystemMetrics, GetSystemMenu, GetSysColorBrush, GetSysColor, GetSubMenu, GetScrollRange, GetScrollPos, GetScrollInfo, GetScrollBarInfo, GetPropW, GetParent, GetWindow, GetMessagePos, GetMessageExtraInfo, GetMenuStringW, GetMenuState, GetMenuItemInfoW, GetMenuItemID, GetMenuItemCount, GetMenu, GetLastActivePopup, GetKeyboardState, GetKeyboardLayoutNameW, GetKeyboardLayoutList, GetKeyboardLayout, GetKeyState, GetKeyNameTextW, GetIconInfo, GetForegroundWindow, GetFocus, GetDlgCtrlID, GetDesktopWindow, GetDCEx, GetDC, GetCursorPos, GetCursor, GetClipboardData, GetClientRect, GetClassNameW, GetClassInfoExW, GetClassInfoW, GetCapture, GetActiveWindow, FrameRect, FindWindowExW, FindWindowW, FillRect, EnumWindows, EnumThreadWindows, EnumChildWindows, EndPaint, EndMenu, EnableWindow, EnableScrollBar, EnableMenuItem, EmptyClipboard, DrawTextExW, DrawTextW, DrawMenuBar, DrawIconEx, DrawIcon, DrawFrameControl, DrawFocusRect, DrawEdge, DispatchMessageA, DispatchMessageW, DestroyWindow, DestroyMenu, DestroyIcon, DestroyCursor, DeleteMenu, DefWindowProcW, DefMDIChildProcW, DefFrameProcW, CreatePopupMenu, CreateMenu, CreateIcon, CreateAcceleratorTableW, CopyImage, CopyIcon, CloseClipboard, ClientToScreen, CheckMenuItem, CharUpperBuffW, CharUpperW, CharNextW, CharLowerBuffW, CharLowerW, CallWindowProcW, CallNextHookEx, BeginPaint, AppendMenuW, AdjustWindowRectEx, ActivateKeyboardLayout
                                gdi32.dllUnrealizeObject, TextOutW, StretchDIBits, StretchBlt, StartPage, StartDocW, SetWindowOrgEx, SetWinMetaFileBits, SetViewportOrgEx, SetTextColor, SetTextAlign, SetStretchBltMode, SetRectRgn, SetROP2, SetPixel, SetMapMode, SetEnhMetaFileBits, SetDIBits, SetDIBColorTable, SetBrushOrgEx, SetBkMode, SetBkColor, SetAbortProc, SelectPalette, SelectObject, SaveDC, RoundRect, RestoreDC, Rectangle, RectVisible, RealizePalette, Polyline, Polygon, PolyBezierTo, PolyBezier, PlayEnhMetaFile, Pie, PatBlt, MoveToEx, MaskBlt, LineTo, IntersectClipRect, GetWindowOrgEx, GetWinMetaFileBits, GetTextMetricsW, GetTextExtentPointW, GetTextExtentPoint32W, GetTextAlign, GetSystemPaletteEntries, GetStockObject, GetRgnBox, GetRegionData, GetPixel, GetPaletteEntries, GetObjectA, GetObjectW, GetMapMode, GetEnhMetaFilePaletteEntries, GetEnhMetaFileHeader, GetEnhMetaFileDescriptionW, GetEnhMetaFileBits, GetDeviceCaps, GetDIBits, GetDIBColorTable, GetCurrentPositionEx, GetClipBox, GetCharABCWidthsFloatW, GetBrushOrgEx, GetBitmapBits, GdiFlush, FrameRgn, ExtTextOutW, ExtFloodFill, ExtCreateRegion, ExcludeClipRect, EnumFontsW, EnumFontFamiliesExW, EndPage, EndDoc, Ellipse, DeleteObject, DeleteEnhMetaFile, DeleteDC, CreateSolidBrush, CreateRectRgn, CreatePenIndirect, CreatePalette, CreateICW, CreateHalftonePalette, CreateFontIndirectW, CreateFontW, CreateDIBitmap, CreateDIBSection, CreateDCW, CreateCompatibleDC, CreateCompatibleBitmap, CreateBrushIndirect, CreateBitmap, CopyEnhMetaFileW, CombineRgn, Chord, BitBlt, ArcTo, Arc, AngleArc, AbortDoc
                                version.dllVerQueryValueW, GetFileVersionInfoSizeW, GetFileVersionInfoW
                                kernel32.dlllstrlenW, WriteFile, WideCharToMultiByte, WaitForSingleObject, WaitForMultipleObjectsEx, VirtualQueryEx, VirtualQuery, VirtualProtect, VirtualFree, VirtualAlloc, VerSetConditionMask, VerifyVersionInfoW, TryEnterCriticalSection, SwitchToThread, SuspendThread, Sleep, SizeofResource, SetThreadPriority, SetThreadLocale, SetLastError, SetFilePointer, SetEvent, SetErrorMode, SetEndOfFile, ResumeThread, ResetEvent, RemoveDirectoryW, ReadFile, RaiseException, QueryPerformanceFrequency, QueryPerformanceCounter, IsDebuggerPresent, OutputDebugStringW, MulDiv, LockResource, LocalFree, LoadResource, LoadLibraryW, LeaveCriticalSection, LCMapStringW, IsValidLocale, InitializeCriticalSection, HeapSize, HeapFree, HeapDestroy, HeapCreate, HeapAlloc, GlobalUnlock, GlobalSize, GlobalLock, GlobalFree, GlobalFindAtomW, GlobalDeleteAtom, GlobalAlloc, GlobalAddAtomW, GetVersionExW, GetVersion, GetUserDefaultLCID, GetTimeZoneInformation, GetTickCount, GetThreadPriority, GetThreadLocale, GetTempPathW, GetSystemDirectoryW, GetStdHandle, GetLongPathNameW, GetProcAddress, GetModuleHandleW, GetModuleFileNameW, GetLocaleInfoW, GetLocalTime, GetLastError, GetFullPathNameW, GetFileSize, GetFileAttributesW, GetExitCodeThread, GetDiskFreeSpaceW, GetDateFormatW, GetCurrentThreadId, GetCurrentThread, GetCurrentProcessId, GetCurrentProcess, GetCPInfoExW, GetCPInfo, GetACP, FreeResource, FreeLibrary, FormatMessageW, FindResourceW, FindFirstFileW, FindClose, ExpandEnvironmentStringsW, EnumSystemLocalesW, EnumResourceNamesW, EnumCalendarInfoW, EnterCriticalSection, DeleteFileW, DeleteCriticalSection, CreateThread, CreateFileW, CreateEventW, CompareStringW, CloseHandle
                                advapi32.dllRegUnLoadKeyW, RegSetValueExW, RegSaveKeyW, RegRestoreKeyW, RegReplaceKeyW, RegQueryValueExW, RegQueryInfoKeyW, RegOpenKeyExW, RegLoadKeyW, RegFlushKey, RegEnumValueW, RegEnumKeyW, RegEnumKeyExW, RegDeleteValueW, RegDeleteKeyW, RegCreateKeyExW, RegConnectRegistryW, RegCloseKey
                                kernel32.dllSleep
                                oleaut32.dllSafeArrayPtrOfIndex, SafeArrayGetUBound, SafeArrayGetLBound, SafeArrayCreate, VariantChangeType, VariantCopyInd, VariantCopy, VariantClear, VariantInit
                                oleaut32.dllGetErrorInfo, SysFreeString
                                ole32.dllCreateStreamOnHGlobal, ReleaseStgMedium, OleDraw, DoDragDrop, RevokeDragDrop, RegisterDragDrop, OleUninitialize, OleInitialize, CoTaskMemFree, CoTaskMemAlloc, CoCreateInstance, CoGetClassObject, CoUninitialize, CoInitialize, IsEqualGUID
                                comctl32.dllInitializeFlatSB, FlatSB_SetScrollProp, FlatSB_SetScrollPos, FlatSB_SetScrollInfo, FlatSB_GetScrollPos, FlatSB_GetScrollInfo, _TrackMouseEvent, ImageList_GetImageInfo, ImageList_SetIconSize, ImageList_GetIconSize, ImageList_Write, ImageList_Read, ImageList_GetDragImage, ImageList_DragShowNolock, ImageList_DragMove, ImageList_DragLeave, ImageList_DragEnter, ImageList_EndDrag, ImageList_BeginDrag, ImageList_Copy, ImageList_LoadImageW, ImageList_GetIcon, ImageList_Remove, ImageList_DrawEx, ImageList_Replace, ImageList_Draw, ImageList_SetOverlayImage, ImageList_GetBkColor, ImageList_SetBkColor, ImageList_ReplaceIcon, ImageList_Add, ImageList_SetImageCount, ImageList_GetImageCount, ImageList_Destroy, ImageList_Create
                                user32.dllEnumDisplayMonitors, GetMonitorInfoW, MonitorFromPoint, MonitorFromRect, MonitorFromWindow
                                msvcrt.dllisxdigit, isupper, isspace, ispunct, isprint, islower, isgraph, isdigit, iscntrl, isalpha, isalnum, toupper, tolower, strchr, strncmp, memset, memcpy, memcmp
                                shell32.dllShellExecuteW, Shell_NotifyIconW, DragQueryFileW
                                comdlg32.dllPageSetupDlgW, PrintDlgW, GetSaveFileNameW, GetOpenFileNameW
                                winspool.drvSetPrinterW, OpenPrinterW, GetPrinterW, GetDefaultPrinterW, EnumPrintersW, DocumentPropertiesW, DeviceCapabilitiesW, ClosePrinter
                                winspool.drvGetDefaultPrinterW
                                winmm.dlltimeGetTime
                                d3d9.dllDirect3DCreate9
                                NameOrdinalAddress
                                TMethodImplementationIntercept30x49efd0
                                __dbk_fcall_wrapper20x417ba0
                                dbkFCallWrapperAddr10xd7af58
                                Language of compilation systemCountry where language is spokenMap
                                EnglishUnited States
                                TimestampProtocolSIDSignatureSource PortDest PortSource IPDest IP
                                2024-07-27T13:43:00.851979+0200TCP2022930ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow4436348140.68.123.157192.168.2.4
                                2024-07-27T13:42:22.481435+0200TCP2022930ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow4434973140.68.123.157192.168.2.4
                                TimestampSource PortDest PortSource IPDest IP
                                Jul 27, 2024 13:42:08.734443903 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:08.739761114 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:08.739878893 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:08.740324020 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:08.745165110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:09.358750105 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:09.400306940 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:10.660351038 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:10.665370941 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:10.665448904 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:10.671946049 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:10.912239075 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:10.962618113 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.037878036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.040160894 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.045329094 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.045413971 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.050339937 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.534740925 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.534755945 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.534776926 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.534785032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.534794092 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.534801006 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.534810066 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.534816980 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.534831047 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.534840107 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.534857988 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.534857988 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.534857988 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.534943104 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.536824942 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.587594032 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.612842083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.612874031 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.613231897 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.623425961 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.623478889 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.623485088 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.623585939 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.623812914 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.628318071 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.628329992 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.628375053 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.628396034 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.628660917 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.628715992 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.633044958 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.633055925 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.633064032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.633100986 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.633107901 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.633158922 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.633457899 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.637794018 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.637804985 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.637851000 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.642611027 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.642662048 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.642668962 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.642694950 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.642725945 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.642748117 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.642757893 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.642811060 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.647387028 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.697191954 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.916518927 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.916572094 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.916606903 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.916654110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.916687012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.916718960 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.916748047 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.916754007 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.916749001 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.916834116 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.916923046 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.916958094 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.916985989 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.916990042 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.917025089 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.917043924 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.917077065 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.917109013 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.917129993 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.917141914 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.917171001 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.917195082 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.917221069 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.917253017 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.917270899 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.917284966 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.917316914 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.917335987 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.917349100 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.917383909 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.917399883 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.917676926 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.917741060 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.917896986 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.917928934 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.917960882 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.917983055 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.917993069 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.918025970 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.918040037 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.918060064 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.918092012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.918104887 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.918124914 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.918155909 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.918169022 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.918189049 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.918226957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.918237925 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.918258905 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.918291092 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.918303013 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.918828964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.918862104 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.918893099 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.918910980 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.918942928 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.918946981 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.918976068 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.919008017 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.919020891 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.919040918 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.919087887 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.919254065 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.919305086 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.922269106 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.922385931 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.922441959 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.923044920 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.923077106 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.923110008 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.923122883 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.923386097 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.923425913 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.923438072 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.923460960 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.923510075 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.923540115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.923572063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.923633099 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.923722029 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.923757076 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.923805952 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.924572945 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.924604893 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.924637079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.924654961 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.925889969 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.925923109 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.925942898 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.925955057 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.925987005 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.926002026 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.926019907 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.926069021 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.927892923 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.927926064 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.928016901 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.928033113 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.928065062 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.928097963 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.928118944 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.928174973 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.928215027 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.928230047 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.928832054 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.928914070 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.929008961 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.929040909 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.929073095 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.929101944 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.929105043 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.929163933 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.929686069 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.929718018 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.929749966 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.929775000 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.929995060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.930027962 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.930054903 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.930691957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.930723906 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.930753946 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.930757046 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.930815935 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.930823088 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.931042910 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.931101084 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.931715965 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.931746960 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.931781054 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.931817055 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.931874990 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.931935072 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.932200909 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.932369947 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.932404041 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.932430029 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.932540894 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.932573080 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.932599068 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.933207035 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.933239937 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.933267117 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.933270931 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.933326960 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.933896065 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.933928013 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.933959961 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.933985949 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.934216976 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.934274912 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.934380054 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.934413910 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.934472084 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.934520960 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.934704065 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.934765100 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.935216904 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.935250044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.935306072 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.935523987 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.935688972 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.935748100 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.935861111 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.936041117 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.936099052 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.936208010 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.936374903 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.936408043 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.936434984 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.936440945 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.936496973 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.936872959 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.937041044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.937098980 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.937201977 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.937232971 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.937267065 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.937290907 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.937521935 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.937582016 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.937706947 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.937738895 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.937772036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.937794924 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.937872887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.937930107 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.938013077 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.938215017 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.938246012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.938276052 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.938277960 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.938334942 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.938391924 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.938424110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.938457012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.938483953 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.938564062 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.938595057 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.938622952 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.938626051 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.938658953 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.938682079 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.938690901 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.938750029 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.939059019 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.939220905 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.939253092 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.939285994 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.939299107 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.939351082 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.939393044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.939424992 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.939457893 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.939483881 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.939563990 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.939594984 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.939623117 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.939627886 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.939660072 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.939682961 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.939907074 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.939965963 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.940092087 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.940123081 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.940155983 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.940180063 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.940248013 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.940279961 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.940305948 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.940313101 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.940367937 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.940399885 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.940434933 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.940491915 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.940740108 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.940773010 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.940804958 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.940828085 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.940838099 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.940891981 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.941132069 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.941164017 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.941196918 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.941217899 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.941227913 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.941282034 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.941308975 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.941342115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.941399097 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.941447020 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.941610098 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.941643953 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.941669941 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.941765070 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.941797018 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.941823006 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.941828966 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.941863060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.941884995 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.941937923 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.941970110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.941994905 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.942117929 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.942150116 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.942174911 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.942182064 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.942214012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.942238092 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.942245960 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.942279100 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.942302942 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.942460060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.942492008 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.942517996 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.942524910 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.942581892 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.942614079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.942646027 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.942677975 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.942703009 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.942711115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.942768097 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.942775011 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.942949057 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.942981005 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.943006039 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.943013906 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.943070889 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.979687929 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.979722023 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.979754925 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.979785919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.979818106 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.979849100 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.979882956 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.980032921 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.980034113 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.980047941 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.980079889 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.980106115 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.980113029 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.980144978 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.980176926 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.980176926 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.980209112 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.980237961 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.980241060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.980274916 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.980298996 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.980585098 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.980616093 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.980647087 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.980648041 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.980680943 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.980705023 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.980714083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.980763912 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.980775118 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.980796099 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.980828047 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.980854034 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.980860949 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.980892897 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.980920076 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.980925083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.980952978 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.980983019 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.981029987 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.981064081 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.981091022 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.981630087 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.981662035 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.981690884 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.981693983 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.981724977 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.981754065 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.981756926 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.981789112 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.981807947 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.981839895 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.981870890 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.981899023 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.981903076 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.981954098 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.981961966 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.981986046 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.982018948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.982043028 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.982662916 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.982697010 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.982726097 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.982747078 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.982778072 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.982803106 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.982810020 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.982841015 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.982865095 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.982872963 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.982903004 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.982928991 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.982935905 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.982968092 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.982990026 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.983000040 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.983031034 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.983057022 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.983063936 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.983094931 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.983119965 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.983125925 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.983156919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.983185053 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.983191967 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.983222961 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.983251095 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.983256102 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.983288050 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.983314991 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.983319044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.983351946 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.983375072 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.983383894 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.983416080 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.983439922 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.983448982 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.983481884 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.983505011 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.983967066 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.983999014 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.984026909 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.984129906 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.984162092 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.984186888 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.984190941 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.984246016 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.984282017 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.984529018 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.984560966 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.984586954 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.984594107 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.984626055 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.984651089 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.984658003 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.984714031 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.985179901 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.985210896 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.985243082 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.985268116 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.985358953 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.985393047 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.985418081 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.985424995 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.985457897 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.985482931 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.985490084 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.985522032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.985552073 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.985553026 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.985586882 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.985609055 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.985893965 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.985924959 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.985949993 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.985956907 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.985989094 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.986012936 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.986021042 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.986069918 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.986077070 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.986103058 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.986135006 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.986156940 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.986166000 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.986197948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.986222029 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.986228943 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.986260891 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.986285925 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.986293077 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.986325026 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.986342907 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.986356020 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.986411095 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:11.986532927 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.986736059 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.986768007 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:11.986792088 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.021492004 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.021542072 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.021576881 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.021610022 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.021644115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.021676064 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.021711111 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.021760941 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.021760941 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.021760941 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.021852016 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.067270994 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.067326069 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.067361116 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.067485094 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.067497015 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.067531109 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.067563057 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.067580938 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.067598104 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.067616940 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.067814112 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.067898989 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.067965984 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.068001032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.068028927 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.068058014 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.068317890 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.068350077 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.068381071 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.068382025 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.068416119 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.068439960 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.068449974 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.068500996 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.068530083 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.068533897 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.068567038 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.068591118 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.068603992 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.068635941 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.068656921 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.068825006 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.068856955 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.068883896 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.068888903 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.068922043 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.068945885 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.068954945 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.069010019 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.069545984 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.069577932 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.069611073 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.069637060 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.069715977 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.069749117 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.069776058 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.069780111 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.069837093 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.069852114 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.069885015 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.069916964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.069941998 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.069947958 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.069981098 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.070003986 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.070013046 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.070046902 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.070075989 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.070076942 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.070110083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.070139885 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.070142984 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.070197105 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.070204020 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.070280075 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.070313931 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.070358992 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.070436001 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.070496082 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.070580959 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.070614100 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.070646048 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.070672035 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.070895910 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.070930958 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.070951939 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.070962906 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.071012020 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.071017981 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.071043968 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.071077108 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.071099043 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.071108103 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.071140051 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.071168900 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.071172953 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.071228027 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.071417093 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.071449995 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.071499109 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.071510077 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.071532011 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.071563005 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.071588993 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.071597099 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.071646929 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.071671963 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.071680069 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.071712017 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.071738005 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.071744919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.071778059 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.071804047 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.072407007 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.072514057 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.072592020 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.072623968 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.072657108 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.072679043 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.072689056 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.072736979 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.072741985 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.072770119 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.072820902 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.072827101 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.072860956 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.072891951 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.072911024 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.072925091 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.072954893 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.072977066 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.073132992 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.073164940 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.073187113 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.073195934 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.073227882 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.073246956 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.073259115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.073291063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.073312998 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.073322058 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.073354006 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.073376894 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.073386908 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.073420048 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.073440075 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.073451042 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.073482990 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.073504925 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.073514938 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.073566914 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.073791981 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.073823929 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.073854923 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.073878050 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.073887110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.073919058 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.073940039 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.073951006 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.073982000 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.074002028 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.074013948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.074047089 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.074064970 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.109884977 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.109954119 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.109988928 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.109991074 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.110023022 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.110049009 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.110057116 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.110089064 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.110112906 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.110126019 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.110179901 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.155960083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.156024933 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.156059027 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.156085968 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.156090975 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.156124115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.156147957 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.156158924 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.156215906 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.156349897 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.156554937 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.156613111 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.156696081 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.156730890 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.156761885 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.156793118 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.156795025 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.156826973 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.156852007 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.156858921 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.156891108 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.156925917 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.156930923 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.156980991 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.156984091 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157016039 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157048941 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157071114 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.157100916 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157133102 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157151937 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.157165051 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157196999 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157217979 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.157227993 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157259941 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157286882 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.157290936 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157322884 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157356977 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157366991 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.157423019 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.157587051 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157618999 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157674074 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.157695055 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157727003 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157758951 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157778978 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.157790899 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157820940 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157845020 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.157854080 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157886028 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157903910 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.157917976 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157948971 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.157965899 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.157980919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.158015013 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.158034086 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.158242941 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.158303022 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.158653975 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.158754110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.158787012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.158809900 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.158989906 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.159043074 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.159116030 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.159148932 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.159181118 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.159205914 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.159212112 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.159245014 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.159281969 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.159295082 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.159326077 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.159352064 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.159358978 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.159424067 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.159544945 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.159576893 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.159609079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.159626007 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.159641027 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.159696102 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.159697056 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.159729958 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.159779072 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.159782887 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.159811974 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.159843922 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.159867048 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.160090923 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.160137892 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.160288095 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.160468102 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.160521984 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.160530090 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.160561085 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.160593033 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.160624027 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.160628080 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.160655975 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.160687923 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.160701990 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.160722971 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.160748959 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.160756111 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.160815954 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.161032915 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.161082983 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.161114931 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.161139011 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.161147118 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.161179066 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.161210060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.161215067 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.161242008 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.161262989 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.161273956 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.161304951 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.161329985 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.161336899 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.161369085 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.161395073 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.161401987 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.161434889 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.161454916 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.161467075 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.161498070 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.161516905 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.161530018 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.161561966 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.161582947 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.162105083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.162153959 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.162158966 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.162185907 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.162218094 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.162235975 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.162250042 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.162281036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.162302971 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.162312984 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.162345886 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.162367105 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.162378073 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.162412882 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.162429094 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.162465096 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.162497044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.162519932 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.162529945 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.162558079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.162585020 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.198358059 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.198415041 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.198486090 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.198518038 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.198565960 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.198569059 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.198601961 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.198633909 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.198649883 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.198668957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.198713064 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.255948067 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256040096 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256094933 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256119967 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.256145954 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256179094 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256198883 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.256211042 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256243944 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256264925 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.256274939 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256292105 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256308079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256324053 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256354094 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256370068 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256386042 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256401062 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256417036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256418943 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.256433010 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256465912 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256519079 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.256520033 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.256535053 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256568909 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256601095 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256627083 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.256633997 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256665945 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256689072 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.256697893 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256731033 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256762981 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256764889 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.256795883 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256819963 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.256828070 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256860971 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256882906 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.256906986 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256942034 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.256963015 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.256973982 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257006884 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257033110 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.257057905 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257091045 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257112980 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.257123947 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257157087 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257179022 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.257193089 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257225990 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257247925 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.257256985 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257289886 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257311106 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.257320881 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257356882 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257381916 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.257397890 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257431030 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257452965 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.257462978 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257497072 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257513046 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257519960 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.257527113 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257540941 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257555008 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.257555962 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257570028 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257589102 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.257621050 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.257875919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257888079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257893085 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.257931948 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.258058071 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.258068085 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.258075953 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.258085012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.258094072 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.258102894 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.258112907 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.258116007 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.258116007 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.258146048 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.258173943 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.258209944 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.258219957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.258229017 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.258270979 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.258291960 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.258296967 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.258337975 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.258898973 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.258908987 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.258918047 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.258923054 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.258927107 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.258930922 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.258934975 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.258987904 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.258996964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259005070 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259013891 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259021044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259030104 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259033918 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259037971 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259038925 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.259078979 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.259107113 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.259449005 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259459019 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259466887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259476900 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259485006 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259495020 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259509087 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.259536982 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.259563923 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.259571075 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259581089 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259589911 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259598970 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259608030 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259619951 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.259622097 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259630919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259639978 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259648085 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.259660959 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.259680033 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.260510921 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.260520935 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.260529041 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.260538101 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.260545969 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.260571003 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.260581970 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.260610104 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.287306070 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.287316084 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.287323952 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.287399054 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.287399054 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.287409067 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.287417889 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.287426949 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.287458897 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.287487984 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.342953920 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.342988014 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343023062 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343055010 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343102932 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343133926 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343168020 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343213081 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.343213081 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.343213081 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.343308926 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343364954 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.343400955 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343419075 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343431950 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343447924 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343462944 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343462944 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.343502045 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.343679905 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343688965 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343698025 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343707085 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343733072 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.343760967 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.343801022 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343811035 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343820095 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343830109 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343839884 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343849897 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343856096 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.343856096 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.343861103 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343872070 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.343880892 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.343904018 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.344568968 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.344578981 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.344587088 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.344595909 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.344605923 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.344614983 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.344623089 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.344624996 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.344634056 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.344644070 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.344649076 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.344649076 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.344654083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.344664097 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.344672918 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.344672918 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.344682932 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.344691038 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.344700098 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.344733953 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.345391989 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.345402002 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.345411062 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.345419884 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.345428944 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.345438957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.345448971 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.345459938 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.345463037 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.345463991 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.345501900 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.345501900 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.345932007 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.345942020 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.345954895 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.345963955 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.345973015 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.345982075 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.345984936 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.345992088 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.346002102 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.346010923 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.346010923 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.346010923 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.346019983 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.346030951 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.346033096 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.346040010 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.346050978 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.346051931 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.346060038 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.346070051 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.346086979 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.346926928 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.346936941 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.346944094 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.346952915 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.346961975 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.346971035 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.346976995 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.346978903 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.346987963 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.346993923 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.346997023 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347007036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347009897 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.347017050 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347026110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347031116 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.347035885 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347044945 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347049952 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.347054958 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347069025 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.347107887 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.347847939 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347857952 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347866058 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347875118 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347883940 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347893000 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347901106 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.347902060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347912073 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347920895 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.347920895 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347930908 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347939968 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347944975 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.347944975 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.347949982 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347959995 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347969055 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347979069 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.347984076 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.348006964 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.348007917 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.348750114 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.348759890 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.348767996 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.348777056 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.348786116 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.348794937 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.348799944 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.348804951 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.348814964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.348817110 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.348824024 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.348834991 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.348838091 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.348839045 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.348844051 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.348867893 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.348897934 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.375539064 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.375571966 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.375608921 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.375658035 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.375708103 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.375741959 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.375775099 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.375776052 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.375865936 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.375865936 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.415936947 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.432588100 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.432631969 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.432666063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.432698011 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.432729959 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.432761908 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.432795048 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.432802916 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.432804108 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.432804108 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.432826996 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.432859898 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.432873964 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.432892084 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.432924032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.432941914 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.432955980 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.432987928 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.433002949 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.433021069 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.433053017 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.433069944 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.433090925 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.433137894 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.435142994 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435174942 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435206890 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435228109 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.435256004 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435303926 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435305119 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.435337067 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435369015 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435386896 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.435403109 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435452938 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435452938 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.435484886 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435517073 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435534000 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.435548067 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435579062 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435594082 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.435611963 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435647011 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435659885 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.435681105 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435713053 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435725927 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.435745001 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435777903 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435816050 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.435826063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435858965 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435879946 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.435889006 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435921907 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435940981 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.435955048 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.435986996 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436005116 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.436018944 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436050892 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436069012 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.436080933 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436114073 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436134100 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.436145067 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436178923 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436189890 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.436211109 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436243057 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436256886 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.436275005 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436306953 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436325073 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.436340094 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436372042 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436388016 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.436403036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436434031 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436451912 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.436466932 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436518908 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436522007 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.436549902 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436582088 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436597109 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.436616898 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436649084 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436669111 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.436681032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436733961 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436748981 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.436767101 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436799049 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436820984 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.436831951 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436863899 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436885118 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.436896086 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436928034 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436950922 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.436959982 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.436990976 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437007904 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.437024117 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437057972 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437079906 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.437089920 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437122107 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437144041 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.437154055 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437186003 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437205076 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.437216997 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437249899 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437268972 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.437280893 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437313080 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437330008 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.437345028 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437376022 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437393904 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.437412024 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437443972 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437462091 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.437475920 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437506914 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437522888 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.437683105 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437715054 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437730074 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.437747002 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437778950 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437798023 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.437809944 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437840939 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437854052 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.437872887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437906027 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437920094 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.437937021 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437953949 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437968016 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437983036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.437983036 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.437997103 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.438011885 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.438014030 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.438041925 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.464201927 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.464243889 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.464293957 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.464302063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.464353085 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.464390039 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.464421988 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.464456081 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.464507103 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.464507103 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.464507103 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.464514017 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.509571075 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.526650906 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.526695013 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.526730061 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.526763916 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.526874065 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.526874065 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.527524948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.527556896 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.527592897 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.527700901 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.527707100 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.527734041 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.527757883 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.527766943 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.527798891 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.527817965 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.527832031 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.527863026 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.527884960 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.527894974 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.527926922 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.527947903 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.527959108 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.527992010 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.528011084 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.528024912 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.528055906 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.528075933 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.528088093 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.528120041 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.528139114 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.528263092 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.528295040 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.528316975 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.528346062 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.528377056 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.528400898 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.528410912 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.528443098 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.528465033 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.528477907 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.528527975 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.528532028 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.528610945 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.528642893 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.528666019 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.528676033 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.528707981 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.528727055 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.528740883 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.528774977 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.528790951 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.529087067 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.529119015 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.529139042 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.529150963 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.529181957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.529201984 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.529222012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.529253006 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.529274940 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.529285908 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.529319048 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.529339075 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.534183025 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.534246922 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.534288883 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.534415960 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.534466028 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.534497976 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.534568071 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.534569025 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.534646988 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.534679890 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.534712076 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.534735918 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.534744978 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.534797907 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.534953117 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.534985065 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.535017014 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.535038948 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.535048962 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.535083055 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.535101891 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.535110950 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.535166025 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.535247087 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.535283089 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.535315037 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.535337925 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.535346985 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.535379887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.535403013 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.535413980 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.535468102 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.535593033 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.535625935 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.535659075 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.535682917 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.535733938 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.535789967 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.535912991 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.535945892 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.535978079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.535999060 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.536010027 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.536040068 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.536063910 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.536072969 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.536103964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.536125898 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.536149025 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.536181927 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.536201954 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.536216021 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.536267042 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.536585093 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.536617041 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.536648035 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.536673069 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.536680937 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.536712885 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.536737919 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.536746025 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.536777973 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.536809921 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.536813021 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.536844015 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.536864996 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.536875010 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.536906958 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.536928892 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.536938906 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.536973000 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.536994934 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.537004948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.537059069 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.537488937 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.537538052 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.537569046 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.537594080 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.537600994 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.537632942 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.537655115 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.537664890 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.537697077 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.537718058 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.537729025 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.537759066 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.537784100 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.537791014 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.537822962 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.537846088 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.537854910 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.537885904 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.537909031 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.537919044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.537950993 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.537975073 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.555242062 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.555289030 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.555321932 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.555354118 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.555389881 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.555422068 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.555459023 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.555488110 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.555802107 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.615777016 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.615866899 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.615900993 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.615932941 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.615967035 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.615998983 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.616030931 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.616064072 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.616096973 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.616127968 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.616159916 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.616161108 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.616161108 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.616161108 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.616194010 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.616249084 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.616249084 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.616249084 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.616286039 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.616318941 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.616350889 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.616378069 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.616381884 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.616432905 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.616450071 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.616499901 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.616533995 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.616554022 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.616565943 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.616600037 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.616621971 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.616684914 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.616735935 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.616739988 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.616769075 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.616822958 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.616916895 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.616965055 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.616997004 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.617017984 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.617028952 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.617060900 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.617084980 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.617288113 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.617341042 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.617347956 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.617372990 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.617408991 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.617429972 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.617439985 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.617472887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.617494106 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.617537022 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.617569923 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.617592096 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.617603064 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.617635012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.617657900 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.617916107 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.617963076 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.617971897 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.618010998 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.618067026 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.622953892 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.623059034 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.623090029 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.623122931 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.623213053 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.623222113 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.623222113 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.623245001 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.623279095 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.623388052 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.623430014 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.623462915 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.623488903 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.623496056 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.623550892 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.623600960 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.623632908 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.623665094 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.623687029 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.623697042 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.623729944 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.623749971 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.624017000 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.624048948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.624070883 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.624080896 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.624113083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.624138117 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.624145031 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.624176979 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.624197960 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.624537945 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.624569893 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.624594927 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.624602079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.624634027 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.624660969 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.624672890 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.624727964 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.624883890 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.624916077 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.624949932 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.624969959 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.625036955 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.625092030 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.625117064 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.625149012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.625180006 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.625201941 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.625212908 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.625243902 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.625264883 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.625276089 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.625308037 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.625329018 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.625339985 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.625392914 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.625905991 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.625937939 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.625969887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.625992060 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.626003027 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.626034975 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.626058102 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.626070023 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.626140118 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.626396894 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.626444101 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.626476049 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.626498938 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.626507998 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.626538992 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.626562119 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.626570940 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.626602888 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.626624107 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.626633883 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.626686096 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.626697063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.626729012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.626760960 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.626781940 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.626791954 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.626823902 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.626842976 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.626856089 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.626908064 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.627510071 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.627542973 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.627574921 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.627599001 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.627608061 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.627660990 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.643364906 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.643418074 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.643479109 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.643583059 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.643625021 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.643656969 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.643688917 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.643721104 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.643800020 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.643800020 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.696973085 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.704881907 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.705046892 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.705077887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.705111980 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.705122948 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.705147028 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.705193043 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.705195904 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.705245972 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.705312967 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.705346107 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.705399036 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.705799103 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.705832005 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.705863953 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.705887079 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.706516981 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.706547976 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.706577063 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.706614971 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.706665039 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.706669092 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.706698895 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.706732035 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.706753016 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.706764936 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.706814051 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.706818104 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.706851006 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.706882000 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.706902027 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.706914902 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.706947088 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.706967115 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.706979036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.707031012 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.707180977 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.707242966 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.707276106 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.707298040 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.707341909 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.707397938 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.707453966 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.707485914 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.707539082 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.707842112 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.707890034 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.707921982 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.707942963 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.707954884 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.707988024 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.708007097 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.708158970 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.708190918 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.708219051 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.708256960 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.708290100 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.708312035 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.708322048 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.708370924 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.708374977 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.708421946 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.708455086 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.708475113 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.708506107 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.708538055 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.708566904 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.708570957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.708625078 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.713639975 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.713691950 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.713723898 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.713748932 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.713844061 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.713876963 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.713902950 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.713908911 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.713943958 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.713962078 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.714231968 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.714263916 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.714287996 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.714296103 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.714328051 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.714348078 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.714360952 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.714394093 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.714420080 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.714426041 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.714457035 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.714478016 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.714490891 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.714545965 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.714804888 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.714838028 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.714869976 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.714895010 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.714901924 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.714981079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.715002060 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.715013027 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.715046883 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.715066910 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.715078115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.715111017 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.715131044 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.715143919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.715209961 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.715504885 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.715537071 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.715568066 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.715593100 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.715600967 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.715632915 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.715656042 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.715665102 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.715697050 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.715718985 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.715728998 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.715780973 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.715792894 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.715825081 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.715857029 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.715878010 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.715888977 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.715920925 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.715941906 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.715953112 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.716006041 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.716526985 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.716559887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.716592073 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.716614962 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.716624975 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.716656923 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.716675997 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.716689110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.716718912 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.716742039 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.716751099 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.716783047 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.716799974 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.716814995 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.716867924 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.716880083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.716912985 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.716943979 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.716964006 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.716980934 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.717031956 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.717279911 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.717312098 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.717344046 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.717363119 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.717375994 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.717411041 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.717428923 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.717443943 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.717485905 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.717495918 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.732036114 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.732132912 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.732165098 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.732253075 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.732259035 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.732291937 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.732325077 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.732366085 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.732403994 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.732435942 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.732460022 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.775177956 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.794084072 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.794135094 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.794167042 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.794198990 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.794208050 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.794233084 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.794256926 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.794265032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.794298887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.794428110 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.794603109 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.794658899 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.794733047 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.794764996 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.794820070 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.794884920 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.794918060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.794950962 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.794970989 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.794982910 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.795036077 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.796199083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.796231031 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.796264887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.796288013 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.796314001 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.796367884 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.796515942 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.796547890 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.796597004 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.796605110 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.796628952 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.796663046 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.796683073 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.796695948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.796731949 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.796746969 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.796765089 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.796818972 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.796930075 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.796962023 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.797014952 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.797080994 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.797112942 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.797144890 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.797166109 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.797218084 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.797249079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.797271967 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.797281981 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.797334909 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.797368050 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.797400951 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.797432899 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.797456980 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.797511101 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.797564983 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.797653913 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.797686100 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.797718048 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.797739029 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.797749996 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.797802925 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.802388906 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.802422047 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.802454948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.802486897 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.802489042 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.802545071 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.802615881 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.802648067 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.802680016 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.802700996 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.802712917 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.802766085 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.802791119 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.802823067 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.802854061 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.802877903 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.802886009 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.802918911 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.802937984 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.803049088 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.803081989 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.803102970 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.803113937 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.803147078 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.803165913 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.803179979 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.803212881 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.803231001 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.803245068 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.803277969 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.803296089 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.803560972 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.803592920 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.803617001 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.803625107 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.803657055 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.803673029 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.803688049 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.803720951 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.803740025 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.803834915 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.803867102 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.803889036 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.803899050 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.803930044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.803950071 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.803961992 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.803988934 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804013014 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.804042101 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804075003 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804092884 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.804106951 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804138899 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804161072 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.804167986 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804198980 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804219961 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.804231882 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804284096 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.804336071 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804363012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804426908 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804430008 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.804460049 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804512024 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804513931 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.804543018 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804572105 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804598093 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.804605007 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804636955 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804658890 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.804670095 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804719925 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.804868937 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804900885 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804933071 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804955006 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.804964066 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.804995060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.805016041 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.805026054 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.805058002 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.805077076 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.805092096 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.805123091 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.805140018 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.805149078 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.805181980 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.805202961 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.805213928 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.805246115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.805264950 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.805278063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.805309057 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.805330038 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.805341005 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.805372953 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.805394888 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.820959091 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.820974112 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.820986986 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.821001053 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.821016073 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.821145058 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.821154118 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.821161032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.821155071 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.821238995 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.821271896 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.869026899 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.882656097 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.882685900 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.882700920 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.882715940 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.882730961 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.882745981 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.882972002 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.883004904 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.883021116 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.883318901 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.883734941 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.883749962 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.883764029 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.883879900 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.883888006 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.883894920 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.883909941 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.883939981 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.883969069 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.883985996 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.884784937 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.884846926 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.884891033 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.884907007 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.884963989 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.884964943 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885066032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885081053 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885096073 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885111094 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885114908 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.885126114 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885139942 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885152102 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.885179043 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.885194063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885209084 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885221958 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885236025 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885243893 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.885251045 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885262012 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.885297060 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.885407925 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885516882 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885531902 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885565996 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.885713100 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885727882 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885741949 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885756969 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885763884 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.885791063 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.885910988 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885935068 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885948896 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885963917 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885967016 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.885978937 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885994911 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.885996103 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.886032104 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.886288881 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.886338949 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.890912056 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.890974998 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.890991926 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891028881 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.891084909 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891100883 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891114950 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891129017 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891144991 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891253948 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.891253948 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.891253948 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.891315937 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891331911 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891345024 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891381979 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.891429901 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891444921 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891459942 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891479969 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.891499043 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.891623974 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891638041 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891652107 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891666889 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891680956 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891690016 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.891696930 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891706944 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.891711950 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891727924 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891741991 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.891783953 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.891968966 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891983986 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.891999006 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.892014980 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.892030954 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.892030954 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.892046928 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.892072916 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.892103910 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.892290115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.892304897 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.892318010 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.892332077 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.892347097 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.892357111 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.892360926 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.892375946 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.892378092 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.892394066 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.892411947 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.892435074 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.892658949 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.892674923 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.892688036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.892703056 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.892719030 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.892724037 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.892733097 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.892749071 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.892750025 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.892777920 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.893007994 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893028975 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893043995 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893059015 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893058062 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.893074036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893093109 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893098116 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.893107891 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893122911 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893130064 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.893136978 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893146992 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.893151999 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893167019 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893181086 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893196106 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893202066 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.893210888 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893223047 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.893229008 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893241882 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.893275023 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.893574953 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893682957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893697977 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893712997 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893728971 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893734932 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.893743038 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893758059 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893759012 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.893773079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.893781900 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.893820047 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.909745932 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.909816980 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.909833908 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.909864902 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.909898996 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.909929991 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.909962893 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.909997940 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.909998894 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.909998894 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.962743044 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.972008944 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.972024918 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.972038984 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.972099066 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.972322941 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.972337008 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.972349882 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.972363949 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.972379923 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.972392082 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.972400904 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.972400904 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.972433090 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.972588062 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.972600937 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.972614050 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.972628117 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.972641945 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.972647905 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.972656965 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.972667933 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.972671986 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.972690105 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.972713947 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.975011110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.975066900 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.975080967 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.975119114 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.975238085 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.975253105 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.975265026 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.975280046 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.975286007 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.975315094 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.975523949 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.975538015 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.975550890 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.975565910 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.975570917 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.975579977 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.975589991 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.975594997 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.975610971 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.975631952 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.975658894 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.976248980 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.976264954 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.976278067 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.976291895 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.976306915 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.976308107 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.976320982 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.976335049 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.976349115 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.976350069 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.976365089 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.976366043 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.976380110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.976393938 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.976401091 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.976408958 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.976418018 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.976452112 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.976641893 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.980917931 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.980931997 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.980948925 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.980993986 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.981025934 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.981060028 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981074095 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981087923 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981101990 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981117964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981127024 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.981148005 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.981257915 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981272936 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981324911 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981324911 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.981338024 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981378078 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.981456995 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981471062 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981484890 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981497049 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981508970 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.981537104 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.981638908 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981653929 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981667995 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981681108 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981693029 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.981698036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981714010 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.981717110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981746912 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.981869936 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981918097 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.981956005 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981977940 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.981992006 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.982023001 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.982127905 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.982142925 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.982156992 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.982172012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.982175112 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.982203007 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.982400894 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.982415915 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.982429028 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.982443094 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.982453108 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.982460022 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.982472897 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.982492924 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.982498884 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.982511997 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.982549906 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.983105898 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983175039 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983186960 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983220100 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.983258009 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983270884 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983283997 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983297110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983309984 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.983311892 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983329058 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.983342886 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983346939 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.983491898 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983505964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983520031 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983532906 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983547926 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983547926 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.983561993 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983566046 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.983577967 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983587027 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.983592987 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983628988 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983629942 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.983644009 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983673096 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.983870029 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983920097 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983920097 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.983936071 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983951092 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.983979940 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.984132051 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.984143972 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.984158039 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.984183073 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.984184027 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.984196901 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.984204054 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.984210968 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.984240055 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.984246969 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.984253883 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.984287024 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.999349117 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.999386072 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.999435902 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.999468088 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.999500036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.999531031 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.999536991 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.999536991 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.999536991 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:12.999563932 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:12.999625921 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.060691118 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.060761929 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.060837030 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.060889959 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.060931921 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.060951948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.061006069 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.061007023 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.061059952 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.061065912 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.061111927 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.061156988 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.061182022 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.061204910 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.061249971 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.061253071 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.061300993 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.061347008 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.061429024 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.061474085 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.061518908 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.061521053 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.063808918 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.063854933 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.063864946 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.063899994 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.063956976 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.063961029 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.064007998 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.064052105 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.064060926 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.064096928 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.064142942 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.064146996 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.064285040 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.064328909 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.064335108 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.064374924 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.064419985 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.064429998 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.064465046 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.064531088 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.064601898 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.064647913 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.064692974 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.064696074 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.064824104 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.064868927 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.064879894 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.064913988 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.064956903 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.064963102 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.065001965 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.065045118 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.065052032 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.065089941 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.065134048 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.065150023 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.065177917 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.065222979 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.065223932 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.065371037 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.065414906 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.065418005 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.069458008 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.069511890 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.069521904 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.069567919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.069617987 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.069808006 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.069869995 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.069915056 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.069919109 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.069976091 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.070022106 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.070023060 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.070066929 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.070118904 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.070125103 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.070177078 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.070220947 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.070223093 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.070266962 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.070300102 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.070321083 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.070354939 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.070409060 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.070417881 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.070462942 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.070514917 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.070522070 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.070566893 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.070611000 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.070614100 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.070676088 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.070738077 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.070739031 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.070782900 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.070827007 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.070830107 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.070872068 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.070916891 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.070931911 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.070976019 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.071022987 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.071028948 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.071067095 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.071111917 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.071113110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.071172953 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.071217060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.071221113 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.071269035 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.071314096 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.071319103 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.071358919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.071407080 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.071408033 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.071482897 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.071544886 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.071830034 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.071924925 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.071969986 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.071978092 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.072016001 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.072062969 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.072088957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.072132111 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.072176933 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.072179079 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.072222948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.072271109 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.072349072 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.072393894 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.072438002 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.072441101 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.072532892 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.072592974 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.072593927 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.072638988 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.072680950 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.072685957 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.072726011 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.072771072 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.072777987 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.072803974 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.072855949 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.072859049 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.072905064 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.072951078 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.072954893 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.073174953 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.073220015 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.073232889 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.073266029 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.073304892 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.073316097 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.073354006 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.073400974 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.073400974 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.088102102 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.088148117 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.088157892 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.088196039 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.088257074 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.088259935 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.088306904 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.088350058 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.088361025 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.088397026 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.088443041 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.150645018 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.151062965 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.151107073 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.151150942 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.151210070 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.151257038 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.151299953 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.151350975 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.151350975 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.151350975 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.151365995 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.151412964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.151423931 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.151458025 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.151516914 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.151530981 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.151576042 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.151633024 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.151684999 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.151839018 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.151895046 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.152678967 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.152740955 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.152785063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.152796030 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.152888060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.152930975 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.152941942 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.152977943 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.153023005 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.153029919 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.153122902 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.153167963 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.153175116 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.153213978 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.153258085 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.153265953 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.153302908 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.153347015 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.153353930 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.153506994 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.153552055 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.153561115 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.154350996 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.154411077 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.154490948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.154659033 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.154704094 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.154711962 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.155009985 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.155055046 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.155065060 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.155169010 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.155222893 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.155299902 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.155344963 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.155390978 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.156248093 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.156308889 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.156353951 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.156358004 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.156394958 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.156440020 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.158881903 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.159200907 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.159259081 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.159382105 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.159427881 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.159471989 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.159482002 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.159517050 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.159560919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.159569979 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.159606934 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.159651995 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.159653902 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.159698009 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.159740925 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.159749031 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.159818888 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.159863949 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.159866095 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.159909964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.159962893 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.160335064 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.160381079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.160424948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.160433054 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.160497904 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.160554886 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.160576105 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.160621881 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.160674095 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.160681009 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.160725117 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.160768032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.160778046 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.160830021 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.160875082 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.160888910 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.160919905 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.160970926 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.160980940 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.161026001 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.161070108 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.161081076 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.161114931 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.161159039 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.161180973 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.161202908 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.161248922 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.161248922 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.161294937 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.161343098 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.161456108 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.161499023 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.161542892 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.161552906 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.161590099 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.161638021 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.161648989 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.161693096 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.161736012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.161737919 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.161794901 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.161840916 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.161847115 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.161884069 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.161926985 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.161937952 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.161986113 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.162030935 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.162039042 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.162075043 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.162118912 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.162133932 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.162167072 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.162209988 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.162214994 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.162254095 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.162300110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.162305117 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.162627935 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.162672997 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.162678003 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.162718058 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.162769079 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.162798882 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.162844896 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.162887096 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.162898064 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.162930965 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.162986040 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.163110971 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.163327932 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.163374901 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.163382053 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.163417101 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.163470030 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.179778099 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.179920912 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.179966927 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.180090904 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.180097103 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.180136919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.180161953 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.180217028 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.180272102 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.180423021 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.228362083 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.240998030 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.241043091 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.241103888 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.241147041 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.241190910 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.241229057 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.241229057 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.241235018 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.241281986 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.241292000 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.241326094 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.241369009 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.241372108 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.241414070 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.241456985 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.241461992 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.241502047 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.241545916 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.241549969 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.241590977 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.241641045 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.242362976 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.242408991 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.242456913 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.242513895 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.242681026 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.242724895 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.242729902 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.242769003 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.242816925 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.242819071 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.243026972 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.243071079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.243076086 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.243201971 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.243246078 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.243249893 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.243290901 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.243335009 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.243340015 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.243396044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.243439913 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.243441105 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.243486881 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.243534088 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.243535995 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.243577957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.243619919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.243623018 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.243680954 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.243725061 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.243729115 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.243846893 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.243891954 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.243895054 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.243936062 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.243979931 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.243987083 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.244025946 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.244076967 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.244345903 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.247443914 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.247515917 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.247612000 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.247657061 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.247700930 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.247704029 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.247783899 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.247827053 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.247833967 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.247873068 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.247919083 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.247952938 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.247997046 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.248039961 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.248044968 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.248100042 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.248143911 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.248147964 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.248188019 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.248236895 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.248239040 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.248279095 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.248322010 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.248325109 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.248366117 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.248410940 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.248411894 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.248456001 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.248522997 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.248538017 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.248584032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.248626947 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.248629093 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.249231100 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.249294996 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.249373913 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.249420881 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.249464035 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.249469042 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.249511003 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.249555111 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.249600887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.249605894 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.249659061 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.249689102 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.249733925 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.249777079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.249780893 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.249820948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.249866009 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.249871969 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.249908924 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.249954939 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.249991894 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.250181913 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.250221968 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.250241041 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.250267982 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.250320911 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.250341892 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.250386000 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.250431061 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.250439882 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.250475883 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.250530958 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.250535011 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.250580072 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.250623941 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.250632048 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.250669003 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.250711918 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.250725985 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.250756979 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.250799894 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.250806093 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.250844955 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.250888109 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.250899076 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.251034021 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.251079082 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.251086950 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.251122952 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.251167059 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.251178980 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.251211882 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.251254082 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.251261950 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.251341105 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.251384974 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.251395941 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.251499891 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.251545906 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.251550913 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.251589060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.251631021 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.251631975 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.251677036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.251729965 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.265522003 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.265567064 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.265613079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.265624046 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.265686989 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.265732050 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.265742064 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.265779018 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.265877962 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.265887976 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.306385994 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.333029032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.333075047 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.333120108 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.333179951 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.333236933 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.333283901 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.333282948 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.333282948 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.333329916 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.333348036 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.333544970 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.333589077 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.333606005 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.333636045 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.333679914 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.333689928 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.333726883 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.333770037 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.333780050 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.333815098 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.333863020 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.333889008 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.333934069 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.333982944 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.334037066 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.334080935 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.334124088 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.334127903 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.334168911 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.334213018 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.334213972 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.334259987 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.334305048 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.334530115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.334574938 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.334614992 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.334618092 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.334695101 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.334738970 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.334743023 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.334784985 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.334830046 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.334831953 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.334892035 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.334934950 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.334938049 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.334979057 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.335022926 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.335025072 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.335067034 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.335110903 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.335114002 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.335155010 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.335200071 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.335899115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.335944891 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.335987091 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.335990906 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.336034060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.336076975 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.336080074 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.336122990 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.336168051 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.340256929 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.340301991 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.340351105 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.340425014 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.340604067 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.340648890 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.340651989 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.340693951 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.340738058 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.340739965 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.340783119 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.340830088 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.341090918 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.341135979 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.341180086 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.341181040 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.341224909 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.341269016 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.341273069 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.341314077 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.341357946 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.341358900 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.341589928 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.341639996 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.341880083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.341924906 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.341969967 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.341970921 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.342014074 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.342057943 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.342058897 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.343086958 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.343151093 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.343244076 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.343290091 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.343333960 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.343334913 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.343379021 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.343425035 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.343440056 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.343483925 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.343528032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.343528986 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.343575954 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.343621016 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.343635082 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.343678951 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.343722105 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.343724012 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.345331907 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.345385075 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.345448017 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.345493078 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.345535994 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.345540047 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.345586061 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.345633030 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.345644951 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.345690012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.345732927 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.345735073 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.345793962 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.345838070 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.345839977 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.345881939 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.345926046 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.345927954 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.345985889 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.346029043 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.346030951 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.346074104 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.346117020 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.346122980 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.346160889 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.346204042 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.346204996 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.346249104 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.346292973 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.346293926 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.346503973 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.346549034 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.346553087 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.346594095 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.346637964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.346640110 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.346683025 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.346726894 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.346729040 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.346771002 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.346813917 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.346815109 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.346858978 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.346901894 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.346904993 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.360589981 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.360610008 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.360626936 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.360651016 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.360676050 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.360681057 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.360708952 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.360743046 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.360934973 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.360935926 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.360935926 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.421637058 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.421688080 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.421720982 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.421751976 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.421785116 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.421804905 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.421817064 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.421850920 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.421874046 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.421874046 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.421993971 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.422025919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.422038078 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.422059059 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.422091007 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.422102928 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.422125101 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.422157049 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.422167063 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.422189951 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.422231913 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.422738075 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.422770023 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.422802925 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.422811985 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.422833920 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.422867060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.422875881 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.422899008 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.422930956 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.422940016 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.422964096 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.422995090 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.423005104 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.423027992 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.423060894 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.423069954 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.423090935 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.423130989 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.423141003 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.423171997 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.423203945 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.423213005 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.423235893 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.423268080 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.423275948 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.423300028 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.423332930 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.423341990 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.423367977 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.423407078 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.423408985 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.423439026 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.423471928 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.423480034 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.423505068 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.423537016 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.423547983 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.423572063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.423613071 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.423958063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.423990965 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.424031019 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.428659916 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.428711891 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.428744078 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.428754091 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.428778887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.428819895 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.428843021 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.428904057 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.428936958 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.428946018 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.428970098 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.429003000 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.429011106 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.429230928 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.429261923 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.429272890 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.429295063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.429327011 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.429333925 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.429359913 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.429400921 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.429668903 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.429701090 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.429733038 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.429742098 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.429784060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.429817915 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.429822922 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.429850101 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.429883003 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.429888010 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.429912090 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.429953098 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.432076931 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.432177067 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.432225943 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.432235003 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.432259083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.432291031 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.432297945 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.432323933 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.432364941 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.432405949 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.432437897 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.432470083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.432477951 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.432522058 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.432563066 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.432718039 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.432749987 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.432781935 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.432790041 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.432813883 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.432852983 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.434201002 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.434232950 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.434267044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.434273005 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.434333086 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.434364080 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.434374094 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.434398890 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.434432030 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.434438944 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.434465885 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.434505939 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.434745073 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.434777021 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.434808969 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.434818029 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.434842110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.434874058 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.434880018 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.434905052 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.434937000 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.434943914 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.434969902 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.435002089 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.435008049 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.435034037 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.435074091 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.435164928 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.435197115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.435226917 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.435235977 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.435259104 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.435297966 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.435301065 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.435332060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.435364962 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.435372114 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.435405016 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.435436964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.435441017 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.435471058 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.435511112 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.448940992 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.448964119 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.448976040 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.449065924 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.449079990 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.449094057 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.449107885 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.449107885 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.449110031 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.449132919 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.449300051 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.449353933 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.510092020 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.510143995 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.510175943 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.510315895 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.510376930 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.510411024 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.510432005 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.510442972 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.510476112 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.510493040 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.510541916 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.510592937 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.510605097 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.510637999 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.510668993 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.510684013 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.510703087 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.510734081 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.510747910 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.510766983 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.510812998 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.511029005 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.511060953 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.511092901 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.511112928 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.511125088 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.511157036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.511173964 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.511190891 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.511224031 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.511235952 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.511529922 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.511576891 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.511579037 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.511611938 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.511642933 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.511657953 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.511676073 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.511707067 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.511723042 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.511739969 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.511770964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.511785984 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.511804104 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.511835098 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.511850119 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.511868000 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.511899948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.511914968 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.511934042 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.511965990 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.511980057 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.512347937 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.512397051 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.512429953 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.512463093 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.512511015 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.512531996 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.512564898 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.512598038 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.512612104 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.519260883 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.519309044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.519315958 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.519341946 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.519378901 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.519388914 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.519418001 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.519465923 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.519467115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.519500017 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.519531012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.519546032 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.519563913 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.519594908 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.519609928 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.519627094 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.519658089 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.519670963 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.519691944 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.519722939 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.519731998 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.519756079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.519785881 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.519795895 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.519819021 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.519853115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.519859076 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.519886017 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.519917011 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.519925117 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.519949913 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.519989014 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.520992994 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.521025896 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.521059036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.521083117 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.521141052 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.521172047 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.521183968 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.521204948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.521238089 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.521245003 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.521271944 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.521312952 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.521477938 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.521509886 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.521542072 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.521549940 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.521574974 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.521606922 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.521615028 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.521639109 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.521678925 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.524036884 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.524086952 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.524120092 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.524128914 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.524220943 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.524251938 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.524260044 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.524285078 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.524323940 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.524558067 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.524590015 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.524622917 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.524630070 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.524655104 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.524687052 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.524694920 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.524720907 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.524760962 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.524852037 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.524883032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.524914980 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.524923086 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.524946928 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.524980068 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.524986982 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.525011063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.525043011 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.525062084 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.525074959 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.525109053 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.525115013 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.525382042 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.525413990 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.525424004 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.525446892 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.525479078 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.525486946 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.525511980 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.525543928 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.525552988 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.525577068 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.525616884 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.539953947 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.539988041 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.540020943 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.540056944 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.540127993 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.540159941 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.540191889 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.540222883 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.540266991 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.540266991 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.587620020 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.600332022 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.600368023 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.600404024 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.600434065 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.600537062 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.600584984 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.600594997 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.600617886 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.600650072 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.600672960 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.600855112 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.600887060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.600908995 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.600919008 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.600950003 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.600972891 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.600982904 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.601013899 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.601035118 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.601044893 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.601077080 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.601099968 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.601110935 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.601162910 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.601502895 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.601551056 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.601582050 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.601603985 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.601613998 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.601645947 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.601665020 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.601677895 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.601708889 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.601723909 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.601742029 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.601773024 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.601790905 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.601804972 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.601835966 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.601854086 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.601867914 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.601932049 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.601936102 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.602351904 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.602382898 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.602412939 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.602416039 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.602447987 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.602480888 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.602489948 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.602513075 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.602526903 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.602545977 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.602576971 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.602592945 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.602610111 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.602641106 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.602657080 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.602675915 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.602725029 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.606643915 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.606794119 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.606827021 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.606852055 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.606925964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.606959105 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.606976032 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.606996059 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.607028961 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.607042074 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.608496904 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.608560085 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.608571053 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.608606100 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.608654022 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.608658075 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.608685970 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.608719110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.608738899 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.608782053 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.608814001 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.608834982 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.608845949 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.608899117 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.608916044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.608948946 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.608980894 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.608999968 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.609014034 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.609045982 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.609066010 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.609677076 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.609731913 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.609761953 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.609793901 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.609843969 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.609869003 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.609875917 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.609908104 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.609922886 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.609994888 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.610028982 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.610044003 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.610061884 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.610095024 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.610106945 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.610172987 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.610205889 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.610224962 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.610238075 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.610270023 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.610291958 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.612950087 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.613003016 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.613007069 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.613034964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.613181114 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.613228083 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.613249063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.613329887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.613352060 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.613362074 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.613395929 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.613409042 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.613445997 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.613476992 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.613493919 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.613509893 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.613543034 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.613564968 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.613576889 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.613609076 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.613627911 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.613708019 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.613739014 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.613760948 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.613771915 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.613804102 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.613826036 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.613836050 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.613867998 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.613883972 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.613898993 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.613945961 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.614114046 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.614146948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.614178896 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.614192963 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.614211082 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.614252090 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.614253998 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.614325047 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.614357948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.614375114 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.628329992 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.628354073 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.628366947 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.628375053 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.628411055 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.628616095 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.628631115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.628644943 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.628659010 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.628683090 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.628706932 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.690116882 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.690458059 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.690769911 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.690928936 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.690978050 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.691009998 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.691030979 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.691041946 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.691075087 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.691097021 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.691106081 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.691139936 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.691152096 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.691314936 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.691346884 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.691369057 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.691385031 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.691421986 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.691443920 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.691454887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.691483021 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.691508055 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.691514969 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.691546917 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.691569090 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.691579103 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.691612005 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.691632032 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.691797972 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.691829920 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.691854000 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.691863060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.691914082 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.692008972 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.692040920 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.692089081 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.692092896 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.692137957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.692168951 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.692189932 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.692200899 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.692233086 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.692253113 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.692265034 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.692296982 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.692317963 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.692327976 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.692359924 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.692382097 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.692393064 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.692425013 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.692445993 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.692456961 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.692511082 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.692894936 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.692945004 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.692976952 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.693000078 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.693008900 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.693063974 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.693078041 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.693109989 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.693161011 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.697527885 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.697577953 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.697609901 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.697645903 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.697741032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.697772026 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.697804928 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.697837114 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.697886944 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.697886944 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.700392008 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.700423956 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.700455904 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.700474024 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.700555086 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.700607061 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.700659990 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.700670958 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.700671911 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.700711012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.700742960 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.700759888 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.700776100 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.700807095 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.700823069 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.700841904 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.700897932 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.700939894 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.700972080 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.701008081 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.701020002 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.701086044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.701114893 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.701137066 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.701147079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.701179028 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.701193094 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.701210976 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.701242924 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.701261044 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.701275110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.701309919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.701322079 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.701766968 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.701817036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.701824903 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.701850891 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.701900959 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.701966047 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.701997995 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.702028990 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.702047110 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.702061892 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.702110052 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.704616070 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.704648972 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.704683065 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.704701900 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.704926014 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.704984903 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.705018997 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.705050945 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.705081940 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.705085039 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.705085039 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.705113888 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.705132008 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.705147028 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.705178022 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.705193996 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.705212116 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.705257893 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.705260992 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.705292940 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.705324888 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.705339909 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.705357075 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.705389977 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.705404043 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.705421925 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.705454111 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.705468893 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.705485106 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.705517054 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.705529928 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.707715988 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.707772970 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.707782030 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.707804918 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.707837105 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.707859993 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.707868099 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.707900047 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.707918882 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.707931042 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.707962990 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.707979918 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.717143059 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.717176914 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.717211008 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.717247963 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.717247963 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.717258930 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.717292070 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.717324018 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.717340946 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.717356920 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.717459917 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.779670954 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.779695988 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.779710054 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.779722929 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.779737949 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.779752016 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.779794931 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.779794931 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.779795885 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.779803991 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.779987097 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.779999971 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.780023098 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.780036926 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.780071020 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.780165911 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.780194998 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.780230999 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.780239105 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.780342102 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.780389071 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.780550957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.780584097 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.780615091 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.780627012 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.780647993 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.780694008 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.780697107 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.780730009 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.780760050 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.780771971 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.780792952 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.780823946 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.780838966 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.780857086 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.780901909 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.781255007 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.781286955 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.781318903 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.781333923 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.781490088 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.781522036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.781542063 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.781553984 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.781603098 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.781606913 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.781636000 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.781667948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.781683922 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.781701088 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.781733036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.781748056 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.781764030 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.781795025 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.781807899 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.781826973 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.781858921 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.781874895 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.781893015 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.781938076 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.782334089 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.782366037 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.782413006 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.787069082 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.787102938 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.787168980 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.787229061 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.787260056 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.787292957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.787307024 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.787417889 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.787450075 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.787467957 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.793575048 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.793623924 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.793627024 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.793659925 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.793701887 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.793778896 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.793811083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.793843031 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.793852091 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.793876886 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.793917894 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.793953896 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.793986082 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.794017076 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.794025898 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.794050932 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.794083118 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.794091940 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.794115067 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.794148922 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.794156075 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.794496059 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.794528008 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.794538021 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.794560909 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.794600964 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.794600964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.794651985 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.794682980 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.794692993 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.794730902 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.794761896 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.794771910 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.794794083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.794825077 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.794833899 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.794857979 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.794888973 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.794898987 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.794922113 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.794953108 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.794962883 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.794986963 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.795020103 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.795027018 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.795456886 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.795488119 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.795499086 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.795520067 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.795562029 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.795568943 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.795602083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.795633078 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.795643091 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.795665026 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.795696974 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.795707941 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.795728922 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.795758963 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.795768976 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.795792103 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.795823097 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.795830965 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.795855999 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.795886993 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.795896053 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.796369076 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.796401978 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.796411991 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.796433926 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.796473026 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.797447920 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.797497988 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.797529936 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.797559023 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.797632933 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.797676086 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.797719955 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.797751904 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.797782898 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.797795057 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.806205034 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.806237936 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.806261063 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.806272030 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.806319952 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.806324959 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.806351900 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.806384087 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.806405067 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.806416988 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.806469917 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.870389938 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.870456934 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.870506048 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.870548964 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.870574951 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.870608091 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.870630980 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.870641947 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.870682955 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.870688915 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.870714903 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.870762110 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.870995998 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.871045113 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.871077061 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.871093988 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.871180058 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.871212006 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.871228933 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.871244907 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.871278048 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.871293068 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.871449947 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.871481895 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.871500969 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.871515036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.871548891 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.871561050 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.871794939 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.871826887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.871845007 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.871857882 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.871890068 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.871905088 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.871922016 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.871952057 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.871968985 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.871985912 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.872016907 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.872030973 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.872049093 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.872082949 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.872101068 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.872364044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.872396946 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.872411966 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.872428894 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.872461081 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.872483969 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.872512102 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.872544050 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.872555017 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.872575998 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.872607946 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.872622967 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.872801065 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.872829914 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.872848988 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.872862101 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.872894049 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.872908115 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.872922897 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.872955084 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.872972965 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.872988939 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.873017073 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.873034954 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.875494003 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.875547886 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.875550985 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.875585079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.875616074 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.875648022 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.875679016 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.875713110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.875725985 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.875725985 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.875760078 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.882308960 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.882436037 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.882498980 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.882546902 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.882579088 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.882596016 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.882611990 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.882617950 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.882644892 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.882677078 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.882888079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.882920027 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.882944107 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.882951975 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.882983923 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.882994890 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.883048058 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.883080006 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.883099079 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.883111000 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.883200884 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.883361101 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.883399963 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.883433104 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.883451939 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.883465052 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.883497000 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.883517981 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.883559942 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.883594990 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.883610964 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.883797884 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.883830070 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.883850098 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.883861065 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.883892059 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.883915901 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.883924007 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.883956909 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.883979082 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.883990049 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.884021044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.884044886 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.884053946 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.884104967 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.884120941 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.884152889 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.884183884 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.884205103 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.884217024 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.884251118 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.884268999 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.884597063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.884675980 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.884687901 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.884708881 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.884740114 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.884758949 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.884773016 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.884804964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.884836912 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.884839058 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.884870052 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.884888887 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.884901047 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.884932995 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.884949923 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.884967089 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.884999037 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.885021925 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.885032892 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.885085106 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.886221886 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.886307955 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.886343956 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.886368036 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.886429071 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.886460066 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.886485100 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.886492968 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.886524916 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.886548996 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.894407034 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.894458055 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.894470930 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.894490957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.894546986 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.894638062 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.894670963 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.894702911 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.894723892 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.894735098 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.894764900 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.894788980 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.947093964 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.962601900 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.962734938 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.962749958 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.962858915 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.962872028 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.962887049 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.962971926 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.962985039 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.962999105 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.963009119 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.963009119 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.963073969 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.964468956 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.964596033 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.964643955 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.964677095 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.964700937 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.964709044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.964741945 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.964744091 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.964765072 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.964775085 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.964833975 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.964909077 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.964940071 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.964972973 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.964998960 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.965007067 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.965065002 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.965099096 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.965127945 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.965184927 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.965265036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.965312004 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.965344906 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.965372086 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.965375900 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.965409994 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.965431929 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.965440989 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.965472937 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.965500116 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.965504885 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.965537071 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.965563059 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.965567112 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.965600967 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.965626001 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.965635061 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.965694904 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.965966940 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.966089964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.966121912 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.966146946 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.966152906 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.966186047 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.966208935 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.966217995 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.966249943 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.966275930 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.966283083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.966315985 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.966342926 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.968434095 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.968465090 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.968503952 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.968534946 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.968581915 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.968592882 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.968621969 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.968652964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.968678951 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.968686104 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.968740940 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.971245050 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.971328974 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.971359968 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.971381903 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.971571922 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.971602917 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.971635103 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.971668005 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.971709967 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.971709967 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.971757889 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.971807003 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.971812010 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.971839905 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.971867085 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.971890926 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.971898079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.971930027 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.971949100 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.971962929 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.971995115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.972013950 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.972027063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.972059965 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.972075939 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.972296953 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.972327948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.972351074 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.972358942 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.972390890 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.972410917 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.972423077 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.972455025 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.972476959 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.972507000 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.972538948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.972564936 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.972572088 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.972603083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.972625017 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.972635984 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.972686052 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.972879887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.972910881 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.972943068 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.972961903 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.972975016 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.973006010 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.973026991 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.973038912 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.973069906 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.973088980 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.973102093 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.973133087 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.973153114 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.973164082 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.973197937 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.973215103 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.973577023 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.973623991 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.973629951 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.973654985 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.973685980 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.973706007 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.973720074 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.973750114 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.973771095 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.973782063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.973814011 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.973835945 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.973846912 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.973890066 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.973898888 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.974747896 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.974780083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.974802017 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.974812984 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.974863052 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.974863052 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.974894047 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.974926949 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.974946022 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.974958897 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.975009918 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.983278990 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.983351946 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.983392000 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.983481884 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.983515978 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.983541965 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.983572960 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:13.983644962 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.983676910 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:13.983843088 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.051136017 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.051188946 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.051219940 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.051295042 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.051332951 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.051367044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.051403046 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.051404953 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.051440001 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.051467896 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.053119898 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.053153038 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.053184032 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.053186893 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.053245068 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.053426027 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.053457022 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.053488970 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.053517103 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.053520918 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.053555012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.053576946 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.053715944 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.053746939 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.053777933 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.053777933 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.053809881 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.053836107 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.053842068 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.053874016 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.053900003 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.053905964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.053937912 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.053971052 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.053975105 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.054006100 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.054030895 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.054161072 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.054193974 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.054214954 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.054225922 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.054282904 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.054397106 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.054430008 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.054461002 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.054486990 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.054493904 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.054553032 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.054748058 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.054780006 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.054811001 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.054836035 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.054842949 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.054874897 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.054903030 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.054905891 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.054939032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.054964066 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.054970026 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.055003881 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.055026054 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.055145979 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.055202961 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.056828976 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.056879997 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.056910992 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.056941032 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.057024956 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.057056904 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.057085037 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.057142973 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.057174921 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.057202101 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.057207108 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.057264090 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.059721947 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.059813976 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.059847116 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.059879065 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.059926987 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.059976101 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.059986115 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.060009956 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060041904 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060066938 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.060074091 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060106993 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060129881 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.060138941 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060172081 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060194969 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.060204983 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060336113 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060352087 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060369015 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060384035 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060400009 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060415983 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060431004 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060547113 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.060705900 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060738087 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060770988 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.060790062 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060817957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060852051 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.060863972 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060897112 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060926914 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.060928106 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060960054 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.060986996 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.060991049 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061024904 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061047077 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.061142921 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061175108 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061203957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061203957 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.061233044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061259985 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.061265945 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061299086 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061325073 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.061331034 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061362982 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061391115 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.061398029 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061429977 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061455011 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.061464071 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061522007 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.061597109 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061625957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061681986 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.061748028 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061779976 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061810970 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061836958 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.061841011 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061873913 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061898947 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.061904907 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061938047 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.061963081 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.061973095 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.062015057 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.062037945 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.062050104 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.062082052 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.062103987 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.063086033 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.063134909 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.063148022 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.063169003 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.063225031 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.063230038 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.063262939 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.063318014 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.063384056 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.063416004 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.063447952 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.063474894 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.071820974 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.071916103 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.071937084 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.071969032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.072017908 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.072074890 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.072105885 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.072138071 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.072159052 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.072170019 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.072225094 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.140242100 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.140256882 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.140269995 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.140425920 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.140525103 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.140575886 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.140609026 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.140640020 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.140692949 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.140692949 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.141578913 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.141612053 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.141644955 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.141724110 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.141724110 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.141798973 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.141830921 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.141863108 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.141880035 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.141896009 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.141943932 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.141976118 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.142008066 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.142040014 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.142055035 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.142072916 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.142117977 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.142178059 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.142210007 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.142244101 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.142257929 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.142358065 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.142390966 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.142405987 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.142425060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.142471075 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.142601013 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.142632961 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.142664909 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.142679930 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.142697096 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.142729044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.142743111 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.142884970 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.142916918 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.142932892 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.142947912 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.143023968 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.143038034 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.143057108 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.143091917 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.143102884 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.143287897 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.143315077 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.143332005 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.143347025 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.143378973 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.143394947 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.143412113 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.143443108 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.143459082 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.143475056 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.143508911 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.143521070 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.146429062 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.146481037 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.146500111 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.146513939 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.146545887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.146576881 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.146609068 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.146641016 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.146681070 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.146681070 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.150043964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.150075912 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.150106907 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.150108099 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.150147915 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.150161982 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.150194883 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.150214911 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.150306940 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.150337934 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.150357008 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.150470972 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.150521040 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.150521040 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.150557041 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.150598049 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.150608063 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.150649071 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.150697947 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.150702953 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.150751114 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.150798082 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.150799036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.150831938 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.150863886 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.150878906 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.150896072 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.150928974 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.150950909 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.150959969 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.150991917 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151011944 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.151041031 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151087999 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151087999 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.151117086 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151148081 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151165962 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.151179075 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151210070 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151226997 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.151242971 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151273966 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151290894 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.151307106 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151338100 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151355982 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.151371956 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151402950 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151418924 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.151434898 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151468992 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151484966 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.151501894 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151532888 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151551008 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.151565075 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151597023 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151612997 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.151628971 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151660919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151678085 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.151694059 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151724100 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151740074 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.151756048 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151787996 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151806116 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.151820898 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151853085 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151870966 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.151884079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151915073 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151931047 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.151948929 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151983023 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.151999950 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.152014017 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.152046919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.152061939 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.152179956 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.152210951 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.152226925 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.152242899 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.152275085 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.152290106 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.160542011 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.160614014 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.160646915 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.160726070 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.160756111 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.160787106 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.160819054 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.160851002 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.160854101 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.160909891 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.230398893 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.230464935 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.230500937 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.230532885 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.230557919 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.230566978 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.230581999 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.230618000 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.230669975 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.230670929 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.230703115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.230736017 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.230755091 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.230767012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.230799913 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.230817080 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.230834007 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.230880976 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.231167078 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.231199026 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.231249094 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.231261969 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.231281042 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.231313944 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.231326103 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.231347084 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.231390953 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.231419086 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.231451035 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.231484890 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.231497049 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.231513977 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.231559992 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.231595993 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.231628895 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.231674910 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.231703043 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.231735945 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.231769085 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.231782913 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.231801033 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.231833935 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.231847048 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.231865883 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.231898069 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.231911898 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.231930017 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.231962919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.231975079 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.232054949 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.232101917 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.232219934 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.232253075 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.232285023 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.232300043 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.232311964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.232342958 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.232356071 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.232376099 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.232408047 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.232419968 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.232440948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.232471943 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.232486963 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.232527018 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.232559919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.232568979 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.234292984 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.234343052 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.234358072 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.234375954 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.234426975 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.234565020 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.234597921 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.234630108 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.234642982 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.234663963 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.234708071 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.237535000 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.237596989 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.237628937 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.237657070 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.237714052 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.237745047 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.237761021 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.237777948 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.237809896 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.237822056 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.237948895 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.237981081 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.237996101 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.238014936 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.238059044 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.238091946 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.238123894 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.238168001 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.238188982 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.238229036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.238260031 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.238271952 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.238293886 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.238325119 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.238341093 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.238358021 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.238390923 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.238401890 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.238424063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.238468885 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.238698959 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.238730907 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.238761902 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.238776922 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.238794088 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.238826036 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.238840103 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.238856077 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.238888025 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.238900900 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.238919973 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.238953114 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.238964081 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.238986015 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.239020109 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.239029884 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.239343882 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.239382029 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.239389896 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.239417076 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.239444017 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.239463091 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.239475965 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.239506960 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.239520073 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.239538908 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.239571095 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.239583015 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.239603043 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.239634991 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.239648104 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.239666939 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.239711046 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.239716053 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.239748001 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.239779949 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.239793062 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.239811897 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.239844084 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.239855051 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.239876032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.239909887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.239921093 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.240607977 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.240655899 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.240715981 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.240751982 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.240797043 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.240829945 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.240860939 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.240892887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.240905046 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.240971088 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.241002083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.241015911 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.249378920 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.249455929 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.249461889 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.249495029 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.249542952 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.249610901 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.249641895 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.249674082 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.249687910 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.249706984 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.249749899 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.318986893 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.319015980 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.319118023 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.319149971 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.319184065 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.319216013 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.319216013 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.319216967 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.319264889 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.319267035 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.319314957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.319346905 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.319365978 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.319386959 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.319421053 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.319438934 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.319453955 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.319485903 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.319504023 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.319725990 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.319753885 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.319777012 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.319835901 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.319868088 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.319886923 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.319900990 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.319931984 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.319952011 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.319964886 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.319996119 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.320014000 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.320029020 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.320077896 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.320312977 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.320344925 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.320375919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.320394993 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.320409060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.320441008 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.320460081 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.320472956 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.320524931 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.320527077 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.320557117 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.320590019 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.320605993 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.320624113 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.320673943 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.320883989 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.320914984 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.320947886 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.320965052 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.320981026 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.321019888 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.321028948 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.321069002 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.321101904 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.321118116 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.321134090 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.321183920 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.321252108 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.321300983 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.321335077 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.321351051 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.321362019 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.321413040 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.322987080 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.323018074 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.323050976 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.323081970 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.323096037 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.323116064 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.323124886 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.323148012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.323180914 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.323196888 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.323208094 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.323256016 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.325920105 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.325970888 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.326003075 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.326035023 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.326035023 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.326071024 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.326083899 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.326148033 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.326179028 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.326199055 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.326211929 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.326261044 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.326288939 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.326322079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.326370001 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.326370001 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.326404095 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.326438904 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.326452971 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.326570988 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.326601982 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.326620102 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.326634884 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.326666117 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.326684952 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.326699972 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.326750040 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.326766014 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.326895952 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.326925039 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.326946020 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.326956987 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.326988935 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327008963 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.327020884 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327053070 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327070951 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.327084064 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327116013 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327131987 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.327148914 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327197075 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.327255011 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327281952 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327330112 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.327424049 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327455044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327486992 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327506065 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.327517986 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327549934 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327568054 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.327580929 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327613115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327630043 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.327644110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327676058 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327693939 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.327708006 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327740908 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327755928 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.327775002 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327821970 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327838898 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.327939034 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327987909 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.327987909 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.328038931 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.328072071 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.328088999 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.328104973 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.328138113 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.328155041 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.328170061 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.328201056 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.328224897 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.329448938 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.329579115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.329596043 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.329627991 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.329660892 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.329679966 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.329693079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.329724073 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.329742908 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.329756021 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.329807043 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.338124037 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.338156939 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.338190079 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.338223934 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.338290930 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.338321924 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.338346004 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.338354111 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.338387012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.338402033 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.384589911 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.407958031 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.407991886 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.408025026 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.408158064 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.408257961 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.408288956 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.408320904 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.408354044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.408385992 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.408415079 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.408415079 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.408418894 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.408427000 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.408514977 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.408546925 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.408584118 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.408617020 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.408648968 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.408672094 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.408672094 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.408680916 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.408695936 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.408798933 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.408830881 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.408848047 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.408863068 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.408895016 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.408907890 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.408927917 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.408960104 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.408973932 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.409256935 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.409287930 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.409303904 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.409321070 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.409352064 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.409367085 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.409392118 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.409427881 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.409440994 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.409610987 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.409638882 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.409662008 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.409670115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.409703970 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.409723997 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.409735918 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.409768105 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.409781933 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.409800053 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.409832001 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.409847021 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.409864902 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.409910917 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.409955978 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.410060883 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.410092115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.410105944 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.410208941 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.410239935 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.410254955 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.410271883 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.410304070 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.410316944 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.411777973 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.411833048 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.411875010 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.411909103 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.411955118 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.411987066 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.412020922 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.412065983 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.412108898 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.412141085 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.412173033 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.412188053 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.417531013 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.417628050 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.417649984 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.417699099 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.417731047 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.417762995 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.417794943 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.417825937 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.417836905 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.417836905 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.417860985 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.417884111 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.418009043 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.418040037 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.418056965 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.418072939 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.418104887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.418118954 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.418137074 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.418169022 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.418181896 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.418243885 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.418276072 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.418292999 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.418309927 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.418338060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.418355942 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.418646097 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.418678045 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.418694973 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.418711901 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.418744087 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.418757915 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.418776035 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.418807030 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.418822050 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.419044971 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.419076920 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.419092894 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.419109106 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.419140100 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.419154882 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.419172049 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.419218063 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.419255972 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.419327021 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.419358969 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.419375896 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.419399023 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.419431925 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.419445038 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.419464111 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.419495106 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.419508934 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.419528961 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.419559956 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.419574976 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.419593096 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.419636965 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.419929981 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.419961929 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.419994116 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.420006990 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.420025110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.420057058 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.420073032 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.420090914 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.420123100 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.420135021 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.420154095 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.420185089 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.420207977 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.420217037 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.420248985 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.420263052 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.420280933 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.420312881 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.420326948 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.420346022 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.420392036 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.420407057 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.420703888 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.420737982 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.420758963 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.420769930 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.420802116 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.420814991 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.432909012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.432960033 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.432980061 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.432992935 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.433046103 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.433089018 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.433166027 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.433197975 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.433216095 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.433229923 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.433280945 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.500257969 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.500303030 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.500318050 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.500390053 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.500428915 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.500485897 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.500499964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.500514984 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.500633955 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.500685930 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.500843048 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.500874043 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.500902891 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.500905991 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.500937939 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.500962973 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.500969887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.500998020 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.501003027 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.501036882 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.501056910 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.501069069 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.501101017 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.501121044 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.501414061 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.501446009 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.501477957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.501490116 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.501533985 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.501562119 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.501595020 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.501626015 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.501646042 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.501657963 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.501688957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.501712084 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.501719952 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.501751900 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.501774073 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.501785040 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.501816034 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.501837969 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.501847982 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.501879930 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.501899958 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.502455950 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.502487898 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.502511024 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.502520084 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.502552032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.502573013 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.502583981 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.502615929 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.502635002 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.502648115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.502680063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.502698898 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.502713919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.502764940 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.502938986 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.502969980 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.503000975 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.503021002 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.503032923 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.503063917 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.503083944 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.503096104 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.503134012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.503149033 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.505783081 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.505832911 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.505847931 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.505861998 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.505916119 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.505923986 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.505955935 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506001949 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506021023 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.506036043 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506088018 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.506112099 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506145000 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506192923 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506195068 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.506226063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506258965 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506277084 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.506335020 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506367922 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506390095 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.506402016 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506455898 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.506506920 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506537914 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506570101 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506588936 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.506603956 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506654024 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.506728888 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506762028 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506795883 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506812096 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.506844997 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506875992 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506896019 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.506907940 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506941080 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.506959915 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.506973982 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.507025003 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.507080078 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.507112980 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.507143974 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.507164001 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.507175922 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.507209063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.507226944 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.507347107 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.507378101 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.507400990 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.507411957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.507443905 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.507462978 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.507477045 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.507508993 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.507529020 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.507556915 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.507589102 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.507610083 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.507622004 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.507653952 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.507671118 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.507685900 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.507736921 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.507889032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.507920980 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.507952929 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.507973909 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.508013010 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.508044004 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.508064985 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.508075953 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.508107901 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.508127928 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.508138895 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.508188009 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.508260965 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.508292913 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.508323908 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.508343935 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.508354902 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.508387089 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.508404970 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.508419991 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.508451939 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.508471966 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.521940947 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.521989107 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.522006035 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.522021055 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.522037029 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.522053003 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.522087097 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.522130013 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.522161007 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.589303970 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.589387894 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.589425087 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.589507103 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.589513063 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.589539051 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.589570045 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.589623928 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.589679956 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.589687109 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.589910984 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.589942932 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.589962006 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.589976072 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.590008020 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.590029001 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.590039968 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.590071917 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.590092897 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.590104103 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.590138912 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.590154886 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.590343952 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.590375900 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.590398073 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.590409040 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.590440989 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.590461016 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.590471983 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.590503931 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.590523005 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.590536118 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.590567112 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.590586901 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.590598106 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.590629101 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.590651035 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.590661049 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.590692043 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.590709925 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.590763092 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.590795040 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.590811014 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.591134071 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.591166019 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.591187000 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.591198921 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.591249943 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.591288090 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.591320038 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.591351032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.591371059 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.591383934 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.591415882 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.591434956 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.591447115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.591479063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.591500044 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.591511011 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.591542006 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.591559887 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.591574907 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.591607094 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.591629028 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.591639042 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.591689110 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.592088938 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.592122078 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.592153072 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.592174053 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.592185020 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.592242002 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.594655037 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.594707012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.594739914 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.594770908 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.594863892 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.594894886 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.594917059 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.594927073 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.594959974 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.594979048 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.595086098 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.595139980 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.595199108 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.595232010 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.595282078 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.595334053 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.595366001 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.595398903 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.595417023 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.595431089 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.595480919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.595483065 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.595510960 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.595541954 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.595561028 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.595674038 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.595706940 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.595726013 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.595755100 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.595786095 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.595809937 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.595834970 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.595865965 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.595886946 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.595917940 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.595946074 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.595969915 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.595977068 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596009016 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596026897 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.596040964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596091032 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.596162081 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596194983 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596226931 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596244097 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.596254110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596286058 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596303940 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.596317053 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596364975 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596365929 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.596398115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596429110 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596448898 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.596460104 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596512079 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.596518040 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596549034 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596580982 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596601963 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.596611023 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596645117 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596663952 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.596676111 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596708059 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596728086 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.596739054 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596788883 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.596808910 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596841097 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.596892118 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.597461939 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.597513914 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.597542048 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.597579002 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.597632885 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.597666025 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.597681999 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.597697973 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.597731113 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.597752094 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.597848892 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.597879887 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.597903013 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.597912073 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.597944975 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.597963095 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.597978115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.598011971 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.598028898 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.598043919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.598078012 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.598093987 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.598104954 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.598150015 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.610572100 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.610676050 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.610707045 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.610785961 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.610801935 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.610887051 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.611000061 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.611031055 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.611061096 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.665971041 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.678092957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.678153038 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.678186893 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.678225994 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.678260088 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.678292990 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.678337097 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.678344011 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.678369999 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.678376913 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.678412914 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.678426027 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.678442001 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.678498030 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.678513050 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.678530931 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.678563118 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.678581953 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.678595066 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.678637028 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.678652048 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.678853989 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.678885937 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.678910971 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.678934097 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.678966999 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.678987980 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.678998947 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.679030895 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.679052114 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.679063082 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.679090977 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.679116011 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.679122925 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.679157972 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.679176092 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.679405928 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.679438114 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.679461956 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.679470062 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.679502964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.679519892 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.679534912 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.679567099 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.679589033 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.679600954 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.679627895 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.679657936 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.680439949 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.680499077 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.680514097 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.680546045 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.680599928 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.680646896 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.680679083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.680711031 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.680733919 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.681193113 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.681225061 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.681251049 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.681257963 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.681291103 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.681341887 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.682584047 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.682634115 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.682652950 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.682666063 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.682718039 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.682837009 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.682868004 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.682899952 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.682921886 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.682931900 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.682984114 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.683141947 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.683273077 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.683305025 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.683326006 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.683336973 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.683370113 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.683391094 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.683402061 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.683434963 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.683454990 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.683461905 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.683511972 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.683919907 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.683968067 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.684000969 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.684020996 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.684032917 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.684082031 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.684082985 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.684129953 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.684163094 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.684181929 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.684683084 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.684732914 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.684741974 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.684766054 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.684815884 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.685419083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.685450077 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.685482979 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.685513973 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.685534000 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.685547113 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.685564995 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.685578108 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.685611010 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.685628891 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.685642958 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.685689926 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.685693026 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.685723066 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.685755014 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.685774088 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.685786009 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.685817003 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.685834885 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.685849905 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.685882092 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.685902119 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.685914040 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.685945988 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.685965061 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.685977936 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686009884 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686028957 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.686041117 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686075926 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686098099 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.686106920 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686140060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686158895 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.686171055 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686203957 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686222076 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.686350107 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686381102 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686403036 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.686414003 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686461926 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.686464071 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686496019 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686527014 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686547995 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.686562061 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686611891 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.686667919 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686717033 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686748028 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686768055 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.686779022 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686810970 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686830997 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.686842918 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686876059 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.686893940 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.701997995 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.702095032 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.702127934 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.702130079 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.702312946 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.702670097 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.702702045 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.702734947 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.702769041 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.702775955 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.702822924 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.767874002 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.767924070 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.767956972 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.767987013 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.768002987 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.768018961 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.768042088 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.768052101 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.768106937 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.768276930 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.768326044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.768373013 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.768381119 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.768424034 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.768462896 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.768492937 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.768512964 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.768543959 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.768570900 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.768577099 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.768630028 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.768738031 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.768769026 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.768800020 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.768821955 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.768832922 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.768881083 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.768882036 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.768913031 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.768944025 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.768964052 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.768975019 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.769007921 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.769025087 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.769038916 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.769071102 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.769093037 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.769104004 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.769134998 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.769154072 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.769182920 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.769215107 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.769237995 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.769246101 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.769279003 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.769309044 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.769315004 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.769357920 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.769365072 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.769391060 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.769448996 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.769460917 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.769491911 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.769524097 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.769546032 CEST497301110192.168.2.491.92.250.213
                                Jul 27, 2024 13:42:14.769556046 CEST11104973091.92.250.213192.168.2.4
                                Jul 27, 2024 13:42:14.769587040 CEST11104973091.92.250.213192.168.2.4

                                Click to jump to process

                                Click to jump to process

                                Click to dive into process behavior distribution

                                Click to jump to process

                                Target ID:0
                                Start time:07:42:03
                                Start date:27/07/2024
                                Path:C:\Users\user\Desktop\QTmGYKK6SL.exe
                                Wow64 process (32bit):false
                                Commandline:"C:\Users\user\Desktop\QTmGYKK6SL.exe"
                                Imagebase:0x400000
                                File size:12'016'128 bytes
                                MD5 hash:190E4ED7759276E78D16398673996B2B
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:Borland Delphi
                                Reputation:low
                                Has exited:true

                                Target ID:1
                                Start time:07:42:06
                                Start date:27/07/2024
                                Path:C:\Users\user\Desktop\QTmGYKK6SL.exe
                                Wow64 process (32bit):false
                                Commandline:C:\Users\user\Desktop\QTmGYKK6SL.exe
                                Imagebase:0x400000
                                File size:12'016'128 bytes
                                MD5 hash:190E4ED7759276E78D16398673996B2B
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:Borland Delphi
                                Reputation:low
                                Has exited:false

                                Target ID:3
                                Start time:07:42:22
                                Start date:27/07/2024
                                Path:C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exe
                                Wow64 process (32bit):false
                                Commandline:C:\Users\user\AppData\Local\Temp\o0c2ddmlg7qrbu2xkviy.exe
                                Imagebase:0x7ff665040000
                                File size:10'636'288 bytes
                                MD5 hash:1455F96A3552BFFCBD01FB90A2A4447B
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Antivirus matches:
                                • Detection: 100%, Joe Sandbox ML
                                • Detection: 21%, ReversingLabs
                                • Detection: 23%, Virustotal, Browse
                                Reputation:low
                                Has exited:true

                                Target ID:6
                                Start time:07:42:26
                                Start date:27/07/2024
                                Path:C:\Windows\System32\sc.exe
                                Wow64 process (32bit):false
                                Commandline:sc.exe stop RDP-Controller
                                Imagebase:0x7ff72bec0000
                                File size:72'192 bytes
                                MD5 hash:3FB5CF71F7E7EB49790CB0E663434D80
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Reputation:moderate
                                Has exited:true

                                Target ID:7
                                Start time:07:42:26
                                Start date:27/07/2024
                                Path:C:\Windows\System32\conhost.exe
                                Wow64 process (32bit):false
                                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                Imagebase:0x7ff7699e0000
                                File size:862'208 bytes
                                MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Reputation:high
                                Has exited:true

                                Target ID:8
                                Start time:07:42:26
                                Start date:27/07/2024
                                Path:C:\Windows\System32\sc.exe
                                Wow64 process (32bit):false
                                Commandline:sc.exe create RDP-Controller binpath= C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe type= own start= auto error= ignore
                                Imagebase:0x7ff6d1780000
                                File size:72'192 bytes
                                MD5 hash:3FB5CF71F7E7EB49790CB0E663434D80
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Reputation:moderate
                                Has exited:true

                                Target ID:9
                                Start time:07:42:26
                                Start date:27/07/2024
                                Path:C:\Windows\System32\conhost.exe
                                Wow64 process (32bit):false
                                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                Imagebase:0x7ff7699e0000
                                File size:862'208 bytes
                                MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Reputation:high
                                Has exited:true

                                Target ID:10
                                Start time:07:42:26
                                Start date:27/07/2024
                                Path:C:\Windows\System32\sc.exe
                                Wow64 process (32bit):false
                                Commandline:sc.exe failure RDP-Controller reset= 1 actions= restart/10000
                                Imagebase:0x7ff6d1780000
                                File size:72'192 bytes
                                MD5 hash:3FB5CF71F7E7EB49790CB0E663434D80
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Reputation:moderate
                                Has exited:true

                                Target ID:11
                                Start time:07:42:26
                                Start date:27/07/2024
                                Path:C:\Windows\System32\conhost.exe
                                Wow64 process (32bit):false
                                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                Imagebase:0x7ff7699e0000
                                File size:862'208 bytes
                                MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Reputation:high
                                Has exited:true

                                Target ID:12
                                Start time:07:42:26
                                Start date:27/07/2024
                                Path:C:\Windows\System32\sc.exe
                                Wow64 process (32bit):false
                                Commandline:sc.exe start RDP-Controller
                                Imagebase:0x7ff6d1780000
                                File size:72'192 bytes
                                MD5 hash:3FB5CF71F7E7EB49790CB0E663434D80
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Reputation:moderate
                                Has exited:true

                                Target ID:13
                                Start time:07:42:26
                                Start date:27/07/2024
                                Path:C:\Windows\System32\conhost.exe
                                Wow64 process (32bit):false
                                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                Imagebase:0x7ff7699e0000
                                File size:862'208 bytes
                                MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Reputation:high
                                Has exited:true

                                Target ID:14
                                Start time:07:42:26
                                Start date:27/07/2024
                                Path:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                Wow64 process (32bit):false
                                Commandline:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                Imagebase:0x7ff7bacd0000
                                File size:89'088 bytes
                                MD5 hash:CFCBC15615FFC698507D32C0A7D21134
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Has exited:true

                                Target ID:15
                                Start time:07:42:26
                                Start date:27/07/2024
                                Path:C:\Windows\System32\icacls.exe
                                Wow64 process (32bit):false
                                Commandline:icacls.exe C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\ /setowner *S-1-5-18
                                Imagebase:0x7ff6c0c40000
                                File size:39'424 bytes
                                MD5 hash:48C87E3B3003A2413D6399EA77707F5D
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Has exited:true

                                Target ID:16
                                Start time:07:42:26
                                Start date:27/07/2024
                                Path:C:\Windows\System32\conhost.exe
                                Wow64 process (32bit):false
                                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                Imagebase:0x7ff7699e0000
                                File size:862'208 bytes
                                MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Has exited:true

                                Target ID:17
                                Start time:07:42:26
                                Start date:27/07/2024
                                Path:C:\Windows\System32\icacls.exe
                                Wow64 process (32bit):false
                                Commandline:icacls.exe C:\Users\Public /restore C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\ZsL2hKzmRChz.acl
                                Imagebase:0x7ff6c0c40000
                                File size:39'424 bytes
                                MD5 hash:48C87E3B3003A2413D6399EA77707F5D
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Has exited:true

                                Target ID:18
                                Start time:07:42:26
                                Start date:27/07/2024
                                Path:C:\Windows\System32\conhost.exe
                                Wow64 process (32bit):false
                                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                Imagebase:0x7ff7699e0000
                                File size:862'208 bytes
                                MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Has exited:true

                                Target ID:19
                                Start time:07:42:48
                                Start date:27/07/2024
                                Path:C:\Windows\System32\svchost.exe
                                Wow64 process (32bit):false
                                Commandline:C:\Windows\System32\svchost.exe -k LocalService -p -s LicenseManager
                                Imagebase:0x7ff6eef20000
                                File size:55'320 bytes
                                MD5 hash:B7F884C1B74A263F746EE12A5F7C9F6A
                                Has elevated privileges:true
                                Has administrator privileges:false
                                Programmed in:C, C++ or other language
                                Has exited:false

                                Target ID:20
                                Start time:07:43:16
                                Start date:27/07/2024
                                Path:C:\Windows\System32\svchost.exe
                                Wow64 process (32bit):false
                                Commandline:C:\Windows\System32\svchost.exe -k WerSvcGroup
                                Imagebase:0x7ff6eef20000
                                File size:55'320 bytes
                                MD5 hash:B7F884C1B74A263F746EE12A5F7C9F6A
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Has exited:false

                                Target ID:21
                                Start time:07:43:16
                                Start date:27/07/2024
                                Path:C:\Windows\System32\WerFault.exe
                                Wow64 process (32bit):false
                                Commandline:C:\Windows\system32\WerFault.exe -pss -s 432 -p 3164 -ip 3164
                                Imagebase:0x7ff6823a0000
                                File size:570'736 bytes
                                MD5 hash:FD27D9F6D02763BDE32511B5DF7FF7A0
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Has exited:true

                                Target ID:22
                                Start time:07:43:16
                                Start date:27/07/2024
                                Path:C:\Windows\System32\WerFault.exe
                                Wow64 process (32bit):false
                                Commandline:C:\Windows\system32\WerFault.exe -u -p 3164 -s 1156
                                Imagebase:0x7ff6823a0000
                                File size:570'736 bytes
                                MD5 hash:FD27D9F6D02763BDE32511B5DF7FF7A0
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Has exited:true

                                Target ID:24
                                Start time:07:43:34
                                Start date:27/07/2024
                                Path:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                Wow64 process (32bit):false
                                Commandline:C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.exe
                                Imagebase:0x7ff7bacd0000
                                File size:89'088 bytes
                                MD5 hash:CFCBC15615FFC698507D32C0A7D21134
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Has exited:false

                                Reset < >
                                  APIs
                                  • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 033A9C07
                                  • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 033A9C0D
                                  • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 033A9C13
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1703305136.00000000033A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_33a0000_QTmGYKK6SL.jbxd
                                  Similarity
                                  • API ID: _invalid_parameter_noinfo_noreturn
                                  • String ID:
                                  • API String ID: 3668304517-0
                                  • Opcode ID: 54b6b3a6a9f18c1c42503a355f895c395cc67f602b7485ac6e008395e2f288b8
                                  • Instruction ID: f2bf6c0f20bdac16dc9d35bce2bdcfe5b46a310b94a0d0956c02eed59a0a9530
                                  • Opcode Fuzzy Hash: 54b6b3a6a9f18c1c42503a355f895c395cc67f602b7485ac6e008395e2f288b8
                                  • Instruction Fuzzy Hash: 52B15C34918F4C8FDB54EF2CC884A9EB7E1FBA9310F60571AA84AD7255DB709581CB41
                                  APIs
                                  • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 033ACC9F
                                  • _invalid_parameter_noinfo_noreturn.LIBCMT ref: 033ACCA5
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1703305136.00000000033A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_33a0000_QTmGYKK6SL.jbxd
                                  Similarity
                                  • API ID: _invalid_parameter_noinfo_noreturn
                                  • String ID:
                                  • API String ID: 3668304517-0
                                  • Opcode ID: 45e471fb9c1d00e182d5068cc72067aebab42eda361a8fe28810466512c0969c
                                  • Instruction ID: 2fd3cb59d81888549c80e505b8c57f92892406441019a13a853798fedafcc6e1
                                  • Opcode Fuzzy Hash: 45e471fb9c1d00e182d5068cc72067aebab42eda361a8fe28810466512c0969c
                                  • Instruction Fuzzy Hash: 9AA18D31928F8C8BDB14EF2CD8856EAB7E1FB99350F10571AA48AC7164DB34E581CB81
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1703305136.00000000033A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_33a0000_QTmGYKK6SL.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 49395fb1db586929925ec1189ca498da1cd1b490b708534174e820a908c43b9f
                                  • Instruction ID: 071e04f15c9dc22d1d9f0a5b95b0677107ac0d786bf636e998162c593e09f712
                                  • Opcode Fuzzy Hash: 49395fb1db586929925ec1189ca498da1cd1b490b708534174e820a908c43b9f
                                  • Instruction Fuzzy Hash: 58A1AF31A18E0C8FCB58EF2CD4C56ADB3E1FBA9310B04461EE48AD7255DA70E985CB85
                                  APIs
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1703305136.00000000033A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_33a0000_QTmGYKK6SL.jbxd
                                  Similarity
                                  • API ID: _clrfp
                                  • String ID:
                                  • API String ID: 3618594692-0
                                  • Opcode ID: efe40dfbbc0780a1a2bfbda1991ae8976835cde26a98ce25ff59e7c94d75e8ca
                                  • Instruction ID: 05f9b9f1d5cf43cece59b55f2f341a5ef724900002a7f53026b73e08036639fb
                                  • Opcode Fuzzy Hash: efe40dfbbc0780a1a2bfbda1991ae8976835cde26a98ce25ff59e7c94d75e8ca
                                  • Instruction Fuzzy Hash: 17B14730610A4DCFDBA9CF1CC8CABA6B7F1FB49304B198599E959CB666C335D852CB01
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1703305136.00000000033A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_33a0000_QTmGYKK6SL.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 5704d865c20122bb7255f085bdd420624eadc4fa98812b431343d99789eb5b45
                                  • Instruction ID: f5c89dab5e4bbf6aa86554bb220772671ee16acc6bcfeba41326f0199f04ed27
                                  • Opcode Fuzzy Hash: 5704d865c20122bb7255f085bdd420624eadc4fa98812b431343d99789eb5b45
                                  • Instruction Fuzzy Hash: 57E15D31928F8D8BC749DF68C8D45BAB3E1FBA8300F44571EE88AD7154EB74AA44C781
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1703305136.00000000033A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_33a0000_QTmGYKK6SL.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: df153f8d60fbe873a3e9d23a0d3d75c95b7a0dac35bf1a23fd1683ae13456419
                                  • Instruction ID: 42753157fcc54892bed690e6dc0509f96cc72abac982e21427f5de33f88db2ed
                                  • Opcode Fuzzy Hash: df153f8d60fbe873a3e9d23a0d3d75c95b7a0dac35bf1a23fd1683ae13456419
                                  • Instruction Fuzzy Hash: 3D61043091CB5C4FDB28EF289C8A1BABBF5FB84710F04475FE586C7156DA30A84286C2
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1703305136.00000000033A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_33a0000_QTmGYKK6SL.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: d2b80bb17cd9c218d1e222d3be9e57a11b086c6eca4a0abdae5755d48babc3af
                                  • Instruction ID: c924d89f1d57c02bf996e2b82112144949b01e2ac07c334419c49361b3e64045
                                  • Opcode Fuzzy Hash: d2b80bb17cd9c218d1e222d3be9e57a11b086c6eca4a0abdae5755d48babc3af
                                  • Instruction Fuzzy Hash: B9511432718E0C4FDB0CDE6CE8989B5B3E2F7AD310315832EE54AD72A5DA74D8468781
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1703305136.00000000033A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_33a0000_QTmGYKK6SL.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: b3bfdd2e48ad19d66b0e37b2c6738ec7b33e2acd157bee24fc1458e38cb5dc2f
                                  • Instruction ID: c1c52f56b5eba081b2ccdd9fbf6309b1b29f043a13fc95fe427325a07c8da24f
                                  • Opcode Fuzzy Hash: b3bfdd2e48ad19d66b0e37b2c6738ec7b33e2acd157bee24fc1458e38cb5dc2f
                                  • Instruction Fuzzy Hash: 932186317156054BE70CCE2EC899575B3D6F7D9205B58C67DD15BCB357C93658038A08
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1703305136.00000000033A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_33a0000_QTmGYKK6SL.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 818b3c2bf741691b3b4d97ce965452ef50dff5a67fbb0249e4fef83404bb3482
                                  • Instruction ID: 07d4b3b4565894dda7b1ab521cb994f938c9bedda78e714fc1ad8eb2d525bf38
                                  • Opcode Fuzzy Hash: 818b3c2bf741691b3b4d97ce965452ef50dff5a67fbb0249e4fef83404bb3482
                                  • Instruction Fuzzy Hash: 7711E572315C008FE74CDE3DCDC566573D6EB89214718C2BCE55ACB26AD6358403C744
                                  APIs
                                  • __FrameHandler3::GetHandlerSearchState.LIBVCRUNTIME ref: 033B096F
                                    • Part of subcall function 033B2CD2: __GetUnwindTryBlock.LIBCMT ref: 033B2D15
                                    • Part of subcall function 033B2CD2: __SetUnwindTryBlock.LIBVCRUNTIME ref: 033B2D3A
                                  • Is_bad_exception_allowed.LIBVCRUNTIME ref: 033B0A47
                                  • __FrameHandler3::ExecutionInCatch.LIBVCRUNTIME ref: 033B0C95
                                  • std::bad_alloc::bad_alloc.LIBCMT ref: 033B0DA2
                                  Strings
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1703305136.00000000033A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_33a0000_QTmGYKK6SL.jbxd
                                  Similarity
                                  • API ID: BlockFrameHandler3::Unwind$CatchExecutionHandlerIs_bad_exception_allowedSearchStatestd::bad_alloc::bad_alloc
                                  • String ID: csm$csm$csm
                                  • API String ID: 849930591-393685449
                                  • Opcode ID: 5b2f6b96f28cff2876ba3c8a704bf2042e89a9c9b999a2398d90b7d5bf9477b5
                                  • Instruction ID: f40cc00bcb35808bcb0536fcfebd5ae3699da60abed44b9f84d8afeec0f6ee18
                                  • Opcode Fuzzy Hash: 5b2f6b96f28cff2876ba3c8a704bf2042e89a9c9b999a2398d90b7d5bf9477b5
                                  • Instruction Fuzzy Hash: 85E17030918B088FDB58EF68C8C56EAB7F0FB98354F54065ED58ADB651DB34E481CB82
                                  APIs
                                  • Is_bad_exception_allowed.LIBVCRUNTIME ref: 033B0F80
                                  • std::bad_alloc::bad_alloc.LIBCMT ref: 033B12A9
                                  Strings
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1703305136.00000000033A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_33a0000_QTmGYKK6SL.jbxd
                                  Similarity
                                  • API ID: Is_bad_exception_allowedstd::bad_alloc::bad_alloc
                                  • String ID: csm$csm$csm
                                  • API String ID: 3523768491-393685449
                                  • Opcode ID: c0e8a6a559005a298c3155eaa0edc71f261e3c6bc1e132040adffd4f92bad855
                                  • Instruction ID: 76a2543c70234b8439309f6dc401aeaf08e02ff6c73872ed68653b8d51859682
                                  • Opcode Fuzzy Hash: c0e8a6a559005a298c3155eaa0edc71f261e3c6bc1e132040adffd4f92bad855
                                  • Instruction Fuzzy Hash: 99E1C334918B488FDB18EF28C8D16E9B7F1FB95310F14465ED596CB662DB30E582CB82
                                  APIs
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1703305136.00000000033A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_33a0000_QTmGYKK6SL.jbxd
                                  Similarity
                                  • API ID: AdjustPointer
                                  • String ID:
                                  • API String ID: 1740715915-0
                                  • Opcode ID: 8e7d662ee8937c04c5f417c45340c4d0fa32b695b79aab3ad2bc43397963f089
                                  • Instruction ID: 33f7f1c23e487028213c14959343fc8419e1ee5b59e70e191b30c0b311a47d3d
                                  • Opcode Fuzzy Hash: 8e7d662ee8937c04c5f417c45340c4d0fa32b695b79aab3ad2bc43397963f089
                                  • Instruction Fuzzy Hash: BAC1E330518F1A8FDB2DEF1C88D42BBB2F0FB94710B58466EC98AC7955EB70D8818791
                                  Strings
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1703305136.00000000033A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_33a0000_QTmGYKK6SL.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID: $($2$H$P!`$`
                                  • API String ID: 0-2682688576
                                  • Opcode ID: f0cd2e5902e2e8dc0272b1842c2263caec52b75ac89b4f60df87ff0c01938c8e
                                  • Instruction ID: 6ce74d92376ef547ee69534806055f4736ca6f44241075241fa12252f90624a7
                                  • Opcode Fuzzy Hash: f0cd2e5902e2e8dc0272b1842c2263caec52b75ac89b4f60df87ff0c01938c8e
                                  • Instruction Fuzzy Hash: C7C1F4B0908B888FD7A4DF1CC48879ABBE0FB99304F504A6ED88DCB215DB745589CF46
                                  APIs
                                  • _CallSETranslator.LIBVCRUNTIME ref: 033B1611
                                  Strings
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1703305136.00000000033A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_33a0000_QTmGYKK6SL.jbxd
                                  Similarity
                                  • API ID: CallTranslator
                                  • String ID: MOC$RCC
                                  • API String ID: 3163161869-2084237596
                                  • Opcode ID: 105ad8849598ec12c5d555c7b147fd1495b1c6b6b71dccbbe2818c1382ea2167
                                  • Instruction ID: 4a0d2444762b1b6be702c155ee88ffcf31dd69278a4723140ba92f354e60fddf
                                  • Opcode Fuzzy Hash: 105ad8849598ec12c5d555c7b147fd1495b1c6b6b71dccbbe2818c1382ea2167
                                  • Instruction Fuzzy Hash: 8FA19230918B488FCB19DF6CC895AE9BBF0FB98304F14465EE589C7551DB74E582CB82
                                  APIs
                                  • _CallSETranslator.LIBVCRUNTIME ref: 033B1391
                                  Strings
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1703305136.00000000033A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_33a0000_QTmGYKK6SL.jbxd
                                  Similarity
                                  • API ID: CallTranslator
                                  • String ID: MOC$RCC
                                  • API String ID: 3163161869-2084237596
                                  • Opcode ID: ce56de7200799010ae32f90d4c8e7df356f577e99ae53dd25fe57116d9e911d3
                                  • Instruction ID: 375abb29002e8972a485089eccbeac0bf8280a935987592605b49008f82ea831
                                  • Opcode Fuzzy Hash: ce56de7200799010ae32f90d4c8e7df356f577e99ae53dd25fe57116d9e911d3
                                  • Instruction Fuzzy Hash: ED71C530918B488FD768DF2CD886BEAB7E0FB99304F144A5ED58AC7211D774E581CB82
                                  APIs
                                  • __except_validate_context_record.LIBVCRUNTIME ref: 033AFC45
                                  • _IsNonwritableInCurrentImage.LIBCMT ref: 033AFCDC
                                  Strings
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1703305136.00000000033A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_33a0000_QTmGYKK6SL.jbxd
                                  Similarity
                                  • API ID: CurrentImageNonwritable__except_validate_context_record
                                  • String ID: csm
                                  • API String ID: 3242871069-1018135373
                                  • Opcode ID: 739d50aa53a7372d3f9f8c4cca6286223fd376175fafd75e91ede1457cd359ba
                                  • Instruction ID: 33d022db0c00ef467534c4680ba591517696032195a22c6b15375791e16f53fd
                                  • Opcode Fuzzy Hash: 739d50aa53a7372d3f9f8c4cca6286223fd376175fafd75e91ede1457cd359ba
                                  • Instruction Fuzzy Hash: 9761C230618E098BCF29EE5CECC5A74B3D5FB54354F14416EE88AC725AEB30E8528BC5
                                  APIs
                                  • __except_validate_context_record.LIBVCRUNTIME ref: 033B2450
                                  • _CreateFrameInfo.LIBVCRUNTIME ref: 033B2479
                                  Strings
                                  Memory Dump Source
                                  • Source File: 00000000.00000002.1703305136.00000000033A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_0_2_33a0000_QTmGYKK6SL.jbxd
                                  Similarity
                                  • API ID: CreateFrameInfo__except_validate_context_record
                                  • String ID: csm
                                  • API String ID: 2558813199-1018135373
                                  • Opcode ID: 06c119407accd39f8435343144e30bf6358969287a5cf68c59ee8460d9e456f2
                                  • Instruction ID: 63d9c317b9c716b5eefb41809b3f355cad937a1695dd4bc65a1580d8552be6b8
                                  • Opcode Fuzzy Hash: 06c119407accd39f8435343144e30bf6358969287a5cf68c59ee8460d9e456f2
                                  • Instruction Fuzzy Hash: FC5165B4918F088FD764EF2CC4C5A69B7E5FB99351F11065EE589CB621DB30E842CB82
                                  Memory Dump Source
                                  • Source File: 00000003.00000002.1970373625.00007FF665041000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF665040000, based on PE: true
                                  • Associated: 00000003.00000002.1970361216.00007FF665040000.00000002.00000001.01000000.00000005.sdmpDownload File
                                  • Associated: 00000003.00000002.1970388570.00007FF665050000.00000004.00000001.01000000.00000005.sdmpDownload File
                                  • Associated: 00000003.00000002.1970402379.00007FF665051000.00000008.00000001.01000000.00000005.sdmpDownload File
                                  • Associated: 00000003.00000002.1970402379.00007FF66564C000.00000008.00000001.01000000.00000005.sdmpDownload File
                                  • Associated: 00000003.00000002.1970402379.00007FF66564E000.00000008.00000001.01000000.00000005.sdmpDownload File
                                  • Associated: 00000003.00000002.1970966457.00007FF665A5D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                  • Associated: 00000003.00000002.1970994571.00007FF665A65000.00000004.00000001.01000000.00000005.sdmpDownload File
                                  • Associated: 00000003.00000002.1970994571.00007FF665A67000.00000004.00000001.01000000.00000005.sdmpDownload File
                                  • Associated: 00000003.00000002.1971086344.00007FF665A68000.00000008.00000001.01000000.00000005.sdmpDownload File
                                  • Associated: 00000003.00000002.1971120425.00007FF665A6B000.00000002.00000001.01000000.00000005.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_3_2_7ff665040000_o0c2ddmlg7qrbu2xkviy.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 9530b670b6bc79fe9eaccb2c34df731090ecf1aa2220e2cef9c324af77e614e1
                                  • Instruction ID: 0a4ca2396aedb37df83db20a4872948c74815feff93d324d997bb0b95425714c
                                  • Opcode Fuzzy Hash: 9530b670b6bc79fe9eaccb2c34df731090ecf1aa2220e2cef9c324af77e614e1
                                  • Instruction Fuzzy Hash: 1EB01234A14305C4F3012F16EC4325C3230AF14F00F400030C80C4B362CF7D98514720

                                  Execution Graph

                                  Execution Coverage:6.3%
                                  Dynamic/Decrypted Code Coverage:0%
                                  Signature Coverage:7.7%
                                  Total number of Nodes:2000
                                  Total number of Limit Nodes:28
                                  execution_graph 57571 7ff7bacd1b75 57601 7ff7bacd161a 57571->57601 57574 7ff7bacd1be4 RegisterServiceCtrlHandlerA 57576 7ff7bacd1c04 57574->57576 57577 7ff7bacd1c25 GetLastError 57574->57577 57575 7ff7bacd1b8d 57578 7ff7bacd1bac 57575->57578 57678 7ff7bacd1360 SetServiceStatus 57575->57678 57620 7ff7bacd1360 SetServiceStatus 57576->57620 57579 7ff7bacd2ef2 7 API calls 57577->57579 57679 7ff7bacd1a63 11 API calls 57578->57679 57595 7ff7bacd1b85 57579->57595 57582 7ff7bacd1c19 57621 7ff7bacd16e3 57582->57621 57585 7ff7bacd1d18 57658 7ff7bacd2ef2 57585->57658 57587 7ff7bacd1bb1 57680 7ff7bacd1b1c 14 API calls 57587->57680 57590 7ff7bacd1bb6 57593 7ff7bacd1dad ExitProcess 57590->57593 57594 7ff7bacd1bbe 57590->57594 57591 7ff7bacd1d48 57597 7ff7bacd2ef2 7 API calls 57591->57597 57592 7ff7bacd1d71 57592->57593 57598 7ff7bacd1bdd 57594->57598 57681 7ff7bacd1360 SetServiceStatus 57594->57681 57595->57575 57595->57592 57657 7ff7bacd1360 SetServiceStatus 57595->57657 57596 7ff7bacd1d32 57596->57591 57669 7ff7bacd19e2 57596->57669 57597->57575 57682 7ff7bacd1fd0 GetModuleHandleExA 57601->57682 57606 7ff7bacd164c 57619 7ff7bacd1650 57606->57619 57744 7ff7bacd28fc 57606->57744 57614 7ff7bacd1fd0 9 API calls 57615 7ff7bacd16b0 57614->57615 57616 7ff7bacd76d9 13 API calls 57615->57616 57617 7ff7bacd16c9 57616->57617 57617->57619 57796 7ff7bacd3452 57617->57796 57619->57574 57619->57595 57620->57582 57622 7ff7bacd1fd0 9 API calls 57621->57622 57623 7ff7bacd172e 57622->57623 57624 7ff7bacd75db 9 API calls 57623->57624 57625 7ff7bacd1743 57624->57625 57626 7ff7bacd174d strlen 57625->57626 57638 7ff7bacd1942 57625->57638 57628 7ff7bacd1783 _mbscpy strlen strlen 57626->57628 57629 7ff7bacd176a 57626->57629 57627 7ff7bacd197a 57627->57595 57641 7ff7bacd17ca 57628->57641 57629->57628 57630 7ff7bacd176f strlen 57629->57630 57630->57628 57631 7ff7bacd1938 58202 7ff7bacd47d8 FindClose 57631->58202 57633 7ff7bacd47f3 13 API calls 57633->57641 57634 7ff7bacd1959 57636 7ff7bacd2ef2 7 API calls 57634->57636 57635 7ff7bacd2ef2 7 API calls 57635->57638 57636->57627 57637 7ff7bacd2304 9 API calls 57637->57641 57638->57627 57638->57634 57638->57635 58114 7ffe11ec1b80 57638->58114 58127 7ffe126d1290 57638->58127 58140 7ffe13228ab0 57638->58140 58158 7ffe10245500 57638->58158 58173 7ffe1150ff90 57638->58173 58190 7ffe1a459120 57638->58190 58203 7ff7bacd1360 SetServiceStatus 57638->58203 57640 7ff7bacd1895 57643 7ff7bacd2ef2 7 API calls 57640->57643 57641->57631 57641->57633 57641->57637 57641->57640 57642 7ff7bacd17ee FreeLibrary 57641->57642 57644 7ff7bacd2283 9 API calls 57641->57644 58201 7ff7bacd1360 SetServiceStatus 57641->58201 57642->57641 57645 7ff7bacd18ad GetProcessHeap HeapAlloc 57643->57645 57644->57641 57647 7ff7bacd18cf _mbscpy 57645->57647 57648 7ff7bacd18f6 57645->57648 57647->57648 57649 7ff7bacd191b 57647->57649 57650 7ff7bacd2ef2 7 API calls 57648->57650 57649->57631 57649->57649 57650->57649 57657->57585 57659 7ff7bacd2f00 57658->57659 59700 7ff7bacdaab0 57659->59700 57662 7ff7bacd2fbc EnterCriticalSection 57665 7ff7bacd2fd6 LeaveCriticalSection 57662->57665 57666 7ff7bacd2ff3 57662->57666 57663 7ff7bacd2f87 fwrite fflush 57664 7ff7bacd2fb0 57663->57664 57664->57596 57665->57663 57667 7ff7bacd302d CopyFileA 57666->57667 57668 7ff7bacd3065 57667->57668 57668->57665 57670 7ff7bacd1fd0 9 API calls 57669->57670 57671 7ff7bacd1a11 57670->57671 57672 7ff7bacd75db 9 API calls 57671->57672 57673 7ff7bacd1a23 57672->57673 57674 7ff7bacd13cd 21 API calls 57673->57674 57677 7ff7bacd1a29 57673->57677 57675 7ff7bacd1a3f 57674->57675 57676 7ff7bacd1a4c SleepEx 57675->57676 57675->57677 57676->57677 57677->57596 57678->57578 57679->57587 57680->57590 57681->57598 57683 7ff7bacd2002 GetLastError 57682->57683 57684 7ff7bacd162f 57682->57684 57685 7ff7bacd2ef2 7 API calls 57683->57685 57686 7ff7bacd76d9 57684->57686 57685->57684 57687 7ff7bacd771f 57686->57687 57688 7ff7bacd76ef 57686->57688 57690 7ff7bacd2ef2 7 API calls 57687->57690 57819 7ff7bacd75db 57688->57819 57693 7ff7bacd1648 57690->57693 57692 7ff7bacd774f strlen 57694 7ff7bacd7761 57692->57694 57695 7ff7bacd7777 _mbscat strlen 57692->57695 57693->57606 57697 7ff7bacd68af 57693->57697 57694->57695 57696 7ff7bacd7766 strlen 57694->57696 57695->57693 57696->57695 57698 7ff7bacd68c6 57697->57698 57699 7ff7bacd69b2 57697->57699 57701 7ff7bacd68cf CreateFileA 57698->57701 57702 7ff7bacd69e2 57698->57702 57700 7ff7bacd2ef2 7 API calls 57699->57700 57705 7ff7bacd6967 57700->57705 57703 7ff7bacd6a15 GetLastError 57701->57703 57704 7ff7bacd691a LockFileEx 57701->57704 57706 7ff7bacd2ef2 7 API calls 57702->57706 57707 7ff7bacd2ef2 7 API calls 57703->57707 57708 7ff7bacd694e 57704->57708 57709 7ff7bacd6afa GetLastError 57704->57709 57712 7ff7bacd6c79 57705->57712 57713 7ff7bacd6991 57705->57713 57706->57705 57717 7ff7bacd6a36 57707->57717 57708->57705 57710 7ff7bacd6c6b CloseHandle 57708->57710 57711 7ff7bacd2ef2 7 API calls 57709->57711 57710->57712 57718 7ff7bacd6b1b 57711->57718 57715 7ff7bacd2ef2 7 API calls 57712->57715 57714 7ff7bacd2ef2 7 API calls 57713->57714 57716 7ff7bacd1669 57714->57716 57715->57716 57716->57619 57720 7ff7bacd309c InitializeCriticalSectionAndSpinCount 57716->57720 57717->57709 57719 7ff7bacd6ba3 57717->57719 57718->57719 57719->57710 57721 7ff7bacd31ed GetLastError 57720->57721 57722 7ff7bacd30ca 57720->57722 57723 7ff7bacd2ef2 7 API calls 57721->57723 57724 7ff7bacd1fd0 9 API calls 57722->57724 57732 7ff7bacd31c6 57723->57732 57725 7ff7bacd30e6 57724->57725 57726 7ff7bacd75db 9 API calls 57725->57726 57727 7ff7bacd30fa 57726->57727 57728 7ff7bacd3104 strlen 57727->57728 57727->57732 57729 7ff7bacd3133 57728->57729 57730 7ff7bacd311d 57728->57730 57734 7ff7bacd3158 strlen fopen 57729->57734 57735 7ff7bacd3138 _mbscat strlen 57729->57735 57730->57729 57733 7ff7bacd3122 strlen 57730->57733 57731 7ff7bacd2ef2 7 API calls 57736 7ff7bacd31e3 57731->57736 57732->57731 57733->57729 57737 7ff7bacd31a4 57734->57737 57738 7ff7bacd32ba 57734->57738 57735->57734 57736->57606 57740 7ff7bacd2ef2 7 API calls 57737->57740 57739 7ff7bacd2ef2 7 API calls 57738->57739 57739->57732 57741 7ff7bacd31be 57740->57741 57741->57732 57742 7ff7bacd332a 57741->57742 57743 7ff7bacd2ef2 7 API calls 57742->57743 57743->57736 57833 7ff7bacd2304 57744->57833 57748 7ff7bacd2963 FreeLibrary 57751 7ff7bacd29c3 GetNativeSystemInfo GetWindowsDirectoryA 57748->57751 57771 7ff7bacd2999 57748->57771 57750 7ff7bacd2ef2 7 API calls 57774 7ff7bacd167e 57750->57774 57753 7ff7bacd2ae0 57751->57753 57754 7ff7bacd2a02 GetLastError 57751->57754 57756 7ff7bacd2ef2 7 API calls 57753->57756 57755 7ff7bacd2ef2 7 API calls 57754->57755 57755->57771 57758 7ff7bacd2b01 57756->57758 57757 7ff7bacd2ef2 7 API calls 57757->57748 57758->57771 57849 7ff7bacd9292 57758->57849 57760 7ff7bacd2ef2 7 API calls 57767 7ff7bacd2b3d 57760->57767 57761 7ff7bacd2b4d GetVolumeInformationA 57762 7ff7bacd2bb0 GetLastError 57761->57762 57763 7ff7bacd2ca7 57761->57763 57765 7ff7bacd2ef2 7 API calls 57762->57765 57764 7ff7bacd2ef2 7 API calls 57763->57764 57766 7ff7bacd2cc4 57764->57766 57765->57767 57768 7ff7bacd2cdb strlen 57766->57768 57769 7ff7bacd2ced 57766->57769 57767->57760 57767->57761 57767->57771 57768->57769 57770 7ff7bacd2db9 57768->57770 57772 7ff7bacd2ef2 7 API calls 57769->57772 57770->57769 57771->57750 57772->57774 57774->57619 57779 7ff7bacd14ef 57774->57779 57780 7ff7bacd1fd0 9 API calls 57779->57780 57781 7ff7bacd1534 57780->57781 57782 7ff7bacd75db 9 API calls 57781->57782 57783 7ff7bacd1546 57782->57783 57784 7ff7bacd1576 57783->57784 57785 7ff7bacd154c _mbscpy 57783->57785 57787 7ff7bacd2ef2 7 API calls 57784->57787 57876 7ff7bacd13cd strlen 57785->57876 57789 7ff7bacd15a1 57787->57789 57789->57614 57789->57619 57790 7ff7bacd1572 57790->57784 57792 7ff7bacd15f1 57790->57792 57794 7ff7bacd2ef2 7 API calls 57792->57794 57794->57789 57797 7ff7bacd3505 57796->57797 57798 7ff7bacd347a 57796->57798 57799 7ff7bacd2ef2 7 API calls 57797->57799 57800 7ff7bacd5015 31 API calls 57798->57800 57801 7ff7bacd3493 57799->57801 57806 7ff7bacd3489 57800->57806 57802 7ff7bacd34b4 57801->57802 57803 7ff7bacd349d GetProcessHeap HeapFree 57801->57803 57804 7ff7bacd3838 57802->57804 57809 7ff7bacd34dc 57802->57809 57803->57802 57805 7ff7bacd2ef2 7 API calls 57804->57805 57810 7ff7bacd385a 57805->57810 57806->57801 57807 7ff7bacd35bd GetProcessHeap HeapAlloc 57806->57807 57808 7ff7bacd3636 57807->57808 57815 7ff7bacd35fa 57807->57815 57812 7ff7bacd2ef2 7 API calls 57808->57812 57813 7ff7bacd2ef2 7 API calls 57809->57813 57811 7ff7bacd382e 57811->57801 57812->57815 57814 7ff7bacd34f2 57813->57814 57814->57619 57815->57801 57815->57811 57816 7ff7bacd37c4 strncpy strncpy 57815->57816 57817 7ff7bacd36d5 strncpy 57815->57817 57816->57815 57817->57815 57820 7ff7bacd7622 57819->57820 57821 7ff7bacd75ec 57819->57821 57822 7ff7bacd2ef2 7 API calls 57820->57822 57823 7ff7bacd75f1 57821->57823 57824 7ff7bacd7652 57821->57824 57830 7ff7bacd7607 57822->57830 57826 7ff7bacd7682 57823->57826 57827 7ff7bacd75fa 57823->57827 57825 7ff7bacd2ef2 7 API calls 57824->57825 57825->57830 57828 7ff7bacd2ef2 7 API calls 57826->57828 57832 7ff7bacd749c 9 API calls 57827->57832 57828->57830 57830->57692 57830->57693 57831 7ff7bacd75ff 57831->57830 57832->57831 57834 7ff7bacd2312 LoadLibraryA 57833->57834 57835 7ff7bacd233b 57833->57835 57836 7ff7bacd2320 57834->57836 57837 7ff7bacd233e GetLastError 57834->57837 57835->57837 57838 7ff7bacd2ef2 7 API calls 57836->57838 57839 7ff7bacd2ef2 7 API calls 57837->57839 57840 7ff7bacd2339 57838->57840 57839->57840 57840->57771 57841 7ff7bacd2283 57840->57841 57842 7ff7bacd22a0 GetProcAddress 57841->57842 57843 7ff7bacd22d1 57841->57843 57844 7ff7bacd22d6 GetLastError 57842->57844 57845 7ff7bacd22b1 57842->57845 57843->57844 57847 7ff7bacd2ef2 7 API calls 57844->57847 57846 7ff7bacd2ef2 7 API calls 57845->57846 57848 7ff7bacd22cf 57846->57848 57847->57848 57848->57748 57848->57757 57850 7ff7bacd92bb 57849->57850 57867 7ff7bacd931a 57849->57867 57851 7ff7bacd92c4 57850->57851 57852 7ff7bacd937d 57850->57852 57854 7ff7bacd93b0 57851->57854 57855 7ff7bacd92cd 57851->57855 57856 7ff7bacd2ef2 7 API calls 57852->57856 57853 7ff7bacd2ef2 7 API calls 57873 7ff7bacd9373 57853->57873 57857 7ff7bacd2ef2 7 API calls 57854->57857 57858 7ff7bacd93e3 57855->57858 57859 7ff7bacd92d6 RegOpenKeyExA 57855->57859 57856->57873 57857->57873 57862 7ff7bacd2ef2 7 API calls 57858->57862 57860 7ff7bacd9416 RegQueryValueExA 57859->57860 57861 7ff7bacd92fd 57859->57861 57874 7ff7bacd9444 57860->57874 57875 7ff7bacd9497 RegCloseKey 57860->57875 57864 7ff7bacd2ef2 7 API calls 57861->57864 57862->57873 57863 7ff7bacd9719 57866 7ff7bacd2ef2 7 API calls 57863->57866 57864->57867 57869 7ff7bacd95b9 57866->57869 57867->57853 57867->57873 57868 7ff7bacd973c 57869->57767 57870 7ff7bacd9576 57870->57868 57871 7ff7bacd2ef2 7 API calls 57870->57871 57871->57869 57872 7ff7bacd2ef2 7 API calls 57872->57874 57873->57863 57873->57870 57874->57872 57874->57875 57875->57873 57877 7ff7bacd13fd strlen 57876->57877 57878 7ff7bacd13e7 57876->57878 57929 7ff7bacd6ed7 57877->57929 57878->57877 57879 7ff7bacd13ec strlen 57878->57879 57879->57877 57882 7ff7bacd1487 strlen 57883 7ff7bacd6ed7 9 API calls 57882->57883 57885 7ff7bacd1425 57883->57885 57884 7ff7bacd14c8 57959 7ff7bacd47d8 FindClose 57884->57959 57885->57882 57885->57884 57887 7ff7bacd14b4 strlen 57885->57887 57888 7ff7bacd1436 57885->57888 57935 7ff7bacd47f3 57885->57935 57887->57885 57888->57790 57889 7ff7bacd77a0 57888->57889 57890 7ff7bacd7842 57889->57890 57891 7ff7bacd77c2 57889->57891 57892 7ff7bacd2ef2 7 API calls 57890->57892 57893 7ff7bacd7872 57891->57893 57894 7ff7bacd77cb 57891->57894 57903 7ff7bacd77f6 57892->57903 57895 7ff7bacd2ef2 7 API calls 57893->57895 57960 7ff7bacd5015 57894->57960 57895->57903 57899 7ff7bacd7aee 57901 7ff7bacd2ef2 7 API calls 57902 7ff7bacd15c7 57901->57902 57902->57784 57917 7ff7bacd55fd 57902->57917 57903->57899 57903->57901 57930 7ff7bacd6ef5 57929->57930 57931 7ff7bacd6ee0 GetFileAttributesA 57929->57931 57933 7ff7bacd2ef2 7 API calls 57930->57933 57932 7ff7bacd6f25 GetLastError 57931->57932 57934 7ff7bacd6eeb 57931->57934 57932->57934 57933->57934 57934->57885 57936 7ff7bacd4813 57935->57936 57952 7ff7bacd4859 57935->57952 57937 7ff7bacd48b2 57936->57937 57938 7ff7bacd481c 57936->57938 57942 7ff7bacd2ef2 7 API calls 57937->57942 57940 7ff7bacd4825 57938->57940 57941 7ff7bacd48ea 57938->57941 57939 7ff7bacd2ef2 7 API calls 57958 7ff7bacd48a3 57939->57958 57944 7ff7bacd4831 FindNextFileA 57940->57944 57945 7ff7bacd4922 FindFirstFileA 57940->57945 57943 7ff7bacd2ef2 7 API calls 57941->57943 57942->57958 57943->57958 57946 7ff7bacd4972 GetLastError 57944->57946 57947 7ff7bacd4847 _mbscpy 57944->57947 57945->57947 57948 7ff7bacd4943 GetLastError 57945->57948 57951 7ff7bacd499b 57946->57951 57956 7ff7bacd4950 57946->57956 57947->57952 57950 7ff7bacd4957 57948->57950 57948->57956 57953 7ff7bacd2ef2 7 API calls 57950->57953 57955 7ff7bacd2ef2 7 API calls 57951->57955 57952->57939 57952->57958 57953->57956 57954 7ff7bacd498d FindClose 57954->57952 57955->57956 57956->57952 57956->57954 57957 7ff7bacd49b8 57956->57957 57957->57885 57958->57885 57959->57888 57961 7ff7bacd50b5 57960->57961 57962 7ff7bacd5037 57960->57962 57965 7ff7bacd2ef2 7 API calls 57961->57965 57963 7ff7bacd5040 57962->57963 57964 7ff7bacd50fa 57962->57964 57966 7ff7bacd5050 fopen 57963->57966 57968 7ff7bacd512d 57963->57968 57967 7ff7bacd2ef2 7 API calls 57964->57967 57975 7ff7bacd50f0 57965->57975 57967->57975 58204 7ffe11ec9f6c InitializeCriticalSectionAndSpinCount 58114->58204 58123 7ffe11ec1b96 58126 7ffe11ec1b9a 58123->58126 58273 7ffe11ec296e WSAStartup 58123->58273 58126->57638 58431 7ffe126d14fc InitializeCriticalSectionAndSpinCount 58127->58431 58134 7ffe126d12a6 58139 7ffe126d12aa 58134->58139 58500 7ffe126d4bae WSAStartup 58134->58500 58135 7ffe126d12f1 58135->58139 58508 7ffe126d2bc8 InitializeCriticalSectionAndSpinCount 58135->58508 58139->57638 58658 7ffe1322794c InitializeCriticalSectionAndSpinCount 58140->58658 58143 7ffe13228ac9 58144 7ffe13228acd 58143->58144 58727 7ffe13221fce WSAStartup 58143->58727 58147 7ffe132277a2 6 API calls 58144->58147 58157 7ffe13228aea 58147->58157 58150 7ffe13228b3b 58150->58144 58735 7ffe132264f8 InitializeCriticalSectionAndSpinCount 58150->58735 58157->57638 58990 7ffe1024427c InitializeCriticalSectionAndSpinCount 58158->58990 58161 7ffe10245516 58162 7ffe1024551a 58161->58162 59059 7ffe102462fe WSAStartup 58161->59059 58162->57638 59225 7ffe1150c9fc InitializeCriticalSectionAndSpinCount 58173->59225 58176 7ffe1150ffa6 58177 7ffe1150ffaa 58176->58177 59294 7ffe11508b63 InitializeCriticalSectionAndSpinCount 58176->59294 58177->57638 59472 7ffe1a45226c InitializeCriticalSectionAndSpinCount 58190->59472 58193 7ffe1a459136 58200 7ffe1a45913a 58193->58200 59539 7ffe1a4532de WSAStartup 58193->59539 58198 7ffe1a459181 58198->58200 59547 7ffe1a453af7 InitializeCriticalSectionAndSpinCount 58198->59547 58200->57638 58201->57641 58202->57638 58203->57638 58205 7ffe11ec9f9a 58204->58205 58206 7ffe11eca0c0 GetLastError 58204->58206 58309 7ffe11ec4ac0 GetModuleHandleExA 58205->58309 58208 7ffe11ec9dc2 6 API calls 58206->58208 58213 7ffe11eca099 58208->58213 58212 7ffe11ec9fd4 strlen 58215 7ffe11ec9fed 58212->58215 58216 7ffe11eca003 58212->58216 58214 7ffe11ec9dc2 6 API calls 58213->58214 58219 7ffe11ec1b92 58214->58219 58215->58216 58220 7ffe11ec9ff2 strlen 58215->58220 58217 7ffe11eca028 strlen fopen 58216->58217 58218 7ffe11eca008 strcat strlen 58216->58218 58221 7ffe11eca18d 58217->58221 58222 7ffe11eca077 58217->58222 58218->58217 58219->58123 58228 7ffe11ecadda 58219->58228 58220->58216 58224 7ffe11ec9dc2 6 API calls 58221->58224 58326 7ffe11ec9dc2 58222->58326 58224->58213 58229 7ffe11ecadfc 58228->58229 58230 7ffe11ecae3f 58228->58230 58346 7ffe11ecaa46 58229->58346 58231 7ffe11ec9dc2 6 API calls 58230->58231 58237 7ffe11ec1bd1 58231->58237 58234 7ffe11ecae6f _errno _strtoui64 _errno 58235 7ffe11ecaea2 _errno 58234->58235 58234->58237 58236 7ffe11ec9dc2 6 API calls 58235->58236 58236->58237 58237->58126 58238 7ffe11ec44cc 58237->58238 58388 7ffe11ec4df4 58238->58388 58252 7ffe11ec4569 58274 7ffe11ec298a 58273->58274 58275 7ffe11ec29b2 58273->58275 58276 7ffe11ec9dc2 6 API calls 58274->58276 58277 7ffe11ec9dc2 6 API calls 58275->58277 58278 7ffe11ec1be1 58276->58278 58279 7ffe11ec29cb 58277->58279 58278->58126 58281 7ffe11ec17f8 InitializeCriticalSectionAndSpinCount 58278->58281 58280 7ffe11ec9dc2 6 API calls 58279->58280 58280->58278 58282 7ffe11ec181d CreateThread 58281->58282 58283 7ffe11ec189b GetLastError 58281->58283 58284 7ffe11ec1869 58282->58284 58285 7ffe11ec1973 GetLastError 58282->58285 58286 7ffe11ec9dc2 6 API calls 58283->58286 58287 7ffe11ec1a6c 58284->58287 58288 7ffe11ec1876 58284->58288 58289 7ffe11ec9dc2 6 API calls 58285->58289 58286->58288 58291 7ffe11ec9dc2 6 API calls 58287->58291 58290 7ffe11ec9dc2 6 API calls 58288->58290 58289->58288 58292 7ffe11ec1893 58290->58292 58291->58292 58292->58126 58310 7ffe11ec4ae8 58309->58310 58311 7ffe11ec4af2 GetLastError 58309->58311 58313 7ffe11ec89db 58310->58313 58312 7ffe11ec9dc2 6 API calls 58311->58312 58312->58310 58314 7ffe11ec89ec 58313->58314 58315 7ffe11ec8a22 58313->58315 58317 7ffe11ec8a52 58314->58317 58318 7ffe11ec89f1 58314->58318 58316 7ffe11ec9dc2 6 API calls 58315->58316 58324 7ffe11ec8a07 58316->58324 58319 7ffe11ec9dc2 6 API calls 58317->58319 58320 7ffe11ec89fa 58318->58320 58321 7ffe11ec8a82 58318->58321 58319->58324 58337 7ffe11ec889c 8 API calls 58320->58337 58322 7ffe11ec9dc2 6 API calls 58321->58322 58322->58324 58324->58212 58324->58213 58325 7ffe11ec89ff 58325->58324 58327 7ffe11ec9dd0 58326->58327 58338 7ffe11ecd5d0 58327->58338 58337->58325 58339 7ffe11ecd5f5 58338->58339 58340 7ffe11ecd5de 58338->58340 58345 7ffe11ece630 fputc 58339->58345 58344 7ffe11ece630 fputc 58340->58344 58347 7ffe11ecaa57 58346->58347 58348 7ffe11ecaa8f 58346->58348 58354 7ffe11eca72f 58347->58354 58349 7ffe11ec9dc2 6 API calls 58348->58349 58352 7ffe11ecaa6e 58349->58352 58352->58234 58352->58237 58355 7ffe11eca747 58354->58355 58356 7ffe11eca762 58354->58356 58357 7ffe11eca74c 58355->58357 58358 7ffe11eca795 58355->58358 58359 7ffe11ec9dc2 6 API calls 58356->58359 58360 7ffe11eca7c8 58357->58360 58367 7ffe11eca751 58357->58367 58361 7ffe11ec9dc2 6 API calls 58358->58361 58366 7ffe11eca78b 58359->58366 58362 7ffe11ec9dc2 6 API calls 58360->58362 58361->58366 58362->58366 58363 7ffe11eca832 58365 7ffe11eca839 58363->58365 58363->58366 58364 7ffe11eca807 strcmp 58364->58367 58369 7ffe11ec9dc2 6 API calls 58366->58369 58367->58363 58367->58364 58370 7ffe11eca84f 58369->58370 58370->58352 58371 7ffe11eca8b6 58370->58371 58389 7ffe11ec4e2b 58388->58389 58390 7ffe11ec4e02 LoadLibraryA 58388->58390 58392 7ffe11ec4e2e GetLastError 58389->58392 58391 7ffe11ec4e10 58390->58391 58390->58392 58393 7ffe11ec9dc2 6 API calls 58391->58393 58394 7ffe11ec9dc2 6 API calls 58392->58394 58395 7ffe11ec44e0 58393->58395 58394->58395 58395->58252 58396 7ffe11ec4d73 58395->58396 58432 7ffe126d152a 58431->58432 58433 7ffe126d1650 GetLastError 58431->58433 58536 7ffe126d3ad0 GetModuleHandleExA 58432->58536 58434 7ffe126d1352 10 API calls 58433->58434 58443 7ffe126d1629 58434->58443 58439 7ffe126d1564 strlen 58440 7ffe126d157d 58439->58440 58441 7ffe126d1593 58439->58441 58440->58441 58444 7ffe126d1582 strlen 58440->58444 58445 7ffe126d15b8 strlen fopen 58441->58445 58446 7ffe126d1598 strcat strlen 58441->58446 58442 7ffe126d1352 10 API calls 58454 7ffe126d12a2 58442->58454 58443->58442 58444->58441 58447 7ffe126d171d 58445->58447 58448 7ffe126d1607 58445->58448 58446->58445 58450 7ffe126d1352 10 API calls 58447->58450 58553 7ffe126d1352 58448->58553 58450->58443 58454->58134 58455 7ffe126d236a 58454->58455 58456 7ffe126d238c 58455->58456 58457 7ffe126d23cf 58455->58457 58573 7ffe126d1fd6 58456->58573 58458 7ffe126d1352 10 API calls 58457->58458 58460 7ffe126d12e1 58458->58460 58460->58139 58465 7ffe126d34dc 58460->58465 58462 7ffe126d23ff _errno _strtoui64 _errno 58462->58460 58463 7ffe126d2432 _errno 58462->58463 58464 7ffe126d1352 10 API calls 58463->58464 58464->58460 58615 7ffe126d3e04 58465->58615 58501 7ffe126d4bca 58500->58501 58502 7ffe126d4bf2 58500->58502 58503 7ffe126d1352 10 API calls 58501->58503 58504 7ffe126d1352 10 API calls 58502->58504 58505 7ffe126d4be4 58503->58505 58506 7ffe126d4c0b 58504->58506 58505->58135 58507 7ffe126d1352 10 API calls 58506->58507 58507->58505 58509 7ffe126d2c6b GetLastError 58508->58509 58510 7ffe126d2bed CreateThread 58508->58510 58513 7ffe126d1352 10 API calls 58509->58513 58511 7ffe126d2c39 58510->58511 58512 7ffe126d2d43 GetLastError 58510->58512 58515 7ffe126d2e3c 58511->58515 58519 7ffe126d2c46 58511->58519 58514 7ffe126d1352 10 API calls 58512->58514 58513->58519 58514->58519 58516 7ffe126d1352 10 API calls 58515->58516 58517 7ffe126d1352 10 API calls 58519->58517 58537 7ffe126d1546 58536->58537 58538 7ffe126d3b02 GetLastError 58536->58538 58540 7ffe126d803b 58537->58540 58539 7ffe126d1352 10 API calls 58538->58539 58539->58537 58541 7ffe126d804c 58540->58541 58542 7ffe126d8082 58540->58542 58544 7ffe126d80b2 58541->58544 58545 7ffe126d8051 58541->58545 58543 7ffe126d1352 10 API calls 58542->58543 58551 7ffe126d155a 58543->58551 58546 7ffe126d1352 10 API calls 58544->58546 58547 7ffe126d805a 58545->58547 58548 7ffe126d80e2 58545->58548 58546->58551 58564 7ffe126d7efc 12 API calls 58547->58564 58549 7ffe126d1352 10 API calls 58548->58549 58549->58551 58551->58439 58551->58443 58552 7ffe126d805f 58552->58551 58554 7ffe126d1360 58553->58554 58565 7ffe126dd110 58554->58565 58564->58552 58566 7ffe126dd135 58565->58566 58567 7ffe126dd11e 58565->58567 58572 7ffe126de170 fputc WideCharToMultiByte _errno ___mb_cur_max_func ___lc_codepage_func 58566->58572 58571 7ffe126de170 fputc WideCharToMultiByte _errno ___mb_cur_max_func ___lc_codepage_func 58567->58571 58574 7ffe126d1fe7 58573->58574 58575 7ffe126d201f 58573->58575 58581 7ffe126d1cbf 58574->58581 58576 7ffe126d1352 10 API calls 58575->58576 58579 7ffe126d1ffe 58576->58579 58579->58460 58579->58462 58582 7ffe126d1cd7 58581->58582 58583 7ffe126d1cf2 58581->58583 58585 7ffe126d1cdc 58582->58585 58586 7ffe126d1d25 58582->58586 58584 7ffe126d1352 10 API calls 58583->58584 58593 7ffe126d1d1b 58584->58593 58587 7ffe126d1d58 58585->58587 58588 7ffe126d1ce1 58585->58588 58589 7ffe126d1352 10 API calls 58586->58589 58590 7ffe126d1352 10 API calls 58587->58590 58591 7ffe126d1dc2 58588->58591 58594 7ffe126d1d97 strcmp 58588->58594 58589->58593 58590->58593 58592 7ffe126d1dc9 58591->58592 58591->58593 58595 7ffe126d1352 10 API calls 58592->58595 58596 7ffe126d1352 10 API calls 58593->58596 58594->58588 58597 7ffe126d1ddf 58595->58597 58596->58597 58597->58579 58598 7ffe126d1e46 58597->58598 58616 7ffe126d3e3b 58615->58616 58617 7ffe126d3e12 LoadLibraryA 58615->58617 58618 7ffe126d3e3e GetLastError 58616->58618 58617->58618 58619 7ffe126d3e20 58617->58619 58621 7ffe126d1352 10 API calls 58618->58621 58620 7ffe126d1352 10 API calls 58619->58620 58622 7ffe126d34f0 58620->58622 58621->58622 58659 7ffe13227aa0 GetLastError 58658->58659 58660 7ffe1322797a 58658->58660 58661 7ffe132277a2 6 API calls 58659->58661 58787 7ffe13227400 GetModuleHandleExA 58660->58787 58663 7ffe13227a79 58661->58663 58670 7ffe132277a2 6 API calls 58663->58670 58667 7ffe132279b4 strlen 58668 7ffe132279e3 58667->58668 58669 7ffe132279cd 58667->58669 58672 7ffe13227a08 strlen fopen 58668->58672 58673 7ffe132279e8 strcat strlen 58668->58673 58669->58668 58671 7ffe132279d2 strlen 58669->58671 58681 7ffe13227a96 58670->58681 58671->58668 58674 7ffe13227a57 58672->58674 58675 7ffe13227b6d 58672->58675 58673->58672 58676 7ffe132277a2 6 API calls 58674->58676 58677 7ffe132277a2 6 API calls 58675->58677 58678 7ffe13227a71 58676->58678 58677->58663 58678->58663 58679 7ffe13227bdd 58678->58679 58680 7ffe132277a2 6 API calls 58679->58680 58680->58681 58681->58143 58682 7ffe132287ba 58681->58682 58683 7ffe1322881f 58682->58683 58684 7ffe132287dc 58682->58684 58686 7ffe132277a2 6 API calls 58683->58686 58805 7ffe13228426 58684->58805 58688 7ffe132287f5 58686->58688 58688->58144 58692 7ffe13226e0c 58688->58692 58689 7ffe1322884f _errno _strtoui64 _errno 58689->58688 58690 7ffe13228882 _errno 58689->58690 58691 7ffe132277a2 6 API calls 58690->58691 58691->58688 58847 7ffe13227734 58692->58847 58720 7ffe13226ea9 58728 7ffe13222012 58727->58728 58729 7ffe13221fea 58727->58729 58731 7ffe132277a2 6 API calls 58728->58731 58730 7ffe132277a2 6 API calls 58729->58730 58732 7ffe13222004 58730->58732 58733 7ffe1322202b 58731->58733 58732->58150 58734 7ffe132277a2 6 API calls 58733->58734 58734->58732 58736 7ffe1322659b GetLastError 58735->58736 58737 7ffe1322651d CreateThread 58735->58737 58739 7ffe132277a2 6 API calls 58736->58739 58738 7ffe13226673 GetLastError 58737->58738 58746 7ffe13226569 58737->58746 58742 7ffe132277a2 6 API calls 58738->58742 58741 7ffe13226576 58739->58741 58740 7ffe1322676c 58742->58746 58746->58740 58746->58741 58788 7ffe13227432 GetLastError 58787->58788 58789 7ffe13227428 58787->58789 58790 7ffe132277a2 6 API calls 58788->58790 58791 7ffe13225dcb 58789->58791 58790->58789 58792 7ffe13225e12 58791->58792 58793 7ffe13225ddc 58791->58793 58794 7ffe132277a2 6 API calls 58792->58794 58795 7ffe13225de1 58793->58795 58796 7ffe13225e42 58793->58796 58802 7ffe13225df7 58794->58802 58797 7ffe13225e72 58795->58797 58798 7ffe13225dea 58795->58798 58799 7ffe132277a2 6 API calls 58796->58799 58801 7ffe132277a2 6 API calls 58797->58801 58804 7ffe13225c8c 8 API calls 58798->58804 58799->58802 58801->58802 58802->58663 58802->58667 58803 7ffe13225def 58803->58802 58804->58803 58806 7ffe1322846f 58805->58806 58807 7ffe13228437 58805->58807 58809 7ffe132277a2 6 API calls 58806->58809 58813 7ffe1322810f 58807->58813 58810 7ffe1322844e 58809->58810 58810->58688 58810->58689 58814 7ffe13228142 58813->58814 58815 7ffe13228127 58813->58815 58818 7ffe132277a2 6 API calls 58814->58818 58816 7ffe13228175 58815->58816 58817 7ffe1322812c 58815->58817 58820 7ffe132277a2 6 API calls 58816->58820 58819 7ffe132281a8 58817->58819 58827 7ffe13228131 58817->58827 58823 7ffe1322816b 58818->58823 58821 7ffe132277a2 6 API calls 58819->58821 58820->58823 58821->58823 58822 7ffe13228212 58822->58823 58825 7ffe13228219 58822->58825 58826 7ffe132277a2 6 API calls 58823->58826 58824 7ffe132281e7 strcmp 58824->58827 58828 7ffe132277a2 6 API calls 58825->58828 58829 7ffe1322822f 58826->58829 58827->58822 58827->58824 58828->58829 58829->58810 58830 7ffe13228296 58829->58830 58848 7ffe13227742 LoadLibraryA 58847->58848 58849 7ffe1322776b 58847->58849 58850 7ffe1322776e GetLastError 58848->58850 58851 7ffe13227750 58848->58851 58849->58850 58853 7ffe132277a2 6 API calls 58850->58853 58852 7ffe132277a2 6 API calls 58851->58852 58854 7ffe13226e20 58852->58854 58853->58854 58854->58720 58855 7ffe132276b3 58854->58855 58991 7ffe102443d0 GetLastError 58990->58991 58992 7ffe102442aa 58990->58992 58993 7ffe102440d2 6 API calls 58991->58993 59103 7ffe10242700 GetModuleHandleExA 58992->59103 59001 7ffe102443a9 58993->59001 58998 7ffe102442e4 strlen 58999 7ffe10244313 58998->58999 59000 7ffe102442fd 58998->59000 59004 7ffe10244338 strlen fopen 58999->59004 59005 7ffe10244318 strcat strlen 58999->59005 59000->58999 59003 7ffe10244302 strlen 59000->59003 59002 7ffe102440d2 6 API calls 59001->59002 59006 7ffe102443c6 59002->59006 59003->58999 59007 7ffe10244387 59004->59007 59008 7ffe1024449d 59004->59008 59005->59004 59006->58161 59014 7ffe1024520a 59006->59014 59120 7ffe102440d2 59007->59120 59009 7ffe102440d2 6 API calls 59008->59009 59009->59001 59015 7ffe1024526f 59014->59015 59016 7ffe1024522c 59014->59016 59018 7ffe102440d2 6 API calls 59015->59018 59140 7ffe10244e76 59016->59140 59023 7ffe10245245 59018->59023 59020 7ffe1024529f _errno _strtoui64 _errno 59021 7ffe102452d2 _errno 59020->59021 59020->59023 59022 7ffe102440d2 6 API calls 59021->59022 59022->59023 59023->58162 59024 7ffe1024210c 59023->59024 59182 7ffe10242a34 59024->59182 59038 7ffe102421a9 59060 7ffe10246342 59059->59060 59061 7ffe1024631a 59059->59061 59062 7ffe102440d2 6 API calls 59060->59062 59063 7ffe102440d2 6 API calls 59061->59063 59064 7ffe1024635b 59062->59064 59065 7ffe10245561 59063->59065 59066 7ffe102440d2 6 API calls 59064->59066 59065->58162 59067 7ffe10248fc4 InitializeCriticalSectionAndSpinCount 59065->59067 59066->59065 59068 7ffe10249014 GetLastError 59067->59068 59069 7ffe10248fdf 59067->59069 59071 7ffe102440d2 6 API calls 59068->59071 59070 7ffe102440d2 6 API calls 59069->59070 59073 7ffe1024556a 59070->59073 59074 7ffe10249032 59071->59074 59072 7ffe102440d2 6 API calls 59072->59073 59073->58162 59075 7ffe102417f8 InitializeCriticalSectionAndSpinCount 59073->59075 59074->59072 59076 7ffe1024181d CreateThread 59075->59076 59077 7ffe1024189b GetLastError 59075->59077 59104 7ffe10242732 GetLastError 59103->59104 59105 7ffe10242728 59103->59105 59106 7ffe102440d2 6 API calls 59104->59106 59107 7ffe1024cebb 59105->59107 59106->59105 59108 7ffe1024cf02 59107->59108 59109 7ffe1024cecc 59107->59109 59110 7ffe102440d2 6 API calls 59108->59110 59111 7ffe1024cf32 59109->59111 59112 7ffe1024ced1 59109->59112 59116 7ffe102442da 59110->59116 59113 7ffe102440d2 6 API calls 59111->59113 59114 7ffe1024cf62 59112->59114 59115 7ffe1024ceda 59112->59115 59113->59116 59117 7ffe102440d2 6 API calls 59114->59117 59131 7ffe1024cd7c 8 API calls 59115->59131 59116->58998 59116->59001 59117->59116 59119 7ffe1024cedf 59119->59116 59121 7ffe102440e0 59120->59121 59132 7ffe1024eef0 59121->59132 59131->59119 59133 7ffe1024ef15 59132->59133 59134 7ffe1024eefe 59132->59134 59141 7ffe10244ebf 59140->59141 59142 7ffe10244e87 59140->59142 59144 7ffe102440d2 6 API calls 59141->59144 59148 7ffe10244b5f 59142->59148 59146 7ffe10244e9e 59144->59146 59146->59020 59146->59023 59149 7ffe10244b92 59148->59149 59150 7ffe10244b77 59148->59150 59153 7ffe102440d2 6 API calls 59149->59153 59151 7ffe10244bc5 59150->59151 59152 7ffe10244b7c 59150->59152 59155 7ffe102440d2 6 API calls 59151->59155 59154 7ffe10244bf8 59152->59154 59161 7ffe10244b81 59152->59161 59160 7ffe10244bbb 59153->59160 59156 7ffe102440d2 6 API calls 59154->59156 59155->59160 59156->59160 59157 7ffe10244c62 59159 7ffe10244c69 59157->59159 59157->59160 59158 7ffe10244c37 strcmp 59158->59161 59162 7ffe102440d2 6 API calls 59159->59162 59163 7ffe102440d2 6 API calls 59160->59163 59161->59157 59161->59158 59164 7ffe10244c7f 59162->59164 59163->59164 59164->59146 59165 7ffe10244ce6 59164->59165 59183 7ffe10242a42 LoadLibraryA 59182->59183 59184 7ffe10242a6b 59182->59184 59185 7ffe10242a50 59183->59185 59186 7ffe10242a6e GetLastError 59183->59186 59184->59186 59187 7ffe102440d2 6 API calls 59185->59187 59188 7ffe102440d2 6 API calls 59186->59188 59189 7ffe10242120 59187->59189 59188->59189 59189->59038 59190 7ffe102429b3 59189->59190 59226 7ffe1150cb50 GetLastError 59225->59226 59227 7ffe1150ca2a 59225->59227 59229 7ffe1150c852 6 API calls 59226->59229 59350 7ffe1150b930 GetModuleHandleExA 59227->59350 59231 7ffe1150cb29 59229->59231 59235 7ffe1150c852 6 API calls 59231->59235 59234 7ffe1150ca64 strlen 59236 7ffe1150ca93 59234->59236 59237 7ffe1150ca7d 59234->59237 59238 7ffe1150cb46 59235->59238 59240 7ffe1150cab8 strlen fopen 59236->59240 59241 7ffe1150ca98 strcat strlen 59236->59241 59237->59236 59239 7ffe1150ca82 strlen 59237->59239 59238->58176 59249 7ffe1150d86a 59238->59249 59239->59236 59242 7ffe1150cb07 59240->59242 59243 7ffe1150cc1d 59240->59243 59241->59240 59367 7ffe1150c852 59242->59367 59244 7ffe1150c852 6 API calls 59243->59244 59244->59231 59250 7ffe1150d8cf 59249->59250 59251 7ffe1150d88c 59249->59251 59252 7ffe1150c852 6 API calls 59250->59252 59387 7ffe1150d4d6 59251->59387 59254 7ffe1150d8a5 59252->59254 59254->58177 59259 7ffe1150c25c 59254->59259 59256 7ffe1150d8ff _errno _strtoui64 _errno 59256->59254 59257 7ffe1150d932 _errno 59256->59257 59258 7ffe1150c852 6 API calls 59257->59258 59258->59254 59429 7ffe1150bc64 59259->59429 59287 7ffe1150c2f9 59295 7ffe11508b7e OpenSCManagerA 59294->59295 59296 7ffe11508be6 GetLastError 59294->59296 59297 7ffe11508cbe GetLastError 59295->59297 59298 7ffe11508bb4 59295->59298 59299 7ffe1150c852 6 API calls 59296->59299 59302 7ffe1150c852 6 API calls 59297->59302 59300 7ffe11508cda 59298->59300 59301 7ffe11508bc1 59298->59301 59299->59301 59304 7ffe1150c852 6 API calls 59300->59304 59303 7ffe1150c852 6 API calls 59301->59303 59302->59300 59305 7ffe11508bde 59303->59305 59304->59305 59305->58177 59306 7ffe1150b87e WSAStartup 59305->59306 59307 7ffe1150b8c2 59306->59307 59308 7ffe1150b89a 59306->59308 59310 7ffe1150c852 6 API calls 59307->59310 59309 7ffe1150c852 6 API calls 59308->59309 59312 7ffe1150b8b4 59309->59312 59311 7ffe1150b8db 59310->59311 59312->58177 59351 7ffe1150b962 GetLastError 59350->59351 59353 7ffe1150b958 59350->59353 59352 7ffe1150c852 6 API calls 59351->59352 59352->59353 59354 7ffe1150466b 59353->59354 59355 7ffe1150467c 59354->59355 59356 7ffe115046b2 59354->59356 59357 7ffe115046e2 59355->59357 59358 7ffe11504681 59355->59358 59359 7ffe1150c852 6 API calls 59356->59359 59360 7ffe1150c852 6 API calls 59357->59360 59361 7ffe1150468a 59358->59361 59362 7ffe11504712 59358->59362 59365 7ffe11504697 59359->59365 59360->59365 59378 7ffe1150452c 8 API calls 59361->59378 59363 7ffe1150c852 6 API calls 59362->59363 59363->59365 59365->59231 59365->59234 59366 7ffe1150468f 59366->59365 59368 7ffe1150c860 59367->59368 59379 7ffe11510b10 59368->59379 59378->59366 59380 7ffe11510b1e 59379->59380 59381 7ffe11510b35 59379->59381 59385 7ffe11511ba0 fputc 59380->59385 59388 7ffe1150d51f 59387->59388 59389 7ffe1150d4e7 59387->59389 59391 7ffe1150c852 6 API calls 59388->59391 59395 7ffe1150d1bf 59389->59395 59393 7ffe1150d4fe 59391->59393 59393->59254 59393->59256 59396 7ffe1150d1f2 59395->59396 59397 7ffe1150d1d7 59395->59397 59400 7ffe1150c852 6 API calls 59396->59400 59398 7ffe1150d225 59397->59398 59399 7ffe1150d1dc 59397->59399 59402 7ffe1150c852 6 API calls 59398->59402 59401 7ffe1150d258 59399->59401 59404 7ffe1150d1e1 59399->59404 59405 7ffe1150d21b 59400->59405 59403 7ffe1150c852 6 API calls 59401->59403 59402->59405 59403->59405 59406 7ffe1150d2c2 59404->59406 59407 7ffe1150d297 strcmp 59404->59407 59409 7ffe1150c852 6 API calls 59405->59409 59406->59405 59408 7ffe1150d2c9 59406->59408 59407->59404 59410 7ffe1150c852 6 API calls 59408->59410 59411 7ffe1150d2df 59409->59411 59410->59411 59411->59393 59412 7ffe1150d346 59411->59412 59430 7ffe1150bc72 LoadLibraryA 59429->59430 59431 7ffe1150bc9b 59429->59431 59432 7ffe1150bc9e GetLastError 59430->59432 59433 7ffe1150bc80 59430->59433 59431->59432 59434 7ffe1150c852 6 API calls 59432->59434 59435 7ffe1150c852 6 API calls 59433->59435 59436 7ffe1150bc99 59434->59436 59435->59436 59436->59287 59437 7ffe1150bbe3 59436->59437 59473 7ffe1a4523c0 GetLastError 59472->59473 59474 7ffe1a45229a 59472->59474 59476 7ffe1a4520c2 13 API calls 59473->59476 59578 7ffe1a454e70 GetModuleHandleExA 59474->59578 59483 7ffe1a452399 59476->59483 59480 7ffe1a4522d4 strlen 59481 7ffe1a452303 59480->59481 59482 7ffe1a4522ed 59480->59482 59486 7ffe1a452328 strlen fopen 59481->59486 59487 7ffe1a452308 strcat strlen 59481->59487 59482->59481 59485 7ffe1a4522f2 strlen 59482->59485 59484 7ffe1a4520c2 13 API calls 59483->59484 59488 7ffe1a4523b6 59484->59488 59485->59481 59489 7ffe1a45248d 59486->59489 59490 7ffe1a452377 59486->59490 59487->59486 59488->58193 59496 7ffe1a451dca 59488->59496 59492 7ffe1a4520c2 13 API calls 59489->59492 59595 7ffe1a4520c2 59490->59595 59492->59483 59497 7ffe1a451e2f 59496->59497 59498 7ffe1a451dec 59496->59498 59500 7ffe1a4520c2 13 API calls 59497->59500 59615 7ffe1a451a36 59498->59615 59502 7ffe1a451e05 59500->59502 59502->58200 59506 7ffe1a45487c 59502->59506 59503 7ffe1a451e5f _errno _strtoui64 _errno 59503->59502 59504 7ffe1a451e92 _errno 59503->59504 59505 7ffe1a4520c2 13 API calls 59504->59505 59505->59502 59657 7ffe1a4551a4 59506->59657 59532 7ffe1a454919 59540 7ffe1a453322 59539->59540 59541 7ffe1a4532fa 59539->59541 59542 7ffe1a4520c2 13 API calls 59540->59542 59543 7ffe1a4520c2 13 API calls 59541->59543 59544 7ffe1a45333b 59542->59544 59545 7ffe1a453314 59543->59545 59546 7ffe1a4520c2 13 API calls 59544->59546 59545->58198 59546->59545 59548 7ffe1a453ca2 GetLastError 59547->59548 59549 7ffe1a453b20 InitializeCriticalSectionAndSpinCount 59547->59549 59552 7ffe1a4520c2 13 API calls 59548->59552 59550 7ffe1a453dbe GetLastError 59549->59550 59551 7ffe1a453b4d 59549->59551 59554 7ffe1a4520c2 13 API calls 59550->59554 59553 7ffe1a453b63 CreateThread 59551->59553 59558 7ffe1a453ddc 59551->59558 59564 7ffe1a453cc0 59552->59564 59555 7ffe1a453ba1 59553->59555 59556 7ffe1a453e96 GetLastError 59553->59556 59554->59558 59557 7ffe1a4520c2 13 API calls 59558->59557 59564->59550 59579 7ffe1a454ea2 GetLastError 59578->59579 59580 7ffe1a4522b6 59578->59580 59581 7ffe1a4520c2 13 API calls 59579->59581 59582 7ffe1a4585eb 59580->59582 59581->59580 59583 7ffe1a458632 59582->59583 59584 7ffe1a4585fc 59582->59584 59585 7ffe1a4520c2 13 API calls 59583->59585 59586 7ffe1a458662 59584->59586 59587 7ffe1a458601 59584->59587 59593 7ffe1a4522ca 59585->59593 59588 7ffe1a4520c2 13 API calls 59586->59588 59589 7ffe1a458692 59587->59589 59590 7ffe1a45860a 59587->59590 59588->59593 59591 7ffe1a4520c2 13 API calls 59589->59591 59606 7ffe1a4584ac 15 API calls 59590->59606 59591->59593 59593->59480 59593->59483 59594 7ffe1a45860f 59594->59593 59596 7ffe1a4520d0 59595->59596 59607 7ffe1a45b180 59596->59607 59606->59594 59608 7ffe1a45b1a5 59607->59608 59609 7ffe1a45b18e 59607->59609 59614 7ffe1a45c1e0 8 API calls 59608->59614 59613 7ffe1a45c1e0 8 API calls 59609->59613 59616 7ffe1a451a7f 59615->59616 59617 7ffe1a451a47 59615->59617 59618 7ffe1a4520c2 13 API calls 59616->59618 59623 7ffe1a45171f 59617->59623 59620 7ffe1a451a5e 59618->59620 59620->59502 59620->59503 59624 7ffe1a451752 59623->59624 59625 7ffe1a451737 59623->59625 59628 7ffe1a4520c2 13 API calls 59624->59628 59626 7ffe1a451785 59625->59626 59627 7ffe1a45173c 59625->59627 59629 7ffe1a4520c2 13 API calls 59626->59629 59630 7ffe1a4517b8 59627->59630 59637 7ffe1a451741 59627->59637 59633 7ffe1a45177b 59628->59633 59629->59633 59631 7ffe1a4520c2 13 API calls 59630->59631 59631->59633 59632 7ffe1a451822 59632->59633 59635 7ffe1a451829 59632->59635 59636 7ffe1a4520c2 13 API calls 59633->59636 59634 7ffe1a4517f7 strcmp 59634->59637 59638 7ffe1a4520c2 13 API calls 59635->59638 59639 7ffe1a45183f 59636->59639 59637->59632 59637->59634 59638->59639 59639->59620 59658 7ffe1a4551b2 LoadLibraryA 59657->59658 59659 7ffe1a4551db 59657->59659 59660 7ffe1a4551de GetLastError 59658->59660 59661 7ffe1a4551c0 59658->59661 59659->59660 59662 7ffe1a4520c2 13 API calls 59660->59662 59663 7ffe1a4520c2 13 API calls 59661->59663 59664 7ffe1a454890 59662->59664 59663->59664 59664->59532 59665 7ffe1a455123 59664->59665 59701 7ff7bacdaad5 59700->59701 59702 7ff7bacdaabe 59700->59702 59707 7ff7bacdbb10 _fputchar strlen 59701->59707 59706 7ff7bacdbb10 _fputchar strlen 59702->59706 59705 7ff7bacd2f59 59705->57662 59705->57663 59705->57664 59706->59705 59707->59705 59708 7ffe11ec135a 59717 7ffe11ec1365 59708->59717 59709 7ffe11ec146e 59710 7ffe11ec147b 59709->59710 59775 7ffe11ec1e65 10 API calls 59709->59775 59711 7ffe11ec138d Sleep 59711->59717 59714 7ffe11ec1e65 10 API calls 59714->59717 59716 7ffe11ec1442 Sleep 59716->59717 59717->59709 59717->59711 59717->59714 59717->59716 59719 7ffe11ec142e memcpy 59717->59719 59720 7ffe11ec20fc socket 59717->59720 59755 7ffe11ec25aa 59717->59755 59766 7ffe11ec1290 59717->59766 59719->59717 59721 7ffe11ec22fb WSAGetLastError 59720->59721 59722 7ffe11ec2133 59720->59722 59725 7ffe11ec9dc2 6 API calls 59721->59725 59723 7ffe11ec2137 59722->59723 59724 7ffe11ec2155 59722->59724 59776 7ffe11ec1d99 59723->59776 59728 7ffe11ec1d99 8 API calls 59724->59728 59727 7ffe11ec231f 59725->59727 59730 7ffe11ec2329 59727->59730 59731 7ffe11ec216f 59727->59731 59732 7ffe11ec2153 59728->59732 59735 7ffe11ec9dc2 6 API calls 59730->59735 59733 7ffe11ec9dc2 6 API calls 59731->59733 59749 7ffe11ec2167 59732->59749 59789 7ffe11ec1eca setsockopt 59732->59789 59736 7ffe11ec2190 59733->59736 59734 7ffe11ec21ae 59738 7ffe11ec21b3 htonl htons connect 59734->59738 59734->59749 59735->59736 59736->59717 59741 7ffe11ec220c WSAGetLastError 59738->59741 59742 7ffe11ec21f1 59738->59742 59744 7ffe11ec221d 59741->59744 59745 7ffe11ec22ce WSAGetLastError 59741->59745 59743 7ffe11ec1d99 8 API calls 59742->59743 59747 7ffe11ec21fe 59743->59747 59748 7ffe11ec2225 select 59744->59748 59744->59749 59746 7ffe11ec9dc2 6 API calls 59745->59746 59746->59749 59747->59727 59747->59749 59750 7ffe11ec2286 59748->59750 59751 7ffe11ec22b0 59748->59751 59793 7ffe11ec1e65 10 API calls 59749->59793 59750->59742 59753 7ffe11ec228c WSAGetLastError 59750->59753 59752 7ffe11ec9dc2 6 API calls 59751->59752 59752->59749 59754 7ffe11ec9dc2 6 API calls 59753->59754 59754->59749 59756 7ffe11ec2638 59755->59756 59757 7ffe11ec25c4 59755->59757 59758 7ffe11ec9dc2 6 API calls 59756->59758 59757->59756 59759 7ffe11ec25c9 recv 59757->59759 59761 7ffe11ec25e3 59758->59761 59760 7ffe11ec25ec WSAGetLastError 59759->59760 59762 7ffe11ec25df 59759->59762 59760->59761 59763 7ffe11ec2600 59760->59763 59761->59717 59762->59761 59764 7ffe11ec9dc2 6 API calls 59762->59764 59765 7ffe11ec9dc2 6 API calls 59763->59765 59764->59761 59765->59761 59767 7ffe11ec1352 59766->59767 59768 7ffe11ec12a8 59766->59768 59767->59717 59768->59767 59794 7ffe11ec8e15 59768->59794 59771 7ffe11ec1344 LeaveCriticalSection 59771->59767 59772 7ffe11ec12d8 59772->59771 59773 7ffe11ec9dc2 6 API calls 59772->59773 59797 7ffe11ec9d36 59772->59797 59773->59772 59775->59710 59777 7ffe11ec1da9 ioctlsocket 59776->59777 59779 7ffe11ec1ddd WSAGetLastError 59777->59779 59780 7ffe11ec1dcc 59777->59780 59781 7ffe11ec9dc2 6 API calls 59779->59781 59780->59734 59782 7ffe11ec1ce4 setsockopt 59780->59782 59781->59780 59783 7ffe11ec1d19 setsockopt 59782->59783 59784 7ffe11ec1d74 WSAGetLastError 59782->59784 59786 7ffe11ec1d4f WSAGetLastError 59783->59786 59787 7ffe11ec1d45 59783->59787 59785 7ffe11ec9dc2 6 API calls 59784->59785 59785->59787 59788 7ffe11ec9dc2 6 API calls 59786->59788 59787->59732 59788->59787 59790 7ffe11ec1f07 59789->59790 59791 7ffe11ec1f11 WSAGetLastError 59789->59791 59790->59734 59792 7ffe11ec9dc2 6 API calls 59791->59792 59792->59790 59793->59731 59795 7ffe11ec8e2b GetSystemTimeAsFileTime 59794->59795 59796 7ffe11ec12bb EnterCriticalSection 59794->59796 59795->59796 59796->59772 59798 7ffe11ec9d81 59797->59798 59799 7ffe11ec9d62 59797->59799 59798->59772 59800 7ffe11ec9d6c 59799->59800 59801 7ffe11ec9d9f 59799->59801 59803 7ffe11ec9d8a 59800->59803 59804 7ffe11ec9d6e 59800->59804 59816 7ffe11ec99b3 23 API calls 59801->59816 59803->59798 59811 7ffe11ec9752 59803->59811 59805 7ffe11ec9d98 59804->59805 59806 7ffe11ec9d75 59804->59806 59815 7ffe11ec9760 25 API calls 59805->59815 59806->59798 59814 7ffe11ec9add 45 API calls 59806->59814 59809 7ffe11ec9d9d 59809->59798 59817 7ffe11ec9510 59811->59817 59814->59798 59815->59809 59816->59798 59846 7ffe11ec3f5b 59817->59846 59820 7ffe11ec4ac0 8 API calls 59821 7ffe11ec9586 59820->59821 59822 7ffe11ec89db 8 API calls 59821->59822 59823 7ffe11ec9598 59822->59823 59824 7ffe11ec95a2 strlen 59823->59824 59843 7ffe11ec9699 59823->59843 59825 7ffe11ec95b9 59824->59825 59826 7ffe11ec95cf strlen 59824->59826 59825->59826 59827 7ffe11ec95be strlen 59825->59827 59849 7ffe11ec82d7 59826->59849 59827->59826 59830 7ffe11ec971b 59905 7ffe11ec5bd8 FindClose 59830->59905 59831 7ffe11ec9601 59834 7ffe11ec9609 strlen 59831->59834 59840 7ffe11ec9537 59831->59840 59837 7ffe11ec9636 strcpy strlen strlen strlen 59834->59837 59838 7ffe11ec9620 59834->59838 59836 7ffe11ec9727 59836->59840 59841 7ffe11ec3f5b 2 API calls 59836->59841 59837->59843 59838->59837 59839 7ffe11ec9625 strlen 59838->59839 59839->59837 59840->59798 59841->59840 59843->59830 59843->59840 59877 7ffe11ec5bf3 59843->59877 59902 7ffe11ec542f 38 API calls 59843->59902 59903 7ffe11ec4e60 20 API calls 59843->59903 59904 7ffe11ec4fe9 66 API calls 59843->59904 59847 7ffe11ec3f71 QueryPerformanceFrequency QueryPerformanceCounter 59846->59847 59848 7ffe11ec3f66 59846->59848 59847->59848 59848->59820 59848->59840 59850 7ffe11ec82f5 59849->59850 59851 7ffe11ec82e0 GetFileAttributesA 59849->59851 59853 7ffe11ec9dc2 6 API calls 59850->59853 59852 7ffe11ec8325 GetLastError 59851->59852 59854 7ffe11ec82eb 59851->59854 59852->59854 59853->59854 59854->59831 59855 7ffe11ec5e9e 59854->59855 59856 7ffe11ec5ef8 59855->59856 59857 7ffe11ec5ebd strlen 59855->59857 59859 7ffe11ec9dc2 6 API calls 59856->59859 59858 7ffe11ec5ece 59857->59858 59871 7ffe11ec5ee9 59857->59871 59860 7ffe11ec5ed7 CreateDirectoryA 59858->59860 59861 7ffe11ec5f76 strcpy strlen 59858->59861 59859->59871 59862 7ffe11ec5f30 GetLastError 59860->59862 59860->59871 59863 7ffe11ec5fae strlen 59861->59863 59868 7ffe11ec5f55 59861->59868 59867 7ffe11ec9dc2 6 API calls 59862->59867 59863->59868 59864 7ffe11ec60e9 59870 7ffe11ec9dc2 6 API calls 59864->59870 59865 7ffe11ec6160 59869 7ffe11ec9dc2 6 API calls 59865->59869 59866 7ffe11ec5f9d strlen 59866->59863 59867->59868 59868->59861 59868->59863 59868->59866 59868->59871 59873 7ffe11ec601a CreateDirectoryA 59868->59873 59872 7ffe11ec6112 59869->59872 59870->59872 59871->59864 59871->59865 59872->59831 59874 7ffe11ec6031 GetLastError 59873->59874 59875 7ffe11ec5fc5 59873->59875 59874->59875 59875->59868 59876 7ffe11ec9dc2 6 API calls 59875->59876 59876->59875 59878 7ffe11ec5c13 59877->59878 59896 7ffe11ec5c59 59877->59896 59879 7ffe11ec5c1c 59878->59879 59880 7ffe11ec5cb2 59878->59880 59883 7ffe11ec5cea 59879->59883 59884 7ffe11ec5c25 59879->59884 59882 7ffe11ec9dc2 6 API calls 59880->59882 59881 7ffe11ec9dc2 6 API calls 59901 7ffe11ec5ca3 59881->59901 59882->59901 59885 7ffe11ec9dc2 6 API calls 59883->59885 59886 7ffe11ec5c31 FindNextFileA 59884->59886 59887 7ffe11ec5d22 FindFirstFileA 59884->59887 59885->59901 59888 7ffe11ec5c47 59886->59888 59889 7ffe11ec5d72 GetLastError 59886->59889 59890 7ffe11ec5d36 59887->59890 59891 7ffe11ec5d43 GetLastError 59887->59891 59892 7ffe11ec5c4c strcpy 59888->59892 59894 7ffe11ec5d9b 59889->59894 59899 7ffe11ec5d50 59889->59899 59890->59892 59893 7ffe11ec5d57 59891->59893 59891->59899 59892->59896 59897 7ffe11ec9dc2 6 API calls 59893->59897 59895 7ffe11ec9dc2 6 API calls 59894->59895 59895->59899 59896->59881 59896->59901 59897->59899 59898 7ffe11ec5d8d FindClose 59898->59896 59899->59896 59899->59898 59900 7ffe11ec5db8 59899->59900 59900->59843 59901->59843 59902->59843 59903->59843 59904->59843 59905->59836 59906 7ffe1a4537db 59909 7ffe1a4537ed 59906->59909 59907 7ffe1a453969 59909->59907 59910 7ffe1a45382e Sleep SleepEx 59909->59910 59911 7ffe1a4538b2 GetProcessHeap HeapAlloc 59909->59911 59919 7ffe1a452f1a 59909->59919 59910->59909 59912 7ffe1a4538d9 memcpy 59911->59912 59916 7ffe1a45384b 59911->59916 59913 7ffe1a4520c2 13 API calls 59912->59913 59915 7ffe1a453939 EnterCriticalSection 59913->59915 59914 7ffe1a4520c2 13 API calls 59914->59916 59915->59916 59916->59909 59916->59914 59917 7ffe1a453871 LeaveCriticalSection 59916->59917 59918 7ffe1a453887 memcpy 59916->59918 59917->59916 59918->59909 59920 7ffe1a452f34 59919->59920 59921 7ffe1a452fa8 59919->59921 59920->59921 59923 7ffe1a452f39 recv 59920->59923 59922 7ffe1a4520c2 13 API calls 59921->59922 59924 7ffe1a452f53 59922->59924 59925 7ffe1a452f4f 59923->59925 59926 7ffe1a452f5c WSAGetLastError 59923->59926 59924->59909 59925->59924 59929 7ffe1a4520c2 13 API calls 59925->59929 59926->59924 59927 7ffe1a452f70 59926->59927 59928 7ffe1a4520c2 13 API calls 59927->59928 59928->59924 59929->59924 59930 7ffe1322605a 59931 7ffe13226065 59930->59931 59932 7ffe1322616e 59931->59932 59936 7ffe1322608d Sleep 59931->59936 59937 7ffe132214c5 10 API calls 59931->59937 59939 7ffe13226142 Sleep 59931->59939 59941 7ffe1322612e memcpy 59931->59941 59942 7ffe1322175c socket 59931->59942 59977 7ffe13221c0a 59931->59977 59988 7ffe13225f90 59931->59988 59933 7ffe1322617b 59932->59933 59997 7ffe132214c5 10 API calls 59932->59997 59936->59931 59937->59931 59939->59931 59941->59931 59943 7ffe13221793 59942->59943 59944 7ffe1322195b WSAGetLastError 59942->59944 59945 7ffe132217b5 59943->59945 59946 7ffe13221797 59943->59946 59947 7ffe132277a2 6 API calls 59944->59947 59950 7ffe132213f9 8 API calls 59945->59950 59998 7ffe132213f9 59946->59998 59949 7ffe1322197f 59947->59949 59952 7ffe132217cf 59949->59952 59953 7ffe13221989 59949->59953 59954 7ffe132217b3 59950->59954 59955 7ffe132277a2 6 API calls 59952->59955 59957 7ffe132277a2 6 API calls 59953->59957 59958 7ffe132217c7 59954->59958 60011 7ffe1322152a setsockopt 59954->60011 59960 7ffe132217f0 59955->59960 59956 7ffe1322180e 59956->59958 59962 7ffe13221813 htonl htons connect 59956->59962 59957->59960 60015 7ffe132214c5 10 API calls 59958->60015 59960->59931 59964 7ffe13221851 59962->59964 59965 7ffe1322186c WSAGetLastError 59962->59965 59966 7ffe132213f9 8 API calls 59964->59966 59967 7ffe1322192e WSAGetLastError 59965->59967 59968 7ffe1322187d 59965->59968 59970 7ffe1322185e 59966->59970 59969 7ffe132277a2 6 API calls 59967->59969 59968->59958 59971 7ffe13221885 select 59968->59971 59969->59958 59970->59949 59970->59958 59972 7ffe13221910 59971->59972 59973 7ffe132218e6 59971->59973 59975 7ffe132277a2 6 API calls 59972->59975 59973->59964 59974 7ffe132218ec WSAGetLastError 59973->59974 59976 7ffe132277a2 6 API calls 59974->59976 59975->59958 59976->59958 59978 7ffe13221c24 59977->59978 59979 7ffe13221c98 59977->59979 59978->59979 59981 7ffe13221c29 recv 59978->59981 59980 7ffe132277a2 6 API calls 59979->59980 59987 7ffe13221c43 59980->59987 59982 7ffe13221c3f 59981->59982 59983 7ffe13221c4c WSAGetLastError 59981->59983 59986 7ffe132277a2 6 API calls 59982->59986 59982->59987 59984 7ffe13221c60 59983->59984 59983->59987 59985 7ffe132277a2 6 API calls 59984->59985 59985->59987 59986->59987 59987->59931 59989 7ffe13226052 59988->59989 59990 7ffe13225fa8 59988->59990 59989->59931 59990->59989 60016 7ffe132222f5 59990->60016 59993 7ffe13226044 LeaveCriticalSection 59993->59989 59994 7ffe13225fd8 59994->59993 59995 7ffe132277a2 6 API calls 59994->59995 60019 7ffe1322bca7 59994->60019 59995->59994 59997->59933 59999 7ffe13221409 ioctlsocket 59998->59999 60001 7ffe1322143d WSAGetLastError 59999->60001 60002 7ffe1322142c 59999->60002 60003 7ffe132277a2 6 API calls 60001->60003 60002->59956 60004 7ffe13221344 setsockopt 60002->60004 60003->60002 60005 7ffe132213d4 WSAGetLastError 60004->60005 60006 7ffe13221379 setsockopt 60004->60006 60007 7ffe132277a2 6 API calls 60005->60007 60008 7ffe132213af WSAGetLastError 60006->60008 60009 7ffe132213a5 60006->60009 60007->60009 60010 7ffe132277a2 6 API calls 60008->60010 60009->59954 60010->60009 60012 7ffe13221571 WSAGetLastError 60011->60012 60013 7ffe13221567 60011->60013 60014 7ffe132277a2 6 API calls 60012->60014 60013->59956 60014->60013 60015->59952 60017 7ffe13222300 EnterCriticalSection 60016->60017 60018 7ffe1322230b GetSystemTimeAsFileTime 60016->60018 60017->59994 60018->60017 60020 7ffe1322bd35 60019->60020 60021 7ffe1322bcc9 60019->60021 60022 7ffe1322bd50 60020->60022 60023 7ffe1322bd3f 60020->60023 60028 7ffe1322bce0 60021->60028 60084 7ffe1322689b 60021->60084 60024 7ffe1322689b 2 API calls 60022->60024 60027 7ffe132222f5 GetSystemTimeAsFileTime 60023->60027 60030 7ffe1322bd2b 60023->60030 60024->60030 60029 7ffe1322be32 60027->60029 60028->60030 60035 7ffe1322c29f GetProcessHeap HeapAlloc 60028->60035 60036 7ffe1322c292 60028->60036 60033 7ffe13227400 8 API calls 60029->60033 60030->59994 60031 7ffe1322c103 60032 7ffe1322c197 60031->60032 60041 7ffe1322c148 60031->60041 60034 7ffe1322689b 2 API calls 60032->60034 60037 7ffe1322becc 60033->60037 60038 7ffe1322c1a1 60034->60038 60039 7ffe1322c339 60035->60039 60040 7ffe1322c2c7 memcpy 60035->60040 60036->60035 60114 7ffe13225ec9 12 API calls 60037->60114 60087 7ffe1322b940 60038->60087 60045 7ffe132277a2 6 API calls 60039->60045 60067 7ffe1322c307 60040->60067 60048 7ffe1322c172 60041->60048 60049 7ffe1322c1b7 60041->60049 60043 7ffe1322bee8 60046 7ffe1322bef0 60043->60046 60047 7ffe1322c069 60043->60047 60050 7ffe1322c05f 60045->60050 60051 7ffe1322d422 9 API calls 60046->60051 60120 7ffe13223805 30 API calls 60047->60120 60054 7ffe1322c1c6 60048->60054 60055 7ffe1322c17c 60048->60055 60093 7ffe1322ba24 60049->60093 60050->60030 60056 7ffe1322bf1c 60051->60056 60057 7ffe1322689b 2 API calls 60054->60057 60059 7ffe1322689b 2 API calls 60055->60059 60060 7ffe1322bf2e 60056->60060 60063 7ffe1322c0bc memcpy 60056->60063 60061 7ffe1322c1d0 60057->60061 60058 7ffe1322c09c 60058->60046 60059->60030 60115 7ffe132268e2 8 API calls 60060->60115 60061->60030 60066 7ffe132222f5 GetSystemTimeAsFileTime 60061->60066 60062 7ffe1322c31d GetProcessHeap HeapFree 60062->60030 60063->60060 60065 7ffe1322bf38 60116 7ffe13226a68 10 API calls 60065->60116 60068 7ffe1322c22d 60066->60068 60074 7ffe1322c30f 60067->60074 60122 7ffe1322bc3e 8 API calls 60067->60122 60071 7ffe1322689b 2 API calls 60068->60071 60072 7ffe1322c23f 60071->60072 60121 7ffe132261a2 13 API calls 60072->60121 60073 7ffe1322bf6d 60117 7ffe132293c0 58 API calls 60073->60117 60074->60030 60074->60062 60078 7ffe1322bfd9 60079 7ffe1322c000 60078->60079 60118 7ffe13221290 7 API calls 60078->60118 60080 7ffe1322c030 60079->60080 60081 7ffe1322c019 GetProcessHeap HeapFree 60079->60081 60119 7ffe132261a2 13 API calls 60080->60119 60081->60080 60085 7ffe132268b1 QueryPerformanceFrequency QueryPerformanceCounter 60084->60085 60086 7ffe132268a6 60084->60086 60085->60086 60086->60028 60086->60031 60088 7ffe1322b950 60087->60088 60090 7ffe1322b96d 60087->60090 60088->60090 60123 7ffe1322b4cb 10 API calls 60088->60123 60089 7ffe1322b984 60089->60030 60090->60089 60124 7ffe132214c5 10 API calls 60090->60124 60094 7ffe1322ba38 60093->60094 60096 7ffe1322bbbc 60093->60096 60094->60096 60097 7ffe1322ba5d 60094->60097 60095 7ffe1322ba96 60095->60030 60096->60095 60098 7ffe1322175c 27 API calls 60096->60098 60099 7ffe1322bab9 60097->60099 60100 7ffe1322ba67 60097->60100 60101 7ffe1322bbf3 60098->60101 60125 7ffe1322b537 60099->60125 60102 7ffe1322bb40 60100->60102 60103 7ffe1322ba74 60100->60103 60101->60095 60108 7ffe1322689b 2 API calls 60101->60108 60164 7ffe1322b357 48 API calls 60102->60164 60103->60095 60163 7ffe1322b836 68 API calls 60103->60163 60107 7ffe1322bb4c 60107->60095 60112 7ffe1322689b 2 API calls 60107->60112 60108->60095 60110 7ffe1322689b 2 API calls 60110->60095 60111 7ffe1322ba8e 60111->60095 60113 7ffe1322689b 2 API calls 60111->60113 60112->60095 60113->60095 60114->60043 60115->60065 60116->60073 60117->60078 60118->60079 60119->60050 60120->60058 60121->60030 60122->60074 60123->60090 60124->60089 60126 7ffe1322b7f6 60125->60126 60127 7ffe1322b56c 60125->60127 60126->60095 60126->60110 60128 7ffe1322b5db 60127->60128 60129 7ffe1322b5c7 strlen 60127->60129 60165 7ffe1322275a 60128->60165 60129->60128 60151 7ffe1322b6a9 60129->60151 60151->60126 60206 7ffe1322b4cb 10 API calls 60151->60206 60163->60111 60164->60107 60166 7ffe132227b2 60165->60166 60167 7ffe13222776 60165->60167 60169 7ffe1322b323 60166->60169 60167->60166 60207 7ffe1322273a rand_s 60167->60207 60208 7ffe1322afba 60169->60208 60173 7ffe1322b348 60173->60151 60174 7ffe1322b000 60173->60174 60176 7ffe1322b02f 60174->60176 60175 7ffe1322ead0 fputc 60175->60176 60176->60175 60177 7ffe1322b094 60176->60177 60178 7ffe1322b0f1 GetProcessHeap HeapAlloc 60176->60178 60179 7ffe1322b043 GetProcessHeap HeapReAlloc 60176->60179 60180 7ffe132277a2 6 API calls 60177->60180 60178->60176 60181 7ffe1322b115 60178->60181 60179->60176 60182 7ffe1322b12d 60179->60182 60183 7ffe1322b0aa strlen 60180->60183 60184 7ffe132277a2 6 API calls 60181->60184 60185 7ffe132277a2 6 API calls 60182->60185 60235 7ffe1322afe8 60183->60235 60187 7ffe1322b12b 60184->60187 60188 7ffe1322b143 60185->60188 60190 7ffe1322b15f 60187->60190 60188->60190 60191 7ffe1322b148 GetProcessHeap HeapFree 60188->60191 60190->60151 60193 7ffe1322b260 60190->60193 60191->60190 60249 7ffe1322b182 60193->60249 60206->60126 60207->60167 60209 7ffe1322175c 27 API calls 60208->60209 60210 7ffe1322afc7 60209->60210 60211 7ffe1322afd0 60210->60211 60227 7ffe13221596 setsockopt 60210->60227 60211->60173 60213 7ffe1322b294 60211->60213 60214 7ffe1322b000 17 API calls 60213->60214 60215 7ffe1322b2a9 60214->60215 60216 7ffe1322b2f2 60215->60216 60217 7ffe1322b260 29 API calls 60215->60217 60233 7ffe132214c5 10 API calls 60216->60233 60218 7ffe1322b2b5 60217->60218 60231 7ffe1322aa70 strcmp strcmp strcmp strcmp 60218->60231 60221 7ffe1322b2ff 60223 7ffe1322b2ed 60221->60223 60234 7ffe1322abdd 6 API calls 60221->60234 60222 7ffe1322b2e1 60222->60216 60224 7ffe1322b2e5 60222->60224 60223->60173 60232 7ffe1322abdd 6 API calls 60224->60232 60228 7ffe132215d5 WSAGetLastError 60227->60228 60229 7ffe132215cb 60227->60229 60230 7ffe132277a2 6 API calls 60228->60230 60229->60211 60230->60229 60231->60222 60232->60223 60233->60221 60234->60223 60238 7ffe13221cbd 60235->60238 60239 7ffe13221ce8 60238->60239 60240 7ffe13221d6c 60238->60240 60239->60240 60242 7ffe13221ced 60239->60242 60241 7ffe132277a2 6 API calls 60240->60241 60262 7ffe1024135a 60265 7ffe10241365 60262->60265 60263 7ffe1024146e 60264 7ffe1024147b 60263->60264 60329 7ffe102457f5 10 API calls 60263->60329 60265->60263 60266 7ffe1024138d Sleep 60265->60266 60270 7ffe10241442 Sleep 60265->60270 60271 7ffe102457f5 10 API calls 60265->60271 60273 7ffe1024142e memcpy 60265->60273 60274 7ffe10245a8c socket 60265->60274 60309 7ffe10245f3a 60265->60309 60320 7ffe10241290 60265->60320 60266->60265 60270->60265 60271->60265 60273->60265 60275 7ffe10245ac3 60274->60275 60276 7ffe10245c8b WSAGetLastError 60274->60276 60277 7ffe10245ae5 60275->60277 60278 7ffe10245ac7 60275->60278 60279 7ffe102440d2 6 API calls 60276->60279 60282 7ffe10245729 8 API calls 60277->60282 60330 7ffe10245729 60278->60330 60281 7ffe10245caf 60279->60281 60284 7ffe10245cb9 60281->60284 60296 7ffe10245aff 60281->60296 60295 7ffe10245ae3 60282->60295 60286 7ffe102440d2 6 API calls 60284->60286 60285 7ffe10245b3e 60289 7ffe10245b43 htonl htons connect 60285->60289 60303 7ffe10245af7 60285->60303 60291 7ffe10245b20 60286->60291 60287 7ffe102440d2 6 API calls 60287->60291 60293 7ffe10245b81 60289->60293 60294 7ffe10245b9c WSAGetLastError 60289->60294 60291->60265 60297 7ffe10245729 8 API calls 60293->60297 60298 7ffe10245c5e WSAGetLastError 60294->60298 60299 7ffe10245bad 60294->60299 60295->60303 60343 7ffe1024585a setsockopt 60295->60343 60296->60287 60301 7ffe10245b8e 60297->60301 60300 7ffe102440d2 6 API calls 60298->60300 60302 7ffe10245bb5 select 60299->60302 60299->60303 60300->60303 60301->60281 60301->60303 60304 7ffe10245c40 60302->60304 60305 7ffe10245c16 60302->60305 60347 7ffe102457f5 10 API calls 60303->60347 60306 7ffe102440d2 6 API calls 60304->60306 60305->60293 60307 7ffe10245c1c WSAGetLastError 60305->60307 60306->60303 60308 7ffe102440d2 6 API calls 60307->60308 60308->60303 60310 7ffe10245f54 60309->60310 60311 7ffe10245fc8 60309->60311 60310->60311 60313 7ffe10245f59 recv 60310->60313 60312 7ffe102440d2 6 API calls 60311->60312 60314 7ffe10245f73 60312->60314 60315 7ffe10245f6f 60313->60315 60316 7ffe10245f7c WSAGetLastError 60313->60316 60314->60265 60315->60314 60319 7ffe102440d2 6 API calls 60315->60319 60316->60314 60317 7ffe10245f90 60316->60317 60318 7ffe102440d2 6 API calls 60317->60318 60318->60314 60319->60314 60321 7ffe10241352 60320->60321 60322 7ffe102412a8 60320->60322 60321->60265 60322->60321 60348 7ffe102493e5 60322->60348 60325 7ffe10241344 LeaveCriticalSection 60325->60321 60326 7ffe102412d8 60326->60325 60327 7ffe102440d2 6 API calls 60326->60327 60351 7ffe1024e21c 60326->60351 60327->60326 60329->60264 60331 7ffe10245739 ioctlsocket 60330->60331 60333 7ffe1024576d WSAGetLastError 60331->60333 60334 7ffe1024575c 60331->60334 60335 7ffe102440d2 6 API calls 60333->60335 60334->60285 60336 7ffe10245674 setsockopt 60334->60336 60335->60334 60337 7ffe10245704 WSAGetLastError 60336->60337 60338 7ffe102456a9 setsockopt 60336->60338 60341 7ffe102440d2 6 API calls 60337->60341 60339 7ffe102456df WSAGetLastError 60338->60339 60340 7ffe102456d5 60338->60340 60342 7ffe102440d2 6 API calls 60339->60342 60340->60295 60341->60340 60342->60340 60344 7ffe102458a1 WSAGetLastError 60343->60344 60345 7ffe10245897 60343->60345 60346 7ffe102440d2 6 API calls 60344->60346 60345->60285 60346->60345 60347->60296 60349 7ffe102412bb EnterCriticalSection 60348->60349 60350 7ffe102493fb GetSystemTimeAsFileTime 60348->60350 60349->60326 60350->60349 60352 7ffe1024e24c 60351->60352 60382 7ffe1024e296 60351->60382 60353 7ffe1024e3a1 60352->60353 60354 7ffe1024e25a 60352->60354 60403 7ffe1024db22 70 API calls 60353->60403 60355 7ffe1024e30e 60354->60355 60356 7ffe1024e260 60354->60356 60358 7ffe1024e315 60355->60358 60359 7ffe1024e356 60355->60359 60360 7ffe1024e3af 60356->60360 60361 7ffe1024e26b 60356->60361 60358->60382 60400 7ffe1024d798 57 API calls 60358->60400 60364 7ffe1024e39a 60359->60364 60365 7ffe1024e35d 60359->60365 60405 7ffe1024df8e 56 API calls 60360->60405 60362 7ffe1024e2c0 60361->60362 60363 7ffe1024e26d 60361->60363 60368 7ffe1024e2cb 60362->60368 60369 7ffe1024e3a8 60362->60369 60370 7ffe1024e274 60363->60370 60371 7ffe1024e2a5 60363->60371 60402 7ffe1024d872 52 API calls 60364->60402 60365->60382 60393 7ffe1024d22b 60365->60393 60373 7ffe1024e2cd 60368->60373 60385 7ffe1024e2f3 60368->60385 60404 7ffe1024dd5a 53 API calls 60369->60404 60375 7ffe1024e27f 60370->60375 60376 7ffe1024e3bd 60370->60376 60371->60382 60397 7ffe1024e106 16 API calls 60371->60397 60380 7ffe1024e3b6 60373->60380 60381 7ffe1024e2d8 60373->60381 60383 7ffe1024e28a 60375->60383 60384 7ffe1024e36b 60375->60384 60407 7ffe1024e196 16 API calls 60376->60407 60406 7ffe1024e032 49 API calls 60380->60406 60381->60382 60389 7ffe1024e2df 60381->60389 60382->60326 60383->60382 60396 7ffe1024d2b2 14 API calls 60383->60396 60401 7ffe1024d239 18 API calls 60384->60401 60385->60382 60399 7ffe1024de74 53 API calls 60385->60399 60398 7ffe1024d946 57 API calls 60389->60398 60392 7ffe1024e2e4 60392->60382 60408 7ffe1024d080 60393->60408 60396->60382 60397->60382 60398->60392 60399->60382 60400->60382 60401->60382 60402->60382 60403->60392 60404->60382 60405->60382 60406->60382 60407->60382 60435 7ffe10241b9b 60408->60435 60413 7ffe1024d0d0 60441 7ffe10248fa8 17 API calls 60413->60441 60414 7ffe1024d0d7 60416 7ffe102493e5 GetSystemTimeAsFileTime 60414->60416 60417 7ffe1024d0ea 60416->60417 60418 7ffe1024d208 60417->60418 60421 7ffe1024d116 strlen 60417->60421 60443 7ffe10248fa8 17 API calls 60418->60443 60420 7ffe1024d20d 60424 7ffe10241b9b 2 API calls 60420->60424 60425 7ffe1024d0aa 60420->60425 60422 7ffe102440d2 6 API calls 60421->60422 60423 7ffe1024d14e GetProcessHeap HeapAlloc 60422->60423 60426 7ffe1024d170 60423->60426 60427 7ffe1024d1ed 60423->60427 60424->60425 60425->60382 60428 7ffe102493e5 GetSystemTimeAsFileTime 60426->60428 60429 7ffe102440d2 6 API calls 60427->60429 60430 7ffe1024d19f strcpy 60428->60430 60431 7ffe1024d203 60429->60431 60442 7ffe102414a2 13 API calls 60430->60442 60431->60418 60433 7ffe1024d1c8 60433->60417 60434 7ffe1024d1d1 GetProcessHeap HeapFree 60433->60434 60434->60417 60436 7ffe10241bb1 QueryPerformanceFrequency QueryPerformanceCounter 60435->60436 60437 7ffe10241ba6 60435->60437 60436->60437 60437->60425 60438 7ffe10248f87 EnterCriticalSection 60437->60438 60444 7ffe10247589 60438->60444 60441->60425 60442->60433 60443->60420 60445 7ffe102475a5 60444->60445 60447 7ffe10247595 60444->60447 60450 7ffe102464df 60445->60450 60448 7ffe1024759f 60447->60448 60472 7ffe10246daf 60447->60472 60448->60413 60448->60414 60493 7ffe102463ff 8 API calls 60450->60493 60452 7ffe10246b02 60453 7ffe10246b48 60452->60453 60454 7ffe10246b0b 60452->60454 60457 7ffe102440d2 6 API calls 60453->60457 60456 7ffe10246c59 60454->60456 60462 7ffe10246b13 60454->60462 60455 7ffe102469fc NetLocalGroupEnum 60458 7ffe102464f4 60455->60458 60460 7ffe102440d2 6 API calls 60456->60460 60457->60462 60458->60452 60458->60455 60461 7ffe102469d9 NetApiBufferFree 60458->60461 60463 7ffe10246a72 GetProcessHeap HeapAlloc 60458->60463 60465 7ffe10246b35 60460->60465 60461->60458 60494 7ffe102463ff 8 API calls 60462->60494 60466 7ffe10246aa5 60463->60466 60467 7ffe10246503 60463->60467 60464 7ffe10246b18 60469 7ffe102440d2 6 API calls 60464->60469 60465->60447 60470 7ffe10246ab1 memcpy GetProcessHeap HeapFree 60466->60470 60471 7ffe10246ae0 60466->60471 60467->60458 60468 7ffe102440d2 6 API calls 60467->60468 60468->60467 60469->60465 60470->60471 60471->60447 60495 7ffe10246ccf 60472->60495 60474 7ffe10247413 60477 7ffe102440d2 6 API calls 60474->60477 60491 7ffe1024741c 60474->60491 60475 7ffe102472f6 NetUserEnum 60478 7ffe10246dc4 60475->60478 60476 7ffe1024756a 60479 7ffe102440d2 6 API calls 60476->60479 60477->60491 60478->60474 60478->60475 60481 7ffe102472d3 NetApiBufferFree 60478->60481 60482 7ffe10247372 GetProcessHeap HeapAlloc 60478->60482 60483 7ffe10247446 60479->60483 60480 7ffe10246ccf 8 API calls 60484 7ffe10247429 60480->60484 60481->60478 60485 7ffe10246dd3 60482->60485 60486 7ffe102473ac 60482->60486 60483->60448 60487 7ffe102440d2 6 API calls 60484->60487 60485->60478 60488 7ffe102440d2 6 API calls 60485->60488 60489 7ffe102473f1 60486->60489 60490 7ffe102473b8 memcpy GetProcessHeap HeapFree 60486->60490 60487->60483 60488->60485 60489->60448 60490->60489 60491->60476 60492 7ffe10247424 60491->60492 60492->60480 60493->60458 60494->60464 60496 7ffe10246d94 60495->60496 60501 7ffe10246ce2 60495->60501 60496->60478 60497 7ffe10246d71 60497->60496 60498 7ffe10246d7d GetProcessHeap HeapFree 60497->60498 60498->60496 60499 7ffe10246d1d GetProcessHeap HeapFree 60499->60501 60500 7ffe10246d42 GetProcessHeap HeapFree 60500->60501 60501->60497 60501->60499 60501->60500 60502 7ffe10246ced LocalFree 60501->60502 60503 7ffe10246d69 LocalFree 60501->60503 60502->60501 60503->60501 60504 7ffe126d272a 60512 7ffe126d2735 60504->60512 60505 7ffe126d283e 60506 7ffe126d284b 60505->60506 60563 7ffe126d40a5 14 API calls 60505->60563 60508 7ffe126d275d Sleep 60508->60512 60510 7ffe126d40a5 14 API calls 60510->60512 60512->60505 60512->60508 60512->60510 60513 7ffe126d2812 Sleep 60512->60513 60515 7ffe126d27fe memcpy 60512->60515 60516 7ffe126d433c socket 60512->60516 60551 7ffe126d47ea 60512->60551 60562 7ffe126d2660 13 API calls 60512->60562 60513->60512 60515->60512 60517 7ffe126d453b WSAGetLastError 60516->60517 60518 7ffe126d4373 60516->60518 60519 7ffe126d1352 10 API calls 60517->60519 60520 7ffe126d4377 60518->60520 60521 7ffe126d4395 60518->60521 60523 7ffe126d455f 60519->60523 60564 7ffe126d3fd9 60520->60564 60524 7ffe126d3fd9 12 API calls 60521->60524 60525 7ffe126d4569 60523->60525 60539 7ffe126d43af 60523->60539 60526 7ffe126d4393 60524->60526 60529 7ffe126d1352 10 API calls 60525->60529 60530 7ffe126d43a7 60526->60530 60577 7ffe126d410a setsockopt 60526->60577 60528 7ffe126d43ee 60528->60530 60532 7ffe126d43f3 htonl htons connect 60528->60532 60534 7ffe126d43d0 60529->60534 60581 7ffe126d40a5 14 API calls 60530->60581 60531 7ffe126d1352 10 API calls 60531->60534 60537 7ffe126d444c WSAGetLastError 60532->60537 60538 7ffe126d4431 60532->60538 60534->60512 60541 7ffe126d445d 60537->60541 60542 7ffe126d450e WSAGetLastError 60537->60542 60540 7ffe126d3fd9 12 API calls 60538->60540 60539->60531 60544 7ffe126d443e 60540->60544 60541->60530 60545 7ffe126d4465 select 60541->60545 60543 7ffe126d1352 10 API calls 60542->60543 60543->60530 60544->60523 60544->60530 60546 7ffe126d44c6 60545->60546 60547 7ffe126d44f0 60545->60547 60546->60538 60548 7ffe126d44cc WSAGetLastError 60546->60548 60549 7ffe126d1352 10 API calls 60547->60549 60550 7ffe126d1352 10 API calls 60548->60550 60549->60530 60550->60530 60552 7ffe126d4878 60551->60552 60553 7ffe126d4804 60551->60553 60554 7ffe126d1352 10 API calls 60552->60554 60553->60552 60555 7ffe126d4809 recv 60553->60555 60557 7ffe126d4823 60554->60557 60556 7ffe126d482c WSAGetLastError 60555->60556 60559 7ffe126d481f 60555->60559 60556->60557 60558 7ffe126d4840 60556->60558 60557->60512 60560 7ffe126d1352 10 API calls 60558->60560 60559->60557 60561 7ffe126d1352 10 API calls 60559->60561 60560->60557 60561->60557 60562->60512 60563->60506 60565 7ffe126d3fe9 ioctlsocket 60564->60565 60567 7ffe126d400c 60565->60567 60568 7ffe126d401d WSAGetLastError 60565->60568 60567->60528 60570 7ffe126d3f24 setsockopt 60567->60570 60569 7ffe126d1352 10 API calls 60568->60569 60569->60567 60571 7ffe126d3f59 setsockopt 60570->60571 60572 7ffe126d3fb4 WSAGetLastError 60570->60572 60573 7ffe126d3f8f WSAGetLastError 60571->60573 60576 7ffe126d3f85 60571->60576 60574 7ffe126d1352 10 API calls 60572->60574 60575 7ffe126d1352 10 API calls 60573->60575 60574->60576 60575->60576 60576->60526 60578 7ffe126d4147 60577->60578 60579 7ffe126d4151 WSAGetLastError 60577->60579 60578->60528 60580 7ffe126d1352 10 API calls 60579->60580 60580->60578 60581->60539 60582 7ffe1a4535a3 60600 7ffe1a4535b3 60582->60600 60583 7ffe1a4537be 60584 7ffe1a4537c4 60583->60584 60662 7ffe1a4527d5 17 API calls 60583->60662 60588 7ffe1a4535e3 Sleep 60588->60600 60589 7ffe1a4520c2 13 API calls 60589->60600 60593 7ffe1a45368e GetProcessHeap HeapAlloc 60594 7ffe1a4536b4 CreateThread 60593->60594 60593->60600 60595 7ffe1a4536f3 EnterCriticalSection 60594->60595 60596 7ffe1a453771 GetLastError 60594->60596 60597 7ffe1a453713 LeaveCriticalSection 60595->60597 60598 7ffe1a4520c2 13 API calls 60596->60598 60601 7ffe1a4520c2 13 API calls 60597->60601 60598->60600 60600->60583 60600->60588 60600->60589 60600->60593 60602 7ffe1a4527d5 17 API calls 60600->60602 60603 7ffe1a4537a2 GetProcessHeap HeapFree 60600->60603 60604 7ffe1a45290a socket 60600->60604 60622 7ffe1a452709 60600->60622 60628 7ffe1a452654 setsockopt 60600->60628 60635 7ffe1a452ce9 60600->60635 60658 7ffe1a45283a setsockopt 60600->60658 60601->60600 60602->60600 60603->60600 60605 7ffe1a452a12 WSAGetLastError 60604->60605 60606 7ffe1a45293b 60604->60606 60607 7ffe1a4520c2 13 API calls 60605->60607 60608 7ffe1a45283a 15 API calls 60606->60608 60609 7ffe1a452a36 60607->60609 60610 7ffe1a452948 60608->60610 60611 7ffe1a452a09 60609->60611 60614 7ffe1a4520c2 13 API calls 60609->60614 60612 7ffe1a452a01 60610->60612 60613 7ffe1a452951 htonl htons bind 60610->60613 60611->60600 60663 7ffe1a4527d5 17 API calls 60612->60663 60615 7ffe1a4529d4 WSAGetLastError 60613->60615 60616 7ffe1a452991 listen 60613->60616 60614->60611 60619 7ffe1a4520c2 13 API calls 60615->60619 60616->60609 60618 7ffe1a4529aa WSAGetLastError 60616->60618 60620 7ffe1a4520c2 13 API calls 60618->60620 60621 7ffe1a4529d2 60619->60621 60620->60621 60621->60609 60621->60612 60623 7ffe1a452719 ioctlsocket 60622->60623 60625 7ffe1a45273c 60623->60625 60626 7ffe1a45274d WSAGetLastError 60623->60626 60625->60600 60627 7ffe1a4520c2 13 API calls 60626->60627 60627->60625 60629 7ffe1a4526e4 WSAGetLastError 60628->60629 60630 7ffe1a452689 setsockopt 60628->60630 60633 7ffe1a4520c2 13 API calls 60629->60633 60631 7ffe1a4526b5 60630->60631 60632 7ffe1a4526bf WSAGetLastError 60630->60632 60631->60600 60634 7ffe1a4520c2 13 API calls 60632->60634 60633->60631 60634->60631 60636 7ffe1a452d14 60635->60636 60637 7ffe1a452da8 accept 60635->60637 60638 7ffe1a452709 15 API calls 60636->60638 60639 7ffe1a452dce 60637->60639 60640 7ffe1a452eea WSAGetLastError 60637->60640 60641 7ffe1a452d1e 60638->60641 60643 7ffe1a452709 15 API calls 60639->60643 60642 7ffe1a4520c2 13 API calls 60640->60642 60644 7ffe1a452d3e select 60641->60644 60655 7ffe1a452d23 60641->60655 60642->60655 60645 7ffe1a452ddb 60643->60645 60646 7ffe1a452da2 60644->60646 60647 7ffe1a452e79 60644->60647 60648 7ffe1a452de4 htonl htons 60645->60648 60649 7ffe1a452ed6 60645->60649 60646->60637 60651 7ffe1a452ea3 WSAGetLastError 60646->60651 60653 7ffe1a4520c2 13 API calls 60647->60653 60652 7ffe1a452e07 60648->60652 60664 7ffe1a4527d5 17 API calls 60649->60664 60656 7ffe1a4520c2 13 API calls 60651->60656 60657 7ffe1a4520c2 13 API calls 60652->60657 60653->60655 60655->60600 60656->60655 60657->60655 60659 7ffe1a452881 WSAGetLastError 60658->60659 60660 7ffe1a452877 60658->60660 60661 7ffe1a4520c2 13 API calls 60659->60661 60660->60600 60661->60660 60662->60584 60663->60611 60664->60655 60665 7ffe1322c445 60673 7ffe1322c452 60665->60673 60666 7ffe1322c662 60667 7ffe1322c473 Sleep 60667->60673 60669 7ffe1322c4ef Sleep 60669->60673 60670 7ffe1322c5c2 memcpy 60670->60673 60671 7ffe132277a2 6 API calls 60671->60673 60673->60666 60673->60667 60673->60669 60673->60670 60673->60671 60674 7ffe1322c3dc 8 API calls 60673->60674 60675 7ffe132261a2 13 API calls 60673->60675 60674->60673 60675->60673 60676 7ffe102471c4 60678 7ffe10246df3 60676->60678 60677 7ffe10247213 wcslen GetProcessHeap HeapAlloc 60677->60678 60678->60677 60680 7ffe10247284 GetProcessHeap HeapAlloc 60678->60680 60686 7ffe10246e1e LocalAlloc 60678->60686 60687 7ffe102472c3 60678->60687 60694 7ffe10246e3d wcsncpy 60678->60694 60706 7ffe102470c0 ConvertSidToStringSidA 60678->60706 60707 7ffe10246ec5 GetLastError 60678->60707 60710 7ffe102440d2 6 API calls 60678->60710 60716 7ffe10246f83 LocalFree 60678->60716 60679 7ffe102472d3 NetApiBufferFree 60679->60687 60680->60678 60690 7ffe102472a8 60680->60690 60681 7ffe10247413 60684 7ffe102440d2 6 API calls 60681->60684 60702 7ffe1024741c 60681->60702 60682 7ffe102472f6 NetUserEnum 60682->60687 60683 7ffe1024756a 60688 7ffe102440d2 6 API calls 60683->60688 60684->60702 60685 7ffe102440d2 6 API calls 60685->60690 60686->60678 60687->60679 60687->60681 60687->60682 60691 7ffe10247372 GetProcessHeap HeapAlloc 60687->60691 60692 7ffe10247446 60688->60692 60689 7ffe10246ccf 8 API calls 60693 7ffe10247429 60689->60693 60690->60678 60690->60685 60695 7ffe10246dd3 60691->60695 60696 7ffe102473ac 60691->60696 60697 7ffe102440d2 6 API calls 60693->60697 60719 7ffe1024943f 60694->60719 60695->60687 60698 7ffe102440d2 6 API calls 60695->60698 60700 7ffe102473f1 60696->60700 60701 7ffe102473b8 memcpy GetProcessHeap HeapFree 60696->60701 60697->60692 60698->60695 60701->60700 60702->60683 60704 7ffe10247424 60702->60704 60704->60689 60705 7ffe10246f0e GetLastError 60705->60678 60708 7ffe10246f31 LocalAlloc 60705->60708 60706->60678 60711 7ffe10247111 GetLastError 60706->60711 60709 7ffe102440d2 6 API calls 60707->60709 60712 7ffe10246f4f LookupAccountNameW 60708->60712 60713 7ffe102470b6 60708->60713 60709->60678 60710->60678 60714 7ffe102440d2 6 API calls 60711->60714 60715 7ffe10246f91 GetLastError 60712->60715 60712->60716 60713->60706 60714->60678 60717 7ffe102440d2 6 API calls 60715->60717 60716->60678 60718 7ffe10246faf 60717->60718 60718->60716 60720 7ffe10249467 wcslen 60719->60720 60721 7ffe10246e67 LookupAccountNameW 60719->60721 60720->60721 60721->60678 60721->60705 60722 7ffe1a45341f 60723 7ffe1a45344a LeaveCriticalSection 60722->60723 60724 7ffe1a453427 60722->60724 60725 7ffe1a4533d8 60723->60725 60724->60722 60741 7ffe1a452fcd 60724->60741 60726 7ffe1a45345c GetProcessHeap HeapFree 60725->60726 60728 7ffe1a45353b Sleep SleepEx 60725->60728 60729 7ffe1a45348a EnterCriticalSection 60725->60729 60730 7ffe1a45354b EnterCriticalSection 60725->60730 60731 7ffe1a4534ad LeaveCriticalSection 60725->60731 60735 7ffe1a453402 60725->60735 60739 7ffe1a4533f8 60725->60739 60752 7ffe1a458a25 GetSystemTimeAsFileTime 60725->60752 60726->60725 60728->60730 60729->60725 60729->60731 60732 7ffe1a453558 60730->60732 60731->60725 60733 7ffe1a453589 LeaveCriticalSection 60732->60733 60734 7ffe1a453570 GetProcessHeap HeapFree 60732->60734 60734->60732 60737 7ffe1a4520c2 13 API calls 60735->60737 60738 7ffe1a45351a EnterCriticalSection 60737->60738 60753 7ffe1a458a25 GetSystemTimeAsFileTime 60739->60753 60742 7ffe1a45307c 60741->60742 60743 7ffe1a452ff8 60741->60743 60744 7ffe1a4520c2 13 API calls 60742->60744 60743->60742 60745 7ffe1a452ffd 60743->60745 60751 7ffe1a453050 60744->60751 60746 7ffe1a453006 send 60745->60746 60747 7ffe1a453049 60745->60747 60746->60745 60748 7ffe1a45302a WSAGetLastError 60746->60748 60750 7ffe1a4520c2 13 API calls 60747->60750 60747->60751 60749 7ffe1a4520c2 13 API calls 60748->60749 60749->60747 60750->60751 60751->60724 60752->60725 60753->60735 60754 7ff7bacd12fd 60757 7ff7bacd1131 60754->60757 60758 7ff7bacd115a 60757->60758 60759 7ff7bacd1172 60758->60759 60760 7ff7bacd1169 Sleep 60758->60760 60761 7ff7bacd1194 60759->60761 60762 7ff7bacd1188 _amsg_exit 60759->60762 60760->60758 60763 7ff7bacd11b5 60761->60763 60764 7ff7bacd119a _initterm 60761->60764 60762->60763 60765 7ff7bacd11c5 _initterm 60763->60765 60766 7ff7bacd11de 60763->60766 60764->60763 60765->60766 60778 7ff7bacda20b 60766->60778 60769 7ff7bacd122e 60770 7ff7bacd1233 _malloc_dbg 60769->60770 60771 7ff7bacd1253 60770->60771 60772 7ff7bacd1283 60771->60772 60773 7ff7bacd1258 strlen _malloc_dbg 60771->60773 60789 7ff7bacd1fa9 60772->60789 60773->60771 60775 7ff7bacd12c4 60776 7ff7bacd12e3 _cexit 60775->60776 60777 7ff7bacd12e8 60775->60777 60776->60777 60779 7ff7bacd1208 SetUnhandledExceptionFilter 60778->60779 60781 7ff7bacda229 60778->60781 60779->60769 60780 7ff7bacda42f 60780->60779 60783 7ff7bacda457 VirtualProtect 60780->60783 60781->60780 60782 7ff7bacda2a0 60781->60782 60787 7ff7bacda2df 60781->60787 60782->60780 60784 7ff7bacda2be 60782->60784 60783->60780 60784->60782 60793 7ff7bacda0c4 VirtualQuery VirtualProtect GetLastError 60784->60793 60786 7ff7bacda34a 60794 7ff7bacda0c4 VirtualQuery VirtualProtect GetLastError 60786->60794 60787->60780 60787->60786 60790 7ff7bacd1fb9 60789->60790 60795 7ff7bacd1dbc 60790->60795 60793->60784 60794->60787 60796 7ff7bacd1dc6 strcmp 60795->60796 60798 7ff7bacd1e40 60796->60798 60799 7ff7bacd1ddd strcmp 60796->60799 60802 7ff7bacd161a 117 API calls 60798->60802 60800 7ff7bacd1df4 StartServiceCtrlDispatcherA 60799->60800 60801 7ff7bacd1f81 60799->60801 60804 7ff7bacd1e98 GetLastError 60800->60804 60812 7ff7bacd1e2d 60800->60812 60803 7ff7bacd2ef2 7 API calls 60801->60803 60805 7ff7bacd1e45 60802->60805 60803->60812 60806 7ff7bacd2ef2 7 API calls 60804->60806 60807 7ff7bacd1e4b 60805->60807 60808 7ff7bacd16e3 383 API calls 60805->60808 60806->60812 60816 7ff7bacd1a63 11 API calls 60807->60816 60814 7ff7bacd1e5f 60808->60814 60810 7ff7bacd1e50 60817 7ff7bacd1b1c 14 API calls 60810->60817 60812->60775 60813 7ff7bacd1e69 _read 60813->60807 60813->60814 60814->60807 60814->60813 60815 7ff7bacd19e2 26 API calls 60814->60815 60815->60814 60816->60810 60817->60812 60818 7ffe1150a31a 60824 7ffe1150a325 60818->60824 60819 7ffe1150a42e 60820 7ffe1150a43b 60819->60820 60885 7ffe1150ad75 10 API calls 60819->60885 60822 7ffe1150a34d Sleep 60822->60824 60824->60819 60824->60822 60825 7ffe1150ad75 10 API calls 60824->60825 60827 7ffe1150a402 Sleep 60824->60827 60829 7ffe1150a3ee memcpy 60824->60829 60830 7ffe1150b00c socket 60824->60830 60865 7ffe1150b4ba 60824->60865 60876 7ffe1150a250 60824->60876 60825->60824 60827->60824 60829->60824 60831 7ffe1150b043 60830->60831 60832 7ffe1150b20b WSAGetLastError 60830->60832 60833 7ffe1150b065 60831->60833 60834 7ffe1150b047 60831->60834 60835 7ffe1150c852 6 API calls 60832->60835 60838 7ffe1150aca9 8 API calls 60833->60838 60886 7ffe1150aca9 60834->60886 60837 7ffe1150b22f 60835->60837 60840 7ffe1150b07f 60837->60840 60841 7ffe1150b239 60837->60841 60842 7ffe1150b063 60838->60842 60844 7ffe1150c852 6 API calls 60840->60844 60846 7ffe1150c852 6 API calls 60841->60846 60843 7ffe1150b077 60842->60843 60899 7ffe1150adda setsockopt 60842->60899 60903 7ffe1150ad75 10 API calls 60843->60903 60847 7ffe1150b0a0 60844->60847 60845 7ffe1150b0be 60845->60843 60850 7ffe1150b0c3 htonl htons connect 60845->60850 60846->60847 60847->60824 60852 7ffe1150b101 60850->60852 60853 7ffe1150b11c WSAGetLastError 60850->60853 60854 7ffe1150aca9 8 API calls 60852->60854 60855 7ffe1150b1de WSAGetLastError 60853->60855 60856 7ffe1150b12d 60853->60856 60859 7ffe1150b10e 60854->60859 60858 7ffe1150c852 6 API calls 60855->60858 60856->60843 60857 7ffe1150b135 select 60856->60857 60860 7ffe1150b1c0 60857->60860 60861 7ffe1150b196 60857->60861 60858->60843 60859->60837 60859->60843 60863 7ffe1150c852 6 API calls 60860->60863 60861->60852 60862 7ffe1150b19c WSAGetLastError 60861->60862 60864 7ffe1150c852 6 API calls 60862->60864 60863->60843 60864->60843 60866 7ffe1150b4d4 60865->60866 60867 7ffe1150b548 60865->60867 60866->60867 60869 7ffe1150b4d9 recv 60866->60869 60868 7ffe1150c852 6 API calls 60867->60868 60871 7ffe1150b4f3 60868->60871 60870 7ffe1150b4fc WSAGetLastError 60869->60870 60872 7ffe1150b4ef 60869->60872 60870->60871 60873 7ffe1150b510 60870->60873 60871->60824 60872->60871 60875 7ffe1150c852 6 API calls 60872->60875 60874 7ffe1150c852 6 API calls 60873->60874 60874->60871 60875->60871 60877 7ffe1150a312 60876->60877 60878 7ffe1150a268 60876->60878 60877->60824 60878->60877 60904 7ffe11509035 60878->60904 60881 7ffe1150a298 60882 7ffe1150a304 LeaveCriticalSection 60881->60882 60883 7ffe1150c852 6 API calls 60881->60883 60907 7ffe1150e467 60881->60907 60882->60877 60883->60881 60885->60820 60887 7ffe1150acb9 ioctlsocket 60886->60887 60889 7ffe1150acdc 60887->60889 60890 7ffe1150aced WSAGetLastError 60887->60890 60889->60845 60892 7ffe1150abf4 setsockopt 60889->60892 60891 7ffe1150c852 6 API calls 60890->60891 60891->60889 60893 7ffe1150ac84 WSAGetLastError 60892->60893 60894 7ffe1150ac29 setsockopt 60892->60894 60895 7ffe1150c852 6 API calls 60893->60895 60896 7ffe1150ac5f WSAGetLastError 60894->60896 60897 7ffe1150ac55 60894->60897 60895->60897 60898 7ffe1150c852 6 API calls 60896->60898 60897->60842 60898->60897 60900 7ffe1150ae21 WSAGetLastError 60899->60900 60901 7ffe1150ae17 60899->60901 60902 7ffe1150c852 6 API calls 60900->60902 60901->60845 60902->60901 60903->60840 60905 7ffe11509040 EnterCriticalSection 60904->60905 60906 7ffe1150904b GetSystemTimeAsFileTime 60904->60906 60905->60881 60906->60905 60908 7ffe1150e497 60907->60908 60927 7ffe1150e4bf 60907->60927 60909 7ffe1150e4a1 60908->60909 60910 7ffe1150e507 60908->60910 60912 7ffe1150e4a3 60909->60912 60913 7ffe1150e4dd 60909->60913 60938 7ffe1150dc9a 90 API calls 60910->60938 60916 7ffe1150e515 60912->60916 60917 7ffe1150e4aa 60912->60917 60914 7ffe1150e50e 60913->60914 60915 7ffe1150e4e4 60913->60915 60939 7ffe1150dd0f 47 API calls 60914->60939 60920 7ffe1150e500 60915->60920 60921 7ffe1150e4eb 60915->60921 60940 7ffe1150de41 24 API calls 60916->60940 60922 7ffe1150e4c8 60917->60922 60923 7ffe1150e4ac 60917->60923 60932 7ffe1150dba8 60920->60932 60921->60927 60937 7ffe1150dbb6 183 API calls 60921->60937 60922->60927 60936 7ffe1150df63 15 API calls 60922->60936 60924 7ffe1150e4b3 60923->60924 60925 7ffe1150e51c 60923->60925 60924->60927 60935 7ffe1150dfe3 34 API calls 60924->60935 60941 7ffe1150deea 18 API calls 60925->60941 60927->60881 60942 7ffe1150db60 60932->60942 60935->60927 60936->60927 60937->60927 60938->60927 60939->60927 60940->60927 60941->60927 60949 7ffe1150bceb 60942->60949 60945 7ffe1150db81 60945->60927 60948 7ffe1150bceb 2 API calls 60948->60945 60950 7ffe1150bd01 QueryPerformanceFrequency QueryPerformanceCounter 60949->60950 60951 7ffe1150bcf6 60949->60951 60950->60951 60951->60945 60952 7ffe11506f2b 60951->60952 60987 7ffe11506eed 60952->60987 60955 7ffe11506f41 60957 7ffe11506f4e 60955->60957 60996 7ffe11508b2c 22 API calls 60955->60996 60956 7ffe1150b930 8 API calls 60958 7ffe11506f69 60956->60958 60957->60948 60960 7ffe1150466b 8 API calls 60958->60960 60961 7ffe11506f7e 60960->60961 60962 7ffe11506f88 strlen 60961->60962 60963 7ffe1150702f 60961->60963 60966 7ffe11506fa5 60962->60966 60967 7ffe11506fbe strlen 60962->60967 60963->60955 60964 7ffe11507037 strlen 60963->60964 60968 7ffe11507064 strlen 60964->60968 60969 7ffe1150704e 60964->60969 60966->60967 60972 7ffe11506faa strlen 60966->60972 60992 7ffe11503714 10 API calls 60967->60992 60994 7ffe11503714 10 API calls 60968->60994 60969->60968 60974 7ffe11507053 strlen 60969->60974 60971 7ffe1150710a 60984 7ffe11507131 60971->60984 60997 7ffe11508b47 GetProcessHeap HeapFree GetProcessHeap HeapFree LeaveCriticalSection 60971->60997 60998 7ffe115081b3 7 API calls 60971->60998 60972->60967 60974->60968 60976 7ffe11507004 60976->60955 60993 7ffe11504246 8 API calls 60976->60993 60977 7ffe115070a7 60979 7ffe115070b4 CompareFileTime 60977->60979 60982 7ffe115070ea 60977->60982 60979->60955 60983 7ffe115070cc 60979->60983 60981 7ffe1150702d 60981->60963 60982->60955 60995 7ffe11502c59 8 API calls 60983->60995 60984->60971 60999 7ffe11508237 41 API calls 60984->60999 61000 7ffe11507e40 19 API calls 60984->61000 61001 7ffe11505dd0 60987->61001 60991 7ffe11506efa 60991->60955 60991->60956 60992->60976 60993->60981 60994->60977 60995->60982 60996->60971 60997->60971 60998->60971 60999->60984 61000->60984 61002 7ffe11505192 9 API calls 61001->61002 61003 7ffe11505e13 61002->61003 61004 7ffe11505e17 strlen 61003->61004 61010 7ffe11505e60 61003->61010 61005 7ffe11505e2d strcmp 61004->61005 61007 7ffe11505e6e 61005->61007 61005->61010 61015 7ffe11504246 8 API calls 61007->61015 61009 7ffe11505e94 61009->61010 61011 7ffe11505ea6 61009->61011 61010->60991 61014 7ffe1150b25e 27 API calls 61010->61014 61016 7ffe11503f67 8 API calls 61011->61016 61013 7ffe11505eb0 61013->61010 61014->60991 61015->61009 61016->61013 61017 7ffe1a453987 61030 7ffe1a453991 61017->61030 61018 7ffe1a453a2a EnterCriticalSection 61018->61030 61019 7ffe1a453a77 EnterCriticalSection 61025 7ffe1a453a84 61019->61025 61020 7ffe1a453adf LeaveCriticalSection 61021 7ffe1a453a90 WaitForSingleObject 61033 7ffe1a4527d5 17 API calls 61021->61033 61023 7ffe1a4539b7 LeaveCriticalSection 61024 7ffe1a453a6a Sleep SleepEx 61023->61024 61023->61030 61024->61019 61025->61020 61025->61021 61027 7ffe1a453ac6 GetProcessHeap HeapFree 61025->61027 61026 7ffe1a4520c2 13 API calls 61028 7ffe1a4539e4 WaitForSingleObject 61026->61028 61027->61025 61032 7ffe1a4527d5 17 API calls 61028->61032 61030->61018 61030->61019 61030->61023 61030->61026 61031 7ffe1a453a09 GetProcessHeap HeapFree 61030->61031 61031->61030 61032->61030 61033->61025

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 799 7ffe10246df3-7ffe10246e09 call 7ffe102440d2 802 7ffe1024727a-7ffe1024727e 799->802 803 7ffe10246e0e 802->803 804 7ffe10247284-7ffe102472a2 GetProcessHeap HeapAlloc 802->804 805 7ffe10246e13-7ffe10246e18 803->805 804->805 806 7ffe102472a8-7ffe102472be call 7ffe102440d2 804->806 808 7ffe10246e1e-7ffe10246e2e LocalAlloc 805->808 809 7ffe10246f04-7ffe10246f09 805->809 806->805 811 7ffe10246e32-7ffe10246e37 808->811 809->811 812 7ffe102471f5 811->812 813 7ffe10246e3d-7ffe10246ebb wcsncpy call 7ffe1024943f LookupAccountNameW 811->813 814 7ffe102471fa-7ffe10247205 812->814 821 7ffe10246f0e-7ffe10246f1a GetLastError 813->821 822 7ffe10246ebd-7ffe10246ebf 813->822 816 7ffe102472c3 814->816 817 7ffe1024720b-7ffe1024720d 814->817 820 7ffe102472c9-7ffe102472d1 816->820 817->816 819 7ffe10247213-7ffe10247274 wcslen GetProcessHeap HeapAlloc 817->819 819->799 819->802 825 7ffe102472d3 NetApiBufferFree 820->825 826 7ffe102472d8-7ffe102472e8 820->826 827 7ffe10246f31-7ffe10246f49 LocalAlloc 821->827 828 7ffe10246f1c-7ffe10246f2f call 7ffe102440d2 821->828 823 7ffe102470c0-7ffe102470d8 ConvertSidToStringSidA 822->823 824 7ffe10246ec5-7ffe10246ee6 GetLastError call 7ffe102440d2 822->824 833 7ffe10247111-7ffe10247135 GetLastError call 7ffe102440d2 823->833 834 7ffe102470da-7ffe102470e1 823->834 849 7ffe10247137-7ffe1024713d 824->849 850 7ffe10246eec 824->850 825->826 830 7ffe102472ee-7ffe102472f0 826->830 831 7ffe10247413-7ffe1024741a 826->831 835 7ffe10246f4f-7ffe10246f81 LookupAccountNameW 827->835 836 7ffe102470b6 827->836 828->824 830->831 841 7ffe102472f6-7ffe10247360 NetUserEnum 830->841 839 7ffe10247459-7ffe10247472 call 7ffe102440d2 831->839 840 7ffe1024741c-7ffe1024741e 831->840 833->834 843 7ffe102470e7-7ffe1024710c call 7ffe102440d2 834->843 844 7ffe102471bd-7ffe102471c2 834->844 845 7ffe10246f91-7ffe10246fb2 GetLastError call 7ffe102440d2 835->845 846 7ffe10246f83-7ffe10246f8c LocalFree 835->846 836->823 872 7ffe10247474 839->872 873 7ffe10247493-7ffe10247499 839->873 851 7ffe10247424-7ffe10247441 call 7ffe10246ccf call 7ffe102440d2 840->851 852 7ffe1024756a-7ffe10247584 call 7ffe102440d2 840->852 841->820 854 7ffe10247366-7ffe1024736c 841->854 843->814 844->814 867 7ffe10246fb4 845->867 868 7ffe10246fcc-7ffe10246fd2 845->868 846->822 859 7ffe10247143-7ffe10247149 849->859 860 7ffe102471cb-7ffe102471d0 849->860 861 7ffe10246ef2-7ffe10246eff 850->861 862 7ffe102471b6-7ffe102471bb 850->862 876 7ffe10247446-7ffe10247458 851->876 852->876 854->820 864 7ffe10247372-7ffe102473a6 GetProcessHeap HeapAlloc 854->864 870 7ffe10247175-7ffe10247178 859->870 871 7ffe1024714b-7ffe10247151 859->871 860->814 861->846 862->814 874 7ffe10246dd3-7ffe10246dee call 7ffe102440d2 864->874 875 7ffe102473ac-7ffe102473b6 864->875 877 7ffe10247066-7ffe1024706b 867->877 878 7ffe10246fba-7ffe10246fc7 867->878 881 7ffe10246fd8-7ffe10246fde 868->881 882 7ffe1024707a-7ffe1024707f 868->882 887 7ffe1024718b-7ffe10247191 870->887 888 7ffe1024717a-7ffe1024717d 870->888 883 7ffe102471e7-7ffe102471ec 871->883 884 7ffe10247157-7ffe1024715d 871->884 885 7ffe10247518-7ffe1024751d 872->885 886 7ffe1024747a-7ffe10247487 872->886 889 7ffe1024749f 873->889 890 7ffe10247522 873->890 874->820 891 7ffe102473f1-7ffe1024740e 875->891 892 7ffe102473b8-7ffe102473eb memcpy GetProcessHeap HeapFree 875->892 877->846 878->868 894 7ffe10246fe0-7ffe10246fe3 881->894 895 7ffe10247014-7ffe1024701a 881->895 882->846 883->814 896 7ffe102471ee-7ffe102471f3 884->896 897 7ffe10247163-7ffe10247169 884->897 885->851 886->873 900 7ffe102471e0-7ffe102471e5 887->900 901 7ffe10247193-7ffe10247198 887->901 898 7ffe1024717f-7ffe10247182 888->898 899 7ffe102471d2-7ffe102471d7 888->899 902 7ffe102474a1-7ffe102474a7 889->902 903 7ffe102474cf-7ffe102474d2 889->903 910 7ffe1024752c-7ffe10247531 890->910 892->891 906 7ffe10246ffe-7ffe10247004 894->906 907 7ffe10246fe5-7ffe10246fe8 894->907 913 7ffe10247020-7ffe10247026 895->913 914 7ffe102470a2-7ffe102470a7 895->914 896->814 908 7ffe1024716b-7ffe10247170 897->908 909 7ffe1024719a-7ffe1024719f 897->909 911 7ffe10247184-7ffe10247189 898->911 912 7ffe102471d9-7ffe102471de 898->912 899->814 900->814 901->814 915 7ffe102474ad-7ffe102474b3 902->915 916 7ffe1024754a-7ffe1024754f 902->916 904 7ffe102474d4-7ffe102474d7 903->904 905 7ffe102474e8-7ffe102474ee 903->905 904->910 917 7ffe102474d9-7ffe102474dc 904->917 918 7ffe10247540 905->918 919 7ffe102474f0-7ffe102474f5 905->919 922 7ffe10247098-7ffe1024709d 906->922 923 7ffe1024700a-7ffe1024700f 906->923 920 7ffe10246fee-7ffe10246ff1 907->920 921 7ffe10247084-7ffe10247089 907->921 908->814 909->814 910->851 911->814 912->814 924 7ffe102470ac-7ffe102470b1 913->924 925 7ffe1024702c-7ffe10247032 913->925 914->846 926 7ffe10247554-7ffe10247559 915->926 927 7ffe102474b9-7ffe102474bf 915->927 916->851 928 7ffe102474de-7ffe102474e3 917->928 929 7ffe10247536-7ffe1024753b 917->929 918->916 919->851 930 7ffe1024708e-7ffe10247093 920->930 931 7ffe10246ff7-7ffe10246ffc 920->931 921->846 922->846 923->846 924->846 932 7ffe1024703e-7ffe10247043 925->932 933 7ffe10247034-7ffe10247039 925->933 926->851 934 7ffe1024755e-7ffe10247563 927->934 935 7ffe102474c5-7ffe102474ca 927->935 928->851 929->851 930->846 931->846 932->846 933->846 934->851 934->852 935->851
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: AllocErrorLastLocal$AccountCriticalHeapLookupNameSection$CopyEnterFileFreeLeaveProcessfflushfwritewcsncpy
                                  • String ID: D$[D] (%s) -> User found(name=%s,s_sid=%s,acct_expires=%x,last_logon=%x)$[E] (%s) -> ConvertSidToStringSid failed(gle=%lu)$[E] (%s) -> LookupAccountNameW failed(gle=%lu)$[E] (%s) -> Memory allocation failed(size=%llu)$mem_alloc$sid_to_str$users_sync
                                  • API String ID: 3624467404-104752423
                                  • Opcode ID: a0c95d91e4369224ee69ffe4f0886408ff921e2969674c85983f0f3a9c1182ca
                                  • Instruction ID: be2ce0ecd693f06a4bd4ed69472f91ee6abe20ddd455084a4561acc6928fa9a2
                                  • Opcode Fuzzy Hash: a0c95d91e4369224ee69ffe4f0886408ff921e2969674c85983f0f3a9c1182ca
                                  • Instruction Fuzzy Hash: 1BF14B66A0CE02C6EB608B16E4443796BA1FBC8774F1500B2DB5E877B6EE7CE845C741
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: Heap$strncpy$Process_errno$AllocFreefflushfopenfseekfwrite
                                  • String ID: (path != NULL)$5$C:/Projects/rdp/bot/codebase/ini.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(path=%s,err=%08x)$[E] (%s) -> Memory allocation failed(size=%llu)$[I] (%s) -> Done(path=%s)$ini_load$mem_alloc$service
                                  • API String ID: 1423203057-455140666
                                  • Opcode ID: 6ddc479bc11967d2225c0c5f849eea2d70ec7ec8fbbd2fd89b086ef18872a135
                                  • Instruction ID: b8b9b561054700a8cd335c857ff629b739339c49c746f73117b839df95ab2456
                                  • Opcode Fuzzy Hash: 6ddc479bc11967d2225c0c5f849eea2d70ec7ec8fbbd2fd89b086ef18872a135
                                  • Instruction Fuzzy Hash: 9CB1B166A0968291FA51BB19A44837AEB91FB72B84FC840B5DF8D0778DDF7CE405C320
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: Find$ErrorFileLast$CloseFirstNextfflushfwritestrcpy
                                  • String ID: (name != NULL)$(path != NULL)$(resume_handle != NULL)$C:/Projects/rdp/bot/codebase/fs.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> FindFirstFileA failed(path=%s,gle=%lu)$[E] (%s) -> FindNextFileA failed(path=%s,gle=%lu)$fs_dir_list
                                  • API String ID: 4253334766-1535167640
                                  • Opcode ID: 409c3b7b22b22245a4a5f9e1b64c03c63d989e592a936231ffe5ac6cae602da9
                                  • Instruction ID: 53e45a94ee3bcfa4063a84e939b21e73158bc332fb1e8387e8e460918d04ef0d
                                  • Opcode Fuzzy Hash: 409c3b7b22b22245a4a5f9e1b64c03c63d989e592a936231ffe5ac6cae602da9
                                  • Instruction Fuzzy Hash: 2E613B21F0CE4389FB249B96AC043BB2258AF10375FD451B2E85E5B2F4DE6CF9458741
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: Find$ErrorFileLast$CloseFirstNext_mbscpyfflushfwrite
                                  • String ID: (name != NULL)$(path != NULL)$(resume_handle != NULL)$C:/Projects/rdp/bot/codebase/fs.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> FindFirstFileA failed(path=%s,gle=%lu)$[E] (%s) -> FindNextFileA failed(path=%s,gle=%lu)$fs_dir_list
                                  • API String ID: 1094913617-1535167640
                                  • Opcode ID: 31ce2ca2e1ee8476024e7a7709de7764d6abc175595fe46fba7d7720874f4b8f
                                  • Instruction ID: 84039e30aed7b1621e74c50bab4f5d8a474654c975cf2a5b812a1aec16821224
                                  • Opcode Fuzzy Hash: 31ce2ca2e1ee8476024e7a7709de7764d6abc175595fe46fba7d7720874f4b8f
                                  • Instruction Fuzzy Hash: CF617231E0C54385FA207B5CA90C3B8E155AF32394FC551B2DFAD6B2DCDE2CA8859365
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: Heap$Free$Process$AllocBufferEnumLocalUsermemcpy
                                  • String ID: [E] (%s) -> Failed(err=%08x)$[E] (%s) -> Memory allocation failed(size=%llu)$[E] (%s) -> NetUserEnum failed(enum_err=%08lx)$[I] (%s) -> Done(sam_user_num=%u)$mem_alloc$users_sync
                                  • API String ID: 1987963910-3382179125
                                  • Opcode ID: f82548c41b64e104f45176bb652d640d323ef8c93e62912a90947e9cbac2ef3b
                                  • Instruction ID: 7b8e61987ced0c77de0a5da6819e961703ab4f274233ea410993374ed1def07e
                                  • Opcode Fuzzy Hash: f82548c41b64e104f45176bb652d640d323ef8c93e62912a90947e9cbac2ef3b
                                  • Instruction Fuzzy Hash: 51617D61A0CE46C5FA209756B8443B96EA0BFD43B4F5400B2DB6D8B7B3EE6DE855C301
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLast$bindfflushfwritehtonlhtonslistensetsockoptsocket
                                  • String ID: [E] (%s) -> bind failed(sock=0x%llx,host=%08x,port=%u,WSAgle=%d)$[E] (%s) -> listen failed(sock=0x%llx,host=%08x,port=%u,WSAgle=%d)$[E] (%s) -> socket failed(host=%08x,port=%u,WSAgle=%d)$[I] (%s) -> Done(sock=0x%llx,host=%08x,port=%u)$tcp_listen
                                  • API String ID: 3590747132-3524496754
                                  • Opcode ID: f8bff91af96c5007eb7fcf78505af45f0c951cb3b5af3f813e452651c67239d6
                                  • Instruction ID: b1e5f74bc5d99e130e64d2497396a62f854540d4cc3dcfe25794bd0c9002a327
                                  • Opcode Fuzzy Hash: f8bff91af96c5007eb7fcf78505af45f0c951cb3b5af3f813e452651c67239d6
                                  • Instruction Fuzzy Hash: C13195A1B48E0646E620AB27A8001B573A0AF54FB4F1853F7E97D436F1EE7CE4658740
                                  APIs
                                  • strcmp.MSVCRT ref: 00007FF7BACD1DD4
                                  • strcmp.MSVCRT ref: 00007FF7BACD1DE7
                                  • StartServiceCtrlDispatcherA.ADVAPI32 ref: 00007FF7BACD1E23
                                  • _read.MSVCRT ref: 00007FF7BACD1E79
                                  • GetLastError.KERNEL32 ref: 00007FF7BACD1E98
                                    • Part of subcall function 00007FF7BACD1A63: FreeLibrary.KERNEL32(?,?,00000000,000002BAD3D813D0,00007FF7BACD1E50,?,?,?,?,?,?,00000001,00007FF7BACD1FC3,?,?,00007FF7BACE8508), ref: 00007FF7BACD1AA1
                                    • Part of subcall function 00007FF7BACD1A63: GetProcessHeap.KERNEL32(?,?,00000000,000002BAD3D813D0,00007FF7BACD1E50,?,?,?,?,?,?,00000001,00007FF7BACD1FC3,?,?,00007FF7BACE8508), ref: 00007FF7BACD1AD4
                                    • Part of subcall function 00007FF7BACD1A63: HeapFree.KERNEL32(?,?,00000000,000002BAD3D813D0,00007FF7BACD1E50,?,?,?,?,?,?,00000001,00007FF7BACD1FC3,?,?,00007FF7BACE8508), ref: 00007FF7BACD1AE5
                                    • Part of subcall function 00007FF7BACD1B1C: GetProcessHeap.KERNEL32(?,?,00000000,00007FF7BACD1E55,?,?,?,?,?,?,00000001,00007FF7BACD1FC3,?,?,00007FF7BACE8508,00000000), ref: 00007FF7BACD1B4D
                                    • Part of subcall function 00007FF7BACD1B1C: HeapFree.KERNEL32(?,?,00000000,00007FF7BACD1E55,?,?,?,?,?,?,00000001,00007FF7BACD1FC3,?,?,00007FF7BACE8508,00000000), ref: 00007FF7BACD1B5E
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: Heap$Free$Processstrcmp$CtrlDispatcherErrorLastLibraryServiceStart_read
                                  • String ID: RDP-Controller$[E] (%s) -> No a valid run mode(mode=%s)$[E] (%s) -> StartServiceCtrlDispatcherA failed(GetLastError=%lu)$main$service$standalone
                                  • API String ID: 3617873859-308889057
                                  • Opcode ID: 55467b970312a76cee8264313134d138696b032ea232789205e1211f0220befb
                                  • Instruction ID: f96eedfeeb343766d1c1b49d62b207654a46f5cc54c6ba34e911030e8c5d0924
                                  • Opcode Fuzzy Hash: 55467b970312a76cee8264313134d138696b032ea232789205e1211f0220befb
                                  • Instruction Fuzzy Hash: B0511714A0C64395FBA0775CA48C378A291AF3A344FD425B3DF8E4669ADF1DE8819232
                                  APIs
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: _initterm_malloc_dbg$ExceptionFilterSleepUnhandled_amsg_exit_cexitstrlen
                                  • String ID:
                                  • API String ID: 4167734774-0
                                  • Opcode ID: b69943c6f9b772719986a418f55e2c71d1b60b008ccac56098dddaa58f381500
                                  • Instruction ID: dd9f97efe163da1b2d848dc4ef9c97bf9ab4efe6e1a8d751fc4249ebb264c099
                                  • Opcode Fuzzy Hash: b69943c6f9b772719986a418f55e2c71d1b60b008ccac56098dddaa58f381500
                                  • Instruction Fuzzy Hash: 3E515A21A0860289FB50FB59E848279A3A0BF7AB94F8454B6CF4D47399DF3DF4419360
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastrecv
                                  • String ID: [D] (%s) -> Disconnected(sock=0x%llx)$[E] (%s) -> Invalid arguments(sock=0x%llx,p=0x%p,l=%d)$[E] (%s) -> recv failed(sock=0x%llx,WSAgle=%d)$tcp_recv
                                  • API String ID: 2514157807-65069805
                                  • Opcode ID: f193efd81dde89f2c72c9f1d13d33f0ca31008ea4ec8f01b3fb2f3a9771b48b3
                                  • Instruction ID: 2374fc6583b07fe21439b539e445a59e98617dc2754a4615ac1455649b25a65b
                                  • Opcode Fuzzy Hash: f193efd81dde89f2c72c9f1d13d33f0ca31008ea4ec8f01b3fb2f3a9771b48b3
                                  • Instruction Fuzzy Hash: FB115E90A0CD27D1F6205717A8442B82A546F8A7B4F4113B0EB6D97BF7EE5CA51AC305

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 0 7ff7bacd5015-7ff7bacd5031 1 7ff7bacd50c7-7ff7bacd50f5 call 7ff7bacd2ef2 0->1 2 7ff7bacd5037-7ff7bacd503a 0->2 13 7ff7bacd5579-7ff7bacd558a 1->13 3 7ff7bacd5040-7ff7bacd5044 2->3 4 7ff7bacd50fa-7ff7bacd5128 call 7ff7bacd2ef2 2->4 6 7ff7bacd5046-7ff7bacd504a 3->6 7 7ff7bacd5050-7ff7bacd5065 fopen 3->7 4->13 6->7 10 7ff7bacd512d-7ff7bacd515b call 7ff7bacd2ef2 6->10 11 7ff7bacd5160-7ff7bacd5189 _errno call 7ff7bacd2ef2 _errno 7->11 12 7ff7bacd506b-7ff7bacd5080 fseek 7->12 10->13 28 7ff7bacd51cf-7ff7bacd51e3 _errno 11->28 29 7ff7bacd518b-7ff7bacd5198 11->29 17 7ff7bacd5233-7ff7bacd5240 call 7ff7bacde488 12->17 18 7ff7bacd5086-7ff7bacd50af _errno call 7ff7bacd2ef2 _errno 12->18 19 7ff7bacd5593-7ff7bacd55a0 13->19 20 7ff7bacd558c 13->20 36 7ff7bacd5242 17->36 37 7ff7bacd526b-7ff7bacd5294 _errno call 7ff7bacd2ef2 _errno 17->37 33 7ff7bacd50b5-7ff7bacd50c2 18->33 34 7ff7bacd521a-7ff7bacd522e _errno 18->34 21 7ff7bacd55a2-7ff7bacd55b3 call 7ff7bacd2ef2 19->21 22 7ff7bacd55d9-7ff7bacd55e0 19->22 20->19 32 7ff7bacd55b8-7ff7bacd55ca 21->32 22->21 35 7ff7bacd5568-7ff7bacd556b 28->35 29->28 33->1 34->35 39 7ff7bacd5575-7ff7bacd5577 35->39 40 7ff7bacd556d-7ff7bacd5570 fclose 35->40 41 7ff7bacd5563 36->41 42 7ff7bacd5248-7ff7bacd524d 36->42 48 7ff7bacd5296-7ff7bacd52a3 37->48 49 7ff7bacd52da-7ff7bacd52ee _errno 37->49 39->13 44 7ff7bacd55e2-7ff7bacd55fb call 7ff7bacd2ef2 39->44 40->39 41->35 45 7ff7bacd52f3-7ff7bacd530b fseek 42->45 46 7ff7bacd5253-7ff7bacd5258 42->46 44->32 50 7ff7bacd5381-7ff7bacd53aa _errno call 7ff7bacd2ef2 _errno 45->50 51 7ff7bacd530d-7ff7bacd5319 45->51 46->45 47 7ff7bacd525e-7ff7bacd5266 46->47 47->35 48->49 49->35 61 7ff7bacd53f0-7ff7bacd5404 _errno 50->61 62 7ff7bacd53ac-7ff7bacd53b9 50->62 54 7ff7bacd531f-7ff7bacd5325 51->54 55 7ff7bacd5409-7ff7bacd542b GetProcessHeap RtlAllocateHeap 51->55 59 7ff7bacd55d2-7ff7bacd55d7 54->59 60 7ff7bacd532b 54->60 55->54 58 7ff7bacd5431-7ff7bacd5447 call 7ff7bacd2ef2 55->58 58->54 59->35 64 7ff7bacd5330-7ff7bacd533f 60->64 61->35 62->61 66 7ff7bacd5345-7ff7bacd5347 64->66 67 7ff7bacd54de-7ff7bacd54e7 64->67 66->67 70 7ff7bacd534d-7ff7bacd5370 fread 66->70 68 7ff7bacd550f-7ff7bacd5532 call 7ff7bacd2ef2 67->68 69 7ff7bacd54e9-7ff7bacd54eb 67->69 72 7ff7bacd54ed-7ff7bacd54f2 68->72 71 7ff7bacd5534-7ff7bacd5539 69->71 69->72 70->67 74 7ff7bacd5376 70->74 77 7ff7bacd5543-7ff7bacd554c 71->77 78 7ff7bacd553b-7ff7bacd5541 71->78 72->35 75 7ff7bacd54f4-7ff7bacd550d GetProcessHeap HeapFree 72->75 79 7ff7bacd544c-7ff7bacd5475 _errno call 7ff7bacd2ef2 _errno 74->79 80 7ff7bacd537c-7ff7bacd537f 74->80 75->35 77->78 78->35 83 7ff7bacd54bb-7ff7bacd54cf _errno 79->83 84 7ff7bacd5477-7ff7bacd5484 79->84 80->64 83->64 84->83
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: _errno$fclosefflushfopenfseekfwrite
                                  • String ID: (((*buf) == NULL) || ((*buf_sz) > 0))$(buf_sz != NULL)$(path != NULL)$C:/Projects/rdp/bot/codebase/fs.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(path=%s,err=%08x)$[E] (%s) -> Memory allocation failed(size=%llu)$[E] (%s) -> fopen failed(path=%s,errno=%d)$[E] (%s) -> fread failed(path=%s,errno=%d)$[E] (%s) -> fread undone(path=%s,l=%ld,n=%ld)$[E] (%s) -> fseek(SEEK_END) failed(path=%s,errno=%d)$[E] (%s) -> fseek(SEEK_SET) failed(path=%s,errno=%d)$[E] (%s) -> ftell failed(path=%s,errno=%d)$[I] (%s) -> Done(path=%s,buf_sz=%llu)$fs_file_read$mem_alloc
                                  • API String ID: 2897271634-4120527733
                                  • Opcode ID: 9f84269571c8a0eedd8a27f15f6e0f61a213b1d19bbe3ba683093f61b2385d4b
                                  • Instruction ID: f55948cb8deaa2c11f3372f9cd8e7a568317f9c6c1be0eabc06e3d1e4a1b534d
                                  • Opcode Fuzzy Hash: 9f84269571c8a0eedd8a27f15f6e0f61a213b1d19bbe3ba683093f61b2385d4b
                                  • Instruction Fuzzy Hash: E8D19E61A0864685FA11BB5DE8483B8A391AF73781FC414B2DF4D476A8EE3CF9859320

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 85 7ffe1a453af7-7ffe1a453b1a InitializeCriticalSectionAndSpinCount 86 7ffe1a453ca2-7ffe1a453cc3 GetLastError call 7ffe1a4520c2 85->86 87 7ffe1a453b20-7ffe1a453b47 InitializeCriticalSectionAndSpinCount 85->87 97 7ffe1a453cc5 86->97 98 7ffe1a453cdd-7ffe1a453ce3 86->98 88 7ffe1a453dbe-7ffe1a453ddf GetLastError call 7ffe1a4520c2 87->88 89 7ffe1a453b4d-7ffe1a453b5d 87->89 107 7ffe1a453de1 88->107 108 7ffe1a453df9-7ffe1a453dff 88->108 91 7ffe1a453b63-7ffe1a453b9b CreateThread 89->91 92 7ffe1a454190-7ffe1a4541a8 call 7ffe1a4520c2 89->92 95 7ffe1a453ba1-7ffe1a453bbd call 7ffe1a4520c2 91->95 96 7ffe1a453e96-7ffe1a453eb7 GetLastError call 7ffe1a4520c2 91->96 106 7ffe1a4541ad-7ffe1a4541b4 92->106 95->92 118 7ffe1a453bc3-7ffe1a453bfb CreateThread 95->118 122 7ffe1a453ecd-7ffe1a453ed3 96->122 123 7ffe1a453eb9 96->123 102 7ffe1a453d6e 97->102 103 7ffe1a453ccb-7ffe1a453cd8 97->103 104 7ffe1a453d82 98->104 105 7ffe1a453ce9-7ffe1a453cef 98->105 102->104 103->98 121 7ffe1a453d8c 104->121 111 7ffe1a453cf1-7ffe1a453cf7 105->111 112 7ffe1a453d1b-7ffe1a453d1e 105->112 113 7ffe1a45418b 107->113 114 7ffe1a453de7-7ffe1a453df4 107->114 116 7ffe1a4541b5-7ffe1a4541ba 108->116 117 7ffe1a453e05-7ffe1a453e0b 108->117 119 7ffe1a453daa 111->119 120 7ffe1a453cfd-7ffe1a453d03 111->120 126 7ffe1a453d34-7ffe1a453d3a 112->126 127 7ffe1a453d20-7ffe1a453d23 112->127 113->92 114->108 116->92 124 7ffe1a453e0d-7ffe1a453e13 117->124 125 7ffe1a453e37-7ffe1a453e3a 117->125 132 7ffe1a453f9e-7ffe1a453fbf GetLastError call 7ffe1a4520c2 118->132 133 7ffe1a453c01-7ffe1a453c1d call 7ffe1a4520c2 118->133 134 7ffe1a453db4 119->134 120->134 135 7ffe1a453d09-7ffe1a453d0f 120->135 144 7ffe1a453d96 121->144 140 7ffe1a453ed5 122->140 141 7ffe1a453f30-7ffe1a453f40 122->141 136 7ffe1a453eef-7ffe1a453eff 123->136 137 7ffe1a453ebb-7ffe1a453ec8 123->137 138 7ffe1a4541d1-7ffe1a4541d6 124->138 139 7ffe1a453e19-7ffe1a453e1f 124->139 128 7ffe1a453e3c-7ffe1a453e3f 125->128 129 7ffe1a453e58-7ffe1a453e5e 125->129 130 7ffe1a453da0 126->130 131 7ffe1a453d3c 126->131 127->121 142 7ffe1a453d25-7ffe1a453d28 127->142 145 7ffe1a453e45-7ffe1a453e48 128->145 146 7ffe1a4541bc-7ffe1a4541c1 128->146 147 7ffe1a453e64-7ffe1a453e69 129->147 148 7ffe1a4541ca-7ffe1a4541cf 129->148 130->119 153 7ffe1a453d46 131->153 172 7ffe1a453fd5-7ffe1a453fdb 132->172 173 7ffe1a453fc1 132->173 133->92 167 7ffe1a453c23-7ffe1a453c5b CreateThread 133->167 134->88 152 7ffe1a453d11 135->152 135->153 136->92 137->122 138->92 155 7ffe1a453e25-7ffe1a453e2b 139->155 156 7ffe1a4541d8-7ffe1a4541dd 139->156 150 7ffe1a453f04-7ffe1a453f07 140->150 151 7ffe1a453ed7-7ffe1a453edd 140->151 141->92 143 7ffe1a453d2a 142->143 142->144 143->126 144->130 159 7ffe1a4541c3-7ffe1a4541c8 145->159 160 7ffe1a453e4e-7ffe1a453e53 145->160 146->92 147->92 148->92 164 7ffe1a453f28-7ffe1a453f2e 150->164 165 7ffe1a453f09-7ffe1a453f0c 150->165 162 7ffe1a453f13-7ffe1a453f23 151->162 163 7ffe1a453edf-7ffe1a453ee5 151->163 152->112 153->102 157 7ffe1a453e6e-7ffe1a453e73 155->157 158 7ffe1a453e2d-7ffe1a453e32 155->158 156->92 157->92 158->92 159->92 160->92 162->92 168 7ffe1a453f45-7ffe1a453f55 163->168 169 7ffe1a453ee7-7ffe1a453eed 163->169 164->136 164->141 170 7ffe1a453f0e-7ffe1a453f11 165->170 171 7ffe1a453f5a-7ffe1a453f6a 165->171 178 7ffe1a453c61-7ffe1a453c7d call 7ffe1a4520c2 167->178 179 7ffe1a45409c-7ffe1a4540bd GetLastError call 7ffe1a4520c2 167->179 168->92 169->136 169->141 170->136 170->162 171->92 176 7ffe1a453fdd 172->176 177 7ffe1a454038-7ffe1a454048 172->177 174 7ffe1a453fc3-7ffe1a453fd0 173->174 175 7ffe1a453ff7-7ffe1a454007 173->175 174->172 175->92 180 7ffe1a453fdf-7ffe1a453fe5 176->180 181 7ffe1a45400c-7ffe1a45400f 176->181 177->92 178->92 194 7ffe1a453c83-7ffe1a453c98 call 7ffe1a4520c2 178->194 195 7ffe1a4540d3-7ffe1a4540d9 179->195 196 7ffe1a4540bf 179->196 184 7ffe1a45401b-7ffe1a45402b 180->184 185 7ffe1a453fe7-7ffe1a453fed 180->185 186 7ffe1a454030-7ffe1a454036 181->186 187 7ffe1a454011-7ffe1a454014 181->187 184->92 190 7ffe1a453fef-7ffe1a453ff5 185->190 191 7ffe1a45404d-7ffe1a45405d 185->191 186->175 186->177 192 7ffe1a454062-7ffe1a454072 187->192 193 7ffe1a454016-7ffe1a454019 187->193 190->175 190->177 191->92 192->92 193->175 193->184 202 7ffe1a453c9d 194->202 200 7ffe1a4540db 195->200 201 7ffe1a454109-7ffe1a454119 195->201 198 7ffe1a454133-7ffe1a454143 196->198 199 7ffe1a4540c1-7ffe1a4540ce 196->199 198->92 199->195 203 7ffe1a45411b-7ffe1a454121 200->203 204 7ffe1a4540dd-7ffe1a4540e0 200->204 201->92 202->106 207 7ffe1a454123-7ffe1a454129 203->207 208 7ffe1a4540ec-7ffe1a4540fc 203->208 205 7ffe1a4540e2-7ffe1a4540e5 204->205 206 7ffe1a454101-7ffe1a454107 204->206 211 7ffe1a454157-7ffe1a454167 205->211 212 7ffe1a4540e7-7ffe1a4540ea 205->212 206->198 206->201 209 7ffe1a454145-7ffe1a454155 207->209 210 7ffe1a45412b-7ffe1a454131 207->210 208->92 209->92 210->198 210->201 211->92 212->198 212->208
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLast$CriticalSection$CreateThread$CountInitializeSpin$CopyEnterFileLeavefflushfwrite
                                  • String ID: $ $ $ $ $Done$P$P$P$P$P$[E] (%s) -> CreateThread(routine_accept) failed(gle=%lu)$[E] (%s) -> CreateThread(routine_gc) failed(gle=%lu)$[E] (%s) -> CreateThread(routine_tx) failed(gle=%lu)$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> InitializeCriticalSectionAndSpinCount(cs_clients) failed(gle=%lu)$[E] (%s) -> InitializeCriticalSectionAndSpinCount(cs_queue) failed(gle=%lu)$[I] (%s) -> %s$[I] (%s) -> CreateThread(%s) done$routine_accept$routine_gc$routine_tx$server_init$~$~$~$~$~
                                  • API String ID: 3214881788-719614687
                                  • Opcode ID: 814ef7d209ae360dfc6d6398dd159066661408ab670544f83ce77df514a77a89
                                  • Instruction ID: b81288ea7108ba2ad67f1e4b08c715eae9fe131356ce730b85256743d9a044e8
                                  • Opcode Fuzzy Hash: 814ef7d209ae360dfc6d6398dd159066661408ab670544f83ce77df514a77a89
                                  • Instruction Fuzzy Hash: 96F108A0F0CF0381FB60A756A89437922A19B14F75F2403F3D53E0B2F6DE6DB9A58241

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 213 7ffe1a45487c-7ffe1a454896 call 7ffe1a4551a4 216 7ffe1a45489c-7ffe1a4548b1 call 7ffe1a455123 213->216 217 7ffe1a454db8 213->217 221 7ffe1a4548b3-7ffe1a4548e1 216->221 222 7ffe1a454907 216->222 220 7ffe1a454dcc-7ffe1a454dd1 217->220 223 7ffe1a454919-7ffe1a454930 call 7ffe1a4520c2 220->223 229 7ffe1a4548e3-7ffe1a4548e8 221->229 230 7ffe1a4548ea-7ffe1a454905 call 7ffe1a4520c2 221->230 224 7ffe1a45490c-7ffe1a454917 FreeLibrary 222->224 228 7ffe1a454935-7ffe1a454942 223->228 224->223 227 7ffe1a454943-7ffe1a45497c GetNativeSystemInfo GetWindowsDirectoryA 224->227 231 7ffe1a454982-7ffe1a4549a3 GetLastError call 7ffe1a4520c2 227->231 232 7ffe1a454a60-7ffe1a454a83 call 7ffe1a4520c2 227->232 229->224 230->224 239 7ffe1a4549c3-7ffe1a4549c9 231->239 240 7ffe1a4549a5 231->240 232->223 241 7ffe1a454a89-7ffe1a454abf call 7ffe1a459b22 232->241 239->220 244 7ffe1a4549cf-7ffe1a4549d5 239->244 242 7ffe1a4549a7-7ffe1a4549b4 240->242 243 7ffe1a4549b9-7ffe1a4549be 240->243 251 7ffe1a454ac5-7ffe1a454ac7 241->251 252 7ffe1a454b70-7ffe1a454b8c call 7ffe1a4520c2 241->252 242->243 243->223 246 7ffe1a454a0e-7ffe1a454a14 244->246 247 7ffe1a4549d7-7ffe1a4549da 244->247 253 7ffe1a454df4-7ffe1a454df9 246->253 254 7ffe1a454a1a-7ffe1a454a20 246->254 249 7ffe1a4549dc-7ffe1a4549df 247->249 250 7ffe1a4549f8-7ffe1a4549fe 247->250 256 7ffe1a4549e5-7ffe1a4549e8 249->256 257 7ffe1a454dd6-7ffe1a454ddb 249->257 259 7ffe1a454a04-7ffe1a454a09 250->259 260 7ffe1a454dea-7ffe1a454def 250->260 251->223 258 7ffe1a454acd-7ffe1a454b2a GetVolumeInformationA 251->258 265 7ffe1a454b91 252->265 253->223 261 7ffe1a454dfe-7ffe1a454e03 254->261 262 7ffe1a454a26-7ffe1a454a2c 254->262 266 7ffe1a4549ee-7ffe1a4549f3 256->266 267 7ffe1a454de0-7ffe1a454de5 256->267 257->223 268 7ffe1a454b30-7ffe1a454b56 GetLastError call 7ffe1a4520c2 258->268 269 7ffe1a454c27-7ffe1a454c59 call 7ffe1a4520c2 258->269 259->223 260->223 261->223 263 7ffe1a454a2e-7ffe1a454a33 262->263 264 7ffe1a454a38-7ffe1a454a3d 262->264 263->223 264->223 265->251 266->223 267->223 276 7ffe1a454b96-7ffe1a454b9c 268->276 277 7ffe1a454b58 268->277 274 7ffe1a454c5b-7ffe1a454c67 strlen 269->274 275 7ffe1a454c6d-7ffe1a454c74 269->275 274->275 278 7ffe1a454d39-7ffe1a454d3d 274->278 279 7ffe1a454c78-7ffe1a454cd5 call 7ffe1a4520c2 275->279 280 7ffe1a454ba2 276->280 281 7ffe1a454cf3-7ffe1a454cf8 276->281 282 7ffe1a454b5e-7ffe1a454b6b 277->282 283 7ffe1a454cdf-7ffe1a454ce4 277->283 278->275 284 7ffe1a454d43-7ffe1a454d47 278->284 289 7ffe1a454cda 279->289 286 7ffe1a454ba4-7ffe1a454ba7 280->286 287 7ffe1a454bdb-7ffe1a454be1 280->287 281->223 282->252 283->223 284->275 288 7ffe1a454d4d-7ffe1a454d80 _errno strtol _errno 284->288 290 7ffe1a454bc5-7ffe1a454bcb 286->290 291 7ffe1a454ba9-7ffe1a454bac 286->291 292 7ffe1a454d1b-7ffe1a454d20 287->292 293 7ffe1a454be7-7ffe1a454bed 287->293 294 7ffe1a454d82-7ffe1a454d85 288->294 295 7ffe1a454d90-7ffe1a454db3 _errno call 7ffe1a4520c2 288->295 289->228 298 7ffe1a454d11-7ffe1a454d16 290->298 299 7ffe1a454bd1-7ffe1a454bd6 290->299 296 7ffe1a454bb2-7ffe1a454bb5 291->296 297 7ffe1a454cfd-7ffe1a454d02 291->297 292->223 300 7ffe1a454bf3-7ffe1a454bf9 293->300 301 7ffe1a454d25-7ffe1a454d2a 293->301 294->279 302 7ffe1a454d8b 294->302 295->275 304 7ffe1a454bbb-7ffe1a454bc0 296->304 305 7ffe1a454d07-7ffe1a454d0c 296->305 297->223 298->223 299->223 306 7ffe1a454d2f-7ffe1a454d34 300->306 307 7ffe1a454bff-7ffe1a454c04 300->307 301->223 302->275 304->223 305->223 306->223 307->223
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: Library$AddressDirectoryErrorFreeInfoLastLoadNativeProcSystemWindows
                                  • String ID: $%$9e146be9-c76a-4720-bcdb-53011b87bd06$:$C:\Windows$MachineGuid$P$RtlGetVersion$SOFTWARE\Microsoft\Cryptography$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> GetVolumeInformationA failed(vol=%s,gle=%lu)$[E] (%s) -> GetWindowsDirectoryA failed(gle=%lu)$[E] (%s) -> RtlGetVersion failed(res=%08lx)$[E] (%s) -> strtol failed(sys_mach_guid=%s,errno=%d)$[I] (%s) -> Done(sys_uid=%016llx,sys_os_ver=%lu.%lu.%lu.%d.%d)$[I] (%s) -> GetVolumeInformationA done(vol=%s,vol_sn=%08lx)$[I] (%s) -> GetWindowsDirectoryA done(sys_mach_guid=%s)$[I] (%s) -> GetWindowsDirectoryA done(sys_win_dir=%s)$\$ntdll.dll$sys_init$~
                                  • API String ID: 3828489143-883582248
                                  • Opcode ID: ce9ae63d77125e1254aada9a548ba752f22cfe5e2c4af01e954c6cc378a2dbe5
                                  • Instruction ID: 1e4fbaa9124b88631b93099a7507f55ab0637853d78d53dd5c06e25b083bd878
                                  • Opcode Fuzzy Hash: ce9ae63d77125e1254aada9a548ba752f22cfe5e2c4af01e954c6cc378a2dbe5
                                  • Instruction Fuzzy Hash: B3D17DA1F0CE5382FB61AB17E4403B863A1AB51F74F1541F3CA5D5B6B2DE2CA9A4C341

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 603 7ffe126d34dc-7ffe126d34f6 call 7ffe126d3e04 606 7ffe126d34fc-7ffe126d3511 call 7ffe126d3d83 603->606 607 7ffe126d3a18 603->607 612 7ffe126d3567 606->612 613 7ffe126d3513-7ffe126d3541 606->613 609 7ffe126d3a2c-7ffe126d3a31 607->609 611 7ffe126d3579-7ffe126d3590 call 7ffe126d1352 609->611 617 7ffe126d3595-7ffe126d35a2 611->617 614 7ffe126d356c-7ffe126d3577 FreeLibrary 612->614 621 7ffe126d354a-7ffe126d3565 call 7ffe126d1352 613->621 622 7ffe126d3543-7ffe126d3548 613->622 614->611 616 7ffe126d35a3-7ffe126d35dc GetNativeSystemInfo GetWindowsDirectoryA 614->616 619 7ffe126d35e2-7ffe126d3603 GetLastError call 7ffe126d1352 616->619 620 7ffe126d36c0-7ffe126d36e3 call 7ffe126d1352 616->620 629 7ffe126d3623-7ffe126d3629 619->629 630 7ffe126d3605 619->630 620->611 631 7ffe126d36e9-7ffe126d371f call 7ffe126dbab2 620->631 621->614 622->614 629->609 634 7ffe126d362f-7ffe126d3635 629->634 632 7ffe126d3607-7ffe126d3614 630->632 633 7ffe126d3619-7ffe126d361e 630->633 643 7ffe126d3725-7ffe126d3727 631->643 644 7ffe126d37d0-7ffe126d37ec call 7ffe126d1352 631->644 632->633 633->611 636 7ffe126d3637-7ffe126d363a 634->636 637 7ffe126d366e-7ffe126d3674 634->637 641 7ffe126d363c-7ffe126d363f 636->641 642 7ffe126d3658-7ffe126d365e 636->642 639 7ffe126d367a-7ffe126d3680 637->639 640 7ffe126d3a54-7ffe126d3a59 637->640 650 7ffe126d3686-7ffe126d368c 639->650 651 7ffe126d3a5e-7ffe126d3a63 639->651 640->611 645 7ffe126d3a36-7ffe126d3a3b 641->645 646 7ffe126d3645-7ffe126d3648 641->646 648 7ffe126d3a4a-7ffe126d3a4f 642->648 649 7ffe126d3664-7ffe126d3669 642->649 643->611 647 7ffe126d372d-7ffe126d378a GetVolumeInformationA 643->647 659 7ffe126d37f1 644->659 645->611 653 7ffe126d364e-7ffe126d3653 646->653 654 7ffe126d3a40-7ffe126d3a45 646->654 655 7ffe126d3887-7ffe126d38b9 call 7ffe126d1352 647->655 656 7ffe126d3790-7ffe126d37b6 GetLastError call 7ffe126d1352 647->656 648->611 649->611 657 7ffe126d3698-7ffe126d369d 650->657 658 7ffe126d368e-7ffe126d3693 650->658 651->611 653->611 654->611 666 7ffe126d38bb-7ffe126d38c7 strlen 655->666 667 7ffe126d38cd-7ffe126d38d4 655->667 664 7ffe126d37f6-7ffe126d37fc 656->664 665 7ffe126d37b8 656->665 657->611 658->611 659->643 671 7ffe126d3802 664->671 672 7ffe126d3953-7ffe126d3958 664->672 668 7ffe126d37be-7ffe126d37cb 665->668 669 7ffe126d393f-7ffe126d3944 665->669 666->667 670 7ffe126d3999-7ffe126d399d 666->670 673 7ffe126d38d8-7ffe126d3935 call 7ffe126d1352 667->673 668->644 669->611 670->667 674 7ffe126d39a3-7ffe126d39a7 670->674 675 7ffe126d383b-7ffe126d3841 671->675 676 7ffe126d3804-7ffe126d3807 671->676 672->611 683 7ffe126d393a 673->683 674->667 680 7ffe126d39ad-7ffe126d39e0 _errno call 7ffe126e0c28 _errno 674->680 678 7ffe126d397b-7ffe126d3980 675->678 679 7ffe126d3847-7ffe126d384d 675->679 681 7ffe126d3809-7ffe126d380c 676->681 682 7ffe126d3825-7ffe126d382b 676->682 678->611 686 7ffe126d3853-7ffe126d3859 679->686 687 7ffe126d3985-7ffe126d398a 679->687 696 7ffe126d39e2-7ffe126d39e5 680->696 697 7ffe126d39f0-7ffe126d3a13 _errno call 7ffe126d1352 680->697 689 7ffe126d395d-7ffe126d3962 681->689 690 7ffe126d3812-7ffe126d3815 681->690 684 7ffe126d3971-7ffe126d3976 682->684 685 7ffe126d3831-7ffe126d3836 682->685 683->617 684->611 685->611 691 7ffe126d398f-7ffe126d3994 686->691 692 7ffe126d385f-7ffe126d3864 686->692 687->611 689->611 694 7ffe126d381b-7ffe126d3820 690->694 695 7ffe126d3967-7ffe126d396c 690->695 691->611 692->611 694->611 695->611 696->673 698 7ffe126d39eb 696->698 697->667 698->667
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Library$AddressDirectoryErrorFreeInfoLastLoadNativeProcSystemWindows
                                  • String ID: $%$9e146be9-c76a-4720-bcdb-53011b87bd06$:$C:\Windows$MachineGuid$P$RtlGetVersion$SOFTWARE\Microsoft\Cryptography$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> GetVolumeInformationA failed(vol=%s,gle=%lu)$[E] (%s) -> GetWindowsDirectoryA failed(gle=%lu)$[E] (%s) -> RtlGetVersion failed(res=%08lx)$[E] (%s) -> strtol failed(sys_mach_guid=%s,errno=%d)$[I] (%s) -> Done(sys_uid=%016llx,sys_os_ver=%lu.%lu.%lu.%d.%d)$[I] (%s) -> GetVolumeInformationA done(vol=%s,vol_sn=%08lx)$[I] (%s) -> GetWindowsDirectoryA done(sys_mach_guid=%s)$[I] (%s) -> GetWindowsDirectoryA done(sys_win_dir=%s)$\$ntdll.dll$sys_init$~
                                  • API String ID: 3828489143-883582248
                                  • Opcode ID: 3b3c1b133227a8bad1d2144b89a4456320b7ea5323494489f9a52021d4d8da23
                                  • Instruction ID: f81a0ad648d5b28d3092c61eec59499c95856ce045bb2a4e1bc6f35bc74c78fe
                                  • Opcode Fuzzy Hash: 3b3c1b133227a8bad1d2144b89a4456320b7ea5323494489f9a52021d4d8da23
                                  • Instruction Fuzzy Hash: 2DD16C61E0CE5F86FB209B57EC803B92250AF45774F1541B2D98E076F4EEECE8948B91

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 407 7ffe1150c25c-7ffe1150c276 call 7ffe1150bc64 410 7ffe1150c798 407->410 411 7ffe1150c27c-7ffe1150c291 call 7ffe1150bbe3 407->411 413 7ffe1150c7ac-7ffe1150c7b1 410->413 416 7ffe1150c293-7ffe1150c2c1 411->416 417 7ffe1150c2e7 411->417 415 7ffe1150c2f9-7ffe1150c310 call 7ffe1150c852 413->415 421 7ffe1150c315-7ffe1150c322 415->421 425 7ffe1150c2c3-7ffe1150c2c8 416->425 426 7ffe1150c2ca-7ffe1150c2e5 call 7ffe1150c852 416->426 418 7ffe1150c2ec-7ffe1150c2f7 FreeLibrary 417->418 418->415 420 7ffe1150c323-7ffe1150c35c GetNativeSystemInfo GetWindowsDirectoryA 418->420 423 7ffe1150c440-7ffe1150c463 call 7ffe1150c852 420->423 424 7ffe1150c362-7ffe1150c383 GetLastError call 7ffe1150c852 420->424 423->415 435 7ffe1150c469-7ffe1150c49f call 7ffe11505192 423->435 433 7ffe1150c3a3-7ffe1150c3a9 424->433 434 7ffe1150c385 424->434 425->418 426->418 433->413 438 7ffe1150c3af-7ffe1150c3b5 433->438 436 7ffe1150c387-7ffe1150c394 434->436 437 7ffe1150c399-7ffe1150c39e 434->437 445 7ffe1150c550-7ffe1150c56c call 7ffe1150c852 435->445 446 7ffe1150c4a5-7ffe1150c4a7 435->446 436->437 437->415 440 7ffe1150c3ee-7ffe1150c3f4 438->440 441 7ffe1150c3b7-7ffe1150c3ba 438->441 447 7ffe1150c7d4-7ffe1150c7d9 440->447 448 7ffe1150c3fa-7ffe1150c400 440->448 443 7ffe1150c3d8-7ffe1150c3de 441->443 444 7ffe1150c3bc-7ffe1150c3bf 441->444 452 7ffe1150c3e4-7ffe1150c3e9 443->452 453 7ffe1150c7ca-7ffe1150c7cf 443->453 449 7ffe1150c3c5-7ffe1150c3c8 444->449 450 7ffe1150c7b6-7ffe1150c7bb 444->450 463 7ffe1150c571 445->463 446->415 451 7ffe1150c4ad-7ffe1150c50a GetVolumeInformationA 446->451 447->415 454 7ffe1150c7de-7ffe1150c7e3 448->454 455 7ffe1150c406-7ffe1150c40c 448->455 457 7ffe1150c3ce-7ffe1150c3d3 449->457 458 7ffe1150c7c0-7ffe1150c7c5 449->458 450->415 459 7ffe1150c510-7ffe1150c536 GetLastError call 7ffe1150c852 451->459 460 7ffe1150c607-7ffe1150c639 call 7ffe1150c852 451->460 452->415 453->415 454->415 461 7ffe1150c40e-7ffe1150c413 455->461 462 7ffe1150c418-7ffe1150c41d 455->462 457->415 458->415 468 7ffe1150c576-7ffe1150c57c 459->468 469 7ffe1150c538 459->469 470 7ffe1150c63b-7ffe1150c647 strlen 460->470 471 7ffe1150c64d-7ffe1150c654 460->471 461->415 462->415 463->446 475 7ffe1150c582 468->475 476 7ffe1150c6d3-7ffe1150c6d8 468->476 472 7ffe1150c53e-7ffe1150c54b 469->472 473 7ffe1150c6bf-7ffe1150c6c4 469->473 470->471 474 7ffe1150c719-7ffe1150c71d 470->474 477 7ffe1150c658-7ffe1150c6b5 call 7ffe1150c852 471->477 472->445 473->415 474->471 478 7ffe1150c723-7ffe1150c727 474->478 479 7ffe1150c584-7ffe1150c587 475->479 480 7ffe1150c5bb-7ffe1150c5c1 475->480 476->415 487 7ffe1150c6ba 477->487 478->471 484 7ffe1150c72d-7ffe1150c760 _errno call 7ffe11514660 _errno 478->484 485 7ffe1150c5a5-7ffe1150c5ab 479->485 486 7ffe1150c589-7ffe1150c58c 479->486 482 7ffe1150c5c7-7ffe1150c5cd 480->482 483 7ffe1150c6fb-7ffe1150c700 480->483 490 7ffe1150c5d3-7ffe1150c5d9 482->490 491 7ffe1150c705-7ffe1150c70a 482->491 483->415 500 7ffe1150c770-7ffe1150c793 _errno call 7ffe1150c852 484->500 501 7ffe1150c762-7ffe1150c765 484->501 488 7ffe1150c6f1-7ffe1150c6f6 485->488 489 7ffe1150c5b1-7ffe1150c5b6 485->489 493 7ffe1150c592-7ffe1150c595 486->493 494 7ffe1150c6dd-7ffe1150c6e2 486->494 487->421 488->415 489->415 497 7ffe1150c70f-7ffe1150c714 490->497 498 7ffe1150c5df-7ffe1150c5e4 490->498 491->415 495 7ffe1150c6e7-7ffe1150c6ec 493->495 496 7ffe1150c59b-7ffe1150c5a0 493->496 494->415 495->415 496->415 497->415 498->415 500->471 501->477 502 7ffe1150c76b 501->502 502->471
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Library$AddressDirectoryErrorFreeInfoLastLoadNativeProcSystemWindows
                                  • String ID: $%$9e146be9-c76a-4720-bcdb-53011b87bd06$:$C:\Windows$MachineGuid$P$RtlGetVersion$SOFTWARE\Microsoft\Cryptography$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> GetVolumeInformationA failed(vol=%s,gle=%lu)$[E] (%s) -> GetWindowsDirectoryA failed(gle=%lu)$[E] (%s) -> RtlGetVersion failed(res=%08lx)$[E] (%s) -> strtol failed(sys_mach_guid=%s,errno=%d)$[I] (%s) -> Done(sys_uid=%016llx,sys_os_ver=%lu.%lu.%lu.%d.%d)$[I] (%s) -> GetVolumeInformationA done(vol=%s,vol_sn=%08lx)$[I] (%s) -> GetWindowsDirectoryA done(sys_mach_guid=%s)$[I] (%s) -> GetWindowsDirectoryA done(sys_win_dir=%s)$\$ntdll.dll$sys_init$~
                                  • API String ID: 3828489143-883582248
                                  • Opcode ID: bfd07b4d3620cfcd3bc3c6517118baa50ff2612316696af1ebdc37463817eb14
                                  • Instruction ID: 053d6743455b8ed8cd1ab44cf0c6d6a8938048f5e9aa3d1e7bbfa83a50c5ca6c
                                  • Opcode Fuzzy Hash: bfd07b4d3620cfcd3bc3c6517118baa50ff2612316696af1ebdc37463817eb14
                                  • Instruction Fuzzy Hash: 70D17B22E0CF57C1FB219BDBE8403BD2269AF06774F1501FAC94E176B0DE2DA9858742

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 701 7ffe13226e0c-7ffe13226e26 call 7ffe13227734 704 7ffe13227348 701->704 705 7ffe13226e2c-7ffe13226e41 call 7ffe132276b3 701->705 708 7ffe1322735c-7ffe13227361 704->708 709 7ffe13226e43-7ffe13226e71 705->709 710 7ffe13226e97 705->710 711 7ffe13226ea9-7ffe13226ec0 call 7ffe132277a2 708->711 717 7ffe13226e73-7ffe13226e78 709->717 718 7ffe13226e7a-7ffe13226e95 call 7ffe132277a2 709->718 712 7ffe13226e9c-7ffe13226ea7 FreeLibrary 710->712 716 7ffe13226ec5-7ffe13226ed2 711->716 712->711 715 7ffe13226ed3-7ffe13226f0c GetNativeSystemInfo GetWindowsDirectoryA 712->715 719 7ffe13226ff0-7ffe13227013 call 7ffe132277a2 715->719 720 7ffe13226f12-7ffe13226f33 GetLastError call 7ffe132277a2 715->720 717->712 718->712 719->711 729 7ffe13227019-7ffe1322704f call 7ffe1322d422 719->729 727 7ffe13226f53-7ffe13226f59 720->727 728 7ffe13226f35 720->728 727->708 732 7ffe13226f5f-7ffe13226f65 727->732 730 7ffe13226f37-7ffe13226f44 728->730 731 7ffe13226f49-7ffe13226f4e 728->731 739 7ffe13227100-7ffe1322711c call 7ffe132277a2 729->739 740 7ffe13227055-7ffe13227057 729->740 730->731 731->711 734 7ffe13226f9e-7ffe13226fa4 732->734 735 7ffe13226f67-7ffe13226f6a 732->735 741 7ffe13227384-7ffe13227389 734->741 742 7ffe13226faa-7ffe13226fb0 734->742 737 7ffe13226f88-7ffe13226f8e 735->737 738 7ffe13226f6c-7ffe13226f6f 735->738 747 7ffe13226f94-7ffe13226f99 737->747 748 7ffe1322737a-7ffe1322737f 737->748 744 7ffe13226f75-7ffe13226f78 738->744 745 7ffe13227366-7ffe1322736b 738->745 753 7ffe13227121 739->753 740->711 746 7ffe1322705d-7ffe132270ba GetVolumeInformationA 740->746 741->711 749 7ffe1322738e-7ffe13227393 742->749 750 7ffe13226fb6-7ffe13226fbc 742->750 754 7ffe13226f7e-7ffe13226f83 744->754 755 7ffe13227370-7ffe13227375 744->755 745->711 756 7ffe132270c0-7ffe132270e6 GetLastError call 7ffe132277a2 746->756 757 7ffe132271b7-7ffe132271e9 call 7ffe132277a2 746->757 747->711 748->711 749->711 751 7ffe13226fbe-7ffe13226fc3 750->751 752 7ffe13226fc8-7ffe13226fcd 750->752 751->711 752->711 753->740 754->711 755->711 764 7ffe13227126-7ffe1322712c 756->764 765 7ffe132270e8 756->765 762 7ffe132271eb-7ffe132271f7 strlen 757->762 763 7ffe132271fd-7ffe13227204 757->763 762->763 766 7ffe132272c9-7ffe132272cd 762->766 767 7ffe13227208-7ffe13227265 call 7ffe132277a2 763->767 768 7ffe13227283-7ffe13227288 764->768 769 7ffe13227132 764->769 770 7ffe1322726f-7ffe13227274 765->770 771 7ffe132270ee-7ffe132270fb 765->771 766->763 772 7ffe132272d3-7ffe132272d7 766->772 777 7ffe1322726a 767->777 768->711 774 7ffe13227134-7ffe13227137 769->774 775 7ffe1322716b-7ffe13227171 769->775 770->711 771->739 772->763 776 7ffe132272dd-7ffe13227310 _errno call 7ffe13232600 _errno 772->776 778 7ffe13227155-7ffe1322715b 774->778 779 7ffe13227139-7ffe1322713c 774->779 780 7ffe13227177-7ffe1322717d 775->780 781 7ffe132272ab-7ffe132272b0 775->781 794 7ffe13227320-7ffe13227343 _errno call 7ffe132277a2 776->794 795 7ffe13227312-7ffe13227315 776->795 777->716 785 7ffe132272a1-7ffe132272a6 778->785 786 7ffe13227161-7ffe13227166 778->786 783 7ffe13227142-7ffe13227145 779->783 784 7ffe1322728d-7ffe13227292 779->784 787 7ffe13227183-7ffe13227189 780->787 788 7ffe132272b5-7ffe132272ba 780->788 781->711 790 7ffe13227297-7ffe1322729c 783->790 791 7ffe1322714b-7ffe13227150 783->791 784->711 785->711 786->711 792 7ffe132272bf-7ffe132272c4 787->792 793 7ffe1322718f-7ffe13227194 787->793 788->711 790->711 791->711 792->711 793->711 794->763 795->767 796 7ffe1322731b 795->796 796->763
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: Library$AddressDirectoryErrorFreeInfoLastLoadNativeProcSystemWindows
                                  • String ID: $%$9e146be9-c76a-4720-bcdb-53011b87bd06$:$C:\Windows$MachineGuid$P$RtlGetVersion$SOFTWARE\Microsoft\Cryptography$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> GetVolumeInformationA failed(vol=%s,gle=%lu)$[E] (%s) -> GetWindowsDirectoryA failed(gle=%lu)$[E] (%s) -> RtlGetVersion failed(res=%08lx)$[E] (%s) -> strtol failed(sys_mach_guid=%s,errno=%d)$[I] (%s) -> Done(sys_uid=%016llx,sys_os_ver=%lu.%lu.%lu.%d.%d)$[I] (%s) -> GetVolumeInformationA done(vol=%s,vol_sn=%08lx)$[I] (%s) -> GetWindowsDirectoryA done(sys_mach_guid=%s)$[I] (%s) -> GetWindowsDirectoryA done(sys_win_dir=%s)$\$ntdll.dll$sys_init$~
                                  • API String ID: 3828489143-883582248
                                  • Opcode ID: 728b767adc8d527ebe255513fc84395f47a792a5c3bda38828877f2e585362b2
                                  • Instruction ID: f94442d07ae30904aebb2d3bd4fb97b918e0a803026ce75e301a410199a5a65e
                                  • Opcode Fuzzy Hash: 728b767adc8d527ebe255513fc84395f47a792a5c3bda38828877f2e585362b2
                                  • Instruction Fuzzy Hash: 46D12B22E1CE5289FB70A71BF8407B96260AFF4B74F1541B6D94E272B1DE6DAC44C381

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 309 7ffe1024210c-7ffe10242126 call 7ffe10242a34 312 7ffe10242648 309->312 313 7ffe1024212c-7ffe10242141 call 7ffe102429b3 309->313 316 7ffe1024265c-7ffe10242661 312->316 318 7ffe10242143-7ffe10242171 313->318 319 7ffe10242197 313->319 317 7ffe102421a9-7ffe102421c0 call 7ffe102440d2 316->317 322 7ffe102421c5-7ffe102421d2 317->322 327 7ffe10242173-7ffe10242178 318->327 328 7ffe1024217a-7ffe10242195 call 7ffe102440d2 318->328 320 7ffe1024219c-7ffe102421a7 FreeLibrary 319->320 320->317 324 7ffe102421d3-7ffe1024220c GetNativeSystemInfo GetWindowsDirectoryA 320->324 325 7ffe102422f0-7ffe10242313 call 7ffe102440d2 324->325 326 7ffe10242212-7ffe10242233 GetLastError call 7ffe102440d2 324->326 325->317 337 7ffe10242319-7ffe1024234f call 7ffe10243402 325->337 335 7ffe10242235 326->335 336 7ffe10242253-7ffe10242259 326->336 327->320 328->320 338 7ffe10242249-7ffe1024224e 335->338 339 7ffe10242237-7ffe10242244 335->339 336->316 340 7ffe1024225f-7ffe10242265 336->340 349 7ffe10242400-7ffe1024241c call 7ffe102440d2 337->349 350 7ffe10242355-7ffe10242357 337->350 338->317 339->338 342 7ffe1024229e-7ffe102422a4 340->342 343 7ffe10242267-7ffe1024226a 340->343 345 7ffe10242684-7ffe10242689 342->345 346 7ffe102422aa-7ffe102422b0 342->346 347 7ffe10242288-7ffe1024228e 343->347 348 7ffe1024226c-7ffe1024226f 343->348 345->317 353 7ffe1024268e-7ffe10242693 346->353 354 7ffe102422b6-7ffe102422bc 346->354 351 7ffe10242294-7ffe10242299 347->351 352 7ffe1024267a-7ffe1024267f 347->352 356 7ffe10242275-7ffe10242278 348->356 357 7ffe10242666-7ffe1024266b 348->357 361 7ffe10242421 349->361 350->317 358 7ffe1024235d-7ffe102423ba GetVolumeInformationA 350->358 351->317 352->317 353->317 359 7ffe102422be-7ffe102422c3 354->359 360 7ffe102422c8-7ffe102422cd 354->360 362 7ffe10242670-7ffe10242675 356->362 363 7ffe1024227e-7ffe10242283 356->363 357->317 364 7ffe102423c0-7ffe102423e6 GetLastError call 7ffe102440d2 358->364 365 7ffe102424b7-7ffe102424e9 call 7ffe102440d2 358->365 359->317 360->317 361->350 362->317 363->317 370 7ffe102423e8 364->370 371 7ffe10242426-7ffe1024242c 364->371 372 7ffe102424fd-7ffe10242504 365->372 373 7ffe102424eb-7ffe102424f7 strlen 365->373 374 7ffe1024256f-7ffe10242574 370->374 375 7ffe102423ee-7ffe102423fb 370->375 377 7ffe10242583-7ffe10242588 371->377 378 7ffe10242432 371->378 379 7ffe10242508-7ffe10242565 call 7ffe102440d2 372->379 373->372 376 7ffe102425c9-7ffe102425cd 373->376 374->317 375->349 376->372 380 7ffe102425d3-7ffe102425d7 376->380 377->317 381 7ffe10242434-7ffe10242437 378->381 382 7ffe1024246b-7ffe10242471 378->382 389 7ffe1024256a 379->389 380->372 386 7ffe102425dd-7ffe10242610 _errno call 7ffe10252a08 _errno 380->386 387 7ffe10242455-7ffe1024245b 381->387 388 7ffe10242439-7ffe1024243c 381->388 384 7ffe10242477-7ffe1024247d 382->384 385 7ffe102425ab-7ffe102425b0 382->385 390 7ffe102425b5-7ffe102425ba 384->390 391 7ffe10242483-7ffe10242489 384->391 385->317 402 7ffe10242620-7ffe10242643 _errno call 7ffe102440d2 386->402 403 7ffe10242612-7ffe10242615 386->403 395 7ffe102425a1-7ffe102425a6 387->395 396 7ffe10242461-7ffe10242466 387->396 393 7ffe10242442-7ffe10242445 388->393 394 7ffe1024258d-7ffe10242592 388->394 389->322 390->317 397 7ffe102425bf-7ffe102425c4 391->397 398 7ffe1024248f-7ffe10242494 391->398 400 7ffe10242597-7ffe1024259c 393->400 401 7ffe1024244b-7ffe10242450 393->401 394->317 395->317 396->317 397->317 398->317 400->317 401->317 402->372 403->379 404 7ffe1024261b 403->404 404->372
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: Library$AddressDirectoryErrorFreeInfoLastLoadNativeProcSystemWindows
                                  • String ID: $%$9e146be9-c76a-4720-bcdb-53011b87bd06$:$C:\Windows$MachineGuid$P$RtlGetVersion$SOFTWARE\Microsoft\Cryptography$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> GetVolumeInformationA failed(vol=%s,gle=%lu)$[E] (%s) -> GetWindowsDirectoryA failed(gle=%lu)$[E] (%s) -> RtlGetVersion failed(res=%08lx)$[E] (%s) -> strtol failed(sys_mach_guid=%s,errno=%d)$[I] (%s) -> Done(sys_uid=%016llx,sys_os_ver=%lu.%lu.%lu.%d.%d)$[I] (%s) -> GetVolumeInformationA done(vol=%s,vol_sn=%08lx)$[I] (%s) -> GetWindowsDirectoryA done(sys_mach_guid=%s)$[I] (%s) -> GetWindowsDirectoryA done(sys_win_dir=%s)$\$ntdll.dll$sys_init$~
                                  • API String ID: 3828489143-883582248
                                  • Opcode ID: 4b40777002c449f6e2d1738e7a259e47248f5ef9ef21cdea825fca1331d142d1
                                  • Instruction ID: 0a79ec13a55af11697f2ad73b71165a0e32ef19f7ca8a4c580d42a226cf35563
                                  • Opcode Fuzzy Hash: 4b40777002c449f6e2d1738e7a259e47248f5ef9ef21cdea825fca1331d142d1
                                  • Instruction Fuzzy Hash: 01D16D61E0CE52C1F7209757A8403B96E60ABC6774F9501B2DB4E973B3EE2DA889C345

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 505 7ffe11ec44cc-7ffe11ec44e6 call 7ffe11ec4df4 508 7ffe11ec4a08 505->508 509 7ffe11ec44ec-7ffe11ec4501 call 7ffe11ec4d73 505->509 511 7ffe11ec4a1c-7ffe11ec4a21 508->511 514 7ffe11ec4557 509->514 515 7ffe11ec4503-7ffe11ec4531 509->515 513 7ffe11ec4569-7ffe11ec4580 call 7ffe11ec9dc2 511->513 519 7ffe11ec4585-7ffe11ec4592 513->519 516 7ffe11ec455c-7ffe11ec4567 FreeLibrary 514->516 523 7ffe11ec453a-7ffe11ec4555 call 7ffe11ec9dc2 515->523 524 7ffe11ec4533-7ffe11ec4538 515->524 516->513 518 7ffe11ec4593-7ffe11ec45cc GetNativeSystemInfo GetWindowsDirectoryA 516->518 521 7ffe11ec46b0-7ffe11ec46d3 call 7ffe11ec9dc2 518->521 522 7ffe11ec45d2-7ffe11ec45f3 GetLastError call 7ffe11ec9dc2 518->522 521->513 533 7ffe11ec46d9-7ffe11ec470f call 7ffe11ec3382 521->533 531 7ffe11ec45f5 522->531 532 7ffe11ec4613-7ffe11ec4619 522->532 523->516 524->516 534 7ffe11ec4609-7ffe11ec460e 531->534 535 7ffe11ec45f7-7ffe11ec4604 531->535 532->511 536 7ffe11ec461f-7ffe11ec4625 532->536 545 7ffe11ec47c0-7ffe11ec47dc call 7ffe11ec9dc2 533->545 546 7ffe11ec4715-7ffe11ec4717 533->546 534->513 535->534 538 7ffe11ec4627-7ffe11ec462a 536->538 539 7ffe11ec465e-7ffe11ec4664 536->539 543 7ffe11ec4648-7ffe11ec464e 538->543 544 7ffe11ec462c-7ffe11ec462f 538->544 541 7ffe11ec466a-7ffe11ec4670 539->541 542 7ffe11ec4a44-7ffe11ec4a49 539->542 552 7ffe11ec4676-7ffe11ec467c 541->552 553 7ffe11ec4a4e-7ffe11ec4a53 541->553 542->513 550 7ffe11ec4a3a-7ffe11ec4a3f 543->550 551 7ffe11ec4654-7ffe11ec4659 543->551 547 7ffe11ec4a26-7ffe11ec4a2b 544->547 548 7ffe11ec4635-7ffe11ec4638 544->548 561 7ffe11ec47e1 545->561 546->513 549 7ffe11ec471d-7ffe11ec477a GetVolumeInformationA 546->549 547->513 555 7ffe11ec4a30-7ffe11ec4a35 548->555 556 7ffe11ec463e-7ffe11ec4643 548->556 557 7ffe11ec4877-7ffe11ec48a9 call 7ffe11ec9dc2 549->557 558 7ffe11ec4780-7ffe11ec47a6 GetLastError call 7ffe11ec9dc2 549->558 550->513 551->513 559 7ffe11ec4688-7ffe11ec468d 552->559 560 7ffe11ec467e-7ffe11ec4683 552->560 553->513 555->513 556->513 568 7ffe11ec48bd-7ffe11ec48c4 557->568 569 7ffe11ec48ab-7ffe11ec48b7 strlen 557->569 566 7ffe11ec47a8 558->566 567 7ffe11ec47e6-7ffe11ec47ec 558->567 559->513 560->513 561->546 570 7ffe11ec492f-7ffe11ec4934 566->570 571 7ffe11ec47ae-7ffe11ec47bb 566->571 573 7ffe11ec4943-7ffe11ec4948 567->573 574 7ffe11ec47f2 567->574 575 7ffe11ec48c8-7ffe11ec4925 call 7ffe11ec9dc2 568->575 569->568 572 7ffe11ec4989-7ffe11ec498d 569->572 570->513 571->545 572->568 576 7ffe11ec4993-7ffe11ec4997 572->576 573->513 577 7ffe11ec482b-7ffe11ec4831 574->577 578 7ffe11ec47f4-7ffe11ec47f7 574->578 585 7ffe11ec492a 575->585 576->568 582 7ffe11ec499d-7ffe11ec49d0 _errno call 7ffe11ed10e8 _errno 576->582 580 7ffe11ec4837-7ffe11ec483d 577->580 581 7ffe11ec496b-7ffe11ec4970 577->581 583 7ffe11ec47f9-7ffe11ec47fc 578->583 584 7ffe11ec4815-7ffe11ec481b 578->584 588 7ffe11ec4975-7ffe11ec497a 580->588 589 7ffe11ec4843-7ffe11ec4849 580->589 581->513 598 7ffe11ec49e0-7ffe11ec4a03 _errno call 7ffe11ec9dc2 582->598 599 7ffe11ec49d2-7ffe11ec49d5 582->599 591 7ffe11ec494d-7ffe11ec4952 583->591 592 7ffe11ec4802-7ffe11ec4805 583->592 586 7ffe11ec4961-7ffe11ec4966 584->586 587 7ffe11ec4821-7ffe11ec4826 584->587 585->519 586->513 587->513 588->513 593 7ffe11ec497f-7ffe11ec4984 589->593 594 7ffe11ec484f-7ffe11ec4854 589->594 591->513 596 7ffe11ec4957-7ffe11ec495c 592->596 597 7ffe11ec480b-7ffe11ec4810 592->597 593->513 594->513 596->513 597->513 598->568 599->575 600 7ffe11ec49db 599->600 600->568
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: Library$AddressDirectoryErrorFreeInfoLastLoadNativeProcSystemWindows
                                  • String ID: $%$9e146be9-c76a-4720-bcdb-53011b87bd06$:$C:\Windows$MachineGuid$P$RtlGetVersion$SOFTWARE\Microsoft\Cryptography$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> GetVolumeInformationA failed(vol=%s,gle=%lu)$[E] (%s) -> GetWindowsDirectoryA failed(gle=%lu)$[E] (%s) -> RtlGetVersion failed(res=%08lx)$[E] (%s) -> strtol failed(sys_mach_guid=%s,errno=%d)$[I] (%s) -> Done(sys_uid=%016llx,sys_os_ver=%lu.%lu.%lu.%d.%d)$[I] (%s) -> GetVolumeInformationA done(vol=%s,vol_sn=%08lx)$[I] (%s) -> GetWindowsDirectoryA done(sys_mach_guid=%s)$[I] (%s) -> GetWindowsDirectoryA done(sys_win_dir=%s)$\$ntdll.dll$sys_init$~
                                  • API String ID: 3828489143-883582248
                                  • Opcode ID: 77ba298abb47a5c0d12a8cf223872496bbf117b7f8215b755508996f17e581e0
                                  • Instruction ID: 4d775a5b07e3972da03216e2e6a202b826dfad9de436e4016110a319b840a0ac
                                  • Opcode Fuzzy Hash: 77ba298abb47a5c0d12a8cf223872496bbf117b7f8215b755508996f17e581e0
                                  • Instruction Fuzzy Hash: 40D17E61E0CE5381FB2097D7EC403BB62A8AB51774F9551B6D94E17BB4EE2CF8448341

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 936 7ff7bacd28fc-7ff7bacd2916 call 7ff7bacd2304 939 7ff7bacd291c-7ff7bacd2931 call 7ff7bacd2283 936->939 940 7ff7bacd2e38 936->940 944 7ff7bacd2933-7ff7bacd2961 939->944 945 7ff7bacd2987 939->945 943 7ff7bacd2e4c-7ff7bacd2e51 940->943 946 7ff7bacd2999-7ff7bacd29b0 call 7ff7bacd2ef2 943->946 952 7ff7bacd2963-7ff7bacd2968 944->952 953 7ff7bacd296a-7ff7bacd2985 call 7ff7bacd2ef2 944->953 947 7ff7bacd298c-7ff7bacd2997 FreeLibrary 945->947 951 7ff7bacd29b5-7ff7bacd29c2 946->951 947->946 950 7ff7bacd29c3-7ff7bacd29fc GetNativeSystemInfo GetWindowsDirectoryA 947->950 954 7ff7bacd2ae0-7ff7bacd2b03 call 7ff7bacd2ef2 950->954 955 7ff7bacd2a02-7ff7bacd2a23 GetLastError call 7ff7bacd2ef2 950->955 952->947 953->947 954->946 964 7ff7bacd2b09-7ff7bacd2b3f call 7ff7bacd9292 954->964 962 7ff7bacd2a43-7ff7bacd2a49 955->962 963 7ff7bacd2a25 955->963 962->943 967 7ff7bacd2a4f-7ff7bacd2a55 962->967 965 7ff7bacd2a27-7ff7bacd2a34 963->965 966 7ff7bacd2a39-7ff7bacd2a3e 963->966 974 7ff7bacd2b45-7ff7bacd2b47 964->974 975 7ff7bacd2bf0-7ff7bacd2c0c call 7ff7bacd2ef2 964->975 965->966 966->946 969 7ff7bacd2a8e-7ff7bacd2a94 967->969 970 7ff7bacd2a57-7ff7bacd2a5a 967->970 976 7ff7bacd2e74-7ff7bacd2e79 969->976 977 7ff7bacd2a9a-7ff7bacd2aa0 969->977 972 7ff7bacd2a5c-7ff7bacd2a5f 970->972 973 7ff7bacd2a78-7ff7bacd2a7e 970->973 981 7ff7bacd2a65-7ff7bacd2a68 972->981 982 7ff7bacd2e56-7ff7bacd2e5b 972->982 984 7ff7bacd2a84-7ff7bacd2a89 973->984 985 7ff7bacd2e6a-7ff7bacd2e6f 973->985 974->946 983 7ff7bacd2b4d-7ff7bacd2baa GetVolumeInformationA 974->983 988 7ff7bacd2c11 975->988 976->946 978 7ff7bacd2aa6-7ff7bacd2aac 977->978 979 7ff7bacd2e7e-7ff7bacd2e83 977->979 986 7ff7bacd2aae-7ff7bacd2ab3 978->986 987 7ff7bacd2ab8-7ff7bacd2abd 978->987 979->946 989 7ff7bacd2e60-7ff7bacd2e65 981->989 990 7ff7bacd2a6e-7ff7bacd2a73 981->990 982->946 991 7ff7bacd2bb0-7ff7bacd2bd6 GetLastError call 7ff7bacd2ef2 983->991 992 7ff7bacd2ca7-7ff7bacd2cd9 call 7ff7bacd2ef2 983->992 984->946 985->946 986->946 987->946 988->974 989->946 990->946 999 7ff7bacd2c16-7ff7bacd2c1c 991->999 1000 7ff7bacd2bd8 991->1000 997 7ff7bacd2cdb-7ff7bacd2ce7 strlen 992->997 998 7ff7bacd2ced-7ff7bacd2cf4 992->998 997->998 1001 7ff7bacd2db9-7ff7bacd2dbd 997->1001 1002 7ff7bacd2cf8-7ff7bacd2d55 call 7ff7bacd2ef2 998->1002 1003 7ff7bacd2d73-7ff7bacd2d78 999->1003 1004 7ff7bacd2c22 999->1004 1005 7ff7bacd2d5f-7ff7bacd2d64 1000->1005 1006 7ff7bacd2bde-7ff7bacd2beb 1000->1006 1001->998 1007 7ff7bacd2dc3-7ff7bacd2dc7 1001->1007 1012 7ff7bacd2d5a 1002->1012 1003->946 1009 7ff7bacd2c24-7ff7bacd2c27 1004->1009 1010 7ff7bacd2c5b-7ff7bacd2c61 1004->1010 1005->946 1006->975 1007->998 1011 7ff7bacd2dcd-7ff7bacd2e00 _errno call 7ff7bacde500 _errno 1007->1011 1013 7ff7bacd2c45-7ff7bacd2c4b 1009->1013 1014 7ff7bacd2c29-7ff7bacd2c2c 1009->1014 1015 7ff7bacd2d9b-7ff7bacd2da0 1010->1015 1016 7ff7bacd2c67-7ff7bacd2c6d 1010->1016 1029 7ff7bacd2e10-7ff7bacd2e33 _errno call 7ff7bacd2ef2 1011->1029 1030 7ff7bacd2e02-7ff7bacd2e05 1011->1030 1012->951 1020 7ff7bacd2d91-7ff7bacd2d96 1013->1020 1021 7ff7bacd2c51-7ff7bacd2c56 1013->1021 1018 7ff7bacd2c32-7ff7bacd2c35 1014->1018 1019 7ff7bacd2d7d-7ff7bacd2d82 1014->1019 1015->946 1022 7ff7bacd2c73-7ff7bacd2c79 1016->1022 1023 7ff7bacd2da5-7ff7bacd2daa 1016->1023 1025 7ff7bacd2c3b-7ff7bacd2c40 1018->1025 1026 7ff7bacd2d87-7ff7bacd2d8c 1018->1026 1019->946 1020->946 1021->946 1027 7ff7bacd2daf-7ff7bacd2db4 1022->1027 1028 7ff7bacd2c7f-7ff7bacd2c84 1022->1028 1023->946 1025->946 1026->946 1027->946 1028->946 1029->998 1030->1002 1031 7ff7bacd2e0b 1030->1031 1031->998
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: Library$AddressDirectoryErrorFreeInfoLastLoadNativeProcSystemWindows
                                  • String ID: %$9e146be9-c76a-4720-bcdb-53011b87bd06$:$C:\Windows$MachineGuid$RtlGetVersion$SOFTWARE\Microsoft\Cryptography$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> GetVolumeInformationA failed(vol=%s,gle=%lu)$[E] (%s) -> GetWindowsDirectoryA failed(gle=%lu)$[E] (%s) -> RtlGetVersion failed(res=%08lx)$[E] (%s) -> strtol failed(sys_mach_guid=%s,errno=%d)$[I] (%s) -> Done(sys_uid=%016llx,sys_os_ver=%lu.%lu.%lu.%d.%d)$[I] (%s) -> GetVolumeInformationA done(vol=%s,vol_sn=%08lx)$[I] (%s) -> GetWindowsDirectoryA done(sys_mach_guid=%s)$[I] (%s) -> GetWindowsDirectoryA done(sys_win_dir=%s)$\$ntdll.dll$service$sys_init
                                  • API String ID: 3828489143-3798070276
                                  • Opcode ID: 6adf132e8037f4d047643bc80ab3c7f8111de06e89ca55ee02caa9d802eb4487
                                  • Instruction ID: 9c5408268f6a3e2cf0177c3fd5c532f2c5d7636c246ae1160f7215ff8ff6aed9
                                  • Opcode Fuzzy Hash: 6adf132e8037f4d047643bc80ab3c7f8111de06e89ca55ee02caa9d802eb4487
                                  • Instruction Fuzzy Hash: 89D17B71E0C656A1FA60BB1CA4483B8E250EB72755FD510B2CF8E1769CDE2CFC45A3A1

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 1034 7ffe1322bca7-7ffe1322bcc7 1035 7ffe1322bd35-7ffe1322bd3d 1034->1035 1036 7ffe1322bcc9-7ffe1322bcd1 1034->1036 1037 7ffe1322bd50-7ffe1322bd66 call 7ffe1322689b 1035->1037 1038 7ffe1322bd3f-7ffe1322bd44 1035->1038 1039 7ffe1322bce0-7ffe1322bce8 1036->1039 1040 7ffe1322bcd3-7ffe1322bcda 1036->1040 1047 7ffe1322c3bc-7ffe1322c3cd 1037->1047 1041 7ffe1322bd46-7ffe1322bd4b 1038->1041 1042 7ffe1322bd6b-7ffe1322bd70 1038->1042 1045 7ffe1322bcee-7ffe1322bcf6 1039->1045 1046 7ffe1322c3b7 1039->1046 1040->1039 1044 7ffe1322c0e3-7ffe1322c0fd call 7ffe1322689b 1040->1044 1041->1047 1050 7ffe1322bd9f-7ffe1322beea call 7ffe132222f5 call 7ffe13227400 call 7ffe13225ec9 1042->1050 1051 7ffe1322bd72-7ffe1322bd78 1042->1051 1044->1039 1062 7ffe1322c103-7ffe1322c10b 1044->1062 1052 7ffe1322bcf8-7ffe1322bcff 1045->1052 1053 7ffe1322bd0b-7ffe1322bd16 1045->1053 1046->1047 1086 7ffe1322bef0-7ffe1322bf1e call 7ffe1322d422 1050->1086 1087 7ffe1322c069-7ffe1322c09e call 7ffe13223805 1050->1087 1051->1050 1055 7ffe1322bd7a-7ffe1322bd9a 1051->1055 1052->1053 1057 7ffe1322bd01-7ffe1322bd09 1052->1057 1058 7ffe1322c3ce-7ffe1322c3d3 1053->1058 1059 7ffe1322bd1c-7ffe1322bd25 1053->1059 1055->1047 1057->1053 1057->1059 1058->1047 1060 7ffe1322c25d-7ffe1322c283 1059->1060 1061 7ffe1322bd2b-7ffe1322bd30 1059->1061 1064 7ffe1322c3d5-7ffe1322c3da 1060->1064 1065 7ffe1322c289-7ffe1322c290 1060->1065 1061->1047 1066 7ffe1322c111-7ffe1322c122 1062->1066 1067 7ffe1322c197-7ffe1322c1b2 call 7ffe1322689b call 7ffe1322b940 1062->1067 1064->1047 1070 7ffe1322c29f-7ffe1322c2c5 GetProcessHeap HeapAlloc 1065->1070 1071 7ffe1322c292-7ffe1322c29c 1065->1071 1072 7ffe1322c124-7ffe1322c13b 1066->1072 1073 7ffe1322c13d-7ffe1322c146 1066->1073 1067->1047 1076 7ffe1322c339-7ffe1322c354 call 7ffe132277a2 1070->1076 1077 7ffe1322c2c7-7ffe1322c309 memcpy call 7ffe13229150 1070->1077 1071->1070 1072->1067 1072->1073 1073->1067 1078 7ffe1322c148-7ffe1322c150 1073->1078 1076->1047 1096 7ffe1322c30f 1077->1096 1097 7ffe1322c3a8-7ffe1322c3ab 1077->1097 1083 7ffe1322c165-7ffe1322c170 1078->1083 1084 7ffe1322c152-7ffe1322c159 1078->1084 1091 7ffe1322c172-7ffe1322c17a 1083->1091 1092 7ffe1322c1b7 call 7ffe1322ba24 1083->1092 1084->1083 1090 7ffe1322c15b-7ffe1322c163 1084->1090 1108 7ffe1322bf20-7ffe1322bf28 1086->1108 1109 7ffe1322bf2e-7ffe1322bf3a call 7ffe132268e2 1086->1109 1087->1086 1114 7ffe1322c0a4-7ffe1322c0b7 call 7ffe1322eac0 1087->1114 1090->1083 1090->1091 1099 7ffe1322c1c6-7ffe1322c1e0 call 7ffe1322689b 1091->1099 1100 7ffe1322c17c-7ffe1322c192 call 7ffe1322689b 1091->1100 1102 7ffe1322c1bc-7ffe1322c1c1 1092->1102 1104 7ffe1322c314-7ffe1322c317 1096->1104 1106 7ffe1322c36a-7ffe1322c36c 1097->1106 1120 7ffe1322c1e2-7ffe1322c1e7 1099->1120 1121 7ffe1322c1ec-7ffe1322c258 call 7ffe132222f5 call 7ffe1322689b call 7ffe132261a2 1099->1121 1100->1047 1102->1047 1104->1047 1113 7ffe1322c31d-7ffe1322c334 GetProcessHeap HeapFree 1104->1113 1110 7ffe1322c36e-7ffe1322c376 1106->1110 1111 7ffe1322c37d-7ffe1322c38c call 7ffe132291cd 1106->1111 1108->1109 1116 7ffe1322c0bc-7ffe1322c0de memcpy 1108->1116 1129 7ffe1322bf59-7ffe1322bf6f call 7ffe13226a68 1109->1129 1130 7ffe1322bf3c-7ffe1322bf51 1109->1130 1110->1111 1117 7ffe1322c378-7ffe1322c37b 1110->1117 1111->1096 1131 7ffe1322c38e-7ffe1322c39c call 7ffe1322bc3e 1111->1131 1113->1047 1114->1086 1116->1109 1117->1111 1123 7ffe1322c356-7ffe1322c366 call 7ffe1322923e 1117->1123 1120->1047 1121->1047 1123->1106 1141 7ffe1322bf71-7ffe1322bf8d 1129->1141 1142 7ffe1322bf94-7ffe1322bfdb call 7ffe132293c0 1129->1142 1130->1129 1143 7ffe1322c39e-7ffe1322c3a3 1131->1143 1144 7ffe1322c3ad-7ffe1322c3b2 1131->1144 1141->1142 1148 7ffe1322c00f-7ffe1322c017 1142->1148 1149 7ffe1322bfdd-7ffe1322bfe5 1142->1149 1143->1104 1144->1104 1151 7ffe1322c030-7ffe1322c064 call 7ffe132261a2 1148->1151 1152 7ffe1322c019-7ffe1322c02a GetProcessHeap HeapFree 1148->1152 1149->1148 1150 7ffe1322bfe7-7ffe1322c002 call 7ffe13221290 1149->1150 1150->1148 1157 7ffe1322c004-7ffe1322c008 1150->1157 1151->1047 1152->1151 1157->1148
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID: $--TSCB--$-ILCCNC-$-ILCCNC-$-ILCCNC-$-VRSCNC-$/line?fields=query$AKAK$AKAK$KCIT$Referer$SYSTEM\CurrentControlSet\Services\UpdateService\Parameters$TPCR$[E] (%s) -> Memory allocation failed(size=%llu)$curl/8.4.0$ip-api.com$last-patch$mem_alloc
                                  • API String ID: 0-4235120829
                                  • Opcode ID: 32f65e0a07db0da76d3cf6bef7a582ef3162b3a37664c1b3ef8a336ad840eee9
                                  • Instruction ID: 85c5c74210971fef07a099aad3a92585704f7ed32fa5bbd4f30f5af1efacb9b1
                                  • Opcode Fuzzy Hash: 32f65e0a07db0da76d3cf6bef7a582ef3162b3a37664c1b3ef8a336ad840eee9
                                  • Instruction Fuzzy Hash: 81126221A08F8289EA70AB56F8843B9A3A0EBD8774F104276DA5D677F5DF3CE545C700

                                  Control-flow Graph

                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: strlen$strcat$HandleLibraryLoadModule
                                  • String ID: --conf=$--datadi$--reseed$.file=$C_InitI2P$C_StartI2P$Done$[E] (%s) -> Failed(err=%08x)$[I] (%s) -> %s$i2p$i2p$i2p.conf$i2p.su3$i2p.su3$i2p_init$libi2p.dll
                                  • API String ID: 1893813203-492052463
                                  • Opcode ID: b5cdc75914d221bfbefe16a4f4c13c465e0792fddc7a04030aebfabb7b88f732
                                  • Instruction ID: 03f341b98b1f3381530bda91f0fbf68e73fb8eb0cfcbbe6205f1394f1a9bf60c
                                  • Opcode Fuzzy Hash: b5cdc75914d221bfbefe16a4f4c13c465e0792fddc7a04030aebfabb7b88f732
                                  • Instruction Fuzzy Hash: 4E71823160CF8289F721AB17F9503EAA291EBE8790F440171DA8D6B7A9DF7CD515C740
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: strlen$CountCriticalErrorHandleInitializeLastModuleSectionSpinfopenstrcat
                                  • String ID: $C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\dwlmgr.log$Done$P$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> InitializeCriticalSectionAndSpinCount(log_cs) failed(gle=%lu)$[E] (%s) -> Log open failed(flog_path=%s)$[I] (%s) -> %s$[I] (%s) -> Log open success(flog_path=%s)$debug_init$dwlmgr.l$log$~
                                  • API String ID: 3395718042-2859552336
                                  • Opcode ID: 978b0a6ebadae812f341b6658679c0ec3d2c2c517391c4d48ff864214b591a68
                                  • Instruction ID: 7d22f3c77e9e8696b9df071bfb90b73c2b2488980118792559118e38d1623a8c
                                  • Opcode Fuzzy Hash: 978b0a6ebadae812f341b6658679c0ec3d2c2c517391c4d48ff864214b591a68
                                  • Instruction Fuzzy Hash: 69512C54E1CE9FC6FB209713AC803B81255AF45774F6441F2C98D066FAEEECA989C301

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 1249 7ffe1150c9fc-7ffe1150ca24 InitializeCriticalSectionAndSpinCount 1250 7ffe1150cb50-7ffe1150cb71 GetLastError call 7ffe1150c852 1249->1250 1251 7ffe1150ca2a-7ffe1150ca5e call 7ffe1150b930 call 7ffe1150466b 1249->1251 1257 7ffe1150cb92-7ffe1150cb98 1250->1257 1258 7ffe1150cb73 1250->1258 1264 7ffe1150ca64-7ffe1150ca7b strlen 1251->1264 1265 7ffe1150cb29-7ffe1150cb41 call 7ffe1150c852 1251->1265 1262 7ffe1150cb9e-7ffe1150cba4 1257->1262 1263 7ffe1150cc5b 1257->1263 1260 7ffe1150cc51-7ffe1150cc56 1258->1260 1261 7ffe1150cb79-7ffe1150cb86 1258->1261 1260->1265 1261->1257 1266 7ffe1150cbd0-7ffe1150cbd3 1262->1266 1267 7ffe1150cba6-7ffe1150cbac 1262->1267 1275 7ffe1150cc65-7ffe1150cc6a 1263->1275 1271 7ffe1150ca93-7ffe1150ca96 1264->1271 1272 7ffe1150ca7d-7ffe1150ca80 1264->1272 1278 7ffe1150cb46-7ffe1150cb4f 1265->1278 1268 7ffe1150cbd5-7ffe1150cbd8 1266->1268 1269 7ffe1150cbed-7ffe1150cbf3 1266->1269 1273 7ffe1150cbb2-7ffe1150cbb8 1267->1273 1274 7ffe1150cc79-7ffe1150cc7e 1267->1274 1276 7ffe1150cc47 1268->1276 1277 7ffe1150cbda-7ffe1150cbdd 1268->1277 1279 7ffe1150cc6f 1269->1279 1280 7ffe1150cbf5-7ffe1150cbfa 1269->1280 1282 7ffe1150cab8-7ffe1150cb01 strlen fopen 1271->1282 1283 7ffe1150ca98-7ffe1150cab2 strcat strlen 1271->1283 1272->1271 1281 7ffe1150ca82-7ffe1150ca8f strlen 1272->1281 1284 7ffe1150cbbe-7ffe1150cbc4 1273->1284 1285 7ffe1150cc83-7ffe1150cc88 1273->1285 1274->1265 1275->1265 1276->1260 1277->1275 1286 7ffe1150cbe3-7ffe1150cbe8 1277->1286 1279->1274 1280->1265 1281->1271 1287 7ffe1150cb07-7ffe1150cb23 call 7ffe1150c852 1282->1287 1288 7ffe1150cc1d-7ffe1150cc38 call 7ffe1150c852 1282->1288 1283->1282 1289 7ffe1150cbff-7ffe1150cc04 1284->1289 1290 7ffe1150cbc6-7ffe1150cbcb 1284->1290 1285->1265 1286->1265 1287->1265 1295 7ffe1150cc8d-7ffe1150cca7 call 7ffe1150c852 1287->1295 1288->1265 1289->1265 1290->1265 1295->1278
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: strlen$CountCriticalErrorHandleInitializeLastModuleSectionSpinfopenstrcat
                                  • String ID: $C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\rdpctl.log$Done$P$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> InitializeCriticalSectionAndSpinCount(log_cs) failed(gle=%lu)$[E] (%s) -> Log open failed(flog_path=%s)$[I] (%s) -> %s$[I] (%s) -> Log open success(flog_path=%s)$debug_init$log$rdpctl.l$~
                                  • API String ID: 3395718042-1794035234
                                  • Opcode ID: 3c2e7bbcb8526972e3423f8e7bc29e03943a38cc64b03e3cdeb29d94f12f5a58
                                  • Instruction ID: e4ab8b5b6ea2877be17033a88d64b18bb8abcb26df47401f9bec8462f484e3ea
                                  • Opcode Fuzzy Hash: 3c2e7bbcb8526972e3423f8e7bc29e03943a38cc64b03e3cdeb29d94f12f5a58
                                  • Instruction Fuzzy Hash: 9E513B61E0CF1381FB219B93E8803BD165EAF0A774F9451FAC90E062B2DF6DA945D341
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: strlen$CountCriticalErrorHandleInitializeLastModuleSectionSpinfopenstrcat
                                  • String ID: $C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\cnccli.log$Done$P$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> InitializeCriticalSectionAndSpinCount(log_cs) failed(gle=%lu)$[E] (%s) -> Log open failed(flog_path=%s)$[I] (%s) -> %s$[I] (%s) -> Log open success(flog_path=%s)$cnccli.l$debug_init$log$~
                                  • API String ID: 3395718042-315528054
                                  • Opcode ID: b87acf069d0c111b26ffbcf509236f87ef9b3c2dec2be1befab7b5d9d08e5bd2
                                  • Instruction ID: 56e411297a7efd9784a07055c28acd31bdd76ed2c7b59028704e6411b18b0677
                                  • Opcode Fuzzy Hash: b87acf069d0c111b26ffbcf509236f87ef9b3c2dec2be1befab7b5d9d08e5bd2
                                  • Instruction Fuzzy Hash: 11511A10A0CE4789FA20775BBC903B99250AFF97B4F5151B2D90D262B2DF6DAA86C341
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: strlen$CountCriticalErrorHandleInitializeLastModuleSectionSpinfopenstrcat
                                  • String ID: $C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\evtsrv.log$Done$P$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> InitializeCriticalSectionAndSpinCount(log_cs) failed(gle=%lu)$[E] (%s) -> Log open failed(flog_path=%s)$[I] (%s) -> %s$[I] (%s) -> Log open success(flog_path=%s)$debug_init$evtsrv.l$log$~
                                  • API String ID: 3395718042-190452282
                                  • Opcode ID: a4a6283dc51dc741a53d2f5bec1208c00311563646a7d26f147c64fa65f9183b
                                  • Instruction ID: 3f1247eb60917f37aaca9810065cc1ad2992a4a8c125d3f0860d8c200f2500e4
                                  • Opcode Fuzzy Hash: a4a6283dc51dc741a53d2f5bec1208c00311563646a7d26f147c64fa65f9183b
                                  • Instruction Fuzzy Hash: DF511CD0B0CE1386FA21AB13E4803B81360AF56F75F5044F3EA1D576B2EE7CA9A58301

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 1200 7ffe1024427c-7ffe102442a4 InitializeCriticalSectionAndSpinCount 1201 7ffe102443d0-7ffe102443f1 GetLastError call 7ffe102440d2 1200->1201 1202 7ffe102442aa-7ffe102442de call 7ffe10242700 call 7ffe1024cebb 1200->1202 1208 7ffe102443f3 1201->1208 1209 7ffe10244412-7ffe10244418 1201->1209 1215 7ffe102442e4-7ffe102442fb strlen 1202->1215 1216 7ffe102443a9-7ffe102443c1 call 7ffe102440d2 1202->1216 1211 7ffe102444d1-7ffe102444d6 1208->1211 1212 7ffe102443f9-7ffe10244406 1208->1212 1213 7ffe1024441e-7ffe10244424 1209->1213 1214 7ffe102444db 1209->1214 1211->1216 1212->1209 1217 7ffe10244450-7ffe10244453 1213->1217 1218 7ffe10244426-7ffe1024442c 1213->1218 1223 7ffe102444e5-7ffe102444ea 1214->1223 1219 7ffe10244313-7ffe10244316 1215->1219 1220 7ffe102442fd-7ffe10244300 1215->1220 1236 7ffe102443c6-7ffe102443cf 1216->1236 1224 7ffe10244455-7ffe10244458 1217->1224 1225 7ffe1024446d-7ffe10244473 1217->1225 1221 7ffe10244432-7ffe10244438 1218->1221 1222 7ffe102444f9-7ffe102444fe 1218->1222 1230 7ffe10244338-7ffe10244381 strlen fopen 1219->1230 1231 7ffe10244318-7ffe10244332 strcat strlen 1219->1231 1220->1219 1229 7ffe10244302-7ffe1024430f strlen 1220->1229 1232 7ffe1024443e-7ffe10244444 1221->1232 1233 7ffe10244503-7ffe10244508 1221->1233 1222->1216 1223->1216 1234 7ffe102444c7 1224->1234 1235 7ffe1024445a-7ffe1024445d 1224->1235 1227 7ffe102444ef 1225->1227 1228 7ffe10244475-7ffe1024447a 1225->1228 1227->1222 1228->1216 1229->1219 1237 7ffe10244387-7ffe102443a3 call 7ffe102440d2 1230->1237 1238 7ffe1024449d-7ffe102444b8 call 7ffe102440d2 1230->1238 1231->1230 1239 7ffe1024447f-7ffe10244484 1232->1239 1240 7ffe10244446-7ffe1024444b 1232->1240 1233->1216 1234->1211 1235->1223 1241 7ffe10244463-7ffe10244468 1235->1241 1237->1216 1246 7ffe1024450d-7ffe10244527 call 7ffe102440d2 1237->1246 1238->1216 1239->1216 1240->1216 1241->1216 1246->1236
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: strlen$CountCriticalErrorHandleInitializeLastModuleSectionSpinfopenstrcat
                                  • String ID: $C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\samctl.log$Done$P$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> InitializeCriticalSectionAndSpinCount(log_cs) failed(gle=%lu)$[E] (%s) -> Log open failed(flog_path=%s)$[I] (%s) -> %s$[I] (%s) -> Log open success(flog_path=%s)$debug_init$log$samctl.l$~
                                  • API String ID: 3395718042-1297835036
                                  • Opcode ID: 016f4638319368af51dd97b999517278ba6aac657be23468ad1dcb1b2069bb53
                                  • Instruction ID: 0d20be8cfb43b57c38eebda674fa9055b7067cfe3db97d591c298f4adf765339
                                  • Opcode Fuzzy Hash: 016f4638319368af51dd97b999517278ba6aac657be23468ad1dcb1b2069bb53
                                  • Instruction Fuzzy Hash: 71512B90A0CE13C5FA205B42A8903F82E50AFC5778FA001F6D70D967B7EE6DB946C305

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 1298 7ffe11ec9f6c-7ffe11ec9f94 InitializeCriticalSectionAndSpinCount 1299 7ffe11ec9f9a-7ffe11ec9fce call 7ffe11ec4ac0 call 7ffe11ec89db 1298->1299 1300 7ffe11eca0c0-7ffe11eca0e1 GetLastError call 7ffe11ec9dc2 1298->1300 1315 7ffe11eca099-7ffe11eca0b1 call 7ffe11ec9dc2 1299->1315 1316 7ffe11ec9fd4-7ffe11ec9feb strlen 1299->1316 1306 7ffe11eca102-7ffe11eca108 1300->1306 1307 7ffe11eca0e3 1300->1307 1311 7ffe11eca1cb 1306->1311 1312 7ffe11eca10e-7ffe11eca114 1306->1312 1309 7ffe11eca0e9-7ffe11eca0f6 1307->1309 1310 7ffe11eca1c1-7ffe11eca1c6 1307->1310 1309->1306 1310->1315 1319 7ffe11eca1d5-7ffe11eca1da 1311->1319 1313 7ffe11eca116-7ffe11eca11c 1312->1313 1314 7ffe11eca140-7ffe11eca143 1312->1314 1317 7ffe11eca1e9-7ffe11eca1ee 1313->1317 1318 7ffe11eca122-7ffe11eca128 1313->1318 1320 7ffe11eca15d-7ffe11eca163 1314->1320 1321 7ffe11eca145-7ffe11eca148 1314->1321 1331 7ffe11eca0b6-7ffe11eca0bf 1315->1331 1323 7ffe11ec9fed-7ffe11ec9ff0 1316->1323 1324 7ffe11eca003-7ffe11eca006 1316->1324 1317->1315 1327 7ffe11eca1f3-7ffe11eca1f8 1318->1327 1328 7ffe11eca12e-7ffe11eca134 1318->1328 1319->1315 1332 7ffe11eca165-7ffe11eca16a 1320->1332 1333 7ffe11eca1df 1320->1333 1329 7ffe11eca14a-7ffe11eca14d 1321->1329 1330 7ffe11eca1b7 1321->1330 1323->1324 1334 7ffe11ec9ff2-7ffe11ec9fff strlen 1323->1334 1325 7ffe11eca028-7ffe11eca071 strlen fopen 1324->1325 1326 7ffe11eca008-7ffe11eca022 strcat strlen 1324->1326 1335 7ffe11eca18d-7ffe11eca1a8 call 7ffe11ec9dc2 1325->1335 1336 7ffe11eca077-7ffe11eca093 call 7ffe11ec9dc2 1325->1336 1326->1325 1327->1315 1337 7ffe11eca136-7ffe11eca13b 1328->1337 1338 7ffe11eca16f-7ffe11eca174 1328->1338 1329->1319 1339 7ffe11eca153-7ffe11eca158 1329->1339 1330->1310 1332->1315 1333->1317 1334->1324 1335->1315 1336->1315 1344 7ffe11eca1fd-7ffe11eca217 call 7ffe11ec9dc2 1336->1344 1337->1315 1338->1315 1339->1315 1344->1331
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: strlen$CountCriticalErrorHandleInitializeLastModuleSectionSpinfopenstrcat
                                  • String ID: $C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\prgmgr.log$Done$P$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> InitializeCriticalSectionAndSpinCount(log_cs) failed(gle=%lu)$[E] (%s) -> Log open failed(flog_path=%s)$[I] (%s) -> %s$[I] (%s) -> Log open success(flog_path=%s)$debug_init$log$prgmgr.l$~
                                  • API String ID: 3395718042-2735303109
                                  • Opcode ID: b3f422636813f9db082be2eff172362a900e087fd06423e4adef8e4629b24b28
                                  • Instruction ID: eb1938a2c650cfb8a2e055e257307fe49b03de579b4967c7d8c6cfd5f7866725
                                  • Opcode Fuzzy Hash: b3f422636813f9db082be2eff172362a900e087fd06423e4adef8e4629b24b28
                                  • Instruction Fuzzy Hash: 4E512C50E0CE4381FB2197E7AC813BB169DAF857E4FD411B6C90E472B2EE6DB9468341
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: OpenQueryValuefflushfwrite
                                  • String ID: $ $(key != NULL)$(root != NULL)$(value != NULL)$(value_sz != NULL)$C:/Projects/rdp/bot/codebase/registry.c$NULL$P$P$[D] (%s) -> Done(root=0x%p,key=%s,param=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$[E] (%s) -> RegOpenKeyA failed(root=0x%p,key=%s,res=%lu)$[E] (%s) -> RegQueryValueA failed(root=0x%p,key=%s,param=%s,res=%lu)$registry_get_value
                                  • API String ID: 1980715187-3890537267
                                  • Opcode ID: e71e00ddab3813d9aa3897deaadce60e761dc9e739cf8e9d2cd97b8039851cba
                                  • Instruction ID: f702d7a0b150f6e71aef12534d5abcd3f3637bfcdc6effa99a9e724cc2f4fe22
                                  • Opcode Fuzzy Hash: e71e00ddab3813d9aa3897deaadce60e761dc9e739cf8e9d2cd97b8039851cba
                                  • Instruction Fuzzy Hash: 42A11E6090CF4FC7FA60A713AC407B96251AF007B5F5401B2DA9E466F9FEEDA985C342
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: OpenQueryValuefflushfwrite
                                  • String ID: $ $(key != NULL)$(root != NULL)$(value != NULL)$(value_sz != NULL)$C:/Projects/rdp/bot/codebase/registry.c$NULL$P$P$[D] (%s) -> Done(root=0x%p,key=%s,param=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$[E] (%s) -> RegOpenKeyA failed(root=0x%p,key=%s,res=%lu)$[E] (%s) -> RegQueryValueA failed(root=0x%p,key=%s,param=%s,res=%lu)$registry_get_value
                                  • API String ID: 1980715187-3890537267
                                  • Opcode ID: 435f0e7a9ab592d34743d64c01d9f013227a1ed4134e646b68ad534058a57e85
                                  • Instruction ID: f05e6675e38f91c5043fbf3e5b3c84852a500581eb7347f7f25b437ca63089ed
                                  • Opcode Fuzzy Hash: 435f0e7a9ab592d34743d64c01d9f013227a1ed4134e646b68ad534058a57e85
                                  • Instruction Fuzzy Hash: 68A15761E1CF4B81F7319B86A8403BD225DAF0077DF5501BAD91E476B1EEADE989C302
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: OpenQueryValuefflushfwrite
                                  • String ID: $ $(key != NULL)$(root != NULL)$(value != NULL)$(value_sz != NULL)$C:/Projects/rdp/bot/codebase/registry.c$NULL$P$P$[D] (%s) -> Done(root=0x%p,key=%s,param=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$[E] (%s) -> RegOpenKeyA failed(root=0x%p,key=%s,res=%lu)$[E] (%s) -> RegQueryValueA failed(root=0x%p,key=%s,param=%s,res=%lu)$registry_get_value
                                  • API String ID: 1980715187-3890537267
                                  • Opcode ID: 7576ae6a36753d6cf1c14af836e9cd5c39fa3049076cbbfb5f585f907a1cd92d
                                  • Instruction ID: 486d5760707648f90153c2aa68ff080708e34ea8fd086900acd5c359e1344c3e
                                  • Opcode Fuzzy Hash: 7576ae6a36753d6cf1c14af836e9cd5c39fa3049076cbbfb5f585f907a1cd92d
                                  • Instruction Fuzzy Hash: 6BA1417190CF4B8DF670BB16BC003B86250AFF5364F5401B2D96E266B5EEACE985D302
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: OpenQueryValuefflushfwrite
                                  • String ID: $ $(key != NULL)$(root != NULL)$(value != NULL)$(value_sz != NULL)$C:/Projects/rdp/bot/codebase/registry.c$NULL$P$P$[D] (%s) -> Done(root=0x%p,key=%s,param=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$[E] (%s) -> RegOpenKeyA failed(root=0x%p,key=%s,res=%lu)$[E] (%s) -> RegQueryValueA failed(root=0x%p,key=%s,param=%s,res=%lu)$registry_get_value
                                  • API String ID: 1980715187-3890537267
                                  • Opcode ID: 2eb85fe08712c9625d29b8c13bccc0ad78cd7b35cc400876baf117bdecc1f14f
                                  • Instruction ID: f7c0b2e78327a0662eb7ecd4368fb7e1308c0b4bdb4921c01c19065ee0e41507
                                  • Opcode Fuzzy Hash: 2eb85fe08712c9625d29b8c13bccc0ad78cd7b35cc400876baf117bdecc1f14f
                                  • Instruction Fuzzy Hash: 48A146A5B0CF4781FA60BB43A9403B86651AF02F64F5401F3DA1D876B3EF6DA969C701
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: OpenQueryValuefflushfwrite
                                  • String ID: $ $(key != NULL)$(root != NULL)$(value != NULL)$(value_sz != NULL)$C:/Projects/rdp/bot/codebase/registry.c$NULL$P$P$[D] (%s) -> Done(root=0x%p,key=%s,param=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$[E] (%s) -> RegOpenKeyA failed(root=0x%p,key=%s,res=%lu)$[E] (%s) -> RegQueryValueA failed(root=0x%p,key=%s,param=%s,res=%lu)$registry_get_value
                                  • API String ID: 1980715187-3890537267
                                  • Opcode ID: 9c977889d563c1987e390171c3469c66642a4b360fa1d16f1788854835f10803
                                  • Instruction ID: 0641b8d06e1bded532e6441f63673ca8af7d146fd5fa6da219b60450446bfd2f
                                  • Opcode Fuzzy Hash: 9c977889d563c1987e390171c3469c66642a4b360fa1d16f1788854835f10803
                                  • Instruction Fuzzy Hash: ACA142A090CF0BE1F6309707A4403B97954AFC0774F5580B2DB5E867B3EEADA985C705
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: OpenQueryValuefflushfwrite
                                  • String ID: $ $(key != NULL)$(root != NULL)$(value != NULL)$(value_sz != NULL)$C:/Projects/rdp/bot/codebase/registry.c$NULL$P$P$[D] (%s) -> Done(root=0x%p,key=%s,param=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$[E] (%s) -> RegOpenKeyA failed(root=0x%p,key=%s,res=%lu)$[E] (%s) -> RegQueryValueA failed(root=0x%p,key=%s,param=%s,res=%lu)$registry_get_value
                                  • API String ID: 1980715187-3890537267
                                  • Opcode ID: 7f19a7410ae59509b384c64feabfbea1f96e87a3bd380099ac3d5f47d3dae185
                                  • Instruction ID: 4d1fef247f26db6a57c20efbb0b68aee9de68f6d512ea7a0d2b93bd471fa6f2d
                                  • Opcode Fuzzy Hash: 7f19a7410ae59509b384c64feabfbea1f96e87a3bd380099ac3d5f47d3dae185
                                  • Instruction Fuzzy Hash: DAA13F65D0CF4B91FB20DBC2AC003BB625CAF14764F9451B2CA1E467B1EE6DFA858702
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: CreateErrorLastThread
                                  • String ID: $Done$P$[E] (%s) -> CreateThread(%s) failed(gle=%lu)$[E] (%s) -> Failed(err=%08x)$[I] (%s) -> %s$[I] (%s) -> CreateThread(%s) done$cnc_init$cnccli$i2p_addr$i2p_sam3_timeo$i2p_try_num$routine_rx$server_host$server_port$server_timeo$~
                                  • API String ID: 1689873465-2891999747
                                  • Opcode ID: 33e71f06e42a99735c9f1285eb2e935319501a0d22f8531b1d7d2ee8e9760a1c
                                  • Instruction ID: 4718c37c946dd03925daf9a31a33f5660334abfa228cc0232f49ab54dccbfe1e
                                  • Opcode Fuzzy Hash: 33e71f06e42a99735c9f1285eb2e935319501a0d22f8531b1d7d2ee8e9760a1c
                                  • Instruction Fuzzy Hash: 3E914E60A0CE538DFA30B766BC843B46694AFA8374F5042B1C95D672F5DFBCA945C342
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: _errno$fclosefopenfwrite
                                  • String ID: (mode != NULL)$(path != NULL)$C:/Projects/rdp/bot/codebase/fs.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(path=%s,mode=%s,err=%08x)$[E] (%s) -> fopen failed(path=%s,mode=%s,errno=%d)$[E] (%s) -> fwrite failed(path=%s,mode=%s,errno=%d)$[I] (%s) -> Done(path=%s,mode=%s,buf_sz=%llu)$fs_file_write
                                  • API String ID: 608220805-544371937
                                  • Opcode ID: 2fa1cd46eac7cf50ee181b8d3ee56f4178c7b011de09ae6be45fd9e8eb5f757e
                                  • Instruction ID: 9c6868a0c03b9d6ecdfafe2f8a69c5c4572f691d0c58f33874818dbf80312a56
                                  • Opcode Fuzzy Hash: 2fa1cd46eac7cf50ee181b8d3ee56f4178c7b011de09ae6be45fd9e8eb5f757e
                                  • Instruction Fuzzy Hash: 0251A031A0864395FA20BB5CDA482B8E2917F76785FC811B2DF9D4769CDF2CF9529320
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: strlen$CreateDirectoryErrorLast$strcpy
                                  • String ID: (path != NULL)$C:/Projects/rdp/bot/codebase/fs.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> CreateDirectoryA failed(path=%s,recursive=%d,gle=%lu)$[E] (%s) -> CreateDirectoryA failed(path=%s,recursive=%d,ptr=%s,gle=%lu)$[E] (%s) -> Failed(path=%s,recursive=%d,err=%08x)$[I] (%s) -> Done(path=%s,recursive=%d)$fs_dir_create
                                  • API String ID: 1104438493-1059260517
                                  • Opcode ID: 8c963961a951776b503a5fc3615dbab1392d406fa737535c647d0a1987d59cda
                                  • Instruction ID: 04c167937374464c988c1f65d77e62abe4af8088b7244f5351f3332cf86733ee
                                  • Opcode Fuzzy Hash: 8c963961a951776b503a5fc3615dbab1392d406fa737535c647d0a1987d59cda
                                  • Instruction Fuzzy Hash: 89716922A0CE438EFA717B17FC807B95251AFE9774F5800B2DA4E662B1DE2CE945C311
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: strlen$CreateDirectoryErrorLast$strcpy
                                  • String ID: (path != NULL)$C:/Projects/rdp/bot/codebase/fs.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> CreateDirectoryA failed(path=%s,recursive=%d,gle=%lu)$[E] (%s) -> CreateDirectoryA failed(path=%s,recursive=%d,ptr=%s,gle=%lu)$[E] (%s) -> Failed(path=%s,recursive=%d,err=%08x)$[I] (%s) -> Done(path=%s,recursive=%d)$fs_dir_create
                                  • API String ID: 1104438493-1059260517
                                  • Opcode ID: 388fdc971c35c5c66298320583c07e34cd3b7c2f582f1aba419fafd61ed40875
                                  • Instruction ID: b00810e7b294dd3e9b1de03cb535212e717ef067157d85a2d52b567adcda7b26
                                  • Opcode Fuzzy Hash: 388fdc971c35c5c66298320583c07e34cd3b7c2f582f1aba419fafd61ed40875
                                  • Instruction Fuzzy Hash: B8717D11B0CE8381FB205B97EC413BB56A9AF88764F9411B2D90E167F6DE2DF885CB01
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: strlen$CountCriticalErrorHandleInitializeLastModuleSectionSpin_mbscatfopen
                                  • String ID: C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.log$Done$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> InitializeCriticalSectionAndSpinCount(log_cs) failed(gle=%lu)$[E] (%s) -> Log open failed(flog_path=%s)$[I] (%s) -> %s$[I] (%s) -> Log open success(flog_path=%s)$debug_init$main.log$service
                                  • API String ID: 3216678114-1460613360
                                  • Opcode ID: 806580b93aadc203eb73588eff232527fbb2f0bd67923d4f8ae07467998f43c7
                                  • Instruction ID: cbde110b28d26ee795f4fffd6b2bdc7541fff9f3713af320b80b93755e2de828
                                  • Opcode Fuzzy Hash: 806580b93aadc203eb73588eff232527fbb2f0bd67923d4f8ae07467998f43c7
                                  • Instruction Fuzzy Hash: 03515910A0C60391FA60775CA8882B8E250AF76744FC400F6CF9D5A3DEDF6CB9469361
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: strlen$_errno_mbscpy$_mbscatfopenfseek
                                  • String ID: %TEMP%$(package != NULL)$(target != NULL)$C:/Projects/rdp/bot/codebase/package.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Entry unpack failed(package=%s,target=%s,pkg_ent=%s,pkg_ent_sz=%u,err=%08x)$[E] (%s) -> Failed(package=%s,target=%s,err=%08x)$[I] (%s) -> Done(package=%s,target=%s)$[I] (%s) -> Entry unpack done(package=%s,target=%s,pkg_ent=%s,pkg_ent_sz=%u)$package_unpack
                                  • API String ID: 3066828623-21863935
                                  • Opcode ID: 4e060256d15c7e919ae692f560fe0c26935cca38bca4517b55ebaffd7a87395a
                                  • Instruction ID: 3bb74a6cbcf9e248131cd362b0358edabc5260ae936852245cf3f912ac25967f
                                  • Opcode Fuzzy Hash: 4e060256d15c7e919ae692f560fe0c26935cca38bca4517b55ebaffd7a87395a
                                  • Instruction Fuzzy Hash: EC81916160874795FA10BF1CE8483A9E3A0AB6A384FD44071EF9D9B68DDF7CE605D720
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: strlen$Heap_mbscpy$AllocFreeHandleLibraryModuleProcess
                                  • String ID: [E] (%s) -> Failed(name=%s,err=%08x)$[E] (%s) -> Memory allocation failed(size=%llu)$[I] (%s) -> Done(name=%s)$[I] (%s) -> Loaded(f_path=%s)$mem_alloc$unit_cleanup$unit_init$units_init
                                  • API String ID: 548194777-214984806
                                  • Opcode ID: 6aa98b60b87720260012a02e692c52bcc889d8618c4132bbe0de95421e261512
                                  • Instruction ID: 1eb69167b4ac263110c3933be10092151fc146037718cf1f78fffaf2f8a2ac09
                                  • Opcode Fuzzy Hash: 6aa98b60b87720260012a02e692c52bcc889d8618c4132bbe0de95421e261512
                                  • Instruction Fuzzy Hash: CA815B21A0864395FA61BB19A4583B9E3A1AF66784FC450B2DF8D0779DDF3CF906C360
                                  APIs
                                  • CreateFileA.KERNEL32(?,?,?,?,?,?,?,?,?,service,000002BAD3D813D0,?,00007FF7BACE8500,00007FF7BACD1669), ref: 00007FF7BACD6907
                                  • LockFileEx.KERNEL32(?,?,?,?,?,?,?,?,?,service,000002BAD3D813D0,?,00007FF7BACE8500,00007FF7BACD1669), ref: 00007FF7BACD6940
                                  • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,service,000002BAD3D813D0,?,00007FF7BACE8500,00007FF7BACD1669), ref: 00007FF7BACD6A15
                                  • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,service,000002BAD3D813D0,?,00007FF7BACE8500,00007FF7BACD1669), ref: 00007FF7BACD6AFA
                                  • CloseHandle.KERNEL32(?,?,?,?,?,?,?,?,?,service,000002BAD3D813D0,?,00007FF7BACE8500,00007FF7BACD1669), ref: 00007FF7BACD6C6E
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorFileLast$CloseCreateHandleLock
                                  • String ID: (lock != NULL)$(path != NULL)$C:/Projects/rdp/bot/codebase/fs.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> CreateFileA failed(path=%s,gle=%lu)$[E] (%s) -> Failed(path=%s,err=%08x)$[E] (%s) -> LockFileEx failed(path=%s,gle=%lu)$[I] (%s) -> Done(path=%s,lock=%p)$fs_file_lock$service
                                  • API String ID: 2747014929-2960251455
                                  • Opcode ID: e0ef4c9546ce209838214ad7d84d2262a497ccc4cf0395369252b85571cb2afe
                                  • Instruction ID: 9b3c2ce68d529b772a6266f18cd8624e5742baf2b20a2b03cc4a5b8a413df8e6
                                  • Opcode Fuzzy Hash: e0ef4c9546ce209838214ad7d84d2262a497ccc4cf0395369252b85571cb2afe
                                  • Instruction Fuzzy Hash: F781432091C74B81FA30BB1CA458378B2509F76354F9446B2CFED066D9EE7DA985E322
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLast$setsockopt$connecthtonlhtonsioctlsocketselectsocket
                                  • String ID: [E] (%s) -> connect failed(sock=0x%llx,host=%08x,port=%u,WSAgle=%d)$[E] (%s) -> connection failed(host=%08x,port=%u)$[E] (%s) -> select failed(sock=0x%llx,WSAgle=%d)$[E] (%s) -> socket failed(host=%08x,port=%u,WSAgle=%d)$[I] (%s) -> Done(sock=0x%llx,host=%08x,port=%u)$[W] (%s) -> select timedout(sock=0x%llx,timeo=%u)$tcp_connect
                                  • API String ID: 3154682637-708158336
                                  • Opcode ID: fbff94c264d50f1a86d27a2dda819544e9a6fd6f171c1843e075d3ead4e5caed
                                  • Instruction ID: 7f8355a90df9a178fa8f2fc7592e8830fb45ffb32eb8ddca8f5c32516366e00b
                                  • Opcode Fuzzy Hash: fbff94c264d50f1a86d27a2dda819544e9a6fd6f171c1843e075d3ead4e5caed
                                  • Instruction Fuzzy Hash: 46519261A08E4E83EA209B17FC416BA7690EF84774F1403B5D9AE466F5DEFDE8058700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLast$setsockopt$connecthtonlhtonsioctlsocketselectsocket
                                  • String ID: [E] (%s) -> connect failed(sock=0x%llx,host=%08x,port=%u,WSAgle=%d)$[E] (%s) -> connection failed(host=%08x,port=%u)$[E] (%s) -> select failed(sock=0x%llx,WSAgle=%d)$[E] (%s) -> socket failed(host=%08x,port=%u,WSAgle=%d)$[I] (%s) -> Done(sock=0x%llx,host=%08x,port=%u)$[W] (%s) -> select timedout(sock=0x%llx,timeo=%u)$tcp_connect
                                  • API String ID: 3154682637-708158336
                                  • Opcode ID: 85fe309330bad522897bd5eab4d8b0bcc446cc89911679206bac38ec5b9cf989
                                  • Instruction ID: b33e81ce788e27c05314779c1b74d0a24e9e3d5dc7a27a189d32465285a778e6
                                  • Opcode Fuzzy Hash: 85fe309330bad522897bd5eab4d8b0bcc446cc89911679206bac38ec5b9cf989
                                  • Instruction Fuzzy Hash: 3351DF21B0CE4282E7209FA7E8502BD7669AF857B4F0403BAE82D466F5DF7DE5058301
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLast$setsockopt$connecthtonlhtonsioctlsocketselectsocket
                                  • String ID: [E] (%s) -> connect failed(sock=0x%llx,host=%08x,port=%u,WSAgle=%d)$[E] (%s) -> connection failed(host=%08x,port=%u)$[E] (%s) -> select failed(sock=0x%llx,WSAgle=%d)$[E] (%s) -> socket failed(host=%08x,port=%u,WSAgle=%d)$[I] (%s) -> Done(sock=0x%llx,host=%08x,port=%u)$[W] (%s) -> select timedout(sock=0x%llx,timeo=%u)$tcp_connect
                                  • API String ID: 3154682637-708158336
                                  • Opcode ID: 3a02b0645d0fc3815985ff98e612554857fcd5d65f34fcb0896d69c42ade57f5
                                  • Instruction ID: e6c1bb8f372111b2c05a322643ee3a0c793a5b2f94078057e1e6ff113dc71f50
                                  • Opcode Fuzzy Hash: 3a02b0645d0fc3815985ff98e612554857fcd5d65f34fcb0896d69c42ade57f5
                                  • Instruction Fuzzy Hash: 4951B029A0CE4289F7207B27BC00679A690AFE5B74F2403B5E92D666F1DE7DF505C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLast$setsockopt$connecthtonlhtonsioctlsocketselectsocket
                                  • String ID: [E] (%s) -> connect failed(sock=0x%llx,host=%08x,port=%u,WSAgle=%d)$[E] (%s) -> connection failed(host=%08x,port=%u)$[E] (%s) -> select failed(sock=0x%llx,WSAgle=%d)$[E] (%s) -> socket failed(host=%08x,port=%u,WSAgle=%d)$[I] (%s) -> Done(sock=0x%llx,host=%08x,port=%u)$[W] (%s) -> select timedout(sock=0x%llx,timeo=%u)$tcp_connect
                                  • API String ID: 3154682637-708158336
                                  • Opcode ID: 58c477ab2743a02f25a3061b18a7333f5a1808f8a51df808fc2496d176c81ab2
                                  • Instruction ID: 7d1c56fefc2b9be82617894070405896701c17857ddfb03b819284c3e929a554
                                  • Opcode Fuzzy Hash: 58c477ab2743a02f25a3061b18a7333f5a1808f8a51df808fc2496d176c81ab2
                                  • Instruction Fuzzy Hash: 4B51B461A08E6281E6244B16E8442BA7A51AFC4774F4403B5EBAD87BF7EE7CE545C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLast$setsockopt$connecthtonlhtonsioctlsocketselectsocket
                                  • String ID: [E] (%s) -> connect failed(sock=0x%llx,host=%08x,port=%u,WSAgle=%d)$[E] (%s) -> connection failed(host=%08x,port=%u)$[E] (%s) -> select failed(sock=0x%llx,WSAgle=%d)$[E] (%s) -> socket failed(host=%08x,port=%u,WSAgle=%d)$[I] (%s) -> Done(sock=0x%llx,host=%08x,port=%u)$[W] (%s) -> select timedout(sock=0x%llx,timeo=%u)$tcp_connect
                                  • API String ID: 3154682637-708158336
                                  • Opcode ID: 00be52f98493886c70a6fc4778f049fbd0ac6de21f4713c6c0349c451989cf9d
                                  • Instruction ID: a4e8e206fae03f077d5d12388a7947ced50ab9c0a54502c878204bcedc588274
                                  • Opcode Fuzzy Hash: 00be52f98493886c70a6fc4778f049fbd0ac6de21f4713c6c0349c451989cf9d
                                  • Instruction Fuzzy Hash: 5251C465A0CE8381EB209B96EC013BFA698EF84770F941376E92E466F5DE3DF4058301
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLast$CountCreateCriticalInitializeSectionSpinThreadfflushfwrite
                                  • String ID: $ $Done$P$P$[E] (%s) -> CreateThread(routine_rx) failed(gle=%lu)$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> InitializeCriticalSectionAndSpinCount(cs_subscribers) failed(gle=%lu)$[I] (%s) -> %s$ebus_init$~$~
                                  • API String ID: 1412730629-3633878399
                                  • Opcode ID: 0d3d345b92d57715ffb7629bc92dc0b7791e0b502c44b520db891954b542ce77
                                  • Instruction ID: 6b21a050c57bc4811038574912a834dd521f02fc28f1d4a8c287a2bc498d8f0d
                                  • Opcode Fuzzy Hash: 0d3d345b92d57715ffb7629bc92dc0b7791e0b502c44b520db891954b542ce77
                                  • Instruction Fuzzy Hash: DD51F960A0CF4FC3FB648716ACC43792251AF18375F2407B6C5AE062F6DEED79899251
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLast$CountCreateCriticalInitializeSectionSpinThreadfflushfwrite
                                  • String ID: $ $Done$P$P$[E] (%s) -> CreateThread(routine_rx) failed(gle=%lu)$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> InitializeCriticalSectionAndSpinCount(cs_subscribers) failed(gle=%lu)$[I] (%s) -> %s$ebus_init$~$~
                                  • API String ID: 1412730629-3633878399
                                  • Opcode ID: 16bc6f95adb63556d6d9dd7628c5118d99aff38ef0e314d2a351385bf1973825
                                  • Instruction ID: 2360eb2ab99108f82431dfa9f6733f8ad39002f6f19093a6ba77ca6d935d778e
                                  • Opcode Fuzzy Hash: 16bc6f95adb63556d6d9dd7628c5118d99aff38ef0e314d2a351385bf1973825
                                  • Instruction Fuzzy Hash: FD513B21F0CF4392FB314796A4C437D22999F05335F6447BAC56E062F1EF6DAA86C242
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLast$CountCreateCriticalInitializeSectionSpinThreadfflushfwrite
                                  • String ID: $ $Done$P$P$[E] (%s) -> CreateThread(routine_rx) failed(gle=%lu)$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> InitializeCriticalSectionAndSpinCount(cs_subscribers) failed(gle=%lu)$[I] (%s) -> %s$ebus_init$~$~
                                  • API String ID: 1412730629-3633878399
                                  • Opcode ID: 4c63b5f3d359f2261d39e7ba9d5db9643061a5a5867b9a114e724cbc38ab18fd
                                  • Instruction ID: aa7c457c3337609ad05a750ba808d5ff003cf6b411e0d6d0bd02475766008425
                                  • Opcode Fuzzy Hash: 4c63b5f3d359f2261d39e7ba9d5db9643061a5a5867b9a114e724cbc38ab18fd
                                  • Instruction Fuzzy Hash: E951EB62E0CF038DF6307716BDC43B862909FB8774F2442B6C56E262F5DEADA995C241
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLast$CountCreateCriticalInitializeSectionSpinThreadfflushfwrite
                                  • String ID: $ $Done$P$P$[E] (%s) -> CreateThread(routine_rx) failed(gle=%lu)$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> InitializeCriticalSectionAndSpinCount(cs_subscribers) failed(gle=%lu)$[I] (%s) -> %s$ebus_init$~$~
                                  • API String ID: 1412730629-3633878399
                                  • Opcode ID: 583c772d6c2aa44c00a4b912cfb21b533add25f1d60aa2102540b12dac15f462
                                  • Instruction ID: bdd344edf036c5772995a3795d9121fb4832f8ecab7be9ccf729e2db5d7fedff
                                  • Opcode Fuzzy Hash: 583c772d6c2aa44c00a4b912cfb21b533add25f1d60aa2102540b12dac15f462
                                  • Instruction Fuzzy Hash: 9651E560F0DF03C2F6205B16A8843B96A509F89374F3457B6C76E863F3EE6DA985D205
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLast$CountCreateCriticalInitializeSectionSpinThreadfflushfwrite
                                  • String ID: $ $Done$P$P$[E] (%s) -> CreateThread(routine_rx) failed(gle=%lu)$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> InitializeCriticalSectionAndSpinCount(cs_subscribers) failed(gle=%lu)$[I] (%s) -> %s$ebus_init$~$~
                                  • API String ID: 1412730629-3633878399
                                  • Opcode ID: a4765926d0bec962e3b64301d7cbedd34045c1c1f3eb295a71ea3bfcd381612a
                                  • Instruction ID: 29962f0adcd3e2c513f443755b1ba9e76e63a906b51857df36bc60fec2b21b6d
                                  • Opcode Fuzzy Hash: a4765926d0bec962e3b64301d7cbedd34045c1c1f3eb295a71ea3bfcd381612a
                                  • Instruction Fuzzy Hash: 07513A61E0CF03C2FB2047DAAC803BB62999F05374FA453B6D56E462F5DE6DF8859281
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: OpenQueryValuefflushfwrite
                                  • String ID: (key != NULL)$(root != NULL)$(value != NULL)$(value_sz != NULL)$C:/Projects/rdp/bot/codebase/registry.c$NULL$[D] (%s) -> Done(root=0x%p,key=%s,param=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$[E] (%s) -> RegOpenKeyA failed(root=0x%p,key=%s,res=%lu)$[E] (%s) -> RegQueryValueA failed(root=0x%p,key=%s,param=%s,res=%lu)$registry_get_value
                                  • API String ID: 1980715187-910542497
                                  • Opcode ID: 652f1f39b9fc6d1d86e7ebec04d142c7ff3a41bee9e90e04d25363eb51b2c210
                                  • Instruction ID: fb4fd6ca49f85d2e19a8f99524a8bc42fbe34cb2f892c656a5fa436c75fed44d
                                  • Opcode Fuzzy Hash: 652f1f39b9fc6d1d86e7ebec04d142c7ff3a41bee9e90e04d25363eb51b2c210
                                  • Instruction Fuzzy Hash: F9A1216890C74B91FA70BF4CA44837CA254AB32744FC402B2DF9E46F99EE6DF9459321
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: Heap$CriticalProcessSection$AllocCreateEnterErrorFreeLastLeaveThread
                                  • String ID: [E] (%s) -> CreateThread(routine_rx) failed(client=0x%llx,gle=%lu)$[E] (%s) -> Memory allocation failed(size=%llu)$[I] (%s) -> Client accepted(client=0x%llx)$[I] (%s) -> Server ready(ssock=0x%llx)$mem_alloc$routine_accept
                                  • API String ID: 871770459-375624272
                                  • Opcode ID: d451663e41dabee467c87c723cfd067be25501a0a92c9c864de93dd7d3f51d57
                                  • Instruction ID: c63b40c5ab1b70d500872347372b7709c3443850aed86b184ad29b1510bee773
                                  • Opcode Fuzzy Hash: d451663e41dabee467c87c723cfd067be25501a0a92c9c864de93dd7d3f51d57
                                  • Instruction Fuzzy Hash: FB51FCA0B09E0241FA54AB17A8243B92260AF55FB4F1443F7D93E477F1EE7CB8668341
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: Heap$AllocProcess$Free$AccountBufferEnumErrorLastLocalLookupNameUsermemcpywcslenwcsncpy
                                  • String ID: D$[E] (%s) -> LookupAccountNameW failed(gle=%lu)$[E] (%s) -> Memory allocation failed(size=%llu)$mem_alloc$users_sync
                                  • API String ID: 2122475568-588975189
                                  • Opcode ID: 54a7b86a98f000bcfd33f2828802400fe62b6061ee7e6fb4c2b4e7f4368a0eca
                                  • Instruction ID: 2ef76d722202e0785721c732daf3e41f8c52b92253da30260e6e60f55bf58e04
                                  • Opcode Fuzzy Hash: 54a7b86a98f000bcfd33f2828802400fe62b6061ee7e6fb4c2b4e7f4368a0eca
                                  • Instruction Fuzzy Hash: 8D513D76A08E42C6EB60CF16E4443697BA1FB88B64F004076DB4D83369EF7CE815C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: Heap$AllocProcess$Free$AccountBufferEnumErrorLastLocalLookupNameUsermemcpywcslenwcsncpy
                                  • String ID: D$[E] (%s) -> LookupAccountNameW failed(gle=%lu)$[E] (%s) -> Memory allocation failed(size=%llu)$mem_alloc$users_sync
                                  • API String ID: 2122475568-588975189
                                  • Opcode ID: 7f593288dc07a425f65f6d7b267199539c6d78595fae3d034de1260608a3864d
                                  • Instruction ID: f1bdad696df931a0b0bc584168385b052e2fbb01c4c708d6217628b101bf7c20
                                  • Opcode Fuzzy Hash: 7f593288dc07a425f65f6d7b267199539c6d78595fae3d034de1260608a3864d
                                  • Instruction Fuzzy Hash: 2C513D76A08E42C6EB60CF16E4443697BA1FB88B64F004076DB4D83369EF7CE815C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: Heap$AllocProcess$Free$AccountBufferEnumErrorLastLocalLookupNameUsermemcpywcslenwcsncpy
                                  • String ID: D$[E] (%s) -> LookupAccountNameW failed(gle=%lu)$[E] (%s) -> Memory allocation failed(size=%llu)$mem_alloc$users_sync
                                  • API String ID: 2122475568-588975189
                                  • Opcode ID: 6bf7cd5875f3512d5a2b98bef802aba34ee915af7b591b1d33da1dc4fe37d457
                                  • Instruction ID: 419819cc74c852edcea57afa8ebd91856639fdec5c70bffb8d4a48172c9d166c
                                  • Opcode Fuzzy Hash: 6bf7cd5875f3512d5a2b98bef802aba34ee915af7b591b1d33da1dc4fe37d457
                                  • Instruction Fuzzy Hash: 08511D76A08E42C6EB60CF16E4443697BA1FB89B64F444175DB4D8336AEF7CE815C740
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: Heap$AllocProcess$Free$AccountBufferEnumErrorLastLocalLookupNameUsermemcpywcslenwcsncpy
                                  • String ID: D$[E] (%s) -> LookupAccountNameW failed(gle=%lu)$[E] (%s) -> Memory allocation failed(size=%llu)$mem_alloc$users_sync
                                  • API String ID: 2122475568-588975189
                                  • Opcode ID: 3fd3404b939de57ddb90f7a22bc993c0f7acd5cce79066ccac611f04a2d12c47
                                  • Instruction ID: 064999778a0f1ddb5dffcfd624c1083146a8fb8e8e99a97ee80a3df1ae30c00d
                                  • Opcode Fuzzy Hash: 3fd3404b939de57ddb90f7a22bc993c0f7acd5cce79066ccac611f04a2d12c47
                                  • Instruction Fuzzy Hash: BB511D76A08E42C6EB60CF16E4443697BA1FB89B64F444175DB4D83369EF7CE815C740
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLast$CountCriticalInitializeManagerOpenSectionSpinfflushfwrite
                                  • String ID: $Done$P$ServicesActive$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> InitializeCriticalSectionAndSpinCount(cs_scm) failed(gle=%lu)$[E] (%s) -> OpenSCManagerA(SERVICES_ACTIVE_DATABASE) failed(gle=%lu)$[I] (%s) -> %s$scm_init$~
                                  • API String ID: 546114577-3142219161
                                  • Opcode ID: f56fc1782bac19320c22608419659dee0f339a9110204879ad83665987f711c4
                                  • Instruction ID: 1798c34a28dcc00e7144b094aa6727eebdfaf3129ba890f0cba47499f04b13b0
                                  • Opcode Fuzzy Hash: f56fc1782bac19320c22608419659dee0f339a9110204879ad83665987f711c4
                                  • Instruction Fuzzy Hash: E941FA61F0CF0792FB605797E4C1B7C226DAF15374F5415FAC90E4A2B2AE5DA9888302
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: CriticalSection$Heap$Enter$FreeLeaveProcess$Sleep
                                  • String ID: $--TSCB--$-VRSTVE-$KCIT$[D] (%s) -> Dispatch an event(size=%u,timestamp=%lld,code=%08x(%.4s),sender=%016llx(%.8s),receiver=%016llx(%.8s))$routine_tx
                                  • API String ID: 610085118-1825955162
                                  • Opcode ID: 166d59042168f0a7efe1bdf5a62cee1bbef3ee65b4c9840a769aaa8e801ae9a5
                                  • Instruction ID: 849cf90c03414411fd993825eac9f55d739a464361b46ccb49b33ba1f5862a8a
                                  • Opcode Fuzzy Hash: 166d59042168f0a7efe1bdf5a62cee1bbef3ee65b4c9840a769aaa8e801ae9a5
                                  • Instruction Fuzzy Hash: 7F5128A1B49E8682F6169B06E8542B96370EF84FA4F1051F6DA6E43774DF3CF4628340
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: EnvironmentErrorExpandLastStringsfflushfwrite
                                  • String ID: ((*xpath_sz) > 0)$(path != NULL)$(xpath != NULL)$(xpath_sz != NULL)$C:/Projects/rdp/bot/codebase/fs.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> ExpandEnvironmentStringsA buffer is too small(path=%s,res=%lu,xpath_sz=%llu)$[E] (%s) -> ExpandEnvironmentStringsA failed(path=%s,gle=%lu)$[E] (%s) -> Failed(path=%s,xpath_sz=%llu,err=%08x)$[I] (%s) -> Done(path=%s,xpath=%s,xpath_sz=%llu)$fs_path_expand
                                  • API String ID: 1721699506-2819899730
                                  • Opcode ID: 888729eddf9796bfe1fb3d6082617d67f92a44ebe7c812a334a5a82067b18351
                                  • Instruction ID: 9528ff39a63cd47de1606724e4a4f5825e914f31f732da87735306c41408ce1a
                                  • Opcode Fuzzy Hash: 888729eddf9796bfe1fb3d6082617d67f92a44ebe7c812a334a5a82067b18351
                                  • Instruction Fuzzy Hash: 43618421A0C58795FA207B4CE8083B8E291AB76348FE540B3DF9D4799CDE3CF9859321
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: strlen$CompareCriticalEnterFileSectionTime
                                  • String ID: %ProgramFiles%\RDP\$TermService$termsrv3$termsrv3$v32.ini$v32.ini
                                  • API String ID: 3718746087-844192579
                                  • Opcode ID: 6fa1ead858abed257b2c38d5e728982964472102b0d536e4fd6da525e34caaab
                                  • Instruction ID: 76c22f4145cfc476a6cdc50a298ebe6a9a20797b1736faea5949e6ee6d64f8ee
                                  • Opcode Fuzzy Hash: 6fa1ead858abed257b2c38d5e728982964472102b0d536e4fd6da525e34caaab
                                  • Instruction Fuzzy Hash: CB511811B0CF8381FB219BA3A5903FE56999F857E4F4800B9DA4D4B7FADE2CE9058750
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: CriticalHeapSection$EnterFreeLeaveObjectProcessSingleWait$Sleep
                                  • String ID: [I] (%s) -> Client gone(client=0x%llx)$routine_gc
                                  • API String ID: 2654219296-2700516951
                                  • Opcode ID: a7a3092cfa429e479cb0c84a87704b60a1abc0a131c3da2467e75d6fc481c899
                                  • Instruction ID: 44d3879aed27afe13a77100e7ccb27a7dbfd38de4d7b7193276f4b434a0541fc
                                  • Opcode Fuzzy Hash: a7a3092cfa429e479cb0c84a87704b60a1abc0a131c3da2467e75d6fc481c899
                                  • Instruction Fuzzy Hash: 5C41D8A1B09E4682FA55AF12D86027433A0AF58F78F1806F7C92E473F4DF7CE8658251
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: strcpystrlen$strcmp
                                  • String ID: DESTINATION$NAMING$NAMING LOOKUP NAME=ME$REPLY$RESULT$SESSION$SESSION CREATE STYLE=STREAM ID=%s DESTINATION=%s SIGNATURE_TYPE=%s %s %s$STATUS$TRANSIENT$VALUE
                                  • API String ID: 245486318-5999096
                                  • Opcode ID: 92f053ff300a285c9ff08484fbff36539a15897fe572236fc635f002e3f1a039
                                  • Instruction ID: ff3644af5cca88f900ab4a7f7603609a6f8d6dfe530b4087b606c0210ec28562
                                  • Opcode Fuzzy Hash: 92f053ff300a285c9ff08484fbff36539a15897fe572236fc635f002e3f1a039
                                  • Instruction Fuzzy Hash: DA717B22E0EE4689FA34AA27AD103B91250AFA57B4F5403B1DD6D3B7F5DE7CA805C241
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: CtrlErrorHandlerLastRegisterServicefflushfwrite
                                  • String ID: $P$RDP-Controller$Service running$Service stopping$[E] (%s) -> RegisterServiceCtrlHandler failed(GetLastError=%lu)$[I] (%s) -> %s$svc_main$~
                                  • API String ID: 3562457520-1478336053
                                  • Opcode ID: ff3701bf76a7f736c7c8bbc0a00331e4bc82fb3c2cc5cc884ae150488136f5bc
                                  • Instruction ID: 3874caec4fb566c71a85d13941cb5c7431e05dff84e3667185f1bfaff31b2bf4
                                  • Opcode Fuzzy Hash: ff3701bf76a7f736c7c8bbc0a00331e4bc82fb3c2cc5cc884ae150488136f5bc
                                  • Instruction Fuzzy Hash: 40512350A0C607A2FA607B9C948C3B8E1809F37755FD021B7DF8E0A5DEDE1DB9859271
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: Heap$Process$AllocFree$fflushfwritestrlen
                                  • String ID: [D] (%s) -> %s$[E] (%s) -> Memory allocation failed(size=%llu)$mem_alloc$mem_realloc$sam3_send_req
                                  • API String ID: 1135201459-1870638116
                                  • Opcode ID: 8a58ce669b0104294b344b86f13099723c98185ab674a1d19de8f1b9eb60847a
                                  • Instruction ID: 5bacc307de695deac08a4f3f6d5927782e2e3e5f595197e586e3a1ee1f99b636
                                  • Opcode Fuzzy Hash: 8a58ce669b0104294b344b86f13099723c98185ab674a1d19de8f1b9eb60847a
                                  • Instruction Fuzzy Hash: 25315051A0DE468DFA60BB13FC403B96650AFE8BE0F5840B5D91E6A3B5EE2CE644C300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: Heap$Process$AllocFreestrcpystrlen
                                  • String ID: -LTCMAS-$-LTCSES-$XESS$[D] (%s) -> Logoff(name=%s,s_sid=%s,acct_expires=%x,ts_now=%llx)$[E] (%s) -> Memory allocation failed(size=%llu)$mem_alloc$on_tick_expiry
                                  • API String ID: 925994320-1558387473
                                  • Opcode ID: 7c8d0ac939547da229ce404f06613a579137493224db218f57ae4127a199a531
                                  • Instruction ID: 6f4412178f255e912d92bdd8542a5b597c0b3bd4ef5ccb1fa9c51bb2db40edef
                                  • Opcode Fuzzy Hash: 7c8d0ac939547da229ce404f06613a579137493224db218f57ae4127a199a531
                                  • Instruction Fuzzy Hash: FA418EA1A09E4281EA44AB17D8403B96EA4EFC4BB4F5440B5EF0E873E7EE7CE445C310
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: strlen
                                  • String ID: ((*path_sz) > 0)$(path != NULL)$(path_sz != NULL)$C:/Projects/rdp/bot/codebase/fs.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(path=%s,path_sz=%llu,err=%08x)$[I] (%s) -> Done(path=%s,path_sz=%llu)$fs_path_temp
                                  • API String ID: 39653677-3302659514
                                  • Opcode ID: 402c1b4db194d08799718f86fa33908b480c5625c88157872f69c697322c0f11
                                  • Instruction ID: 20d4b154d109ed36c73a576d6f1fef722d618396e1a0ebcb42b6d57f605fc8f3
                                  • Opcode Fuzzy Hash: 402c1b4db194d08799718f86fa33908b480c5625c88157872f69c697322c0f11
                                  • Instruction Fuzzy Hash: 70415F61A0864395FA20BF5CD8083B9E351AF76784FD451B2DFAD07A9DDF3CA5069320
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLast$accepthtonlhtonsioctlsocketselect
                                  • String ID: [E] (%s) -> Failed(sock=0x%llx,WSAgle=%d)$[E] (%s) -> select failed(sock=0x%llx,WSAgle=%d)$[I] (%s) -> Done(sock=0x%llx,client=0x%llx,h=%08x,p=%u)$[W] (%s) -> select timedout(sock=0x%llx)$tcp_accept
                                  • API String ID: 2278979430-4175654481
                                  • Opcode ID: ddfcd42498865aed8750f33cd64a4479b183540ed0ffbad3860233e409b71f32
                                  • Instruction ID: c8be4f40c94cfbd2cd29fd6a66b62290b775a3d95599ac32974787fd0ef80dd4
                                  • Opcode Fuzzy Hash: ddfcd42498865aed8750f33cd64a4479b183540ed0ffbad3860233e409b71f32
                                  • Instruction Fuzzy Hash: BD5191B2B08A4245E760AB17E8403B96260AB44FB4F1443F3E97D17AE4EF7D9525C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: strlen$strcpy
                                  • String ID: *$schtasks$veK
                                  • API String ID: 2790333442-3550129123
                                  • Opcode ID: a317d2316905fc7f98087aa0c4bb8d80657517462ccdb74ec008b7c0b05d0c3e
                                  • Instruction ID: 869cbb48733b572802bccfbd6f3dbc245ce3088d14d337edd7ab771b3e8aa9a5
                                  • Opcode Fuzzy Hash: a317d2316905fc7f98087aa0c4bb8d80657517462ccdb74ec008b7c0b05d0c3e
                                  • Instruction Fuzzy Hash: B151A612B0CE8345FB616B97EC503BB5699AB85364FD810B5EA4E473E6EE2DF9048700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: strcmp
                                  • String ID: (name != NULL)$(sec != NULL)$(var != NULL)$C:/Projects/rdp/bot/codebase/ini.c$NULL$[D] (%s) -> Done(sec=%s,name=%s,value=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[W] (%s) -> Failed(sec=%s,name=%s,err=%08x)$ini_get_var$main$version
                                  • API String ID: 1004003707-636894343
                                  • Opcode ID: 7b0570f3fc05e8893923189e1b132b853666a32ff7ee4e45f27c5479a354f6e2
                                  • Instruction ID: c99d8fff69c1373cf6e8e63fbf669bf0e9894d84f3d95040372d3f77f8a38e71
                                  • Opcode Fuzzy Hash: 7b0570f3fc05e8893923189e1b132b853666a32ff7ee4e45f27c5479a354f6e2
                                  • Instruction Fuzzy Hash: 0041D9A1A08E4FDAFB109B12AD407F863A1AB04764F4441B2EA9D065F5DFFDA649C340
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: strcmp
                                  • String ID: (name != NULL)$(sec != NULL)$(var != NULL)$C:/Projects/rdp/bot/codebase/ini.c$NULL$[D] (%s) -> Done(sec=%s,name=%s,value=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[W] (%s) -> Failed(sec=%s,name=%s,err=%08x)$ini_get_var$main$version
                                  • API String ID: 1004003707-636894343
                                  • Opcode ID: b95fd872987beb657bc04632a610eedb0f0ea1cda37f36d9322da4db09f6558e
                                  • Instruction ID: bd18eb5d8ea3989e3892ba1a0e3026086da3c8c0a67869b428c15fdbf8d3da4a
                                  • Opcode Fuzzy Hash: b95fd872987beb657bc04632a610eedb0f0ea1cda37f36d9322da4db09f6558e
                                  • Instruction Fuzzy Hash: CF412B65E48E9791FB109B86ED423F66268BB40368F8951B2DA5D062B5EF3CF545C300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: strcmp
                                  • String ID: (ini != NULL)$(name != NULL)$(sec != NULL)$C:/Projects/rdp/bot/codebase/ini.c$NULL$[D] (%s) -> Done(name=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[W] (%s) -> Failed(name=%s,err=%08x)$ini_get_sec$main$version
                                  • API String ID: 1004003707-4168131722
                                  • Opcode ID: 1aef3687247d6ab1c35fe33cc4892387064830156e0a07758e676d56871140b1
                                  • Instruction ID: e144f14899583b73918eaf8a97982b116594df21b80b2578542735187dfa7af1
                                  • Opcode Fuzzy Hash: 1aef3687247d6ab1c35fe33cc4892387064830156e0a07758e676d56871140b1
                                  • Instruction Fuzzy Hash: EB410DA1A08E4FDAFB109B52EC803F82251AF14368F4841F6DA9D165F5DFFDA646C340
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: strcmp
                                  • String ID: (ini != NULL)$(name != NULL)$(sec != NULL)$C:/Projects/rdp/bot/codebase/ini.c$NULL$[D] (%s) -> Done(name=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[W] (%s) -> Failed(name=%s,err=%08x)$ini_get_sec$main$version
                                  • API String ID: 1004003707-4168131722
                                  • Opcode ID: 525ba5f3bf202e8e33ed72c5627b9f19f67cb6abea7e404eca9e8a277ca48769
                                  • Instruction ID: 12823cfa366a22a97cb21514f7416190e3bdf0c4e163c042d2741ebf2036f7c7
                                  • Opcode Fuzzy Hash: 525ba5f3bf202e8e33ed72c5627b9f19f67cb6abea7e404eca9e8a277ca48769
                                  • Instruction Fuzzy Hash: C9411D62E48E9792FF109B92ED543B6A368BB40368F8455B6DA1D161B1FF3CF946C300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: CriticalHeapSection$AllocEnterLeaveProcess
                                  • String ID: (handler != NULL)$C:/Projects/rdp/bot/codebase/ebus.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(handler=0x%p,err=%08x)$[E] (%s) -> Memory allocation failed(size=%llu)$[I] (%s) -> Done(handler=0x%p)$ebus_subscribe$mem_alloc
                                  • API String ID: 285244410-4028107517
                                  • Opcode ID: 3a9cae1aa01884bae7efa0b9705455bec305580ba13712b9611d3d2762addf92
                                  • Instruction ID: 8380f90fc1c6bcdc6ea2a9982e548f5d029e4ab87cdac10abf699908afe91ca6
                                  • Opcode Fuzzy Hash: 3a9cae1aa01884bae7efa0b9705455bec305580ba13712b9611d3d2762addf92
                                  • Instruction Fuzzy Hash: 1E31E9A1E09E0F86FE25DB07EC512792361BF54BB4F5841B5C88D1B2F6EEECA9458310
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: CriticalHeapSection$AllocEnterLeaveProcess
                                  • String ID: (handler != NULL)$C:/Projects/rdp/bot/codebase/ebus.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(handler=0x%p,err=%08x)$[E] (%s) -> Memory allocation failed(size=%llu)$[I] (%s) -> Done(handler=0x%p)$ebus_subscribe$mem_alloc
                                  • API String ID: 285244410-4028107517
                                  • Opcode ID: 51182e06d6a6c07dd0c69d8f58770b2ddf4b90986f4ad3826cd256bf4d6556e1
                                  • Instruction ID: 662aa070d00f04f907fdceed82a92e2ead865eabb8b5603f5aba00ee88bf4b8d
                                  • Opcode Fuzzy Hash: 51182e06d6a6c07dd0c69d8f58770b2ddf4b90986f4ad3826cd256bf4d6556e1
                                  • Instruction Fuzzy Hash: 5C311E61E0DE8381FF528B87E9503BD22AABF44B74F5841B9C84D072B0DF2DE9458301
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: CriticalHeapSection$AllocEnterLeaveProcess
                                  • String ID: (handler != NULL)$C:/Projects/rdp/bot/codebase/ebus.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(handler=0x%p,err=%08x)$[E] (%s) -> Memory allocation failed(size=%llu)$[I] (%s) -> Done(handler=0x%p)$ebus_subscribe$mem_alloc
                                  • API String ID: 285244410-4028107517
                                  • Opcode ID: 68ee7d6c3dcbe8250ebf0b5e1c74b75c7be04cfa2e8da067a8f3604feb2f1e69
                                  • Instruction ID: 87b7699e45aad3ef3a733375695b3c345b9823de7732d47d2a10d256e4a1ec52
                                  • Opcode Fuzzy Hash: 68ee7d6c3dcbe8250ebf0b5e1c74b75c7be04cfa2e8da067a8f3604feb2f1e69
                                  • Instruction Fuzzy Hash: 06310A61A0DD0389FA31BB07FC846B96265BFE8BB4F5844B5C84D2B2B0DE6DE845C340
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: CriticalHeapSection$AllocEnterLeaveProcess
                                  • String ID: (handler != NULL)$C:/Projects/rdp/bot/codebase/ebus.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(handler=0x%p,err=%08x)$[E] (%s) -> Memory allocation failed(size=%llu)$[I] (%s) -> Done(handler=0x%p)$ebus_subscribe$mem_alloc
                                  • API String ID: 285244410-4028107517
                                  • Opcode ID: 8cba05d6f9e1b72bd78fcb301e5002d50a2927f161767b6a42ce7369a5e9e9f7
                                  • Instruction ID: f3d642c0ae474f8a5ded4f87c01fb269d143b6a116cebfb1b47a75c5c6d6c307
                                  • Opcode Fuzzy Hash: 8cba05d6f9e1b72bd78fcb301e5002d50a2927f161767b6a42ce7369a5e9e9f7
                                  • Instruction Fuzzy Hash: FB314DA0F09E1381FA109B03E8503B46B65AFC0BB4F5980B5CB4D873B6EE6DE895C304
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: CriticalHeapSection$AllocEnterLeaveProcess
                                  • String ID: (handler != NULL)$C:/Projects/rdp/bot/codebase/ebus.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(handler=0x%p,err=%08x)$[E] (%s) -> Memory allocation failed(size=%llu)$[I] (%s) -> Done(handler=0x%p)$ebus_subscribe$mem_alloc
                                  • API String ID: 285244410-4028107517
                                  • Opcode ID: d7eaba8990d9bb82a883ab9eac106acf4eb305b5d3dced1ada31524724a4bca5
                                  • Instruction ID: 6924f338594ddcf80a59e0a6c7b8134697ea9d379810d5aa05970ff0fd0a9ac9
                                  • Opcode Fuzzy Hash: d7eaba8990d9bb82a883ab9eac106acf4eb305b5d3dced1ada31524724a4bca5
                                  • Instruction Fuzzy Hash: A13105A1E0DE0381FF109B97EC503762369AF41BA4F9895B5C94E0B2B0EE2CF945D340
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: CountCriticalErrorInitializeLastSectionSpinfflushfwrite
                                  • String ID: $Done$P$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> InitializeCriticalSectionAndSpinCount(cs_proxies) failed(gle=%lu)$[I] (%s) -> %s$proxy_init$~
                                  • API String ID: 3179112426-3318474754
                                  • Opcode ID: 62679cb6203fdb9ce5ed245b295c2cc3eaac5c932b8f41fb294838f1a43f0853
                                  • Instruction ID: 6a63f089aaa34b70ee286b2b6a9fc89a6a9c7c5b7e75c9745092db4ed94d49e2
                                  • Opcode Fuzzy Hash: 62679cb6203fdb9ce5ed245b295c2cc3eaac5c932b8f41fb294838f1a43f0853
                                  • Instruction Fuzzy Hash: DF312B61E0DF4392FB214792A8C03BC229E9F053B4F5002BAC50E472F2DF5DA988D396
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: CountCriticalErrorInitializeLastSectionSpinfflushfwrite
                                  • String ID: $Done$P$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> InitializeCriticalSectionAndSpinCount(cs_sam) failed(gle=%lu)$[I] (%s) -> %s$sam_init$~
                                  • API String ID: 3179112426-2019511216
                                  • Opcode ID: 6d845e0d6a9590898fbd72cf9fa3a20257545eac1df6b55605c1f25e501395dc
                                  • Instruction ID: 58816fc73376b853062f03f0f2b8c9f6f419240296a01656f08953b01b95f29d
                                  • Opcode Fuzzy Hash: 6d845e0d6a9590898fbd72cf9fa3a20257545eac1df6b55605c1f25e501395dc
                                  • Instruction Fuzzy Hash: 6B310750B0CE07C2FB20571AA4C43B95A60AFD8334E6025B2C70E863B3ED9FA995D355
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: CriticalHeapSectionmemcpy$AllocEnterLeaveProcessSleepfflushfwriterecv
                                  • String ID: [D] (%s) -> Got an event(size=%u,code=%08x(%.4s),sender=%016llx(%.8s),receiver=%016llx(%.8s))$[E] (%s) -> Memory allocation failed(size=%llu)$mem_alloc$routine_rx
                                  • API String ID: 3537583691-1494920791
                                  • Opcode ID: 31c41d8f3d353521e05e7039790eb1b398b2d1753936df8f63205f0b186b839b
                                  • Instruction ID: 346a5c17a0edfe2c8b2337add042a4ec645906ed541c52f8d066dc22ad1a1c0e
                                  • Opcode Fuzzy Hash: 31c41d8f3d353521e05e7039790eb1b398b2d1753936df8f63205f0b186b839b
                                  • Instruction Fuzzy Hash: 8B418CE6B09E4292EA15AB16E8543BA23A0FB44FA8F4444F7D91D437B4EF3CE465C300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: CriticalSection$CopyEnterFileLeavefflushfwrite
                                  • String ID: .$1$C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\rdpctl.log$kernel32
                                  • API String ID: 513531256-1037688549
                                  • Opcode ID: 290cff32685f0655480806e3de325ceb6f6beb8475b13025fcd8d82ed4c7bc66
                                  • Instruction ID: c32afaab338c3f3c988f2508f3ffaaf74ea6de69d564bac917958625157538c6
                                  • Opcode Fuzzy Hash: 290cff32685f0655480806e3de325ceb6f6beb8475b13025fcd8d82ed4c7bc66
                                  • Instruction Fuzzy Hash: 5B41B132A0CE41C6F321AB92E8503BA675AFB897A4F4440B5DA4D43BB6CF3CE5858741
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: CriticalSection$CopyEnterFileLeavefflushfwrite
                                  • String ID: .$1$C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\main.log$service
                                  • API String ID: 513531256-4171087551
                                  • Opcode ID: ff03a3c64f5a0a3273bf4fcc8a7fdb10c483b7055a1fb86f620f71fefe6cafa4
                                  • Instruction ID: 00cccd9c940d547735f47d5daecf5c38971bd7c9b0f9431069f2b0c6e7f3c356
                                  • Opcode Fuzzy Hash: ff03a3c64f5a0a3273bf4fcc8a7fdb10c483b7055a1fb86f620f71fefe6cafa4
                                  • Instruction Fuzzy Hash: 3C415E21A086418AF320BB1CE8593AAF691FBB6780FC400B5EF4D5769DCF3CE5469764
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: _errno$strtol
                                  • String ID: (value != NULL)$C:/Projects/rdp/bot/codebase/ini.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> strtol failed(sec_name=%s,var_name=%s,radix=%d,s=%s,errno=%d)$ini_get_uint16
                                  • API String ID: 3596500743-1991603811
                                  • Opcode ID: 907f382a5ba98dec77372e742d60424ff237156aec945cc14e22ff214607486b
                                  • Instruction ID: d1328c19826f10a57ba20a3c6fd7f79dc6d19632ef4c3525fcb593fb7ca68555
                                  • Opcode Fuzzy Hash: 907f382a5ba98dec77372e742d60424ff237156aec945cc14e22ff214607486b
                                  • Instruction Fuzzy Hash: 0321BF22A08E4789E721AB16FC407AAB760BBE87A4F444071EE4C17674DF7DE896C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: _errno$_strtoui64
                                  • String ID: (value != NULL)$C:/Projects/rdp/bot/codebase/ini.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> _strtoi64 failed(sec_name=%s,var_name=%s,radix=%d,s=%s,errno=%d)$ini_get_uint64
                                  • API String ID: 3513630032-2210897324
                                  • Opcode ID: 9b0511abb579528206ab036c6171041c0e158e3b6c79a86c4ac1b033516cc75b
                                  • Instruction ID: 6cd042fb1a25eb64207e1d8ee7ba047db9bdca24838fa40a7010d48385164949
                                  • Opcode Fuzzy Hash: 9b0511abb579528206ab036c6171041c0e158e3b6c79a86c4ac1b033516cc75b
                                  • Instruction Fuzzy Hash: 0C217C21A08E4A9BF710DF16EC407AA2361FB447A4F444072EE8C476B5DFBCD945C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: _errno$_strtoui64
                                  • String ID: (value != NULL)$C:/Projects/rdp/bot/codebase/ini.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> _strtoi64 failed(sec_name=%s,var_name=%s,radix=%d,s=%s,errno=%d)$ini_get_uint64
                                  • API String ID: 3513630032-2210897324
                                  • Opcode ID: c0b0fbd09f3da1b4c45f6ef4981d212609730e8146d06a22dced7ad410dac946
                                  • Instruction ID: eb06dd2ec1219582567cd6ad3154736d949d15424da7dfbb2ddd03f2d5acd85f
                                  • Opcode Fuzzy Hash: c0b0fbd09f3da1b4c45f6ef4981d212609730e8146d06a22dced7ad410dac946
                                  • Instruction Fuzzy Hash: 3121AB22A08F4696E3219F5AE8407AE73A9BF447A4F4400BAEE4C47670DF7DE985C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: _errno$_strtoui64
                                  • String ID: (value != NULL)$C:/Projects/rdp/bot/codebase/ini.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> _strtoi64 failed(sec_name=%s,var_name=%s,radix=%d,s=%s,errno=%d)$ini_get_uint64
                                  • API String ID: 3513630032-2210897324
                                  • Opcode ID: 95c28f316ae3dced59099252dd5eb60debe0ef91a749774188ed2787cb9e6fd7
                                  • Instruction ID: 5eff5825f5eea9540e6d402efd8516438e78df71e8aa30256f56d0d5c5eda632
                                  • Opcode Fuzzy Hash: 95c28f316ae3dced59099252dd5eb60debe0ef91a749774188ed2787cb9e6fd7
                                  • Instruction Fuzzy Hash: BC219421A08E468AE721AF16FC407AA7764BBE87A4F444075EE4C57774DF7CE885C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: _errno$_strtoui64
                                  • String ID: (value != NULL)$C:/Projects/rdp/bot/codebase/ini.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> _strtoi64 failed(sec_name=%s,var_name=%s,radix=%d,s=%s,errno=%d)$ini_get_uint64
                                  • API String ID: 3513630032-2210897324
                                  • Opcode ID: 3a693b30f3fed3e0b5b27e4b3a7631ccc436d3eb64aac9c6a68fb11d98a42b4e
                                  • Instruction ID: e9f02320d6cd6aec39f7237fb84dc1dfc8900471a9849b6bf9de8e16916ccb63
                                  • Opcode Fuzzy Hash: 3a693b30f3fed3e0b5b27e4b3a7631ccc436d3eb64aac9c6a68fb11d98a42b4e
                                  • Instruction Fuzzy Hash: F7215961708E4286E261AF16B8407BA2370AB84BA8F4440B3EE5D47674DF7CE855C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: _errno$_strtoui64
                                  • String ID: (value != NULL)$C:/Projects/rdp/bot/codebase/ini.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> _strtoi64 failed(sec_name=%s,var_name=%s,radix=%d,s=%s,errno=%d)$ini_get_uint64
                                  • API String ID: 3513630032-2210897324
                                  • Opcode ID: afd57179b788ab8042d738f0ecd9690e60cdbfc3fc4c221921d7512056222b8c
                                  • Instruction ID: 24d307714faae5b41ed6944d594844631ff20d161a16c18a9a2d3e6c534cabe1
                                  • Opcode Fuzzy Hash: afd57179b788ab8042d738f0ecd9690e60cdbfc3fc4c221921d7512056222b8c
                                  • Instruction Fuzzy Hash: CF218261608E46C5E6619F16F8407AA7B60BB857B4F444072EF8C87776DF7DE845C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: _errno$_strtoui64
                                  • String ID: (value != NULL)$C:/Projects/rdp/bot/codebase/ini.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> _strtoi64 failed(sec_name=%s,var_name=%s,radix=%d,s=%s,errno=%d)$ini_get_uint64
                                  • API String ID: 3513630032-2210897324
                                  • Opcode ID: c98d56caddfe9f1803b30f6abedb8c54f4c40d8d5babb1193f961330c0d8c415
                                  • Instruction ID: 038dd727f577a87a9d5af0e0a5f2edefc1c92d2b0f301a57e40cebef8684d60b
                                  • Opcode Fuzzy Hash: c98d56caddfe9f1803b30f6abedb8c54f4c40d8d5babb1193f961330c0d8c415
                                  • Instruction Fuzzy Hash: 4E216222A18E8699E7119F96EC407AB7368BB447A8F845072EE4C47774EF3CE885C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: strcmp
                                  • String ID: (name != NULL)$(sec != NULL)$(var != NULL)$C:/Projects/rdp/bot/codebase/ini.c$NULL$[D] (%s) -> Done(sec=%s,name=%s,value=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[W] (%s) -> Failed(sec=%s,name=%s,err=%08x)$ini_get_var
                                  • API String ID: 1004003707-3780280517
                                  • Opcode ID: 90a1d6f335128956a62a7103d04ff1ad9150fa8fac7c4f88965bf51ef95dc4dc
                                  • Instruction ID: c7ead441ec6ab973680b06fab7902a4228b6380f4ccd26870aff1f78723a5814
                                  • Opcode Fuzzy Hash: 90a1d6f335128956a62a7103d04ff1ad9150fa8fac7c4f88965bf51ef95dc4dc
                                  • Instruction Fuzzy Hash: FF417EA1A0CE4792FB618B82E9403FC2359BF00368F4541BAEA5D065B5DFBDF646C300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: strcmp
                                  • String ID: (name != NULL)$(sec != NULL)$(var != NULL)$C:/Projects/rdp/bot/codebase/ini.c$NULL$[D] (%s) -> Done(sec=%s,name=%s,value=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[W] (%s) -> Failed(sec=%s,name=%s,err=%08x)$ini_get_var
                                  • API String ID: 1004003707-3780280517
                                  • Opcode ID: 2a494826ab3a02a5482b6e3f4126a8c6dab1ab56026e8cfd8e5de912d3562d2e
                                  • Instruction ID: 3b2612c384c648920c424a6786a5cd02df1af12b0bf36270a03946e2d1a43abb
                                  • Opcode Fuzzy Hash: 2a494826ab3a02a5482b6e3f4126a8c6dab1ab56026e8cfd8e5de912d3562d2e
                                  • Instruction Fuzzy Hash: DB412C61A08E4799FA20AB16FD407F86661BBB8368F4445B2EA4C271B5DF7CE945C300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: strcmp
                                  • String ID: (name != NULL)$(sec != NULL)$(var != NULL)$C:/Projects/rdp/bot/codebase/ini.c$NULL$[D] (%s) -> Done(sec=%s,name=%s,value=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[W] (%s) -> Failed(sec=%s,name=%s,err=%08x)$ini_get_var
                                  • API String ID: 1004003707-3780280517
                                  • Opcode ID: 26a8aec39e63d80b3a6a2e0af29e304c521df3c4844df0dd894cc3ea5f02c8db
                                  • Instruction ID: 1486b1311a1b13421b588244e7dfb7533c3917df780573eaaa5d2060f2f13285
                                  • Opcode Fuzzy Hash: 26a8aec39e63d80b3a6a2e0af29e304c521df3c4844df0dd894cc3ea5f02c8db
                                  • Instruction Fuzzy Hash: D9414CA1B09E4795FA50AB16E8403F462B0BB44B78F4481F3DA5D075B5DF7DEA69C300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: strcmp
                                  • String ID: (name != NULL)$(sec != NULL)$(var != NULL)$C:/Projects/rdp/bot/codebase/ini.c$NULL$[D] (%s) -> Done(sec=%s,name=%s,value=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[W] (%s) -> Failed(sec=%s,name=%s,err=%08x)$ini_get_var
                                  • API String ID: 1004003707-3780280517
                                  • Opcode ID: 72217337c509de583f68b329069bee542afed452c8429e3a1f904cfec3f1c659
                                  • Instruction ID: 69b6ca978eebd13b924dbcacd879ca2e5036e5303fe30311fa95d1ce72ae7a89
                                  • Opcode Fuzzy Hash: 72217337c509de583f68b329069bee542afed452c8429e3a1f904cfec3f1c659
                                  • Instruction Fuzzy Hash: B3416DA2A09E57D1FA148B12A8113F46A60BF84378F8400B2DB4D867B3EF7CE659C304
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: strcmp
                                  • String ID: (ini != NULL)$(name != NULL)$(sec != NULL)$C:/Projects/rdp/bot/codebase/ini.c$NULL$[D] (%s) -> Done(name=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[W] (%s) -> Failed(name=%s,err=%08x)$ini_get_sec
                                  • API String ID: 1004003707-386092548
                                  • Opcode ID: 618a3ba5102a25f4a4e99f73f7530d6141bd131dabe7675f288ecb13050b53f0
                                  • Instruction ID: 9186d8b023803b5577828eea4adf64e53236d94c5f13a842584219ec9e85d62b
                                  • Opcode Fuzzy Hash: 618a3ba5102a25f4a4e99f73f7530d6141bd131dabe7675f288ecb13050b53f0
                                  • Instruction Fuzzy Hash: C4416B61A08E4792FB118F82E8507FC6359BF053B8F4441BAEA5D1A1B1DF7DEA46C304
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: strcmp
                                  • String ID: (ini != NULL)$(name != NULL)$(sec != NULL)$C:/Projects/rdp/bot/codebase/ini.c$NULL$[D] (%s) -> Done(name=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[W] (%s) -> Failed(name=%s,err=%08x)$ini_get_sec
                                  • API String ID: 1004003707-386092548
                                  • Opcode ID: 87455912ead1290854d53aadc5de93c4cc76d8ea5eb4fad9aa8be9e6bc8e3c8b
                                  • Instruction ID: 9497f7a20767cba554cf34bf9d43bb4a03552c1e2bf3ae4b31ba33d7a0b4ae4e
                                  • Opcode Fuzzy Hash: 87455912ead1290854d53aadc5de93c4cc76d8ea5eb4fad9aa8be9e6bc8e3c8b
                                  • Instruction Fuzzy Hash: 2E414F61A08E4799FE21BB57FD403B46660BBF4768F4445B2E90D2A1B1DF7CE986D300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: strcmp
                                  • String ID: (ini != NULL)$(name != NULL)$(sec != NULL)$C:/Projects/rdp/bot/codebase/ini.c$NULL$[D] (%s) -> Done(name=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[W] (%s) -> Failed(name=%s,err=%08x)$ini_get_sec
                                  • API String ID: 1004003707-386092548
                                  • Opcode ID: 4ee169d75e5fef8cee7d4765d1123835c996cd13fb81b496226cd40a7a75204a
                                  • Instruction ID: 87af22bc57a3f71f245a479fd47aa716297ecc73f760f4ac3f6c0d67caf8eca6
                                  • Opcode Fuzzy Hash: 4ee169d75e5fef8cee7d4765d1123835c996cd13fb81b496226cd40a7a75204a
                                  • Instruction Fuzzy Hash: 10416EA1B08E4795FB24AB16E8403F46370AB50B78F4481F7DA5E175B1DF7DA56AC300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: strcmp
                                  • String ID: (ini != NULL)$(name != NULL)$(sec != NULL)$C:/Projects/rdp/bot/codebase/ini.c$NULL$[D] (%s) -> Done(name=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[W] (%s) -> Failed(name=%s,err=%08x)$ini_get_sec
                                  • API String ID: 1004003707-386092548
                                  • Opcode ID: 417fe31033794c81dc4fac87fe95a17616cb4ad367c15a763e8c33d239fb3119
                                  • Instruction ID: ce86bdd47b59638646e45eb52eb067ecee6f56f9f659de98044521f34ef6e7ba
                                  • Opcode Fuzzy Hash: 417fe31033794c81dc4fac87fe95a17616cb4ad367c15a763e8c33d239fb3119
                                  • Instruction Fuzzy Hash: 714100A1A09D57D1FA109B12E8553F46A50AF80378F4841B6DB0D867B3EE7DE656C304
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: strlen
                                  • String ID: .applied$????-pat$pkg$tch.pkg$update.p
                                  • API String ID: 39653677-1686225151
                                  • Opcode ID: fd8be1e0bde5d4174c07ae97815dca9be3a69ec8f04d504e3e11fc7cf0860efd
                                  • Instruction ID: a2c9392835f3ab6bfc303c48f924b48b651424c19acca699758313d215e25f6b
                                  • Opcode Fuzzy Hash: fd8be1e0bde5d4174c07ae97815dca9be3a69ec8f04d504e3e11fc7cf0860efd
                                  • Instruction Fuzzy Hash: 5421D91290C78345F7217A1D991C37D99914B27BD8FC49071DF9D0B79ADE2CE854C361
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: CriticalSection$CopyEnterFileLeavefflushfwrite
                                  • String ID: .$1$C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\dwlmgr.log
                                  • API String ID: 513531256-2729875187
                                  • Opcode ID: 881a5b53a5bb7506d09258d8e568057d3d55aabc544c6f286c9c88e1ab55bd9f
                                  • Instruction ID: 89b017880ca03b3ccb0907d0c162e49906747514e73680881b08211b2f1455b8
                                  • Opcode Fuzzy Hash: 881a5b53a5bb7506d09258d8e568057d3d55aabc544c6f286c9c88e1ab55bd9f
                                  • Instruction Fuzzy Hash: C7415F31A0CA8A86F320DB13EC503FA6360BB957A4F5400B1DA4D577F5EFADEA858710
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: CriticalSection$CopyEnterFileLeavefflushfwrite
                                  • String ID: .$1$C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\cnccli.log
                                  • API String ID: 513531256-3034662401
                                  • Opcode ID: e9fe6dcfa54ce63d27811a76ac8203d1c50aa696a46daedf3aa209349255c63d
                                  • Instruction ID: a2cfb68fbc0288f028737a926c3e52bb87ebb2bc509109d06ca6e5bbd317b30e
                                  • Opcode Fuzzy Hash: e9fe6dcfa54ce63d27811a76ac8203d1c50aa696a46daedf3aa209349255c63d
                                  • Instruction Fuzzy Hash: BD414F61A0CA418DF320BB16F8517FAA251FBE97A0F400075DA4D677A6DF2CE985C641
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: CriticalSection$CopyEnterFileLeavefflushfwrite
                                  • String ID: .$1$C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\evtsrv.log
                                  • API String ID: 513531256-1680544107
                                  • Opcode ID: c615f18cd2e190ad2369cd65d0a7030d48e7d55922bcfeb7a273152cb55ce53a
                                  • Instruction ID: ccc3de5c8e3d5f64f9d95e9a767234b0f74d13383f6ae50159ab728c2be4f47d
                                  • Opcode Fuzzy Hash: c615f18cd2e190ad2369cd65d0a7030d48e7d55922bcfeb7a273152cb55ce53a
                                  • Instruction Fuzzy Hash: AF414DB1B0CA8186F321AB12E8553BA6360AB89FA0F4444F7DA4D477A5CF3CE5A58740
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: CriticalSection$CopyEnterFileLeavefflushfwrite
                                  • String ID: .$1$C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\samctl.log
                                  • API String ID: 513531256-2115573132
                                  • Opcode ID: 0701abe5e6b4113c319c1a3fcfaf5a85de49f02ce8cf4394365a2b4eee2c185e
                                  • Instruction ID: c0301c9ff316f29333ac77477d96e8e865cff4d331c8767c5d17b6a1e7b762e3
                                  • Opcode Fuzzy Hash: 0701abe5e6b4113c319c1a3fcfaf5a85de49f02ce8cf4394365a2b4eee2c185e
                                  • Instruction Fuzzy Hash: E24152A1A0CA4296F320AB12E8543FA6A51FBD57B0F5000B5EB4D877A7DF3CE586C705
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: CriticalSection$CopyEnterFileLeavefflushfwrite
                                  • String ID: .$1$C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\prgmgr.log
                                  • API String ID: 513531256-2601447032
                                  • Opcode ID: d8a4d70d1091bcee7d7597d0687069c9020cfcc5d155bc2906374e90e94bd78c
                                  • Instruction ID: 15218be9ccc817619b14d66cf259967bd6829c71cf8751aceb6a143027e38c9e
                                  • Opcode Fuzzy Hash: d8a4d70d1091bcee7d7597d0687069c9020cfcc5d155bc2906374e90e94bd78c
                                  • Instruction Fuzzy Hash: 2A418021A0CA8186FB20AB96EC503BB22A9FB947A0F8411B5DA0D877B5DF2DE5558700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: _errno
                                  • String ID: (value != NULL)$C:/Projects/rdp/bot/codebase/ini.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> strtoul failed(sec_name=%s,var_name=%s,radix=%d,s=%s,errno=%d)$ini_get_uint32
                                  • API String ID: 2918714741-1670302297
                                  • Opcode ID: 91ba29964d5e43633be1b5e770adbf17932a663eca218fc6386b8ea3f266736c
                                  • Instruction ID: bd87183e19eff3f8b5f6deb218296e4e7e1a0edf7fb275e816f978ab638b1ee8
                                  • Opcode Fuzzy Hash: 91ba29964d5e43633be1b5e770adbf17932a663eca218fc6386b8ea3f266736c
                                  • Instruction Fuzzy Hash: 22218222A08E469AE721AF16FC407AA7760BBE87A4F444072EE4C57665DF7CD845CB00
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: CopyErrorFileLastfflushfwrite
                                  • String ID: NULL$[E] (%s) -> CopyFileA failed(src=%s,dst=%s,overwrite=%d,gle=%lu)$[E] (%s) -> Failed(src=%s,dst=%s,overwrite=%d,err=%08x)$[I] (%s) -> Done(src=%s,dst=%s,overwrite=%d)$fs_file_copy
                                  • API String ID: 2887799713-3464183404
                                  • Opcode ID: fd605aaf4db597eced6ced2d9d2d87b021e2d4b9aaba73da000a0e55a61a74d3
                                  • Instruction ID: f1433f093bd14d54d5d59e4ad7906142a6a9267c199d3f4c103e8c50dd996e67
                                  • Opcode Fuzzy Hash: fd605aaf4db597eced6ced2d9d2d87b021e2d4b9aaba73da000a0e55a61a74d3
                                  • Instruction Fuzzy Hash: D8418D5190C61E95FA247B0D950C375E6907F36B8CFD440B2CF8E0A69CEE6DAE819331
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: DeleteErrorFileLast
                                  • String ID: NULL$[E] (%s) -> DeleteFileA failed(path=%s,gle=%lu)$[E] (%s) -> Failed(path=%s,err=%08x)$[I] (%s) -> Done(path=%s)$fs_file_delete
                                  • API String ID: 2018770650-4119452840
                                  • Opcode ID: b632b39c16b9f4b3703e6e54833c6082dbce87455845bf215ca43283f0fd4c86
                                  • Instruction ID: ef37433f52f5b116416e487c48240dcc9e9dd96d8424d00346389ee75a7a6cee
                                  • Opcode Fuzzy Hash: b632b39c16b9f4b3703e6e54833c6082dbce87455845bf215ca43283f0fd4c86
                                  • Instruction Fuzzy Hash: 54314925E0D30EC6FA207B0CA9487BDA1405F77345FE514B2CF9E06399ED1CAC869322
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastsend
                                  • String ID: [E] (%s) -> !!!WTF!!!(sock=0x%llx,l=%d,n=%d)$[E] (%s) -> Invalid arguments(sock=0x%llx,p=0x%p,l=%d)$[E] (%s) -> send failed(sock=0x%llx,WSAgle=%d)$tcp_recv$tcp_send
                                  • API String ID: 1802528911-690514478
                                  • Opcode ID: e062259bd43d2a03cc96d2b743a1224e8478a6f9752f452444a431d641df0616
                                  • Instruction ID: 619e875e42fba6fbf887cbc577786022294f1671e65772b0883bc181cd0a9926
                                  • Opcode Fuzzy Hash: e062259bd43d2a03cc96d2b743a1224e8478a6f9752f452444a431d641df0616
                                  • Instruction Fuzzy Hash: EC21CF19B08D1289EA306B27BD40AB952416FB8BF0F6403B1DC2C7B6F5CE2CB445C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastsend
                                  • String ID: [E] (%s) -> !!!WTF!!!(sock=0x%llx,l=%d,n=%d)$[E] (%s) -> Invalid arguments(sock=0x%llx,p=0x%p,l=%d)$[E] (%s) -> send failed(sock=0x%llx,WSAgle=%d)$tcp_recv$tcp_send
                                  • API String ID: 1802528911-690514478
                                  • Opcode ID: 75c57b4803f513cc00bf28dd4b7e33e098bdbc37b9468f2d07df0aead4d443a2
                                  • Instruction ID: b20483bf383a38759a956013d101573df1f0091fb9fb981992cf03249afbf3a5
                                  • Opcode Fuzzy Hash: 75c57b4803f513cc00bf28dd4b7e33e098bdbc37b9468f2d07df0aead4d443a2
                                  • Instruction Fuzzy Hash: 4721FF91B18E0241E6206727A8A06B953A0AF05FF4F4483F3ED3C47AF9DF2DB4218300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastsetsockopt
                                  • String ID: [E] (%s) -> setsockopt(SO_RCVTIMEO) failed(sock=0x%llx,value=%d,WSAgle=%d)$[E] (%s) -> setsockopt(SO_SNDTIMEO) failed(sock=0x%llx,value=%d,WSAgle=%d)$tcp_set_timeo
                                  • API String ID: 1729277954-887953274
                                  • Opcode ID: a8a822929329817c646cbce2d4e361976d30dcb38590b87bac484261df8b9273
                                  • Instruction ID: 1f8346aac7f068e2429bb9035cf412927d6a82c0e96b5bba0e2eed78c724cdce
                                  • Opcode Fuzzy Hash: a8a822929329817c646cbce2d4e361976d30dcb38590b87bac484261df8b9273
                                  • Instruction Fuzzy Hash: DD113371A1894A87F760DB17AC044796660AF88774F1042B5E9AD83BF4DFFCD5198B00
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastsetsockopt
                                  • String ID: [E] (%s) -> setsockopt(SO_RCVTIMEO) failed(sock=0x%llx,value=%d,WSAgle=%d)$[E] (%s) -> setsockopt(SO_SNDTIMEO) failed(sock=0x%llx,value=%d,WSAgle=%d)$tcp_set_timeo
                                  • API String ID: 1729277954-887953274
                                  • Opcode ID: 3ba9905c85f0b21fd7e894e96f07bcb23402eeca7c15dd9aa80b4b2fa724bb98
                                  • Instruction ID: 87509217975cf1b4493ef45a30c91ba02e85c2175e4ea8b3d598f2e455393d8b
                                  • Opcode Fuzzy Hash: 3ba9905c85f0b21fd7e894e96f07bcb23402eeca7c15dd9aa80b4b2fa724bb98
                                  • Instruction Fuzzy Hash: 4011E271A0CA8286E3209B67E8000696668FF88770F104379E96E83BF4DFBCD5498B01
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastsetsockopt
                                  • String ID: [E] (%s) -> setsockopt(SO_RCVTIMEO) failed(sock=0x%llx,value=%d,WSAgle=%d)$[E] (%s) -> setsockopt(SO_SNDTIMEO) failed(sock=0x%llx,value=%d,WSAgle=%d)$tcp_set_timeo
                                  • API String ID: 1729277954-887953274
                                  • Opcode ID: 6379c91b5731d717c0f3b6262f2420aa8a6b144e231e77b39eb1e399a8ede991
                                  • Instruction ID: 428733479d68b223181de4be78af5e6b512d97d686d0aaea3e682ad4d277dd33
                                  • Opcode Fuzzy Hash: 6379c91b5731d717c0f3b6262f2420aa8a6b144e231e77b39eb1e399a8ede991
                                  • Instruction Fuzzy Hash: C2113675A189428AF320BB17F8005A9A661AFE8764F104275E95DA3AB4DF7CD549CB00
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastsetsockopt
                                  • String ID: [E] (%s) -> setsockopt(SO_RCVTIMEO) failed(sock=0x%llx,value=%d,WSAgle=%d)$[E] (%s) -> setsockopt(SO_SNDTIMEO) failed(sock=0x%llx,value=%d,WSAgle=%d)$tcp_set_timeo
                                  • API String ID: 1729277954-887953274
                                  • Opcode ID: efe5f0d0443900c824ac0ecae0eee080c4f220c923adaaa28da585d9a2211f5d
                                  • Instruction ID: e30d174d36040ecd6e0fdc7726ab83708345d9661f68512abf477711045edfba
                                  • Opcode Fuzzy Hash: efe5f0d0443900c824ac0ecae0eee080c4f220c923adaaa28da585d9a2211f5d
                                  • Instruction Fuzzy Hash: 8A1121B1B0894646E250AB17A8005B66770EF98B64F5042B7EA6D83AB4DF7CD51ACB00
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastsetsockopt
                                  • String ID: [E] (%s) -> setsockopt(SO_RCVTIMEO) failed(sock=0x%llx,value=%d,WSAgle=%d)$[E] (%s) -> setsockopt(SO_SNDTIMEO) failed(sock=0x%llx,value=%d,WSAgle=%d)$tcp_set_timeo
                                  • API String ID: 1729277954-887953274
                                  • Opcode ID: 595f278b8cb7e5ecd8ef4898eedba44af6b209527af487a0ff7d6983d01de273
                                  • Instruction ID: 34a56ad31dee3a41f1b3141fe95341e68a7835429ff6c0a63ac6c4c38ad9604d
                                  • Opcode Fuzzy Hash: 595f278b8cb7e5ecd8ef4898eedba44af6b209527af487a0ff7d6983d01de273
                                  • Instruction Fuzzy Hash: 1A11D670618D4286F3209B17A444076AA61AFC8774F104275EB6D83BF3DF7CD509CB00
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastsetsockopt
                                  • String ID: [E] (%s) -> setsockopt(SO_RCVTIMEO) failed(sock=0x%llx,value=%d,WSAgle=%d)$[E] (%s) -> setsockopt(SO_SNDTIMEO) failed(sock=0x%llx,value=%d,WSAgle=%d)$tcp_set_timeo
                                  • API String ID: 1729277954-887953274
                                  • Opcode ID: 965785d7ab7d92e0704bde05fb8876d09001233a2ee5dad71bbbf6162b0393d8
                                  • Instruction ID: f7283f629b7c5daacf95ceda7177fd133839d824f97f78351d3dad6f755dc1cd
                                  • Opcode Fuzzy Hash: 965785d7ab7d92e0704bde05fb8876d09001233a2ee5dad71bbbf6162b0393d8
                                  • Instruction Fuzzy Hash: 7011B671A1C94286E710AB9BEC00567AAA4FF887A4F505271EA6D837F4DF7CD5068B01
                                  APIs
                                  Strings
                                  • [D] (%s) -> Dispatch an event(size=%u,timestamp=%lld,code=%08x(%.4s),sender=%016llx(%.8s),receiver=%016llx(%.8s)), xrefs: 00007FFE1A45350E
                                  • routine_tx, xrefs: 00007FFE1A453507
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: CriticalSection$EnterHeapLeave$FreeProcess
                                  • String ID: [D] (%s) -> Dispatch an event(size=%u,timestamp=%lld,code=%08x(%.4s),sender=%016llx(%.8s),receiver=%016llx(%.8s))$routine_tx
                                  • API String ID: 2539320189-3555278722
                                  • Opcode ID: 89816472452a277170d6f847842745fb66cf2df46b1e7d352c300a1510bda61f
                                  • Instruction ID: 8fe737fac6b781984dc669e606477c656391dcbf654ecfb2e3d109397ccc5ddf
                                  • Opcode Fuzzy Hash: 89816472452a277170d6f847842745fb66cf2df46b1e7d352c300a1510bda61f
                                  • Instruction Fuzzy Hash: 2031F9B1B08E4282EA259B12E89027963B0EB45FA4F1441F7DA6E43B74DF3CF4618340
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: Sleep
                                  • String ID: /$[W] (%s) -> Not a valid event received(size=%u,suid=%llx,packed_event_sz=%u,event_sz=%u)$[W] (%s) -> Not a valid packet received(size=%u,suid=%llx)$routine_rx
                                  • API String ID: 3472027048-1600310168
                                  • Opcode ID: bd8907607193d04b0b746e095c4958e2ce26e3d534a5acf4106b3ad7b865447c
                                  • Instruction ID: 3648b7db0e1db63fbe9d725991f8e4ab5472636aa3aa213524d5337289e23ce9
                                  • Opcode Fuzzy Hash: bd8907607193d04b0b746e095c4958e2ce26e3d534a5acf4106b3ad7b865447c
                                  • Instruction Fuzzy Hash: A0514A21E0CE534DFE30AB66BC403BA6251AFE8378F5042B1E56E676F5DE6CE945C600
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: AttributesErrorFileLast
                                  • String ID: (path != NULL)$C:/Projects/rdp/bot/codebase/fs.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$fs_path_exists
                                  • API String ID: 1799206407-4111913120
                                  • Opcode ID: f4f8ca6e4fc1f669f841e132278fecc6c365d377e5f726a2308636182496b49a
                                  • Instruction ID: 2a25bc3466328c13f593130cfc1020b6f81a59c49f6e675ecf27ea88b3cc97f4
                                  • Opcode Fuzzy Hash: f4f8ca6e4fc1f669f841e132278fecc6c365d377e5f726a2308636182496b49a
                                  • Instruction Fuzzy Hash: F921BA50E4DD43CAFB346A5AB844779A1409FB0379FB085B2D50FA91F0DE2CEC85D642
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: AttributesErrorFileLast
                                  • String ID: (path != NULL)$C:/Projects/rdp/bot/codebase/fs.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$fs_path_exists
                                  • API String ID: 1799206407-4111913120
                                  • Opcode ID: 5791759264d75a3a417900a43a506217477ce90d88af35a370718004647d8d75
                                  • Instruction ID: bdbfcf5ee682757445da6942159dfe1d88cd1ab64e0e33dc45ea36ca3933022f
                                  • Opcode Fuzzy Hash: 5791759264d75a3a417900a43a506217477ce90d88af35a370718004647d8d75
                                  • Instruction Fuzzy Hash: 6621E770E0CC9382FB2446DAAE48B7F91599F02735FA465B2E40E8A1F1CF5CFC859246
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: AttributesErrorFileLast
                                  • String ID: (path != NULL)$C:/Projects/rdp/bot/codebase/fs.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$fs_path_exists
                                  • API String ID: 1799206407-4111913120
                                  • Opcode ID: a3926301e1c0742d2235a749b79f787c5beb0c834c74044c1e987ba9a7664592
                                  • Instruction ID: 32a8b0e0ce6ddfd8df68f618f35abfefa04a2c7a21b3f0326caebc9b2ec049f9
                                  • Opcode Fuzzy Hash: a3926301e1c0742d2235a749b79f787c5beb0c834c74044c1e987ba9a7664592
                                  • Instruction Fuzzy Hash: 7021B650E2C48386FB20765C945C37991915F32309FE459B2EFAEC99D9CE3CF8859262
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastrecv
                                  • String ID: [D] (%s) -> Disconnected(sock=0x%llx)$[E] (%s) -> Invalid arguments(sock=0x%llx,p=0x%p,l=%d)$[E] (%s) -> recv failed(sock=0x%llx,WSAgle=%d)$tcp_recv
                                  • API String ID: 2514157807-65069805
                                  • Opcode ID: fc40e6edaa8fa7b1080357af52e10cb7cea27ec9b135f9fc78f50a74537f11a8
                                  • Instruction ID: d8d9a2b6924d63b6f2a7c24f9d2990bc8af4375195e88f1748505be17e0d367b
                                  • Opcode Fuzzy Hash: fc40e6edaa8fa7b1080357af52e10cb7cea27ec9b135f9fc78f50a74537f11a8
                                  • Instruction Fuzzy Hash: BC116A50E4CD8F82FA209767AC902B81250AF557F0F4113B0DCBD8A6F5EEDCE9568300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastrecv
                                  • String ID: [D] (%s) -> Disconnected(sock=0x%llx)$[E] (%s) -> Invalid arguments(sock=0x%llx,p=0x%p,l=%d)$[E] (%s) -> recv failed(sock=0x%llx,WSAgle=%d)$tcp_recv
                                  • API String ID: 2514157807-65069805
                                  • Opcode ID: 0e96e8ceabe4403754de825ae533e2122814fe55cf48ca520f1a4bc828f32c8d
                                  • Instruction ID: 59fcde386241d4ba033d88f6b88787e69fd55ee88f9f044b5ba0fd6e47bb3287
                                  • Opcode Fuzzy Hash: 0e96e8ceabe4403754de825ae533e2122814fe55cf48ca520f1a4bc828f32c8d
                                  • Instruction Fuzzy Hash: 65115164E0CE1791F7215B97A88167C125EAF067B4F5153F8DC3D876F2EE5CAA468300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastrecv
                                  • String ID: [D] (%s) -> Disconnected(sock=0x%llx)$[E] (%s) -> Invalid arguments(sock=0x%llx,p=0x%p,l=%d)$[E] (%s) -> recv failed(sock=0x%llx,WSAgle=%d)$tcp_recv
                                  • API String ID: 2514157807-65069805
                                  • Opcode ID: 76ea935c0bce3dd6aec93ac844d92415e9719370cc7bb794730bde63caadc0b7
                                  • Instruction ID: fdda6d77dac98894389c95f32b6be76e1ced30e4174b442a3a815c47f9edb7e3
                                  • Opcode Fuzzy Hash: 76ea935c0bce3dd6aec93ac844d92415e9719370cc7bb794730bde63caadc0b7
                                  • Instruction Fuzzy Hash: 26115B6CE0CD1649FA307717BC426B512406FF4BB4E6013B1D82DB66F6DE1CA546C301
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastrecv
                                  • String ID: [D] (%s) -> Disconnected(sock=0x%llx)$[E] (%s) -> Invalid arguments(sock=0x%llx,p=0x%p,l=%d)$[E] (%s) -> recv failed(sock=0x%llx,WSAgle=%d)$tcp_recv
                                  • API String ID: 2514157807-65069805
                                  • Opcode ID: ba4425752d638a4246313bb9637b71cb7cad2bd656f8008d4fc390104ada7b7c
                                  • Instruction ID: 8cab349bb5fea979eada7369b7f1960fcb33bc3997aa44f0f905e372d138b212
                                  • Opcode Fuzzy Hash: ba4425752d638a4246313bb9637b71cb7cad2bd656f8008d4fc390104ada7b7c
                                  • Instruction Fuzzy Hash: 3111BF92B0DE0351E5106757B8406B81260AF94FB4F4083F3F93D97AF1EE6CA922D700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastrecv
                                  • String ID: [D] (%s) -> Disconnected(sock=0x%llx)$[E] (%s) -> Invalid arguments(sock=0x%llx,p=0x%p,l=%d)$[E] (%s) -> recv failed(sock=0x%llx,WSAgle=%d)$tcp_recv
                                  • API String ID: 2514157807-65069805
                                  • Opcode ID: 0a37630b3d380bdfb3f3fd602d5d7a95be8cc216344c10ecf61644671f1c9a02
                                  • Instruction ID: c1234c4bba00ae3bf777ca1c4c50d7e5f42740b075ed20207bd49dda22ee1675
                                  • Opcode Fuzzy Hash: 0a37630b3d380bdfb3f3fd602d5d7a95be8cc216344c10ecf61644671f1c9a02
                                  • Instruction Fuzzy Hash: A5116A90F0CD5351EB20A7A6AC503BB1248AF107B0F8053B0D92E9AAF1EE1CF9068302
                                  APIs
                                  • LoadLibraryA.KERNEL32(?,?,service,000002BAD3D813D0,00007FF7BACD2910), ref: 00007FF7BACD2312
                                  • GetLastError.KERNEL32(?,?,service,000002BAD3D813D0,00007FF7BACD2910), ref: 00007FF7BACD233E
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastLibraryLoadfflushfwrite
                                  • String ID: [E] (%s) -> Failed(name=%s,gle=%lu)$[I] (%s) -> Done(name=%s,ret=0x%p)$module_load$service
                                  • API String ID: 4085810780-4145076245
                                  • Opcode ID: afa2715ad1d40dcdb6138738783ab23cee6b69dc419e77c1a9849a41664b9388
                                  • Instruction ID: 20c806460dff43d357d60df0ab5182029ad9a583b20075878c538fc4f2517c57
                                  • Opcode Fuzzy Hash: afa2715ad1d40dcdb6138738783ab23cee6b69dc419e77c1a9849a41664b9388
                                  • Instruction Fuzzy Hash: 2EF0E974E4A607A0FD61BB5DE8481B4A254AF77784FC800B1CE4C17B5CED2CB5429330
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Startupfflushfwrite
                                  • String ID: Done$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> WSAStartup failed(ret=%d)$[I] (%s) -> %s$net_init
                                  • API String ID: 3771387389-898331216
                                  • Opcode ID: bab2e39ec6692b915c421a0e347685575d46c63aa9fb390bc6655246fc116005
                                  • Instruction ID: 66f462eb510a47152c703d3323b3e21163dcff52521dc65cc67adda6fa3a49cb
                                  • Opcode Fuzzy Hash: bab2e39ec6692b915c421a0e347685575d46c63aa9fb390bc6655246fc116005
                                  • Instruction Fuzzy Hash: 32F01D64B08D4BD2FB10EB12EC853F92350AF607A4F4401F6D45E4A5F5EEDDE5598700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Startupfflushfwrite
                                  • String ID: Done$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> WSAStartup failed(ret=%d)$[I] (%s) -> %s$net_init
                                  • API String ID: 3771387389-898331216
                                  • Opcode ID: 5867243fe78a8a9678cdcbe041f3a43d3773ff52e058a36803f4b046501692db
                                  • Instruction ID: a2aafd08f44e5e81993b0f93b815cef2ca437301e010f37a69017197128f2199
                                  • Opcode Fuzzy Hash: 5867243fe78a8a9678cdcbe041f3a43d3773ff52e058a36803f4b046501692db
                                  • Instruction Fuzzy Hash: F9F03A60F08D0391FB12AF52E8947F8232AEF153A4F4800BAD44D4A2B2EF5CE6498740
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: Startupfflushfwrite
                                  • String ID: Done$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> WSAStartup failed(ret=%d)$[I] (%s) -> %s$net_init
                                  • API String ID: 3771387389-898331216
                                  • Opcode ID: e148c1505a25f62cb7a05b63b51d8fd1f84f4de33bb0dfc63fbfd9e7fb4bd7dc
                                  • Instruction ID: da64f56b355b646484032f324aa8ea547dde2681b5f70a4c9d6f3325b86dd8e3
                                  • Opcode Fuzzy Hash: e148c1505a25f62cb7a05b63b51d8fd1f84f4de33bb0dfc63fbfd9e7fb4bd7dc
                                  • Instruction Fuzzy Hash: 4FF0F969A18D4699FB20B717FC443F55250AFF97A4F4440B2D80D761B6EE2DE649C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: Startupfflushfwrite
                                  • String ID: Done$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> WSAStartup failed(ret=%d)$[I] (%s) -> %s$net_init
                                  • API String ID: 3771387389-898331216
                                  • Opcode ID: 2585bac7f94ac208da8aed220b95251551914fdb0870a766e68bdde5b4c7b006
                                  • Instruction ID: e1768f3548b32c91442fd5a2420493970ee3c15fa27d407145284440494cb77d
                                  • Opcode Fuzzy Hash: 2585bac7f94ac208da8aed220b95251551914fdb0870a766e68bdde5b4c7b006
                                  • Instruction Fuzzy Hash: BCF049A0B49D0281FB10AB12E8403F82370AF90FB4F8444F3D41D4B5B2EE6DE569C310
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: Startupfflushfwrite
                                  • String ID: Done$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> WSAStartup failed(ret=%d)$[I] (%s) -> %s$net_init
                                  • API String ID: 3771387389-898331216
                                  • Opcode ID: 7f8974921c108dd6a4f51004028284d201da0f61c2f87654e5b1ad4d1f08ae34
                                  • Instruction ID: a1654836ba1f4f93d476cb0c0b525dceaeaca95bddb653be3076083c5911d585
                                  • Opcode Fuzzy Hash: 7f8974921c108dd6a4f51004028284d201da0f61c2f87654e5b1ad4d1f08ae34
                                  • Instruction Fuzzy Hash: 7BF03C90A09C46D1FB209B12E8483F55A506FC8764F4400B6DB0D873B3AE5DE558C300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: Startupfflushfwrite
                                  • String ID: Done$[E] (%s) -> Failed(err=%08x)$[E] (%s) -> WSAStartup failed(ret=%d)$[I] (%s) -> %s$net_init
                                  • API String ID: 3771387389-898331216
                                  • Opcode ID: e3dde975791e3de8b401d5cfbee0aeead71d3cb9e73e6ec49a542f101dd95df3
                                  • Instruction ID: c930110f3009d4a667ed1e1bda237866eab9658782d227b5580edf3fb375176b
                                  • Opcode Fuzzy Hash: e3dde975791e3de8b401d5cfbee0aeead71d3cb9e73e6ec49a542f101dd95df3
                                  • Instruction Fuzzy Hash: 4AF017A1B0DE4391FF109B97EC453F62318AF107A4F8424B2D80E4A2B6EE2CE5498720
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: strlen$HandleModule_mbscpy
                                  • String ID: [E] (%s) -> Failed(pkg_path=%s,tgt_path=%s,err=%08x)$[I] (%s) -> Done(pkg_path=%s,tgt_path=%s)$package_install$service
                                  • API String ID: 3656010895-1379287937
                                  • Opcode ID: 243bcceac2b2cf495365e14ed80776c3980eeb34683763cf197341da1b5c127a
                                  • Instruction ID: dcbe5fc0ea45ad07b6185f76493258af2cbe588ab5a829480588015131023842
                                  • Opcode Fuzzy Hash: 243bcceac2b2cf495365e14ed80776c3980eeb34683763cf197341da1b5c127a
                                  • Instruction Fuzzy Hash: 9C31953260CA8791FB60BB58E4883E9A351EBA6344FD01472EB8E4768DEE7DD505C750
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: AddressErrorLastProcfflushfwrite
                                  • String ID: [D] (%s) -> Done(hnd=0x%p,name=%s,ret=0x%p)$[E] (%s) -> Failed(hnd=0x%p,name=%s,gle=%lu)$module_get_proc
                                  • API String ID: 1224403792-3063791425
                                  • Opcode ID: 841548102f0441e2b449492bf23c60b6e7a9478fbae2933be7f6227edc1bcd85
                                  • Instruction ID: 1b2b96bc154280881e2ab5a7af7af2aa6a88ef47cb4187e08c9338cfa02beba8
                                  • Opcode Fuzzy Hash: 841548102f0441e2b449492bf23c60b6e7a9478fbae2933be7f6227edc1bcd85
                                  • Instruction Fuzzy Hash: 27F06D90A09B8A92FA518B47AC015B967116F84BE4F1840B1DC8C0BBE5EEACA5568B00
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: AddressErrorLastProcfflushfwrite
                                  • String ID: [D] (%s) -> Done(hnd=0x%p,name=%s,ret=0x%p)$[E] (%s) -> Failed(hnd=0x%p,name=%s,gle=%lu)$module_get_proc
                                  • API String ID: 1224403792-3063791425
                                  • Opcode ID: fafc799aa92d9d60547a22b758ba0d3b5ae50fba84d732ef87da3ca2ea9f435e
                                  • Instruction ID: b4665eb7d5bf7c9b333cabbcc54a0b4b50e5e46566550dc777c0ab7d9078823f
                                  • Opcode Fuzzy Hash: fafc799aa92d9d60547a22b758ba0d3b5ae50fba84d732ef87da3ca2ea9f435e
                                  • Instruction Fuzzy Hash: D4F08691A0DF4791FB524B87E8401A9536A7F04BF5F4841B5DC4D077B5EE6CD6468300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: AddressErrorLastProcfflushfwrite
                                  • String ID: [D] (%s) -> Done(hnd=0x%p,name=%s,ret=0x%p)$[E] (%s) -> Failed(hnd=0x%p,name=%s,gle=%lu)$module_get_proc
                                  • API String ID: 1224403792-3063791425
                                  • Opcode ID: 3eb3fec21974d1c33607cd9f0875c61634fd29d425503903a865395fab3e12b1
                                  • Instruction ID: a35ac7f2ec86a6dd66502398595143512d0fdda740bb28caceaf081be69fafcd
                                  • Opcode Fuzzy Hash: 3eb3fec21974d1c33607cd9f0875c61634fd29d425503903a865395fab3e12b1
                                  • Instruction Fuzzy Hash: 45F0AD90A0DE0389FE62670BBC002B59251AFE8BE4F1880B1CC4D6B7B5EF2CA542D300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: AddressErrorLastProcfflushfwrite
                                  • String ID: [D] (%s) -> Done(hnd=0x%p,name=%s,ret=0x%p)$[E] (%s) -> Failed(hnd=0x%p,name=%s,gle=%lu)$module_get_proc
                                  • API String ID: 1224403792-3063791425
                                  • Opcode ID: dd80609e35f32fcee8c8c732da1e7394ae43990534841add2fd081b06968f394
                                  • Instruction ID: e6e376b8083a313f809dcaa3103c8cf13c6aacf133c8b774b69b88c776d893f9
                                  • Opcode Fuzzy Hash: dd80609e35f32fcee8c8c732da1e7394ae43990534841add2fd081b06968f394
                                  • Instruction Fuzzy Hash: 8BF06D90F09B4782FA15AB5BA8006B957616F44FE4F1840F3DD6E4B7B9EE2CA5668300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: AddressErrorLastProcfflushfwrite
                                  • String ID: [D] (%s) -> Done(hnd=0x%p,name=%s,ret=0x%p)$[E] (%s) -> Failed(hnd=0x%p,name=%s,gle=%lu)$module_get_proc
                                  • API String ID: 1224403792-3063791425
                                  • Opcode ID: d6f635ec5a0df26ccf6e6996869f1d90831f24c58e261922a5a0457e10abdacb
                                  • Instruction ID: 7da05196de2f9ce015e5f45b19a14c5a65559a9f6eb265ed910eaae36c3050e1
                                  • Opcode Fuzzy Hash: d6f635ec5a0df26ccf6e6996869f1d90831f24c58e261922a5a0457e10abdacb
                                  • Instruction Fuzzy Hash: 1AF0AD90B09A5381FA158B47E8001E6AA216FC4BF8F4840B1DF0C4B7B6FE2DA56AC304
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: AddressErrorLastProcfflushfwrite
                                  • String ID: [D] (%s) -> Done(hnd=0x%p,name=%s,ret=0x%p)$[E] (%s) -> Failed(hnd=0x%p,name=%s,gle=%lu)$module_get_proc
                                  • API String ID: 1224403792-3063791425
                                  • Opcode ID: 0279ee0fba7c6e178516fd32448990f9dbb55b2387454419a162d72c715561de
                                  • Instruction ID: cd190a78cc78940587662a6f917e353ebeeae1a993397093ebc04b5e94364ed8
                                  • Opcode Fuzzy Hash: 0279ee0fba7c6e178516fd32448990f9dbb55b2387454419a162d72c715561de
                                  • Instruction Fuzzy Hash: 8BF08150A09E5352FF119BD7AD006A767696F04BE0F8855B1DD4D0B7B4EE2CE5468300
                                  APIs
                                  • GetProcAddress.KERNEL32(?,?,00000000,000002BAD3D813D0,?,00007FF7BACD292B), ref: 00007FF7BACD22A3
                                  • GetLastError.KERNEL32(?,?,00000000,000002BAD3D813D0,?,00007FF7BACD292B), ref: 00007FF7BACD22D6
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: AddressErrorLastProcfflushfwrite
                                  • String ID: [D] (%s) -> Done(hnd=0x%p,name=%s,ret=0x%p)$[E] (%s) -> Failed(hnd=0x%p,name=%s,gle=%lu)$module_get_proc
                                  • API String ID: 1224403792-3063791425
                                  • Opcode ID: 1fc9960f30abe22bcb097999b6fdb8156779ff557b7e3ad85cbb521ca77be5c5
                                  • Instruction ID: 68955a5ac44da5bcf8b15e2509ea1159b75cbde148c44a100edfef685a9de5e3
                                  • Opcode Fuzzy Hash: 1fc9960f30abe22bcb097999b6fdb8156779ff557b7e3ad85cbb521ca77be5c5
                                  • Instruction Fuzzy Hash: 87F0D661A49647A1FA517B4DF8082B5D255BF76BD0F844071DE8C0BB5DEE2CE542A320
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastLibraryLoadfflushfwrite
                                  • String ID: [E] (%s) -> Failed(name=%s,gle=%lu)$[I] (%s) -> Done(name=%s,ret=0x%p)$module_load
                                  • API String ID: 4085810780-3386190286
                                  • Opcode ID: 5fddbdf422b911f2cfa20be25fea559564566e4750bc4449b058397c527fc971
                                  • Instruction ID: 6fff45a808bb1a81469a3a777170e3e1a1d2dfa2c2ccb0d1f64d1185cdab0659
                                  • Opcode Fuzzy Hash: 5fddbdf422b911f2cfa20be25fea559564566e4750bc4449b058397c527fc971
                                  • Instruction Fuzzy Hash: F2F05850E0AE8F92FE55E76BAC408B412506F44BB0B4805F2CC4D1A7F5EEECA99A8300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastLibraryLoadfflushfwrite
                                  • String ID: [E] (%s) -> Failed(name=%s,gle=%lu)$[I] (%s) -> Done(name=%s,ret=0x%p)$module_load
                                  • API String ID: 4085810780-3386190286
                                  • Opcode ID: 697fd883e4c98c3a111c703db0c1e2690921e3af5536f40dc2a3e64cf62ec6d9
                                  • Instruction ID: e4343cef7585882ab76bc06dbbd6aab6aabd1295e0c8134ca3afff971ccaf231
                                  • Opcode Fuzzy Hash: 697fd883e4c98c3a111c703db0c1e2690921e3af5536f40dc2a3e64cf62ec6d9
                                  • Instruction Fuzzy Hash: 79F08265E0DE4791FF52AB97F8904B81369AF19BB5F4804F5CC0D17B71EE5CA6858300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastLibraryLoadfflushfwrite
                                  • String ID: [E] (%s) -> Failed(name=%s,gle=%lu)$[I] (%s) -> Done(name=%s,ret=0x%p)$module_load
                                  • API String ID: 4085810780-3386190286
                                  • Opcode ID: 2d904e0336c752fe2b4ec070d29754f63c154fb52a4c8fd111e034c049b23102
                                  • Instruction ID: 4b2ab46a27879a7da7d6ad28544922ad37eb48a3eaa94028baccab3bb98353ed
                                  • Opcode Fuzzy Hash: 2d904e0336c752fe2b4ec070d29754f63c154fb52a4c8fd111e034c049b23102
                                  • Instruction Fuzzy Hash: 8AF03A54A0EE0788FE61B75FBC408B452506FF9BA4F4955B1C80D36376EE2CA586C300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastLibraryLoadfflushfwrite
                                  • String ID: [E] (%s) -> Failed(name=%s,gle=%lu)$[I] (%s) -> Done(name=%s,ret=0x%p)$module_load
                                  • API String ID: 4085810780-3386190286
                                  • Opcode ID: 510dd79922be8292572f51b1a03c4048553ca2c394016cbcf0cbdc80bd490f0b
                                  • Instruction ID: ea48477884a7cb98cd2fb153a6561f8532630acffbfd867b04848d83246a56d6
                                  • Opcode Fuzzy Hash: 510dd79922be8292572f51b1a03c4048553ca2c394016cbcf0cbdc80bd490f0b
                                  • Instruction Fuzzy Hash: 48F03A90F0AF0750EA11A76BA8405B026606F15FE4B4804F3CD1E57775FD2CA9A68350
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastLibraryLoadfflushfwrite
                                  • String ID: [E] (%s) -> Failed(name=%s,gle=%lu)$[I] (%s) -> Done(name=%s,ret=0x%p)$module_load
                                  • API String ID: 4085810780-3386190286
                                  • Opcode ID: ec556a9ea55f9255c441b329aff869bbd06fcc73dad67f2e20d2d58b0e07e6e5
                                  • Instruction ID: e4b5cb0212b8b0f9851376f9231c6a3e0afdb657405614741284d66192a2e6ed
                                  • Opcode Fuzzy Hash: ec556a9ea55f9255c441b329aff869bbd06fcc73dad67f2e20d2d58b0e07e6e5
                                  • Instruction Fuzzy Hash: 36F09A90B0AE1781F9519B17A8414E86E106F89BB4F8800B1CF0C97373FD9CA5AAC300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastLibraryLoadfflushfwrite
                                  • String ID: [E] (%s) -> Failed(name=%s,gle=%lu)$[I] (%s) -> Done(name=%s,ret=0x%p)$module_load
                                  • API String ID: 4085810780-3386190286
                                  • Opcode ID: 5fbb28a5f4c7af40752bc095f375c462acbc214c46beb02d6261729f1a54ccff
                                  • Instruction ID: b61386176c2584c8444e8ee932afc73a2809ceb6fea62dbf1d27c2ecf3099d5e
                                  • Opcode Fuzzy Hash: 5fbb28a5f4c7af40752bc095f375c462acbc214c46beb02d6261729f1a54ccff
                                  • Instruction Fuzzy Hash: 05F05E10E0EE5794EF11ABEBAC406B217685F05BA4F8864B1DD0D1B7B5FD1CB5868740
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Openstrcmpstrlen
                                  • String ID: SYSTEM\CurrentControlSet\Services\TermService\Parameters$ServiceDll$termsrv.dll
                                  • API String ID: 679246061-1413152910
                                  • Opcode ID: a669b3e55fb7fbdb9034081471d1f4139a13afc1e2d4e3c1df5cfdd1dd9f6d6b
                                  • Instruction ID: fd8d6ac1599e3906aa63dae4fad54b6c528548ee8e63835cb8c2839677fdd835
                                  • Opcode Fuzzy Hash: a669b3e55fb7fbdb9034081471d1f4139a13afc1e2d4e3c1df5cfdd1dd9f6d6b
                                  • Instruction Fuzzy Hash: E2217271A1CE8394EB319752A8803FE6359EF50368F8440B6E6DD465B9DF3CDA49C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastfflushfwriteioctlsocket
                                  • String ID: [E] (%s) -> ioctlsocket(FIONBIO) failed(sock=0x%llx,value=%d,WSAgle=%d)$sock_set_blocking
                                  • API String ID: 325303940-110789774
                                  • Opcode ID: 997ea10e0a0afaa560f16a201e8a6b0979890f832b0c0f9fc0be994573b025cc
                                  • Instruction ID: fbc918217d8ac7550a4f5dabd8ecba86b9fd5886864228cce339df898eec9984
                                  • Opcode Fuzzy Hash: 997ea10e0a0afaa560f16a201e8a6b0979890f832b0c0f9fc0be994573b025cc
                                  • Instruction Fuzzy Hash: BDF09661F0CA4A83F710976BAC001B95660EB947B8F5481B1EC6DC77F4EDBCE84A8B01
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastfflushfwriteioctlsocket
                                  • String ID: [E] (%s) -> ioctlsocket(FIONBIO) failed(sock=0x%llx,value=%d,WSAgle=%d)$sock_set_blocking
                                  • API String ID: 325303940-110789774
                                  • Opcode ID: a1b16873526868662f2b8e44185e2007aaa97beb29f34de54a1bb7cc9e5aaaa1
                                  • Instruction ID: 7b48cc1ceb76bd9f9795f171d2bfc123979f3096147873b0a23483c5ecb9b641
                                  • Opcode Fuzzy Hash: a1b16873526868662f2b8e44185e2007aaa97beb29f34de54a1bb7cc9e5aaaa1
                                  • Instruction Fuzzy Hash: 06F06261F0CD0297F3505BABA8001A96668BB947B4F118375EC2E837B5EE7C9946C701
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastfflushfwriteioctlsocket
                                  • String ID: [E] (%s) -> ioctlsocket(FIONBIO) failed(sock=0x%llx,value=%d,WSAgle=%d)$sock_set_blocking
                                  • API String ID: 325303940-110789774
                                  • Opcode ID: b354aedee55958963019c6122c39cc69e1555e929ecb80dac140b4e119317628
                                  • Instruction ID: 5593005df048fb39d5df83bab265a827e635958a619582207ea4eb6f690381a5
                                  • Opcode Fuzzy Hash: b354aedee55958963019c6122c39cc69e1555e929ecb80dac140b4e119317628
                                  • Instruction Fuzzy Hash: 2CF04F65B08D028AF320676BBC005A55560AFE4BB4F6082B1ED5DA77B4EE7CE946C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastfflushfwriteioctlsocket
                                  • String ID: [E] (%s) -> ioctlsocket(FIONBIO) failed(sock=0x%llx,value=%d,WSAgle=%d)$sock_set_blocking
                                  • API String ID: 325303940-110789774
                                  • Opcode ID: 135a6f05bdc116822d5e610c2f15010f3701e696d6330d2acb47104c4ec000a3
                                  • Instruction ID: eb8133894a8324ec783c52aeba32cf9865608eea71a609a8709409581a3e0231
                                  • Opcode Fuzzy Hash: 135a6f05bdc116822d5e610c2f15010f3701e696d6330d2acb47104c4ec000a3
                                  • Instruction Fuzzy Hash: DDF068E1F08D0246F7106727A4005B55270AB94FB4F1481F3ED2D537B4DD3C99568701
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastfflushfwriteioctlsocket
                                  • String ID: [E] (%s) -> ioctlsocket(FIONBIO) failed(sock=0x%llx,value=%d,WSAgle=%d)$sock_set_blocking
                                  • API String ID: 325303940-110789774
                                  • Opcode ID: 72c6b5354f39e4f60dc1d2ca6b54408bdd8efb7eb36cfdec92208a0580954f27
                                  • Instruction ID: a4c4394170df1a6a09e99c0f42454aa798263eb7a26d00a7d6a4458467bc9154
                                  • Opcode Fuzzy Hash: 72c6b5354f39e4f60dc1d2ca6b54408bdd8efb7eb36cfdec92208a0580954f27
                                  • Instruction Fuzzy Hash: 51F06861B18A12C6F3105727A8401AA6A60ABD4BB4F144171EE6DC77B7EE7C9946C701
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastfflushfwriteioctlsocket
                                  • String ID: [E] (%s) -> ioctlsocket(FIONBIO) failed(sock=0x%llx,value=%d,WSAgle=%d)$sock_set_blocking
                                  • API String ID: 325303940-110789774
                                  • Opcode ID: 2d33a153289c306b5fce3851330099b23ac3c9fe11635c37375803fd0bd15f23
                                  • Instruction ID: c3059832a71ca8f3b37614c4c8419c76f4f62a31cc914f441e6dc103e457814d
                                  • Opcode Fuzzy Hash: 2d33a153289c306b5fce3851330099b23ac3c9fe11635c37375803fd0bd15f23
                                  • Instruction Fuzzy Hash: FFF0FC65F0CD4382F710AB9BAC002B75664AB84774F505171ED2D433F4DE3CE8468701
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastsetsockopt
                                  • String ID: [E] (%s) -> setsockopt(TCP_NODELAY) failed(sock=0x%llx,value=%d,WSAgle=%d)$tcp_set_nodelay
                                  • API String ID: 1729277954-3534120083
                                  • Opcode ID: 2def49b3e8dde4bc52cc6a915181034d1c7b828b8fc5a8572d795ea2fbbfeffa
                                  • Instruction ID: c6564845dc5e21386c5c28fcf1e322fc16817f54ec005f5f4b35ca4535875068
                                  • Opcode Fuzzy Hash: 2def49b3e8dde4bc52cc6a915181034d1c7b828b8fc5a8572d795ea2fbbfeffa
                                  • Instruction Fuzzy Hash: E6F09661B1894686F7109B27AC045BA6660EB987B4F148271ED6D837F8DEBCD949C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastsetsockopt
                                  • String ID: [E] (%s) -> setsockopt(TCP_NODELAY) failed(sock=0x%llx,value=%d,WSAgle=%d)$tcp_set_nodelay
                                  • API String ID: 1729277954-3534120083
                                  • Opcode ID: bb85fe7d9bbd166f945c4a08f9790791af09f0990742d847ed14dacead1f49e5
                                  • Instruction ID: 0adf58bc627a9dd790d5a8de38f09fbbdc452e3e6d2703aaa213675387d4b633
                                  • Opcode Fuzzy Hash: bb85fe7d9bbd166f945c4a08f9790791af09f0990742d847ed14dacead1f49e5
                                  • Instruction Fuzzy Hash: 8DF02B71B0C9428AF3105F67B8001AA2665AB88770F008375ED1D83BB4DF7CD949CB00
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastsetsockopt
                                  • String ID: [E] (%s) -> setsockopt(TCP_NODELAY) failed(sock=0x%llx,value=%d,WSAgle=%d)$tcp_set_nodelay
                                  • API String ID: 1729277954-3534120083
                                  • Opcode ID: 57e81dc25d0e2735cd4f3f4553f12b00c4549c20b6b19b168c977355f186c27b
                                  • Instruction ID: d61ecf7a0446121ec8eb3cd3ad1e95fecaeb7c63b1900d4777987dcfda5592cc
                                  • Opcode Fuzzy Hash: 57e81dc25d0e2735cd4f3f4553f12b00c4549c20b6b19b168c977355f186c27b
                                  • Instruction Fuzzy Hash: 29F09C65A0C9428DF3206F17BC005A55660AFE8774F1082B1ED5DA37B4DF7CD545C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastsetsockopt
                                  • String ID: [E] (%s) -> setsockopt(TCP_NODELAY) failed(sock=0x%llx,value=%d,WSAgle=%d)$tcp_set_nodelay
                                  • API String ID: 1729277954-3534120083
                                  • Opcode ID: 6f296f5ef29b4410b5240992c365a66909ad1a2542281a2a36cd03236096ca54
                                  • Instruction ID: 631307848caffcb4ed937b8a1a3f7f1b0d882e64e8a516b66d6a5fdc4a73c202
                                  • Opcode Fuzzy Hash: 6f296f5ef29b4410b5240992c365a66909ad1a2542281a2a36cd03236096ca54
                                  • Instruction Fuzzy Hash: 7BF09CA1B0890246E3106B57B8005B55670FB94BB5F4482B7ED6D837B4DE7CD956CB00
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastsetsockopt
                                  • String ID: [E] (%s) -> setsockopt(TCP_NODELAY) failed(sock=0x%llx,value=%d,WSAgle=%d)$tcp_set_nodelay
                                  • API String ID: 1729277954-3534120083
                                  • Opcode ID: a117d3b95be01c1d26287a382867f1caf9ae502f2f2b167c9d15ce388bd83f4f
                                  • Instruction ID: a18bcc63e48f795767897db361da633e24d01c4671178657a705d1ae5d27fd7f
                                  • Opcode Fuzzy Hash: a117d3b95be01c1d26287a382867f1caf9ae502f2f2b167c9d15ce388bd83f4f
                                  • Instruction Fuzzy Hash: 47F0F6A1A0891286F3105B17B8042A66A61ABC8770F0442B5FF6DC3BF7DF7CD989CB00
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastsetsockopt
                                  • String ID: [E] (%s) -> setsockopt(TCP_NODELAY) failed(sock=0x%llx,value=%d,WSAgle=%d)$tcp_set_nodelay
                                  • API String ID: 1729277954-3534120083
                                  • Opcode ID: a7b5a3e27d61408e24ef4262097601e5cd0ffd2068a5939ebe3b84e33d613beb
                                  • Instruction ID: cb2a71b02602d0ab2c0e725a7831b0356faab133829673c196dbf2f364ce400f
                                  • Opcode Fuzzy Hash: a7b5a3e27d61408e24ef4262097601e5cd0ffd2068a5939ebe3b84e33d613beb
                                  • Instruction Fuzzy Hash: 6CF0F6A2B0C94286F7109BABAC006A76664EB84774F445271EE6D837F4DF3CD546C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastsetsockopt
                                  • String ID: [E] (%s) -> setsockopt(SO_KEEPALIVE) failed(sock=0x%llx,value=%d,WSAgle=%d)$tcp_set_keepalive
                                  • API String ID: 1729277954-536111009
                                  • Opcode ID: 83077c85c346e4cc9edd0ec430fc601c2b0a2a9c7ae86faeb29d9e23a9128367
                                  • Instruction ID: 8ba155dd722f38b90a82489187d25bb9daacaf59d3c5a6ae8137a9542f7de18c
                                  • Opcode Fuzzy Hash: 83077c85c346e4cc9edd0ec430fc601c2b0a2a9c7ae86faeb29d9e23a9128367
                                  • Instruction Fuzzy Hash: F4F09661A1C9428DF3206B17B800565A660AFE87B4F1082B1E96DA37B4DE3CD549CB00
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: fflushfwritememsetstrchr
                                  • String ID: [D] (%s) -> %s$sam3_recv_rsp
                                  • API String ID: 3817172176-4292814133
                                  • Opcode ID: 2227c43b3338bd450b4eae028e79698311915104578b8c364eb7ae355b9b6c9a
                                  • Instruction ID: 581eef5082f989ba1fc35c9584c09778c025f12c0292cb72e9f30b36b9af39b4
                                  • Opcode Fuzzy Hash: 2227c43b3338bd450b4eae028e79698311915104578b8c364eb7ae355b9b6c9a
                                  • Instruction Fuzzy Hash: AA21AE11B0CF4649FA35756BAC1437D55404FA6BB4E1843B0EE7D6ABE1DE2CA481D341
                                  APIs
                                  Strings
                                  • ebus_dispatch, xrefs: 00007FFE1150A2EF
                                  • [D] (%s) -> Done(size=%u,code=%08x(%.4s),sender=%016llx(%.8s),receiver=%016llx(%.8s),td=%lld,err=%08x), xrefs: 00007FFE1150A2F6
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: CriticalSection$EnterLeave
                                  • String ID: [D] (%s) -> Done(size=%u,code=%08x(%.4s),sender=%016llx(%.8s),receiver=%016llx(%.8s),td=%lld,err=%08x)$ebus_dispatch
                                  • API String ID: 3168844106-1717220914
                                  • Opcode ID: ec7771e1e83ac3cc9bd1e3336a2124f394ccde0f83b3c0cf51d2ad677df23565
                                  • Instruction ID: 38c0cacfbadb942daf38755e26697fd5eda955bc85a06557e815c65f6d44d3ea
                                  • Opcode Fuzzy Hash: ec7771e1e83ac3cc9bd1e3336a2124f394ccde0f83b3c0cf51d2ad677df23565
                                  • Instruction Fuzzy Hash: D4215E32A08E82C1EB618F96E84016D73A9FB54BA4F184275DE8D47BB8DF3CE841C700
                                  APIs
                                  Strings
                                  • [D] (%s) -> Done(size=%u,code=%08x(%.4s),sender=%016llx(%.8s),receiver=%016llx(%.8s),td=%lld,err=%08x), xrefs: 00007FFE13226036
                                  • ebus_dispatch, xrefs: 00007FFE1322602F
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: CriticalSection$EnterLeave
                                  • String ID: [D] (%s) -> Done(size=%u,code=%08x(%.4s),sender=%016llx(%.8s),receiver=%016llx(%.8s),td=%lld,err=%08x)$ebus_dispatch
                                  • API String ID: 3168844106-1717220914
                                  • Opcode ID: 0d2c5e85bbeec01ed5dbfb1c4b04cb0874fbcf1eb32e2e4c82c4743cf51419ed
                                  • Instruction ID: a3db5600d691aecb1211b00a7d296438a4ad0e50d1e99d6a515540998d02c271
                                  • Opcode Fuzzy Hash: 0d2c5e85bbeec01ed5dbfb1c4b04cb0874fbcf1eb32e2e4c82c4743cf51419ed
                                  • Instruction Fuzzy Hash: E0213E32A08E46C9E760AF16F880169A360FBE8BB4F148171DA5E676B4DF3CE855C700
                                  APIs
                                  Strings
                                  • ebus_dispatch, xrefs: 00007FFE1024132F
                                  • [D] (%s) -> Done(size=%u,code=%08x(%.4s),sender=%016llx(%.8s),receiver=%016llx(%.8s),td=%lld,err=%08x), xrefs: 00007FFE10241336
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: CriticalSection$EnterLeave
                                  • String ID: [D] (%s) -> Done(size=%u,code=%08x(%.4s),sender=%016llx(%.8s),receiver=%016llx(%.8s),td=%lld,err=%08x)$ebus_dispatch
                                  • API String ID: 3168844106-1717220914
                                  • Opcode ID: a54e1ac1fbeda3552c73b3bf99aa8b967ebb31501520f89eb189004cd740223f
                                  • Instruction ID: 923a425b5dc2b19c2f2d099aaddc3e99a46db9e109d9e1d1b963e331541dd8df
                                  • Opcode Fuzzy Hash: a54e1ac1fbeda3552c73b3bf99aa8b967ebb31501520f89eb189004cd740223f
                                  • Instruction Fuzzy Hash: C8212C72A09E42C2EB64DF16E8402697B60EB84BB4F144171DB5D877B5DF3CD856C700
                                  APIs
                                  Strings
                                  • [D] (%s) -> Done(size=%u,code=%08x(%.4s),sender=%016llx(%.8s),receiver=%016llx(%.8s),td=%lld,err=%08x), xrefs: 00007FFE11EC1336
                                  • ebus_dispatch, xrefs: 00007FFE11EC132F
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: CriticalSection$EnterLeave
                                  • String ID: [D] (%s) -> Done(size=%u,code=%08x(%.4s),sender=%016llx(%.8s),receiver=%016llx(%.8s),td=%lld,err=%08x)$ebus_dispatch
                                  • API String ID: 3168844106-1717220914
                                  • Opcode ID: 7f831e8638b2e21ef89d0a88fef1dfe03948884cf0943f83d1e1e332d764cd1f
                                  • Instruction ID: d1802466f999ca27a23f750e49e627106a8b5deefce7c3fd6ad3e9a0a0182231
                                  • Opcode Fuzzy Hash: 7f831e8638b2e21ef89d0a88fef1dfe03948884cf0943f83d1e1e332d764cd1f
                                  • Instruction Fuzzy Hash: 59215132A08E42C1EB14DF97EC4026A67A8FB45BA4F545275DA5D877B4DF3CE851C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 4baa850ea32367f99f564dbd85c6b8d89eb68a121a44affb4fcb460d545b763e
                                  • Instruction ID: 243c65e8020480ae8509c53fd5f560e332456d1ca163a5e0c9912908f509b8db
                                  • Opcode Fuzzy Hash: 4baa850ea32367f99f564dbd85c6b8d89eb68a121a44affb4fcb460d545b763e
                                  • Instruction Fuzzy Hash: 38F05463B0810651FD53BA0CB4447B992421F723B5F8D09B28F990A6D9BE3EAC969220
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 1fa99dbfe3c0ae3303e941b713d6245083e29630d68c19c4364f68e429e4d30a
                                  • Instruction ID: ec380cc5c285f19dc7ed61e440c195cd0d550a018cbe7623b2d27e2da0ef7fda
                                  • Opcode Fuzzy Hash: 1fa99dbfe3c0ae3303e941b713d6245083e29630d68c19c4364f68e429e4d30a
                                  • Instruction Fuzzy Hash: 15F05463B0810651FD53BA0CB4447B992421F723B5F8D09B28F9D0A6D9BE3EAC969220
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 47be94292563895e537d5cde29b61123ba99bab4bc184283351cc113b9d5a01b
                                  • Instruction ID: 919015c4e7133e443f385b4e4556740eaa103b65cd24d4843d02912b9576e7a9
                                  • Opcode Fuzzy Hash: 47be94292563895e537d5cde29b61123ba99bab4bc184283351cc113b9d5a01b
                                  • Instruction Fuzzy Hash: BEF05463B0810651FD53BA0CB4457B992421F723B5F8D09B28F990B6D9BE3EAC969220
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 2796a4fda047bc9d9d8d2092542dfd42e2adf876a0c4b6754514bb1db6429f31
                                  • Instruction ID: 73d68e883f5c849d07aa08f80aa4878cd88439adaca888265e8e5d4e14520d54
                                  • Opcode Fuzzy Hash: 2796a4fda047bc9d9d8d2092542dfd42e2adf876a0c4b6754514bb1db6429f31
                                  • Instruction Fuzzy Hash: D1F05B53B0810655FD53BA0CB44477991421F72375F8D09B28F990A6D9BE3DAC969210
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: fb890878b09f2417daf7a18940c6da63fc9dd87647a05d628e5655eae9bb3537
                                  • Instruction ID: 144ff9696bddf674486843b26727b8c85d75b127c2bd5cffa83802367e29f833
                                  • Opcode Fuzzy Hash: fb890878b09f2417daf7a18940c6da63fc9dd87647a05d628e5655eae9bb3537
                                  • Instruction Fuzzy Hash: 4AF05463B0810651FD53BA0CB4447B992421F723B5F8D09B28F9D0A6D9BE3EAC969220
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 2796a4fda047bc9d9d8d2092542dfd42e2adf876a0c4b6754514bb1db6429f31
                                  • Instruction ID: 73d68e883f5c849d07aa08f80aa4878cd88439adaca888265e8e5d4e14520d54
                                  • Opcode Fuzzy Hash: 2796a4fda047bc9d9d8d2092542dfd42e2adf876a0c4b6754514bb1db6429f31
                                  • Instruction Fuzzy Hash: D1F05B53B0810655FD53BA0CB44477991421F72375F8D09B28F990A6D9BE3DAC969210
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: fb890878b09f2417daf7a18940c6da63fc9dd87647a05d628e5655eae9bb3537
                                  • Instruction ID: 144ff9696bddf674486843b26727b8c85d75b127c2bd5cffa83802367e29f833
                                  • Opcode Fuzzy Hash: fb890878b09f2417daf7a18940c6da63fc9dd87647a05d628e5655eae9bb3537
                                  • Instruction Fuzzy Hash: 4AF05463B0810651FD53BA0CB4447B992421F723B5F8D09B28F9D0A6D9BE3EAC969220
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 4baa850ea32367f99f564dbd85c6b8d89eb68a121a44affb4fcb460d545b763e
                                  • Instruction ID: 243c65e8020480ae8509c53fd5f560e332456d1ca163a5e0c9912908f509b8db
                                  • Opcode Fuzzy Hash: 4baa850ea32367f99f564dbd85c6b8d89eb68a121a44affb4fcb460d545b763e
                                  • Instruction Fuzzy Hash: 38F05463B0810651FD53BA0CB4447B992421F723B5F8D09B28F990A6D9BE3EAC969220
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 1fa99dbfe3c0ae3303e941b713d6245083e29630d68c19c4364f68e429e4d30a
                                  • Instruction ID: ec380cc5c285f19dc7ed61e440c195cd0d550a018cbe7623b2d27e2da0ef7fda
                                  • Opcode Fuzzy Hash: 1fa99dbfe3c0ae3303e941b713d6245083e29630d68c19c4364f68e429e4d30a
                                  • Instruction Fuzzy Hash: 15F05463B0810651FD53BA0CB4447B992421F723B5F8D09B28F9D0A6D9BE3EAC969220
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 47be94292563895e537d5cde29b61123ba99bab4bc184283351cc113b9d5a01b
                                  • Instruction ID: 919015c4e7133e443f385b4e4556740eaa103b65cd24d4843d02912b9576e7a9
                                  • Opcode Fuzzy Hash: 47be94292563895e537d5cde29b61123ba99bab4bc184283351cc113b9d5a01b
                                  • Instruction Fuzzy Hash: BEF05463B0810651FD53BA0CB4457B992421F723B5F8D09B28F990B6D9BE3EAC969220
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 47be94292563895e537d5cde29b61123ba99bab4bc184283351cc113b9d5a01b
                                  • Instruction ID: 919015c4e7133e443f385b4e4556740eaa103b65cd24d4843d02912b9576e7a9
                                  • Opcode Fuzzy Hash: 47be94292563895e537d5cde29b61123ba99bab4bc184283351cc113b9d5a01b
                                  • Instruction Fuzzy Hash: BEF05463B0810651FD53BA0CB4457B992421F723B5F8D09B28F990B6D9BE3EAC969220
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 2796a4fda047bc9d9d8d2092542dfd42e2adf876a0c4b6754514bb1db6429f31
                                  • Instruction ID: 73d68e883f5c849d07aa08f80aa4878cd88439adaca888265e8e5d4e14520d54
                                  • Opcode Fuzzy Hash: 2796a4fda047bc9d9d8d2092542dfd42e2adf876a0c4b6754514bb1db6429f31
                                  • Instruction Fuzzy Hash: D1F05B53B0810655FD53BA0CB44477991421F72375F8D09B28F990A6D9BE3DAC969210
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: fb890878b09f2417daf7a18940c6da63fc9dd87647a05d628e5655eae9bb3537
                                  • Instruction ID: 144ff9696bddf674486843b26727b8c85d75b127c2bd5cffa83802367e29f833
                                  • Opcode Fuzzy Hash: fb890878b09f2417daf7a18940c6da63fc9dd87647a05d628e5655eae9bb3537
                                  • Instruction Fuzzy Hash: 4AF05463B0810651FD53BA0CB4447B992421F723B5F8D09B28F9D0A6D9BE3EAC969220
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 7ff4f935a0e7efc509331f44364ecea8fb99d43b10d137736ca2d1964f8f1081
                                  • Instruction ID: 22861003e376fe72eed57583a681a6b7125b7a1b64abe501e3246b873d8e1ae7
                                  • Opcode Fuzzy Hash: 7ff4f935a0e7efc509331f44364ecea8fb99d43b10d137736ca2d1964f8f1081
                                  • Instruction Fuzzy Hash: CFF05B53B0810651FD53BA0CB44477991421F72364F8D09B28F9D0B6D9BE3DAC969210
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 4baa850ea32367f99f564dbd85c6b8d89eb68a121a44affb4fcb460d545b763e
                                  • Instruction ID: 243c65e8020480ae8509c53fd5f560e332456d1ca163a5e0c9912908f509b8db
                                  • Opcode Fuzzy Hash: 4baa850ea32367f99f564dbd85c6b8d89eb68a121a44affb4fcb460d545b763e
                                  • Instruction Fuzzy Hash: 38F05463B0810651FD53BA0CB4447B992421F723B5F8D09B28F990A6D9BE3EAC969220
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 1fa99dbfe3c0ae3303e941b713d6245083e29630d68c19c4364f68e429e4d30a
                                  • Instruction ID: ec380cc5c285f19dc7ed61e440c195cd0d550a018cbe7623b2d27e2da0ef7fda
                                  • Opcode Fuzzy Hash: 1fa99dbfe3c0ae3303e941b713d6245083e29630d68c19c4364f68e429e4d30a
                                  • Instruction Fuzzy Hash: 15F05463B0810651FD53BA0CB4447B992421F723B5F8D09B28F9D0A6D9BE3EAC969220
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 9303b2e73d1f21f3a53bf0e74cb2595b6792b49952dc4c628fb5bbef4c6401bd
                                  • Instruction ID: 7429711888b8113e56f8c9459e243e8752fbdb95d4e1329ce7ca301305cd8f1b
                                  • Opcode Fuzzy Hash: 9303b2e73d1f21f3a53bf0e74cb2595b6792b49952dc4c628fb5bbef4c6401bd
                                  • Instruction Fuzzy Hash: E5F05463B0810651FD53BA0CB4447B992421F723B5F8D09B28F990A6D9BE3EAC969220
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 9303b2e73d1f21f3a53bf0e74cb2595b6792b49952dc4c628fb5bbef4c6401bd
                                  • Instruction ID: 7429711888b8113e56f8c9459e243e8752fbdb95d4e1329ce7ca301305cd8f1b
                                  • Opcode Fuzzy Hash: 9303b2e73d1f21f3a53bf0e74cb2595b6792b49952dc4c628fb5bbef4c6401bd
                                  • Instruction Fuzzy Hash: E5F05463B0810651FD53BA0CB4447B992421F723B5F8D09B28F990A6D9BE3EAC969220
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 9303b2e73d1f21f3a53bf0e74cb2595b6792b49952dc4c628fb5bbef4c6401bd
                                  • Instruction ID: 7429711888b8113e56f8c9459e243e8752fbdb95d4e1329ce7ca301305cd8f1b
                                  • Opcode Fuzzy Hash: 9303b2e73d1f21f3a53bf0e74cb2595b6792b49952dc4c628fb5bbef4c6401bd
                                  • Instruction Fuzzy Hash: E5F05463B0810651FD53BA0CB4447B992421F723B5F8D09B28F990A6D9BE3EAC969220
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 2796a4fda047bc9d9d8d2092542dfd42e2adf876a0c4b6754514bb1db6429f31
                                  • Instruction ID: 73d68e883f5c849d07aa08f80aa4878cd88439adaca888265e8e5d4e14520d54
                                  • Opcode Fuzzy Hash: 2796a4fda047bc9d9d8d2092542dfd42e2adf876a0c4b6754514bb1db6429f31
                                  • Instruction Fuzzy Hash: D1F05B53B0810655FD53BA0CB44477991421F72375F8D09B28F990A6D9BE3DAC969210
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: fb890878b09f2417daf7a18940c6da63fc9dd87647a05d628e5655eae9bb3537
                                  • Instruction ID: 144ff9696bddf674486843b26727b8c85d75b127c2bd5cffa83802367e29f833
                                  • Opcode Fuzzy Hash: fb890878b09f2417daf7a18940c6da63fc9dd87647a05d628e5655eae9bb3537
                                  • Instruction Fuzzy Hash: 4AF05463B0810651FD53BA0CB4447B992421F723B5F8D09B28F9D0A6D9BE3EAC969220
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 4baa850ea32367f99f564dbd85c6b8d89eb68a121a44affb4fcb460d545b763e
                                  • Instruction ID: 243c65e8020480ae8509c53fd5f560e332456d1ca163a5e0c9912908f509b8db
                                  • Opcode Fuzzy Hash: 4baa850ea32367f99f564dbd85c6b8d89eb68a121a44affb4fcb460d545b763e
                                  • Instruction Fuzzy Hash: 38F05463B0810651FD53BA0CB4447B992421F723B5F8D09B28F990A6D9BE3EAC969220
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 1fa99dbfe3c0ae3303e941b713d6245083e29630d68c19c4364f68e429e4d30a
                                  • Instruction ID: ec380cc5c285f19dc7ed61e440c195cd0d550a018cbe7623b2d27e2da0ef7fda
                                  • Opcode Fuzzy Hash: 1fa99dbfe3c0ae3303e941b713d6245083e29630d68c19c4364f68e429e4d30a
                                  • Instruction Fuzzy Hash: 15F05463B0810651FD53BA0CB4447B992421F723B5F8D09B28F9D0A6D9BE3EAC969220
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 47be94292563895e537d5cde29b61123ba99bab4bc184283351cc113b9d5a01b
                                  • Instruction ID: 919015c4e7133e443f385b4e4556740eaa103b65cd24d4843d02912b9576e7a9
                                  • Opcode Fuzzy Hash: 47be94292563895e537d5cde29b61123ba99bab4bc184283351cc113b9d5a01b
                                  • Instruction Fuzzy Hash: BEF05463B0810651FD53BA0CB4457B992421F723B5F8D09B28F990B6D9BE3EAC969220
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 3787b264349805c3f2e146bafce26e6071b31fa2ce125b22b29e845be593ce53
                                  • Instruction ID: 1b693a6134813ed3472029db86e7dcbdcea410f3aee1c3ab9e9fecb8210a8be2
                                  • Opcode Fuzzy Hash: 3787b264349805c3f2e146bafce26e6071b31fa2ce125b22b29e845be593ce53
                                  • Instruction Fuzzy Hash: 15F09662608F4E83E5528F02FC403BD6255AF417B4F4801B6ED9D466F4EFADD9899700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 6470fc9d1d3c22d2aeb0edb3da20f8fec96e8fd10e0b1d1327b3b09f566962b1
                                  • Instruction ID: fbbb3cc7762fe6d4bd8f238b55b4c16905cc0d79932ec4baf73042a1753fcd11
                                  • Opcode Fuzzy Hash: 6470fc9d1d3c22d2aeb0edb3da20f8fec96e8fd10e0b1d1327b3b09f566962b1
                                  • Instruction Fuzzy Hash: 0FF0F622608F0E83E552CF02FC403BD2244AF407B4F4802B6ED8D466F4EFADD9898700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 9693e49df37661324c830eed715e65ea3fab7e6ae61be3aa30e6675c6512d582
                                  • Instruction ID: 7764d6c81d1a13a2baf8f6acc434ffc37cb5b70e6684aae824ab5b249e88acd8
                                  • Opcode Fuzzy Hash: 9693e49df37661324c830eed715e65ea3fab7e6ae61be3aa30e6675c6512d582
                                  • Instruction Fuzzy Hash: B0F09662608F4E83E552CF02FC403BD6255AF417B4F4801B6ED9D466F4EFADD9899700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 60c5f8e22a2949e27c745340d96f2c89e003dc503e943f142536a8d784ae8074
                                  • Instruction ID: 7ea5394a2f6877cc38d093b00948661793f08788da6791993a101381e52d796e
                                  • Opcode Fuzzy Hash: 60c5f8e22a2949e27c745340d96f2c89e003dc503e943f142536a8d784ae8074
                                  • Instruction Fuzzy Hash: 7EF06262608B4E82E5528F02BC403B96255AF417B4F4801B6ED9D466F4EFADDA899700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: ddd441fecf9825be158138d3e89adceed430b0210fddd248ec8933bdfd9c2ef5
                                  • Instruction ID: 7d7ff70dddbc197dda84e41745796c091da43f0b5e5278653c37817144c0e823
                                  • Opcode Fuzzy Hash: ddd441fecf9825be158138d3e89adceed430b0210fddd248ec8933bdfd9c2ef5
                                  • Instruction Fuzzy Hash: 1AF09662608F4E83E652CF12FC403BD6255AF407B4F4802B6ED9D466F4EFADD9899700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 090d597a9b1f28875ad6d45f6679cbd5da47c45444663eb49efbe71bafab15ff
                                  • Instruction ID: f692ff175ee90543bc815fb776beeafad38dbfe42db2873a4859dc4cf4e2fa49
                                  • Opcode Fuzzy Hash: 090d597a9b1f28875ad6d45f6679cbd5da47c45444663eb49efbe71bafab15ff
                                  • Instruction Fuzzy Hash: 6DF0F622618F4A42E7528F41BC403BD624DAF417B8F08027ADD5D466B0DF3CD9898300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 7540e1a66fc6686d969aba4d5a662a22a3092066e406f677bd1371b9416a87bc
                                  • Instruction ID: fecfa64ad0af38932b7d1d1f6166b3944b3b1c3245c8cbe1313e8dbbea51b651
                                  • Opcode Fuzzy Hash: 7540e1a66fc6686d969aba4d5a662a22a3092066e406f677bd1371b9416a87bc
                                  • Instruction Fuzzy Hash: D3F0F622618F4A42E7538F41BC403BD224DAF417B8F08027ADD5D462B0DF3CDA898300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 9569925857baad9d83274aefa34eeb2a47794240e04e45bf96f4fb7c4f6da266
                                  • Instruction ID: 1e05dcf8ac2761afd10b0c8a3f9f4ba33463a697f37f97a76b901b30f65d2989
                                  • Opcode Fuzzy Hash: 9569925857baad9d83274aefa34eeb2a47794240e04e45bf96f4fb7c4f6da266
                                  • Instruction Fuzzy Hash: 62F09662618F4642E7529F41BC403BD625DAF457B8F08027ADD5D466B1DF3DD9899300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: e638fd45968e93b56570e475a3f40e1af91e8fb340a94d33487af47f6295cefe
                                  • Instruction ID: bded6a29cc02af10a85ab1fc2be91c8b804111a4155266df5ef31ffa9e7a790b
                                  • Opcode Fuzzy Hash: e638fd45968e93b56570e475a3f40e1af91e8fb340a94d33487af47f6295cefe
                                  • Instruction Fuzzy Hash: D9F0F622618E4A42E7628F41BC403BD224DAF417B8F08027ADD5D462B0DF3CD9898300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 1f1443341065272b26f8778fb621d4f4bce8ddecc7e485dcee93d47f1416b181
                                  • Instruction ID: 088b38f2320aee107fc4ebe3ea104e9abd9be5d9dd5255652d229cbb74f9f1d9
                                  • Opcode Fuzzy Hash: 1f1443341065272b26f8778fb621d4f4bce8ddecc7e485dcee93d47f1416b181
                                  • Instruction Fuzzy Hash: 0EF0F622718F4A42E7528F41BC403BD224DAF417B8F08027ADD5D462B1EF3CD9898300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 50bce3b7bf616760c42d00d66563879c40cc30f9e69380af2d925f2cf431fad1
                                  • Instruction ID: 0dac8e801666b9eea4159cbe542188dcbe3cff411adae91050eac767b8326164
                                  • Opcode Fuzzy Hash: 50bce3b7bf616760c42d00d66563879c40cc30f9e69380af2d925f2cf431fad1
                                  • Instruction Fuzzy Hash: 1DF0F662A08F064AE662AF12BC407B96254FFE47B4F080275ED5D566F0DF3CD98AD301
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 1d38aa518cd8cb70aaa1eb48d605735a9ea8bfb1ae1be2480bc1e9ba4e74c517
                                  • Instruction ID: 4abc9d7a8cd6f34b317bf1b6264df924ce69ec3af61e6bf20459c35f7f7256d7
                                  • Opcode Fuzzy Hash: 1d38aa518cd8cb70aaa1eb48d605735a9ea8bfb1ae1be2480bc1e9ba4e74c517
                                  • Instruction Fuzzy Hash: 3CF0F662A08E064AE662AF12BC407B96254FFE47B4F080175ED5C562F0DF3CD98AC300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 55f2d8677f6c725d11c004d8530db456bcec3bb002d427c848e4a1a5171d9bf3
                                  • Instruction ID: 566f4d687a2ff1f3339ea744e0d0696f66f9b12d86768362beaef9427c07e729
                                  • Opcode Fuzzy Hash: 55f2d8677f6c725d11c004d8530db456bcec3bb002d427c848e4a1a5171d9bf3
                                  • Instruction Fuzzy Hash: 37F0F662A08F064AE662AF12BC407B96254FFE47B4F080176ED5D562F0DF3CD98AC301
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 99d068cd179612c1ac27f654ff5c3bffab30fe45e6ed73a2eb49f776a9b7b215
                                  • Instruction ID: adf63701abc5844a4187a6c0a5e873ac77856ce08228ad40cab823fe119aee82
                                  • Opcode Fuzzy Hash: 99d068cd179612c1ac27f654ff5c3bffab30fe45e6ed73a2eb49f776a9b7b215
                                  • Instruction Fuzzy Hash: 7AF0F662A08F064AE662AF12BC407B96254FFE47B4F080176ED5D566F0DF3CD98AC301
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: cc24d5a41572f0b9054779423aa4415a2b35953dfb0d16ce3bc8e918d1e42980
                                  • Instruction ID: ad21fee1d9a13c1fdeef967e0fe60f114723f0d0a15c61f87366b328c94e6d2b
                                  • Opcode Fuzzy Hash: cc24d5a41572f0b9054779423aa4415a2b35953dfb0d16ce3bc8e918d1e42980
                                  • Instruction Fuzzy Hash: AFF0C262A08B0A4AE662AB12BC407B96254AFE47B4F080275ED5D562B0DF2CD98AC301
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: d7883f0e83be7938c30f7875dd83222e5db045926900550beb03412174322eaa
                                  • Instruction ID: 2d7139fb26cb7ee87a920331071c1f136cff884d1e2a556c5f54bfbbac52cbdb
                                  • Opcode Fuzzy Hash: d7883f0e83be7938c30f7875dd83222e5db045926900550beb03412174322eaa
                                  • Instruction Fuzzy Hash: A1F0F6A3708B0A42EA529F41BD403B56255BF41FB8F0802F7EE5D876A1EF3DD9998300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 1314e7eb479eee44c360a1dda5ebfda798b09de611a92089ca54b1cad1582c1c
                                  • Instruction ID: 1fffdaf3e64a93d209db71afc0426122688f924cd168c1e922b326b9dec8e544
                                  • Opcode Fuzzy Hash: 1314e7eb479eee44c360a1dda5ebfda798b09de611a92089ca54b1cad1582c1c
                                  • Instruction Fuzzy Hash: 12F0F6A3708B0A42E9529F41BD403B56255AF41FB8F4802F7EE5D876A2EF3DD9598300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 52ca38a0f41c609ff6feed84d880264454f237d8eec51bd4b63ad4a758567895
                                  • Instruction ID: cb5140a8a775e954e1c9b8c7a1ece8b9225c0ebf0e7c9d347ca6944117467fd3
                                  • Opcode Fuzzy Hash: 52ca38a0f41c609ff6feed84d880264454f237d8eec51bd4b63ad4a758567895
                                  • Instruction Fuzzy Hash: 54F0F6A3708A0A42E9529F41BD403B56255BF41FB4F4802F7EE5C876E1EF3DD9598300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 542d86327ba9c28ab8ec20c7288c7cbdfa14ef08d990c92e9d9a782d7052aa8a
                                  • Instruction ID: 2c01c13bcdee6257a0101692140429094ed1b1bd5b9d87d2b7289f4dbfadb51a
                                  • Opcode Fuzzy Hash: 542d86327ba9c28ab8ec20c7288c7cbdfa14ef08d990c92e9d9a782d7052aa8a
                                  • Instruction Fuzzy Hash: 4BF0F6A7708B0A42E9529F41BD403B56255EF41FB8F4802F7EE5D876A1EF3DDA598300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2485076859.00007FFE1A451000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FFE1A450000, based on PE: true
                                  • Associated: 0000000E.00000002.2485026464.00007FFE1A450000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485112540.00007FFE1A460000.00000002.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485132730.00007FFE1A468000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485218789.00007FFE1A46B000.00000004.00000001.01000000.00000009.sdmpDownload File
                                  • Associated: 0000000E.00000002.2485304937.00007FFE1A46C000.00000008.00000001.01000000.00000009.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe1a450000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 69f171f29a88397c0965eaea77cd01dbdd428adf63aaa7c2c2cec3eadda95624
                                  • Instruction ID: 2dd5cc90de3640323b0400737a5cb2e450f7ddf9836056960a03dde97ece0d8d
                                  • Opcode Fuzzy Hash: 69f171f29a88397c0965eaea77cd01dbdd428adf63aaa7c2c2cec3eadda95624
                                  • Instruction Fuzzy Hash: A4F0F6A3708B0A42E9529F41BD403B56255AF41FB8F4802F7EE5D876A1EF3DD9598700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 2de525bd892358ed90625d972d9654884f7263b8b6fc151aa038f3d36500a56e
                                  • Instruction ID: aec44ddafabe793b918cdb66dc4707dc0d5f4ad9b2040dc080108da210b573b1
                                  • Opcode Fuzzy Hash: 2de525bd892358ed90625d972d9654884f7263b8b6fc151aa038f3d36500a56e
                                  • Instruction Fuzzy Hash: A4F0F662A08A0A91E5528F01B8403B9BA54BFC07B4F444176EF1DC63B2EF2DE989D300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: a5b1a65c1664cf4ca3954329d89323b1914421e003bf91b17dbda7f137d406a3
                                  • Instruction ID: 6008cafd1103f0301c46746545f13f8bb97b1c8f0dc74fc1ebe196390085ef32
                                  • Opcode Fuzzy Hash: a5b1a65c1664cf4ca3954329d89323b1914421e003bf91b17dbda7f137d406a3
                                  • Instruction Fuzzy Hash: 82F0F662A08B0A91E5528F01B8403B9BA54BFC07B4F444276EF1DC63B2EF2DE989D300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 4d260aa501de199a9fa28ce901ea3f4f2d3f329601dbaea7c6a3156e5fb32778
                                  • Instruction ID: 1fff163548d87d1dc23c2e9974015a759238deb28f4bef91ab9439ccfe61ebc2
                                  • Opcode Fuzzy Hash: 4d260aa501de199a9fa28ce901ea3f4f2d3f329601dbaea7c6a3156e5fb32778
                                  • Instruction Fuzzy Hash: BAF0F662A08A0A91E5528F01B8403B9BA54FFC07B4F444176EF1DC63B2EF2DE989D300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 9c9e253ef25150492f77c9fdcebcbb4b0432c3996a4bfa578f81661baafe1c98
                                  • Instruction ID: 697cbae8d6dd0754574ae7cfe88e010b848af181d91d2c6cea52f54fadaa2fe7
                                  • Opcode Fuzzy Hash: 9c9e253ef25150492f77c9fdcebcbb4b0432c3996a4bfa578f81661baafe1c98
                                  • Instruction Fuzzy Hash: E9F0F662A08A0A92E5528F01B8403B9BA54BFC07B4F444176EF1DC67B2EF2DE989D300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: ca5c7dfc72b2e17d51c62d0c4d2562fa867c2ac92d1f36bbf7205825bb34c6af
                                  • Instruction ID: b708a35835875b97fb6c2e7f5e5a958d8e32b70457e35918f5117329429909fc
                                  • Opcode Fuzzy Hash: ca5c7dfc72b2e17d51c62d0c4d2562fa867c2ac92d1f36bbf7205825bb34c6af
                                  • Instruction Fuzzy Hash: 45F0FC52A08B0A91E5518F01B8403B57554BFC07B4F444175EF5DC67B2EF2DD989D300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: dfc3d5452ae4924382ea6fe93a0fbf9d4bc3aad60b172f611cf4cb8f220826fa
                                  • Instruction ID: 865976c47217a6dc972fc020065fe6f52cc4c7c658cfc36007e6b4143e060c49
                                  • Opcode Fuzzy Hash: dfc3d5452ae4924382ea6fe93a0fbf9d4bc3aad60b172f611cf4cb8f220826fa
                                  • Instruction Fuzzy Hash: 49F09C13A0CA4641E752DF91BC403B7625CAF407B4F840175DD5D467E0DF2DFA459700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: b4c4cdc361995d3af475825b5b9592a90d7172a47e3cb3fd7d6a7c25dfe11def
                                  • Instruction ID: 7648a2f62bd943bcb222eb3cf26851344e859881db3804f4df7d160461e922a0
                                  • Opcode Fuzzy Hash: b4c4cdc361995d3af475825b5b9592a90d7172a47e3cb3fd7d6a7c25dfe11def
                                  • Instruction Fuzzy Hash: FEF06223A08A4641EB52DF91BC403BB625CAF407B4F880176DD5D466E0EF2DFA8A9300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 167771c8c1c4554efda54008c580c9ff860e930fcaca6236bde73388e3653b50
                                  • Instruction ID: bf70345671271f3e6e3ebcbe30e483ba29fe51fc68d351a34719ec48912e5856
                                  • Opcode Fuzzy Hash: 167771c8c1c4554efda54008c580c9ff860e930fcaca6236bde73388e3653b50
                                  • Instruction Fuzzy Hash: BAF09623A0CA4641EB52DF91BC403BB625CBF407B4F880175DD5D466E0EF2DFA8A9300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: b65c7fc0dbd9a7b0299e0c2b8e0232ef07709154f27581d121896d02f68235f8
                                  • Instruction ID: 4919d6799bf9276306e7dff8f4bad38bdcd5d0c632e67abf5f15bd6ce57f4830
                                  • Opcode Fuzzy Hash: b65c7fc0dbd9a7b0299e0c2b8e0232ef07709154f27581d121896d02f68235f8
                                  • Instruction Fuzzy Hash: E1F06223A08A4641EB52DF91BC403BB625CAF407B5F880275DD5D466E0EF2DFA8A9300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 3cc0958dc823a3f95ba49ee48407de72d55fdcc69baeec2a75528ed6b1a49501
                                  • Instruction ID: 6fe03270a9d6831e09ee4b2c12cf2ee0ca3beed67f7bb5634ac7178aecf75b00
                                  • Opcode Fuzzy Hash: 3cc0958dc823a3f95ba49ee48407de72d55fdcc69baeec2a75528ed6b1a49501
                                  • Instruction Fuzzy Hash: 2CF06223A08A4641EB52DF91BC403BB625CAF407B4F880275DD5D466E0EF2DFA8A9300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: a0f005fceefb8e82cee0c1d8cbf4e62ea635758a479f9d1777f55c149fc0051b
                                  • Instruction ID: 6db733602e45b4804245e667e9ec6eab2b356f0a1badc456338dfd9b6f1e5ec6
                                  • Opcode Fuzzy Hash: a0f005fceefb8e82cee0c1d8cbf4e62ea635758a479f9d1777f55c149fc0051b
                                  • Instruction Fuzzy Hash: A3F04C2660834A81F552BF08F8483B9B254AF62794FC80276DF5C4BA88EF3CE9859310
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: a1ec69f4c8712f672cfade87aeab5974d39464317b52c9e07f38e400d49238b3
                                  • Instruction ID: cabfcc4b87703017c4c8c799c3eee60203ba003c263a57a16c30bd3bf0c3dde4
                                  • Opcode Fuzzy Hash: a1ec69f4c8712f672cfade87aeab5974d39464317b52c9e07f38e400d49238b3
                                  • Instruction Fuzzy Hash: 3FF0FC2660874A81F5527F08FC483B9B254AF62794FC80276DF5C4BA98DF3CE5899310
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 128564e3011a9d4c739a2c6f455a0b654ffdf6d148fc863d885cc2fd8148f5e1
                                  • Instruction ID: 13c1f6bc6a437fe089dbf2ab4f8fe4e9b5c2a214e09bf82a3bcc3b6930269676
                                  • Opcode Fuzzy Hash: 128564e3011a9d4c739a2c6f455a0b654ffdf6d148fc863d885cc2fd8148f5e1
                                  • Instruction Fuzzy Hash: 38F0FC2660874681F552BF08F8483B9B254AF62794F880276DF9D4BA98DF3CE9899310
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 5b72ae64b84b18650a09ac6363dcd029a3fe82bf69d366367befe2071cc93e9a
                                  • Instruction ID: 3400651b1c408d26273c9419e10c192da06843f3e1c9c496c03cbad51fdbdc60
                                  • Opcode Fuzzy Hash: 5b72ae64b84b18650a09ac6363dcd029a3fe82bf69d366367befe2071cc93e9a
                                  • Instruction Fuzzy Hash: 80F0FC2660874A82F552BF08F8483B9B254AF62794FC80276DF5D4BA98DF3CE9859310
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$registry_get_value
                                  • API String ID: 1001908780-1680961811
                                  • Opcode ID: 4927b445d6697eeb77b539b734dd78bf961b55804fc4d70544ee3474e2d44dc7
                                  • Instruction ID: 0226995efa889725bbf69a6f3cb6617bcab8bebf77e184557cad774d0a7acf4f
                                  • Opcode Fuzzy Hash: 4927b445d6697eeb77b539b734dd78bf961b55804fc4d70544ee3474e2d44dc7
                                  • Instruction Fuzzy Hash: 5BF0FC2660874A81F552BF08FC483B9B258EF62794FC80276DF5D4BA98DF3CE9859310
                                  APIs
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Sleepmemcpy
                                  • String ID:
                                  • API String ID: 1125407320-0
                                  • Opcode ID: fb84f6463fe680fa275dda8fb65c326a96006e217f1acf09d6a33ec17a0a7cad
                                  • Instruction ID: f4c93a237ec1e241574c16677d07080eb6cce776af3e94d1da6696d2e35a1a8f
                                  • Opcode Fuzzy Hash: fb84f6463fe680fa275dda8fb65c326a96006e217f1acf09d6a33ec17a0a7cad
                                  • Instruction Fuzzy Hash: DA311E20F18E4F83F770D727AC842B92251AF40734F5003F2D4BD566F6DEADA9896640
                                  APIs
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Sleepmemcpy
                                  • String ID:
                                  • API String ID: 1125407320-0
                                  • Opcode ID: 1712466607cc19edf77195b7408d88e3b6fb03c6fc7980baadae87da0139e872
                                  • Instruction ID: 1de9eb69fe1eb8d8befa859fd1b15402d7de81577cfd1d229b18327c1a1375c3
                                  • Opcode Fuzzy Hash: 1712466607cc19edf77195b7408d88e3b6fb03c6fc7980baadae87da0139e872
                                  • Instruction Fuzzy Hash: FB313E21E1CE0382F73197EBE8842BC235AAF46374F1803B9D47E466F5DE6CE6455282
                                  APIs
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484585677.00007FFE13221000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FFE13220000, based on PE: true
                                  • Associated: 0000000E.00000002.2484559489.00007FFE13220000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484636422.00007FFE13233000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484713223.00007FFE13234000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484787873.00007FFE1323D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484824285.00007FFE13240000.00000004.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484911935.00007FFE13241000.00000008.00000001.01000000.00000007.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484988899.00007FFE13244000.00000002.00000001.01000000.00000007.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe13220000_main.jbxd
                                  Similarity
                                  • API ID: Sleepmemcpy
                                  • String ID:
                                  • API String ID: 1125407320-0
                                  • Opcode ID: 802c4bf2ef1d69723389f337516ab35167bb485818cd60641b3131450e3edc32
                                  • Instruction ID: 8ba4d86a20bf33a83bef36314f3eb64f8bc5613360885ba391dc5a652c759418
                                  • Opcode Fuzzy Hash: 802c4bf2ef1d69723389f337516ab35167bb485818cd60641b3131450e3edc32
                                  • Instruction Fuzzy Hash: C8311A25E08E028AF630BB26BC843786251AFF4770F6007B1D5BD667F2CE6DB645E640
                                  APIs
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: Sleepmemcpy
                                  • String ID:
                                  • API String ID: 1125407320-0
                                  • Opcode ID: 31f2c3afba6f06f983378b2c262b5bf194ce88f71d24dd3fe1f977f8be1561fb
                                  • Instruction ID: 056976b811b0e814d676960407a12990bcf380eb50457b68023925e2d0343d1b
                                  • Opcode Fuzzy Hash: 31f2c3afba6f06f983378b2c262b5bf194ce88f71d24dd3fe1f977f8be1561fb
                                  • Instruction Fuzzy Hash: 8131D660B08F02D2F6209B27A8852B93E51AFC5770F2053B1DA7D86BF7EE2CA545D644
                                  APIs
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483895548.00007FFE11EC1000.00000020.00000001.01000000.0000000B.sdmp, Offset: 00007FFE11EC0000, based on PE: true
                                  • Associated: 0000000E.00000002.2483858550.00007FFE11EC0000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483959444.00007FFE11ED3000.00000002.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484044801.00007FFE11EDC000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484077580.00007FFE11EDF000.00000004.00000001.01000000.0000000B.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484133830.00007FFE11EE0000.00000008.00000001.01000000.0000000B.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11ec0000_main.jbxd
                                  Similarity
                                  • API ID: Sleepmemcpy
                                  • String ID:
                                  • API String ID: 1125407320-0
                                  • Opcode ID: d4928e6c661d6caba36c55ca416f4f350e7122a74768f68a3dc5570ea04a3a9d
                                  • Instruction ID: aac8a3822c5ab8f9979dd1374992364b74f22c162e862aba53e7f120166faea8
                                  • Opcode Fuzzy Hash: d4928e6c661d6caba36c55ca416f4f350e7122a74768f68a3dc5570ea04a3a9d
                                  • Instruction Fuzzy Hash: BB31EA20A0CE03C2FB319BABAC8537B225AAF44774F9017B5D47D86AF5DE2CF545A640
                                  APIs
                                    • Part of subcall function 00007FF7BACD1FD0: GetModuleHandleExA.KERNEL32(?,?,?,?,?,?,00007FF7BACD162F), ref: 00007FF7BACD1FEE
                                  • SleepEx.KERNEL32 ref: 00007FF7BACD1A51
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: HandleModuleSleep
                                  • String ID:
                                  • API String ID: 1071907932-0
                                  • Opcode ID: c8c003f471b71a30b05e0dbd92c2347c511595d06f4733816d1c0ed97604998d
                                  • Instruction ID: fad8d4355c6105e277f0249e6de5edcf22a61b9eb4aa256d72fcdf5df632a716
                                  • Opcode Fuzzy Hash: c8c003f471b71a30b05e0dbd92c2347c511595d06f4733816d1c0ed97604998d
                                  • Instruction Fuzzy Hash: 5E01A92171C64382F7503A5DE4583B9A2519BA5354FD43072EF8E5B2DDDE7CD9458320
                                  APIs
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: ServiceStatus
                                  • String ID:
                                  • API String ID: 3969395364-0
                                  • Opcode ID: e32b914f392c1bb68bce297dc10430292cf8290041b41d2df93b278c97710b2f
                                  • Instruction ID: ab9cdc1a56298e61ee80613f208f96d0dd9db5172faf18dd6ee5269a3b19052d
                                  • Opcode Fuzzy Hash: e32b914f392c1bb68bce297dc10430292cf8290041b41d2df93b278c97710b2f
                                  • Instruction Fuzzy Hash: C0D06774D19602C9F704BF0DE889024B7A0BF7B741BD090B5CB4D43228CE2C7A599764
                                  APIs
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2481739051.00007FF7BACD1000.00000020.00000001.01000000.00000006.sdmp, Offset: 00007FF7BACD0000, based on PE: true
                                  • Associated: 0000000E.00000002.2481714108.00007FF7BACD0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481760014.00007FF7BACE0000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACE8000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481780576.00007FF7BACEA000.00000004.00000001.01000000.00000006.sdmpDownload File
                                  • Associated: 0000000E.00000002.2481818019.00007FF7BACEE000.00000002.00000001.01000000.00000006.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ff7bacd0000_main.jbxd
                                  Similarity
                                  • API ID: rand_s
                                  • String ID:
                                  • API String ID: 863162693-0
                                  • Opcode ID: 9d1dea8f0649f6ea471d177bbf6b5905a76924c58d29f7228f0de2b116ca011d
                                  • Instruction ID: 91f0a7176cd7b52ee5d2ba54be3de7c1ef2539111ffca0f3b973211ddc19e007
                                  • Opcode Fuzzy Hash: 9d1dea8f0649f6ea471d177bbf6b5905a76924c58d29f7228f0de2b116ca011d
                                  • Instruction Fuzzy Hash: CCC04C36A18540CAD730EB24E855359B770F799308FD08151EA9D83668CB3CD61FCF54
                                  APIs
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483245989.00007FFE10241000.00000020.00000001.01000000.0000000E.sdmp, Offset: 00007FFE10240000, based on PE: true
                                  • Associated: 0000000E.00000002.2483206013.00007FFE10240000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483323686.00007FFE10254000.00000002.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483364192.00007FFE1025D000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483403761.00007FFE10260000.00000004.00000001.01000000.0000000E.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483482910.00007FFE10261000.00000008.00000001.01000000.0000000E.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe10240000_main.jbxd
                                  Similarity
                                  • API ID: CriticalEnterSection
                                  • String ID:
                                  • API String ID: 1904992153-0
                                  • Opcode ID: df13fde7c40af4feb2eb82e8b692fbb7fa95fd958b49ba1763114e1b7b31d811
                                  • Instruction ID: 64d24e8b47b2e6ae4335cdc7bb78c44ab7d6c6860b0a85809fc2fe9cca587ca8
                                  • Opcode Fuzzy Hash: df13fde7c40af4feb2eb82e8b692fbb7fa95fd958b49ba1763114e1b7b31d811
                                  • Instruction Fuzzy Hash: E1C08C91F1990283EB186763A8C107416206FDC330F4010B4EE6F86373AE5C98E9C204
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: strlen$strcat$CloseErrorHandleLastLogonUser
                                  • String ID: (app != NULL)$(pi != NULL)$(usr == NULL) || (pwd != NULL)$C:/Projects/rdp/bot/codebase/process.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> CreateProcessA failed(cmd=%s,gle=%lu)$[E] (%s) -> CreateProcessAsUserA failed(usr=%s,pwd=%s,cmd=%s,gle=%lu)$[E] (%s) -> Failed(usr=%s,pwd=%s,dir=%s,app=%s,arg=%s,err=%08x)$[E] (%s) -> LogonUserA failed(usr=%s,pwd=%s,cmd=%s,gle=%lu)$[I] (%s) -> CreateProcessA done(cmd=%s,pid=%lu)$[I] (%s) -> CreateProcessAsUserA done(usr=%s,pwd=%s,cmd=%s,pid=%lu)$[I] (%s) -> Done(usr=%s,pwd=%s,dir=%s,app=%s,arg=%s,pid=%lu)$h$process_create
                                  • API String ID: 1842180197-3127737957
                                  • Opcode ID: 44147f0eca4062257ca80a990bffced13053b235bce53c1a3c5539a3f3aaa508
                                  • Instruction ID: 3c12c3c2f1725c0f723d167812c4eb0bad900dc5f736c6e628d40f615ac8e982
                                  • Opcode Fuzzy Hash: 44147f0eca4062257ca80a990bffced13053b235bce53c1a3c5539a3f3aaa508
                                  • Instruction Fuzzy Hash: 25128EA290CE4392FB708B93E8403BD6298BB447B4F4405BBD94E476B4DF7CE6498742
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Heap$Process$AdaptersAllocInfo$Free
                                  • String ID: (adapter_num != NULL)$(pref_adapter_type != NULL)$C:/Projects/rdp/bot/codebase/net.c$[D] (%s) -> Adapter detected(name=%s,desc=%s,type=%d)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> GetAdaptersInfo failed(res=%08lx)$[E] (%s) -> GetBestInterface failed(res=%08lx)$[E] (%s) -> Memory allocation failed(size=%llu)$mem_alloc$net_info
                                  • API String ID: 2437369060-2367710237
                                  • Opcode ID: d36da1cc80b8a827c5ded2bf8d6e028523035197614a5e5e6860143e21c20d33
                                  • Instruction ID: 04176a79b6eada49dd7e458f7205ab3505db728d74631fe79a0fbd4e305093c2
                                  • Opcode Fuzzy Hash: d36da1cc80b8a827c5ded2bf8d6e028523035197614a5e5e6860143e21c20d33
                                  • Instruction Fuzzy Hash: 91513E61A09E4F86FB10DB27DC902F86360EF54764F4840B6E98E4A6F5EEECE945C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Find$ErrorFileLast$CloseFirstNextfflushfwritestrcpy
                                  • String ID: (name != NULL)$(path != NULL)$(resume_handle != NULL)$C:/Projects/rdp/bot/codebase/fs.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> FindFirstFileA failed(path=%s,gle=%lu)$[E] (%s) -> FindNextFileA failed(path=%s,gle=%lu)$fs_dir_list
                                  • API String ID: 4253334766-1535167640
                                  • Opcode ID: 6aadc2b219b212e17a858383751c278242b6d0d50526d6d0705503b6f386a0d3
                                  • Instruction ID: 2d0c0cf2b3c942db4f318e91478e8f781601170bfe5f8bca1fa53c7654756c1f
                                  • Opcode Fuzzy Hash: 6aadc2b219b212e17a858383751c278242b6d0d50526d6d0705503b6f386a0d3
                                  • Instruction Fuzzy Hash: D5611761E0CE4F83FB209B16BD443BC2250AB00775F5501F2E89E6BAF5DEECA9458742
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Find$ErrorFileLast$CloseFirstNextfflushfwritestrcpy
                                  • String ID: (name != NULL)$(path != NULL)$(resume_handle != NULL)$C:/Projects/rdp/bot/codebase/fs.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> FindFirstFileA failed(path=%s,gle=%lu)$[E] (%s) -> FindNextFileA failed(path=%s,gle=%lu)$fs_dir_list
                                  • API String ID: 4253334766-1535167640
                                  • Opcode ID: 0094431108ba3f5c5190efbdba4996ce3899097f65e245319e231a0f545943fc
                                  • Instruction ID: f3f484fa9c24982c640ad813e8e4ea4c49f856743d37c1c92333c227fdb00f5f
                                  • Opcode Fuzzy Hash: 0094431108ba3f5c5190efbdba4996ce3899097f65e245319e231a0f545943fc
                                  • Instruction Fuzzy Hash: F7614025E0CE4385FB615B96A4803BC7299AF01374F4805BAD85E4B2F5DFACE984C382
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLast$bindfflushfwritehtonlhtonslistensetsockoptsocket
                                  • String ID: [E] (%s) -> bind failed(sock=0x%llx,host=%08x,port=%u,WSAgle=%d)$[E] (%s) -> listen failed(sock=0x%llx,host=%08x,port=%u,WSAgle=%d)$[E] (%s) -> socket failed(host=%08x,port=%u,WSAgle=%d)$[I] (%s) -> Done(sock=0x%llx,host=%08x,port=%u)$tcp_listen
                                  • API String ID: 3590747132-3524496754
                                  • Opcode ID: d5e897e1aaa087f2d347b2d46b08636267edeac801a2d3536124c18d3f8c1a96
                                  • Instruction ID: 21f4a6fee81e92bc510b83a830cff631e5b80b88d9982947be5d75b4b8cf1e99
                                  • Opcode Fuzzy Hash: d5e897e1aaa087f2d347b2d46b08636267edeac801a2d3536124c18d3f8c1a96
                                  • Instruction Fuzzy Hash: EA317361A08E4A83EB20AB2BAC401B97790EF547B4F1407B5D9BE437F5DEBCE9058700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: _errno$fclosefflushfopenfseekfwrite
                                  • String ID: (((*buf) == NULL) || ((*buf_sz) > 0))$(buf_sz != NULL)$(path != NULL)$C:/Projects/rdp/bot/codebase/fs.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(path=%s,err=%08x)$[E] (%s) -> Memory allocation failed(size=%llu)$[E] (%s) -> fopen failed(path=%s,errno=%d)$[E] (%s) -> fread failed(path=%s,errno=%d)$[E] (%s) -> fread undone(path=%s,l=%ld,n=%ld)$[E] (%s) -> fseek(SEEK_END) failed(path=%s,errno=%d)$[E] (%s) -> fseek(SEEK_SET) failed(path=%s,errno=%d)$[E] (%s) -> ftell failed(path=%s,errno=%d)$[I] (%s) -> Done(path=%s,buf_sz=%llu)$fs_file_read$mem_alloc
                                  • API String ID: 2897271634-4120527733
                                  • Opcode ID: 58d5b68a868d91137c60689cf324d86add9f7a65a7f9d01c8a5330c5a1896d0d
                                  • Instruction ID: c8ac8942f69e52d133a05a9420fa593261910ec1367e8dcfaa36078da649f86c
                                  • Opcode Fuzzy Hash: 58d5b68a868d91137c60689cf324d86add9f7a65a7f9d01c8a5330c5a1896d0d
                                  • Instruction Fuzzy Hash: 82D13861A08E0B82FB10DB66FC403B82361EF507B5F5555B2D98E5BAF4DEBCE9468700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: _errno$fclosefflushfopenfseekfwrite
                                  • String ID: (((*buf) == NULL) || ((*buf_sz) > 0))$(buf_sz != NULL)$(path != NULL)$C:/Projects/rdp/bot/codebase/fs.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(path=%s,err=%08x)$[E] (%s) -> Memory allocation failed(size=%llu)$[E] (%s) -> fopen failed(path=%s,errno=%d)$[E] (%s) -> fread failed(path=%s,errno=%d)$[E] (%s) -> fread undone(path=%s,l=%ld,n=%ld)$[E] (%s) -> fseek(SEEK_END) failed(path=%s,errno=%d)$[E] (%s) -> fseek(SEEK_SET) failed(path=%s,errno=%d)$[E] (%s) -> ftell failed(path=%s,errno=%d)$[I] (%s) -> Done(path=%s,buf_sz=%llu)$fs_file_read$mem_alloc
                                  • API String ID: 2897271634-4120527733
                                  • Opcode ID: 95d49460dc818b3e80d8de5b21ae2c04c5fcdc35da095f5c456abc36f31e6c23
                                  • Instruction ID: 3f0a83bfeac2b76e12e305597a0560b949c73cb6255f3f2e9793fc40f642f8c5
                                  • Opcode Fuzzy Hash: 95d49460dc818b3e80d8de5b21ae2c04c5fcdc35da095f5c456abc36f31e6c23
                                  • Instruction Fuzzy Hash: 1CD18B62A0DE0391EB119B97E8503BC23AAAF457F4F4540BAC90E4B2B1DFBCE585C310
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Service$ErrorLast$DependentEnumHeapOpenServices$AllocCloseControlHandleProcessSleepfflushfwrite
                                  • String ID: $ $(svc != NULL)$C:/Projects/rdp/bot/codebase/scm.c$No dependent service(s) to be stopped$P$P$[D] (%s) -> %s$[D] (%s) -> Service is already stopped(lpServiceName=%s)$[D] (%s) -> Service stop requested(lpServiceName=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> ControlService(SERVICE_CONTROL_STOP) failed(lpServiceName=%s,gle=%lu)$[E] (%s) -> EnumDependentServicesA(SERVICE_STATE_ALL) failed(lpServiceName=%s,gle=%lu)$[E] (%s) -> Memory allocation failed(size=%llu)$[E] (%s) -> OpenServiceA(SERVICE_CONTROL_STOP) failed(lpServiceName=%s,gle=%lu)$[E] (%s) -> OpenServiceA(SERVICE_ENUMERATE_DEPENDENTS) failed(lpServiceName=%s,gle=%lu)$[E] (%s) -> Service stop failed(lpServiceName=%s,pid=%lu,err=%08x)$[I] (%s) -> EnumDependentServicesA(SERVICE_STATE_ALL) done(lpServiceName=%s,dep_num=%lu)$[I] (%s) -> Service stopped(lpServiceName=%s,pid=%lu)$[W] (%s) -> scm_find failed(lpServiceName=%s)$mem_alloc$scm_stop$~$~
                                  • API String ID: 1728296876-1811208690
                                  • Opcode ID: f6b4076402929f921958397003b3befe8e4b2cde3b81bb6dcf8e080ef3907e48
                                  • Instruction ID: fbec41bf41de03d36cf25f3721cc1c3506552b55215bec6297c6507ce4595fd5
                                  • Opcode Fuzzy Hash: f6b4076402929f921958397003b3befe8e4b2cde3b81bb6dcf8e080ef3907e48
                                  • Instruction Fuzzy Hash: BE126F61E0CF0386FB605787E880BBD125DAF55778F1440FACA4E466B6DEADA985C302
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: strlen$strcat$CloseErrorHandleLastLogonUser
                                  • String ID: (app != NULL)$(pi != NULL)$(usr == NULL) || (pwd != NULL)$C:/Projects/rdp/bot/codebase/process.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> CreateProcessA failed(cmd=%s,gle=%lu)$[E] (%s) -> CreateProcessAsUserA failed(usr=%s,pwd=%s,cmd=%s,gle=%lu)$[E] (%s) -> Failed(usr=%s,pwd=%s,dir=%s,app=%s,arg=%s,err=%08x)$[E] (%s) -> LogonUserA failed(usr=%s,pwd=%s,cmd=%s,gle=%lu)$[I] (%s) -> CreateProcessA done(cmd=%s,pid=%lu)$[I] (%s) -> CreateProcessAsUserA done(usr=%s,pwd=%s,cmd=%s,pid=%lu)$[I] (%s) -> Done(usr=%s,pwd=%s,dir=%s,app=%s,arg=%s,pid=%lu)$h$process_create
                                  • API String ID: 1842180197-3127737957
                                  • Opcode ID: 91d5cc4be0632d887239797a333ab1f121351889201fa55c62988aa2e63f0e81
                                  • Instruction ID: 277f1d539ec027798bc34d3a230f6c49217cec2f95858e7c652ac5cfa29d3730
                                  • Opcode Fuzzy Hash: 91d5cc4be0632d887239797a333ab1f121351889201fa55c62988aa2e63f0e81
                                  • Instruction Fuzzy Hash: D81280A190EE4F86FA709B13EC403B96291BB447A4F5441B2D98E476F4DEFCE949C701
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLast$Process$CloseHandleOpenTerminatestrcmp
                                  • String ID: $ $(name != NULL) || (pid != 0)$C:/Projects/rdp/bot/codebase/process.c$NULL$P$P$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> CreateToolhelp32Snapshot failed(gle=%lu)$[E] (%s) -> Failed(name=%s,pid=%lu,err=%08x)$[E] (%s) -> OpenProcess failed(gle=%lu)$[E] (%s) -> Process32First failed(gle=%lu)$[E] (%s) -> Process32Next failed(gle=%lu)$[E] (%s) -> TerminateProcess failed(gle=%lu)$[I] (%s) -> Done(name=%s,pid=%lu)$process_kill$|$~$~
                                  • API String ID: 2412365107-4109375376
                                  • Opcode ID: 8db4f565d0db8aad6615902c4b8094c6e450a968460a31bfeea8b32dc0ef4057
                                  • Instruction ID: eacc53d1ba8e4e964bbd4e1e984c33147e1c4a48bca9a6944d45741e0a5e0fc1
                                  • Opcode Fuzzy Hash: 8db4f565d0db8aad6615902c4b8094c6e450a968460a31bfeea8b32dc0ef4057
                                  • Instruction Fuzzy Hash: 1DF13815E1EE4F87FB608657ACC43B922429F15774F2401B2D98E066F2DDEEBC859202
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: strlen$DirectoryErrorLastRemovestrcmpstrcpy$fflushfwrite
                                  • String ID: (path != NULL)$*$C:/Projects/rdp/bot/codebase/fs.c$NULL$[D] (%s) -> Delete(path_wc=%s,f_path=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(path=%s,recursive=%d,err=%08x)$[E] (%s) -> RemoveDirectoryA failed(path=%s,recursive=%d,gle=%lu)$[I] (%s) -> Done(path=%s,recursive=%d)$fs_dir_delete
                                  • API String ID: 2460052984-4087913290
                                  • Opcode ID: 26f1af922d5ebc9079b911d7e4bf6bebecebb65ae47c2c1eade9d866be8a22ad
                                  • Instruction ID: 9af188f93c8638d2f659429f35a127fcaa9b099154ad76aa21833955c88f3f33
                                  • Opcode Fuzzy Hash: 26f1af922d5ebc9079b911d7e4bf6bebecebb65ae47c2c1eade9d866be8a22ad
                                  • Instruction Fuzzy Hash: 51A1B26190CE8E8BFB208B17BC443BD6351AF84764F5540B2DA8D466F9EEFCE8498701
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: strlen$DirectoryErrorLastRemovestrcmpstrcpy$fflushfwrite
                                  • String ID: (path != NULL)$*$C:/Projects/rdp/bot/codebase/fs.c$NULL$[D] (%s) -> Delete(path_wc=%s,f_path=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(path=%s,recursive=%d,err=%08x)$[E] (%s) -> RemoveDirectoryA failed(path=%s,recursive=%d,gle=%lu)$[I] (%s) -> Done(path=%s,recursive=%d)$fs_dir_delete
                                  • API String ID: 2460052984-4087913290
                                  • Opcode ID: 51ad9032e29619aec93c3608d2f578bfcac488de460c65f97f87e95cac6161ff
                                  • Instruction ID: 68c24ffbe963b5d697b3af2dcf3b2514dc0f30b38369abb34291716c5b9a5863
                                  • Opcode Fuzzy Hash: 51ad9032e29619aec93c3608d2f578bfcac488de460c65f97f87e95cac6161ff
                                  • Instruction Fuzzy Hash: 60A1EF21A0CE8395FB219B93E4443FE635AAF803E4F5804BAD94D476B5DFBCE9458B01
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: strlen$strcatstrcpy$strcmp
                                  • String ID: (dst != NULL)$(src != NULL)$*$C:/Projects/rdp/bot/codebase/fs.c$NULL$[D] (%s) -> Copy(f_src=%s,f_dst=%s)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(src=%s,dst=%s,err=%08x)$[I] (%s) -> Done(src=%s,dst=%s)$[I] (%s) -> Filtered(f_src=%s,flt=%s)$fs_dir_copy$|
                                  • API String ID: 2140730755-3699962909
                                  • Opcode ID: 7dcd5c13d9d8dd0a9773e803e60b51585db6b403c331d98dca1257e479660d22
                                  • Instruction ID: deb7d387ba6fb7c64857e9c6ae420970a6bd1cd3be25a25225fc6846becd348e
                                  • Opcode Fuzzy Hash: 7dcd5c13d9d8dd0a9773e803e60b51585db6b403c331d98dca1257e479660d22
                                  • Instruction Fuzzy Hash: ADC1816190CA8ECAFA20CB17BD443FD6251EB857A4F8440B2DA8D176E5DFEDE909C701
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorFileLast$CloseCreateHandleLock
                                  • String ID: $ $(lock != NULL)$(path != NULL)$C:/Projects/rdp/bot/codebase/fs.c$NULL$P$P$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> CreateFileA failed(path=%s,gle=%lu)$[E] (%s) -> Failed(path=%s,err=%08x)$[E] (%s) -> LockFileEx failed(path=%s,gle=%lu)$[I] (%s) -> Done(path=%s,lock=%p)$fs_file_lock$~$~
                                  • API String ID: 2747014929-4251196842
                                  • Opcode ID: 704981e107e05e0129ca2e9ec01e2c6c966bd2d82bb1131230a1c9ef7a36e905
                                  • Instruction ID: dcef3938355af80026c11f3fbfe0b1bd7cfac93c5a3be11973ee66d543243385
                                  • Opcode Fuzzy Hash: 704981e107e05e0129ca2e9ec01e2c6c966bd2d82bb1131230a1c9ef7a36e905
                                  • Instruction Fuzzy Hash: C9814C60D4CF8E83FB2AA716AD4037C32519F00774F1502B2D9AE066F1FEEDA9859653
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: ErrorFileLast$CloseCreateHandleLock
                                  • String ID: $ $(lock != NULL)$(path != NULL)$C:/Projects/rdp/bot/codebase/fs.c$NULL$P$P$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> CreateFileA failed(path=%s,gle=%lu)$[E] (%s) -> Failed(path=%s,err=%08x)$[E] (%s) -> LockFileEx failed(path=%s,gle=%lu)$[I] (%s) -> Done(path=%s,lock=%p)$fs_file_lock$~$~
                                  • API String ID: 2747014929-4251196842
                                  • Opcode ID: a664f431d0384db3085f0158279076aec845581227eba355486688f3ec06e6b2
                                  • Instruction ID: a926e91bafbd3ca487fbf6064cce3d68d2560b6b80cfd1b0ca67a3d894457135
                                  • Opcode Fuzzy Hash: a664f431d0384db3085f0158279076aec845581227eba355486688f3ec06e6b2
                                  • Instruction Fuzzy Hash: AC815420D4CF4A89F7B05B86E48137E22596F00774F1405BAC96E476F3EF9EA989D342
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastLocalToken$AllocInformation$CloseFreeHandleLengthOpenProcessfflushfwritememcpy
                                  • String ID: (hnd != NULL)$(sid != NULL)$C:/Projects/rdp/bot/codebase/process.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(hnd=0x%p,err=%08x)$[E] (%s) -> GetTokenInformation failed(hnd=0x%p,gle=%lu)$[E] (%s) -> OpenProcessToken failed(hnd=0x%p,gle=%lu)$process_get_user_sid
                                  • API String ID: 3826151639-1775164968
                                  • Opcode ID: 68207ade090d25bf802874d9709f6b9207fcde198e90ef34ef7b7da26412a7de
                                  • Instruction ID: 6bf5df1cfc6a66e8e9a79ec444aeadcb27248b86d4477eb2a1c23451ba461e3e
                                  • Opcode Fuzzy Hash: 68207ade090d25bf802874d9709f6b9207fcde198e90ef34ef7b7da26412a7de
                                  • Instruction Fuzzy Hash: 71916062F0CE5281FB615B96F84037D125AEF84774F2914BAD50E072F5EE3DE985A301
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: CloseOpenValuefflushfwrite
                                  • String ID: $ $ $ $(key != NULL)$(root != NULL)$C:/Projects/rdp/bot/codebase/registry.c$NULL$P$P$P$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$[E] (%s) -> RegOpenKeyA failed(root=0x%p,key=%s,res=%lu)$[E] (%s) -> RegSetValueExA failed(root=0x%p,key=%s,param=%s,res=%lu)$[I] (%s) -> Done(root=0x%p,key=%s,param=%s)$registry_set_value
                                  • API String ID: 716145365-86941537
                                  • Opcode ID: 5384ac0ee4a9e4bb19451bcca3ec91683df4e8ef98abd54195bb8da859f00dd1
                                  • Instruction ID: f036a743950cf5e85114f8911b7b6be193ff921c89889af685ef189b6f07969b
                                  • Opcode Fuzzy Hash: 5384ac0ee4a9e4bb19451bcca3ec91683df4e8ef98abd54195bb8da859f00dd1
                                  • Instruction Fuzzy Hash: 9A816D6194CF4F83FA30AB46AD402783250AF44BB4F1401B2D99E46AF9FEEDE9958345
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: CloseOpenValuefflushfwrite
                                  • String ID: $ $ $ $(key != NULL)$(root != NULL)$C:/Projects/rdp/bot/codebase/registry.c$NULL$P$P$P$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$[E] (%s) -> RegOpenKeyA failed(root=0x%p,key=%s,res=%lu)$[E] (%s) -> RegSetValueExA failed(root=0x%p,key=%s,param=%s,res=%lu)$[I] (%s) -> Done(root=0x%p,key=%s,param=%s)$registry_set_value
                                  • API String ID: 716145365-86941537
                                  • Opcode ID: 323139f66bf16ca94d1327e2aeac6fc6fa3c29ff571b33d5149d3581ee6bf9ff
                                  • Instruction ID: d25bfdb3275149a9022c1acf9f1dadf04c55f70df31c64af567f6d10055519a5
                                  • Opcode Fuzzy Hash: 323139f66bf16ca94d1327e2aeac6fc6fa3c29ff571b33d5149d3581ee6bf9ff
                                  • Instruction Fuzzy Hash: D981826192CF0B81FB31A786E84477D325CBF0477CF4402BACA1E46AB5EE6DE9848741
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: CloseDeleteOpenValuefflushfwrite
                                  • String ID: $ $ $ $(key != NULL)$(root != NULL)$C:/Projects/rdp/bot/codebase/registry.c$NULL$P$P$P$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(root=0x%p,key=%s,param=%s,err=%08x)$[E] (%s) -> RegDeleteValueA failed(root=0x%p,key=%s,param=%s,res=%lu)$[E] (%s) -> RegOpenKeyA failed(root=0x%p,key=%s,res=%lu)$[I] (%s) -> Done(root=0x%p,key=%s,param=%s)$registry_del_value
                                  • API String ID: 3240087161-1026589300
                                  • Opcode ID: a268a20a4ed75a55644bd1d860c98e745d9983276619bd552cc9458a4e6a3f6f
                                  • Instruction ID: ef7be361f7873c11b123cace10eeacc1247303a3e4a917a7a0ecd783e984698c
                                  • Opcode Fuzzy Hash: a268a20a4ed75a55644bd1d860c98e745d9983276619bd552cc9458a4e6a3f6f
                                  • Instruction Fuzzy Hash: 2B819E2094CF4F83FA75AB56AC803782250AF51BB4F5401B2D99E466F9EEDDAD858302
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastLocalToken$AllocInformation$CloseFreeHandleLengthOpenProcessfflushfwrite
                                  • String ID: (hnd != NULL)$(sid != NULL)$C:/Projects/rdp/bot/codebase/process.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(hnd=0x%p,err=%08x)$[E] (%s) -> GetTokenInformation failed(hnd=0x%p,gle=%lu)$[E] (%s) -> OpenProcessToken failed(hnd=0x%p,gle=%lu)$process_get_user_sid
                                  • API String ID: 1151404744-1775164968
                                  • Opcode ID: aa1985b96967479882025d48cd8a0add947c3715c92882144cc10cca8a9276db
                                  • Instruction ID: dc3710e83dfba47e247343dfddf8c0273530b3a637c582146a98b4446ec9b17e
                                  • Opcode Fuzzy Hash: aa1985b96967479882025d48cd8a0add947c3715c92882144cc10cca8a9276db
                                  • Instruction Fuzzy Hash: 76913B61A0ED4EC7FA609B16EC8837D1252AF84774F1508B2D58E476F4EEFCE8868741
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: _errno$fclosefopenfwrite
                                  • String ID: (mode != NULL)$(path != NULL)$C:/Projects/rdp/bot/codebase/fs.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(path=%s,mode=%s,err=%08x)$[E] (%s) -> fopen failed(path=%s,mode=%s,errno=%d)$[E] (%s) -> fwrite failed(path=%s,mode=%s,errno=%d)$[I] (%s) -> Done(path=%s,mode=%s,buf_sz=%llu)$fs_file_write
                                  • API String ID: 608220805-544371937
                                  • Opcode ID: a24b7f980791a68b7fa53d2f65726dba68c6577be98862efab153ef87cc2f980
                                  • Instruction ID: 29dd271a6373d96784e8d94d94d32095d069ba2f253d962897e92ac4491a61bc
                                  • Opcode Fuzzy Hash: a24b7f980791a68b7fa53d2f65726dba68c6577be98862efab153ef87cc2f980
                                  • Instruction Fuzzy Hash: 32513B61E08E5B86FA10DB67ED802B82351AF547B5F4941B2D99D47AF4EFBCE906C300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: strlen$CreateDirectoryErrorLast$strcpy
                                  • String ID: (path != NULL)$C:/Projects/rdp/bot/codebase/fs.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> CreateDirectoryA failed(path=%s,recursive=%d,gle=%lu)$[E] (%s) -> CreateDirectoryA failed(path=%s,recursive=%d,ptr=%s,gle=%lu)$[E] (%s) -> Failed(path=%s,recursive=%d,err=%08x)$[I] (%s) -> Done(path=%s,recursive=%d)$fs_dir_create
                                  • API String ID: 1104438493-1059260517
                                  • Opcode ID: d76066d44835d25d9b9fc0eced468d3f038e21c78a99d494400721fdddfc8336
                                  • Instruction ID: fc314cfcbf37c5504f914dc76e448d0b5b26ea428dfddc6effb124f02b3ec490
                                  • Opcode Fuzzy Hash: d76066d44835d25d9b9fc0eced468d3f038e21c78a99d494400721fdddfc8336
                                  • Instruction Fuzzy Hash: 71715C55A0CA4FC3FB609B17BC807B91651AB547B4F6501B2D99E07AF1EEECA8458301
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: _errno$fwrite
                                  • String ID: (mode != NULL)$(path != NULL)$C:/Projects/rdp/bot/codebase/fs.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(path=%s,mode=%s,err=%08x)$[E] (%s) -> fopen failed(path=%s,mode=%s,errno=%d)$[E] (%s) -> fwrite failed(path=%s,mode=%s,errno=%d)$[I] (%s) -> Done(path=%s,mode=%s,buf_sz=%llu)$fs_file_write
                                  • API String ID: 116495842-544371937
                                  • Opcode ID: 5c51432be4c91dae380d84349e0e6eaa9f8980b1305bb4fd1393100d6ed1f6a9
                                  • Instruction ID: 4d8d585275e0fb12a25b23f2cc2ffa2608645e5784d6204304ce77a97920667c
                                  • Opcode Fuzzy Hash: 5c51432be4c91dae380d84349e0e6eaa9f8980b1305bb4fd1393100d6ed1f6a9
                                  • Instruction Fuzzy Hash: D3518D62A09E0385FB119B97E9802BC375ABF557B0F4845BAD91D072B1EF7CEA06C311
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: CloseEnumOpen
                                  • String ID: (key != NULL)$(root != NULL)$(subkey != NULL)$(subkey_len != NULL)$C:/Projects/rdp/bot/codebase/registry.c$NULL$[D] (%s) -> Step(root=0x%p,key=%s,enum_index=%lu,subkey=%s,subkey_len=%llu)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(root=0x%p,key=%s,err=%08x)$[E] (%s) -> RegEnumKeyExA failed(root=0x%p,key=%s,enum_index=%lu,subkey_len=%llu,res=%lu)$[E] (%s) -> RegOpenKeyExA failed(root=0x%p,key=%s,res=%lu)$[I] (%s) -> Done(root=0x%p,key=%s)$registry_enum_key
                                  • API String ID: 1332880857-2775769510
                                  • Opcode ID: 6d6f2deb07fbd300a12f15b35bdcc2a36a80df8de26e6c5148ed774bc397a8c8
                                  • Instruction ID: 827d6cbaaa17fe9ea26b27a29665d9c00e4df284ebdf4e2e32282d102aa9fb6d
                                  • Opcode Fuzzy Hash: 6d6f2deb07fbd300a12f15b35bdcc2a36a80df8de26e6c5148ed774bc397a8c8
                                  • Instruction Fuzzy Hash: 6DB12D6290CE4E87FA608B07EC5077C2251AF887B4F5901B2D59E476F8EEFCE9859701
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastProcess$CloseCodeExitHandle$ObjectSingleTerminateWait
                                  • String ID: (pi != NULL)$C:/Projects/rdp/bot/codebase/process.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(pid=%lu,err=%08x)$[E] (%s) -> GetExitCodeProcess failed(pid=%lugle=%lu)$[E] (%s) -> TerminateProcess failed(pid=%lugle=%lu)$[I] (%s) -> Done(pid=%lu,exit_code=%08lx)$[W] (%s) -> GetExitCodeProcess failed(pid=%lugle=%lu)$process_close
                                  • API String ID: 1879646588-710610406
                                  • Opcode ID: e8e6b9f4422fb004d09ffc293bcc363bc8cb5c77a933e93e734cb42eecae558a
                                  • Instruction ID: 56becb0871034acd1cf1c2bbd90c0c4f45ab5ea4e193408a9ba04f7fdb7fb65b
                                  • Opcode Fuzzy Hash: e8e6b9f4422fb004d09ffc293bcc363bc8cb5c77a933e93e734cb42eecae558a
                                  • Instruction Fuzzy Hash: 9C811A62E0CD1F87FB609667AC8037C5250AF10774F2A80B2C99E576F4DDEDAD858385
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: AttributesErrorFileLast
                                  • String ID: $(attr != NULL)$(path != NULL)$C:/Projects/rdp/bot/codebase/fs.c$NULL$P$[D] (%s) -> Done(path=%s,attr=%08lx)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(path=%s,err=%08x)$[E] (%s) -> GetFileAttributesA failed(path=%s,gle=%lu)$c$fs_attr_get$~
                                  • API String ID: 1799206407-3397184676
                                  • Opcode ID: c7e33f04ff16cf37bf5fd111f9ee312e69900af82985126f10243b3bf2d85368
                                  • Instruction ID: ca0e73250f86bdda0f476dfc7881a027cad49801a74b462b5083112b287718a2
                                  • Opcode Fuzzy Hash: c7e33f04ff16cf37bf5fd111f9ee312e69900af82985126f10243b3bf2d85368
                                  • Instruction Fuzzy Hash: BE514960A0CE1F93FA609B17AD803F86250AF457B4F5801B2D9DE466F0EEEDAE55C341
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Heap$Process$Free_errnostrlen$AllocErrorLastfopenfseekrecvsendstrcmpstrcpy
                                  • String ID: %TEMP%$($-RGMLWD-$ORRE$[E] (%s) -> Memory allocation failed(size=%llu)$exe$mem_alloc
                                  • API String ID: 420611922-3475107310
                                  • Opcode ID: 6e6fe1dfc1eb4a1130b16d29e8eec07b0b219799b9145ee21665383f07fc91da
                                  • Instruction ID: 3a8beba803789bed405547a6865fec6205837c575f12bfdeb3b231bdbddabba7
                                  • Opcode Fuzzy Hash: 6e6fe1dfc1eb4a1130b16d29e8eec07b0b219799b9145ee21665383f07fc91da
                                  • Instruction Fuzzy Hash: 43D18F65A0CE8E87EA709A12AC503FD6351EB847B4F140272DADE477E5DEBCE9468700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Heap$strncpy$Process_errno$AllocFreefflushfopenfseekfwrite
                                  • String ID: (path != NULL)$5$C:/Projects/rdp/bot/codebase/ini.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(path=%s,err=%08x)$[E] (%s) -> Memory allocation failed(size=%llu)$[I] (%s) -> Done(path=%s)$ini_load$mem_alloc
                                  • API String ID: 1423203057-2746879330
                                  • Opcode ID: 9be5403554ed5b9d2fd351719c7c0188976e2f168b2ffec24e6810c309642929
                                  • Instruction ID: 62dcdcf5989576511481d2a241287f459bb32a6f1c425ffafb2b47f69526e53e
                                  • Opcode Fuzzy Hash: 9be5403554ed5b9d2fd351719c7c0188976e2f168b2ffec24e6810c309642929
                                  • Instruction Fuzzy Hash: 32B18D62A0DA8EC7EB108B16EC407B96751BB41BA4F5840F2EE8D4B6E5DEFDE545C300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Heap$strncpy$Process_errno$AllocFreefflushfopenfseekfwrite
                                  • String ID: (path != NULL)$5$C:/Projects/rdp/bot/codebase/ini.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(path=%s,err=%08x)$[E] (%s) -> Memory allocation failed(size=%llu)$[I] (%s) -> Done(path=%s)$ini_load$mem_alloc
                                  • API String ID: 1423203057-2746879330
                                  • Opcode ID: 56bc86e53c2632a91d80b26c311624891b06787dbdbc78ba6a2e3c22bbe57d6b
                                  • Instruction ID: 50be097f931c5619f977db252332ef475dcb6bcd672f412486d19aa37558f82e
                                  • Opcode Fuzzy Hash: 56bc86e53c2632a91d80b26c311624891b06787dbdbc78ba6a2e3c22bbe57d6b
                                  • Instruction Fuzzy Hash: 20B1C262A0DF8295EB118B86E45037D6B69FB42BE4F4840B9DA8D0B7B5DE7DE506C300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastMetricsSystem$fflushfwrite
                                  • String ID: (height != NULL)$(ratio != NULL)$(width != NULL)$C:/Projects/rdp/bot/codebase/sys.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> GetSystemMetrics(SM_CXSCREEN) failed(gle=%lu)$[E] (%s) -> GetSystemMetrics(SM_CYSCREEN) failed(gle=%lu)$c$sys_screen_info
                                  • API String ID: 144387239-450147120
                                  • Opcode ID: afd6aafe6363ac8c875ecee674a6e95eab4597803f0cf22cdfa7e6b2acb006d0
                                  • Instruction ID: 2bca7cd64650c4e2141008e42fef4cdbcae80d331f49e9ae5cb01c3c3c52cc1a
                                  • Opcode Fuzzy Hash: afd6aafe6363ac8c875ecee674a6e95eab4597803f0cf22cdfa7e6b2acb006d0
                                  • Instruction Fuzzy Hash: FE717F51E0CD8FD7FB219B5BAC8037811526F54778F1000B2D58E4A6F5DEECBAA58B01
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: EnvironmentErrorExpandLastStringsfflushfwrite
                                  • String ID: ((*xpath_sz) > 0)$(path != NULL)$(xpath != NULL)$(xpath_sz != NULL)$C:/Projects/rdp/bot/codebase/fs.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> ExpandEnvironmentStringsA buffer is too small(path=%s,res=%lu,xpath_sz=%llu)$[E] (%s) -> ExpandEnvironmentStringsA failed(path=%s,gle=%lu)$[E] (%s) -> Failed(path=%s,xpath_sz=%llu,err=%08x)$[I] (%s) -> Done(path=%s,xpath=%s,xpath_sz=%llu)$fs_path_expand
                                  • API String ID: 1721699506-2819899730
                                  • Opcode ID: 41490a2305b85c2478e28147bbc9dbf03624ea93a6eaf622d1fde9142c044732
                                  • Instruction ID: ecfd8ab0b0099bc1998860394365448134c9d47224d2cb771a99086fe5768602
                                  • Opcode Fuzzy Hash: 41490a2305b85c2478e28147bbc9dbf03624ea93a6eaf622d1fde9142c044732
                                  • Instruction Fuzzy Hash: F361F961A08D8FD7FB258B16EC403B82261AF84774F5900B2D58D4B2F5EEFCE9468746
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLast$Resource$FindLoadfflushfwrite
                                  • String ID: (hnd != NULL)$(out != NULL)$C:/Projects/rdp/bot/codebase/module.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> FindResourceA failed(hnd=0x%p,gle=%lu)$[E] (%s) -> LoadResource failed(hnd=0x%p,gle=%lu)$[I] (%s) -> Done(hnd=0x%p,dwSignature=%08lx,dwStrucVersion=%08lx,dwFileVersionMS=%08lx,dwFileVersionLS=%08lx,dwProductVersionMS=%08lx,dwProductVersionLS=%08lx,dwFileFlagsMask=%08lx,dwFileFlags=%08lx,dwFileOS=%08lx,dwFileType=%08lx,dwFileSubtype=%08lx,dwFileDat$module_get_version
                                  • API String ID: 2123903355-2019010457
                                  • Opcode ID: c16fb8f60e3d7b95e93b160d2e82be184e3f56b221acaafd34387a8e24b589ad
                                  • Instruction ID: f730d0abfa9791624ce5574a5e94cf4edce98066d4716e6cb882fcc8e5bd1659
                                  • Opcode Fuzzy Hash: c16fb8f60e3d7b95e93b160d2e82be184e3f56b221acaafd34387a8e24b589ad
                                  • Instruction Fuzzy Hash: B0411CB1A09A4A9BE750DF2AE84057977A0FB487B4F1001B5EE5C837E4EBBCE554CB00
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLast$Resource$FindLoadfflushfwrite
                                  • String ID: (hnd != NULL)$(out != NULL)$C:/Projects/rdp/bot/codebase/module.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> FindResourceA failed(hnd=0x%p,gle=%lu)$[E] (%s) -> LoadResource failed(hnd=0x%p,gle=%lu)$[I] (%s) -> Done(hnd=0x%p,dwSignature=%08lx,dwStrucVersion=%08lx,dwFileVersionMS=%08lx,dwFileVersionLS=%08lx,dwProductVersionMS=%08lx,dwProductVersionLS=%08lx,dwFileFlagsMask=%08lx,dwFileFlags=%08lx,dwFileOS=%08lx,dwFileType=%08lx,dwFileSubtype=%08lx,dwFileDat$module_get_version
                                  • API String ID: 2123903355-2019010457
                                  • Opcode ID: 6d07efb8b9a29b0ef45917083a3045d5452420d837a48b44e036b7da16b2d510
                                  • Instruction ID: 0684cb4071b3c1d91bc279cedc5cba47207857e2d58eca84efe48137cd87cf5d
                                  • Opcode Fuzzy Hash: 6d07efb8b9a29b0ef45917083a3045d5452420d837a48b44e036b7da16b2d510
                                  • Instruction Fuzzy Hash: 1F413D75A08A429BE750DF6AE48056977E5FB08764F040279EE5C837B4EF7CE941CB00
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: CloseCreate
                                  • String ID: (key != NULL)$(root != NULL)$?$C:/Projects/rdp/bot/codebase/registry.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(root=0x%p,key=%s,err=%08x)$[E] (%s) -> RegCreateKeyExA failed(root=0x%p,key=%s,res=%lu)$[I] (%s) -> Done(root=0x%p,key=%s)$registry_create_key
                                  • API String ID: 2932200918-3746808683
                                  • Opcode ID: 7395b13ae56abe0f666d962b920d62f6dcaee7a7211ea3f8e48394038bb57052
                                  • Instruction ID: f3383e38295eed967c9a748603d01cfcfd9aad151e064e35dba220d2a9fec67e
                                  • Opcode Fuzzy Hash: 7395b13ae56abe0f666d962b920d62f6dcaee7a7211ea3f8e48394038bb57052
                                  • Instruction Fuzzy Hash: 55516D62E0CD9F86FA208B06EC407B96250AF44774F4901B2D9DD5B6F8EEECED458741
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: strlen
                                  • String ID: ((*path_sz) > 0)$(path != NULL)$(path_sz != NULL)$C:/Projects/rdp/bot/codebase/fs.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(path=%s,path_sz=%llu,err=%08x)$[I] (%s) -> Done(path=%s,path_sz=%llu)$fs_path_temp
                                  • API String ID: 39653677-3302659514
                                  • Opcode ID: b228bde257ffa359012d8eb0d4441a787e09ebdeb2bc99d06e816fd44712abe2
                                  • Instruction ID: 76791340e564b3ed10aec0f54cb20343d526be7e9afa8de56f543f8f1a582e8f
                                  • Opcode Fuzzy Hash: b228bde257ffa359012d8eb0d4441a787e09ebdeb2bc99d06e816fd44712abe2
                                  • Instruction Fuzzy Hash: FF413D6190CE8FD2FA16DF16EC503B96251AF40764F8841F2D59E072F5EEFCA9068341
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: strlen
                                  • String ID: ((*path_sz) > 0)$(path != NULL)$(path_sz != NULL)$C:/Projects/rdp/bot/codebase/fs.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(path=%s,path_sz=%llu,err=%08x)$[I] (%s) -> Done(path=%s,path_sz=%llu)$fs_path_temp
                                  • API String ID: 39653677-3302659514
                                  • Opcode ID: 504d0030ac419fe348b57e2595d458b11ef43f11ff175aa72df08dca8dc9a66d
                                  • Instruction ID: 9089c3a11df5666f4144cbb1b1f61888a34e23e3c649759409536a6a8bb8bf57
                                  • Opcode Fuzzy Hash: 504d0030ac419fe348b57e2595d458b11ef43f11ff175aa72df08dca8dc9a66d
                                  • Instruction Fuzzy Hash: C8418C61E08E4391FB129F96E8003B86B5ABF51774F4885B6D55E0B2B6DF7CAA06C340
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Heap$Processstrlen$AllocFree
                                  • String ID: (buf != NULL)$(buf_sz != NULL)$C:/Projects/rdp/bot/codebase/ini.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Memory allocation failed(size=%llu)$ini_get_bytes$mem_alloc
                                  • API String ID: 1318626975-3964590784
                                  • Opcode ID: a1aee74ea129f77ad3509245ff35311005da0208ebc3f74bfa544f2155ba53c2
                                  • Instruction ID: 535ffc3c4c1679bbe61619525930df1f7d7b303544b85f2b3be21dbc5aaaeef8
                                  • Opcode Fuzzy Hash: a1aee74ea129f77ad3509245ff35311005da0208ebc3f74bfa544f2155ba53c2
                                  • Instruction Fuzzy Hash: 81316061A09E4F86FB519F53AC207B92350AF40BB4F5840B1DE8D176F6DEBCE9458300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Heap$Processstrlen$AllocFree
                                  • String ID: (buf != NULL)$(buf_sz != NULL)$C:/Projects/rdp/bot/codebase/ini.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Memory allocation failed(size=%llu)$ini_get_bytes$mem_alloc
                                  • API String ID: 1318626975-3964590784
                                  • Opcode ID: 1dfc74628edd97181b9eed0ee955ae26f9792dec49582829bd24eacfc9af28ac
                                  • Instruction ID: aae53ad68fb99755f7656e97e589cb5e4e8a48d5c1915dbde0167f30ab0286b9
                                  • Opcode Fuzzy Hash: 1dfc74628edd97181b9eed0ee955ae26f9792dec49582829bd24eacfc9af28ac
                                  • Instruction Fuzzy Hash: 6D315971A0CF4785FB519B97A8103BD23A9AF40BA4F4850BADA4D076B5DFBCE9858340
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Service$ErrorLast$CloseHandleOpenQueryStatus
                                  • String ID: (svc != NULL)$C:/Projects/rdp/bot/codebase/scm.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> OpenServiceA(SERVICE_QUERY_STATUS) failed(lpServiceName=%s,gle=%lu)$[E] (%s) -> QueryServiceStatusEx(SC_STATUS_PROCESS_INFO) failed(lpServiceName=%s,gle=%lu)$service_query_status
                                  • API String ID: 1743273550-1326671558
                                  • Opcode ID: b7003ba37fa737a96ce3ecc8ed53b08ab55ba1b154839673403375584cf9a386
                                  • Instruction ID: 139f1a984fdd9c1f3d19a87f995295fcce26465b0da22fc695772b963831b912
                                  • Opcode Fuzzy Hash: b7003ba37fa737a96ce3ecc8ed53b08ab55ba1b154839673403375584cf9a386
                                  • Instruction Fuzzy Hash: 7A515052E0DD2382FBB096DBA4403BC525A5F04B74F1A00FADCDE672B1DE5DAD8042C2
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: AttributesFile$ErrorLast
                                  • String ID: (attr != NULL)$(path != NULL)$C:/Projects/rdp/bot/codebase/fs.c$NULL$[D] (%s) -> Done(path=%s,attr=%08lx)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(path=%s,attr=%08lx,err=%08x)$[E] (%s) -> SetFileAttributesA failed(path=%s,gle=%lu)$fs_attr_set
                                  • API String ID: 365566950-3085771803
                                  • Opcode ID: af1c426e514422b69e51c88ff44b0fe656143a45afeeb04e1f3d3cb18f47015e
                                  • Instruction ID: d821777886d3ab628004a09289266397c3114b6deff8fc4fe2abcb5bddf8afa9
                                  • Opcode Fuzzy Hash: af1c426e514422b69e51c88ff44b0fe656143a45afeeb04e1f3d3cb18f47015e
                                  • Instruction Fuzzy Hash: E3517E61A0CE4F97FB20DB12BC403BD7650AF00364F5440B2D99E4AAF4EEECE8458742
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: AttributesFile$ErrorLast
                                  • String ID: (attr != NULL)$(path != NULL)$C:/Projects/rdp/bot/codebase/fs.c$NULL$[D] (%s) -> Done(path=%s,attr=%08lx)$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(path=%s,attr=%08lx,err=%08x)$[E] (%s) -> SetFileAttributesA failed(path=%s,gle=%lu)$fs_attr_set
                                  • API String ID: 365566950-3085771803
                                  • Opcode ID: f22dd1c2fdd686c3c2f54cf2612dd1b2b312c938556c7605be4ecf5b2faec8a7
                                  • Instruction ID: d54daa1b35798663d5fa6364744afba30618bb54b54c5930a9ead683cd9b16e7
                                  • Opcode Fuzzy Hash: f22dd1c2fdd686c3c2f54cf2612dd1b2b312c938556c7605be4ecf5b2faec8a7
                                  • Instruction Fuzzy Hash: 4C519365E0CE0786FB618B92E5C03BD329DAF00374F1441BAD92E466B5DF6CEA45C702
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLast$accepthtonlhtonsioctlsocketselect
                                  • String ID: [E] (%s) -> Failed(sock=0x%llx,WSAgle=%d)$[E] (%s) -> select failed(sock=0x%llx,WSAgle=%d)$[I] (%s) -> Done(sock=0x%llx,client=0x%llx,h=%08x,p=%u)$[W] (%s) -> select timedout(sock=0x%llx)$tcp_accept
                                  • API String ID: 2278979430-4175654481
                                  • Opcode ID: b15167baa39f87c9e19412fe59424759e963d6e486aca754582e955809ebfd41
                                  • Instruction ID: 28c1b23b65c7a58969732d11bf6b0abb0aaa356957580aba0ca7028e83184833
                                  • Opcode Fuzzy Hash: b15167baa39f87c9e19412fe59424759e963d6e486aca754582e955809ebfd41
                                  • Instruction Fuzzy Hash: B2518235A08E8A87E7208B16EC443F966A0EB45BB4F5403B1D9BD476F8EFBDD9158700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Deletefflushfwrite
                                  • String ID: (key != NULL)$(root != NULL)$C:/Projects/rdp/bot/codebase/registry.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(root=0x%p,key=%s,err=%08x)$[E] (%s) -> RegDeleteKeyExA failed(root=0x%p,key=%s,res=%lu)$[I] (%s) -> Done(root=0x%p,key=%s)$registry_delete_key$u
                                  • API String ID: 2939363742-1701293196
                                  • Opcode ID: 424352b5c16577fcef74a4d4c8063d5f40111192ebe28781416230669f555a05
                                  • Instruction ID: c9993ea77259b04e64819b0047af50e774bf57b9fdc4282f7cb24d5864938650
                                  • Opcode Fuzzy Hash: 424352b5c16577fcef74a4d4c8063d5f40111192ebe28781416230669f555a05
                                  • Instruction Fuzzy Hash: B8414966D0CD5F83FA209756AC503B862506F047B4F5E01F2C89E5B6F8EEECAD858385
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Deletefflushfwrite
                                  • String ID: (key != NULL)$(root != NULL)$C:/Projects/rdp/bot/codebase/registry.c$NULL$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(root=0x%p,key=%s,err=%08x)$[E] (%s) -> RegDeleteKeyExA failed(root=0x%p,key=%s,res=%lu)$[I] (%s) -> Done(root=0x%p,key=%s)$registry_delete_key$u
                                  • API String ID: 2939363742-1701293196
                                  • Opcode ID: 66bf5e16b675843c047dd5bcf32e8603fcaca12fb8c088c74fe4f08f4f45e0d2
                                  • Instruction ID: c2248b8c955c4281aa12c69d57033b268fb1f7dd1c6f9891fd223abcf68f1d66
                                  • Opcode Fuzzy Hash: 66bf5e16b675843c047dd5bcf32e8603fcaca12fb8c088c74fe4f08f4f45e0d2
                                  • Instruction Fuzzy Hash: 13417B63D0CD6782FB3097CAE4413BC1A596F00774F4A01FAD96E572B0DE5CAD858382
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: CloseErrorFileHandleLastUnlockfflushfwrite
                                  • String ID: ((*lock) != INVALID_HANDLE_VALUE)$(lock != NULL)$C:/Projects/rdp/bot/codebase/fs.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(lock=%p,err=%08x)$[E] (%s) -> UnlockFileEx failed(hnd=%p,gle=%lu)$[I] (%s) -> Done(lock=%p)$fs_file_unlock
                                  • API String ID: 497672076-1436771859
                                  • Opcode ID: 7be23ca87f09eee718d3021cbdd44a05adf3a9e995dd523e5db5aa8cae75dc7a
                                  • Instruction ID: 48e9031c3842092ee7b509cbe34122fe9bc20f5445d522f8efb36e0f1402119f
                                  • Opcode Fuzzy Hash: 7be23ca87f09eee718d3021cbdd44a05adf3a9e995dd523e5db5aa8cae75dc7a
                                  • Instruction Fuzzy Hash: C7412A61F0CD8FC2FA268717FC40BB812506F54B78F5406B2D99E5B6F0AEACA585C302
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorGlobalLastMemoryStatus
                                  • String ID: $(mi != NULL)$;$C:/Projects/rdp/bot/codebase/sys.c$P$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> GlobalMemoryStatusEx failed(gle=%lu)$sys_mem_info$~
                                  • API String ID: 3848946878-3004215591
                                  • Opcode ID: 61cfa59afa55dc0c5d2d279ce2976c6e81242ce9473eeed649ce93707e0ac7f6
                                  • Instruction ID: 1b7fedf726eb68aa97de93d446928db869e63905af50fb4fbe89bf2f32214794
                                  • Opcode Fuzzy Hash: 61cfa59afa55dc0c5d2d279ce2976c6e81242ce9473eeed649ce93707e0ac7f6
                                  • Instruction Fuzzy Hash: 99312550E0CE8F87FB25871A9C807BC2250AF14338F2445B7D68E865F2DFEEA895D601
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: ErrorGlobalLastMemoryStatus
                                  • String ID: $(mi != NULL)$;$C:/Projects/rdp/bot/codebase/sys.c$P$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> GlobalMemoryStatusEx failed(gle=%lu)$sys_mem_info$~
                                  • API String ID: 3848946878-3004215591
                                  • Opcode ID: bd18ab770a9f7ff8caf3dd049ff7be8a6d92134794dafb974f7253b07fc17702
                                  • Instruction ID: d1d7c077464ce393272548c481d734890e290679e948003ccc19daecc4220615
                                  • Opcode Fuzzy Hash: bd18ab770a9f7ff8caf3dd049ff7be8a6d92134794dafb974f7253b07fc17702
                                  • Instruction Fuzzy Hash: 4B310B5AE0CF47C6FB318B96D4C037C5268AF58728F2451BBC60E066B2DE6DADC5D602
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorFileLastModuleName
                                  • String ID: (hnd != NULL)$(path != NULL)$(path_sz != NULL)$C:/Projects/rdp/bot/codebase/fs.c$C:\Users\Public\Computer.{20d04fe0-3aea-1069-a2d8-08002b30309d}\dwlmgr.log$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> Failed(hnd=0x%p,err=%08x)$[E] (%s) -> GetModuleFileNameA failed(hnd=0x%p,gle=%lu)$fs_module_path
                                  • API String ID: 2776309574-668612727
                                  • Opcode ID: f1f30cb962d20f73838f72ba81ecd51969fa8e708423d99813306ed40ad5a0a8
                                  • Instruction ID: 6b3227627d7509486cb6abac61c3506b3b59ad25dacf57cfafdccc22fd6a521a
                                  • Opcode Fuzzy Hash: f1f30cb962d20f73838f72ba81ecd51969fa8e708423d99813306ed40ad5a0a8
                                  • Instruction Fuzzy Hash: 40310CA1A08E4F92FB21CB16ED507B82350BB00778F9440F1E98D476F1EEFCA9058341
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorFileLast$CloseCreateHandleSize
                                  • String ID: (path != NULL)$(size != NULL)$C:/Projects/rdp/bot/codebase/fs.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$fs_file_size
                                  • API String ID: 3555958901-1687387729
                                  • Opcode ID: 523f5176cd2a95eed4221483572ea6ee8aa4e126005045c1d11278065c56e8a4
                                  • Instruction ID: a14da445345cf575f6bc6182f13658b14f445d2415569be4045a03f915333121
                                  • Opcode Fuzzy Hash: 523f5176cd2a95eed4221483572ea6ee8aa4e126005045c1d11278065c56e8a4
                                  • Instruction Fuzzy Hash: 80611661D0CD5E8BFA758A26BC4437912509B04778F6946F2C99E8B2F0DEEDEC8542C2
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastObjectSingleWait
                                  • String ID: $(pi != NULL)$C:/Projects/rdp/bot/codebase/process.c$P$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> WaitForSingleObject failed(pid=%lugle=%lu)$process_wait$~
                                  • API String ID: 1211598281-4195011794
                                  • Opcode ID: 33222ba2366101c01b252ae6301b05a5ab58f31267f596e88950aa1946cedbb3
                                  • Instruction ID: 42ae06af818244ca71558b2910cf4e3f189d7665cb845f1883629530e92bd42e
                                  • Opcode Fuzzy Hash: 33222ba2366101c01b252ae6301b05a5ab58f31267f596e88950aa1946cedbb3
                                  • Instruction Fuzzy Hash: 0731D520E0CA8F87FB609756ACC037C12949F1973CFA805B2C59E466F1DDDEACC59292
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastObjectSingleWait
                                  • String ID: $(pi != NULL)$C:/Projects/rdp/bot/codebase/process.c$P$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> WaitForSingleObject failed(pid=%lugle=%lu)$process_wait$~
                                  • API String ID: 1211598281-4195011794
                                  • Opcode ID: 248ffea18eab27a6145b458739dfee685e23cc5e334c8328949daeb22b0749aa
                                  • Instruction ID: 64b3b77197543d8597123ad71cca0b0e160516e5a2601dc53361b81c6a735369
                                  • Opcode Fuzzy Hash: 248ffea18eab27a6145b458739dfee685e23cc5e334c8328949daeb22b0749aa
                                  • Instruction Fuzzy Hash: 9B31C760F1CF0383FBA097AAA49437C12999F09378E2411BBC60E462B1DD9DADC59643
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: File$CloseCreateErrorHandleLastTime
                                  • String ID: (ctime != NULL) || (atime != NULL) || (mtime != NULL)$(path != NULL)$C:/Projects/rdp/bot/codebase/fs.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$fs_file_stat
                                  • API String ID: 2291555494-3647951244
                                  • Opcode ID: 98bfd3265da5604791deef92f63323e3687dd05aea63e579915609cbd7d4b579
                                  • Instruction ID: 012ac91be81a16a5fe0d0b5a9229dac4d8e961736d41d2cfb3023d181ce36af6
                                  • Opcode Fuzzy Hash: 98bfd3265da5604791deef92f63323e3687dd05aea63e579915609cbd7d4b579
                                  • Instruction Fuzzy Hash: AA516461D0C9DE83FB6A8B639C843795250AF01774F1846B2E99D472F4DEEDAC458342
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: _errno$strtol
                                  • String ID: (value != NULL)$C:/Projects/rdp/bot/codebase/ini.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> strtol failed(sec_name=%s,var_name=%s,radix=%d,s=%s,errno=%d)$ini_get_uint16
                                  • API String ID: 3596500743-1991603811
                                  • Opcode ID: 64825c6309542d30ee2689645938860f6a5046a5c42dcd9b72a0ba098a2be6ed
                                  • Instruction ID: f6bc019e7ba13116933521276d932432a8be0d968a2f2a11cc9e99faaced2598
                                  • Opcode Fuzzy Hash: 64825c6309542d30ee2689645938860f6a5046a5c42dcd9b72a0ba098a2be6ed
                                  • Instruction Fuzzy Hash: B9216D21A08A4B96F7119B12EC407AA7361FB44BB4F4441B1EE8C07AF9DFBDE985C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: _errno$strtol
                                  • String ID: (value != NULL)$C:/Projects/rdp/bot/codebase/ini.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> strtol failed(sec_name=%s,var_name=%s,radix=%d,s=%s,errno=%d)$ini_get_uint16
                                  • API String ID: 3596500743-1991603811
                                  • Opcode ID: 9552bb2bda148b1a40ad1404c5e2a8462fa6d9b251cb6eba0aa7c66b080a6eb3
                                  • Instruction ID: 4213278e4a105fda7b622aa74429e8c94b3a9416389fcb487b34cf4ba004acc4
                                  • Opcode Fuzzy Hash: 9552bb2bda148b1a40ad1404c5e2a8462fa6d9b251cb6eba0aa7c66b080a6eb3
                                  • Instruction Fuzzy Hash: 6021BC22A08A4792E7119F82E840BAE3369BB457A8F004175EE4C47774DF7EE985CB00
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Heapstrlen$FreeProcessstrcmpstrcpy
                                  • String ID: ($-RGMLWD-$ORRE$exe
                                  • API String ID: 173675053-901114122
                                  • Opcode ID: 11a2caeb227a089ab727a8f333dd61d59964033babc5344b47066f642f710bcb
                                  • Instruction ID: b29a674a24a4b7b88227a5fb9dcc179959824acdff3b7b1a9e9c72ffdbe31202
                                  • Opcode Fuzzy Hash: 11a2caeb227a089ab727a8f333dd61d59964033babc5344b47066f642f710bcb
                                  • Instruction Fuzzy Hash: E6517662A0CB8E87EB609B23EC543BE6751EB847A4F440071E9CD476E9DFACD945C740
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Virtual$ErrorLastProtectQuery
                                  • String ID: Unknown pseudo relocation protocol version %d.$ VirtualProtect failed with code 0x%x$ VirtualQuery failed for %d bytes at address %p$Address %p has no image-section$Mingw-w64 runtime failure:
                                  • API String ID: 637304234-2693646698
                                  • Opcode ID: 1061ffdd13e99e9696300e9951f80e08d87b1537a1cf5918fcce34f21a829f6f
                                  • Instruction ID: 14f2cf9bb0d2928a9fb78759167c612de59a45221e2de9b1fb80b8d8fb2bb9f2
                                  • Opcode Fuzzy Hash: 1061ffdd13e99e9696300e9951f80e08d87b1537a1cf5918fcce34f21a829f6f
                                  • Instruction Fuzzy Hash: 14317061B09E0E86EA01DF17EC416A86761FF84BA4B548175DD4D473F8DEBCE445C340
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: _errno
                                  • String ID: (value != NULL)$C:/Projects/rdp/bot/codebase/ini.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$[E] (%s) -> strtoul failed(sec_name=%s,var_name=%s,radix=%d,s=%s,errno=%d)$ini_get_uint32
                                  • API String ID: 2918714741-1670302297
                                  • Opcode ID: 7c09ed77c8e874615c8ea014a46ffa95f55d1f593164a3137fd829f44bd58e1b
                                  • Instruction ID: 7dcec2fb26cec161c228dbb9edc64aeafab2116d5beebf366da1c851553e2701
                                  • Opcode Fuzzy Hash: 7c09ed77c8e874615c8ea014a46ffa95f55d1f593164a3137fd829f44bd58e1b
                                  • Instruction Fuzzy Hash: F7217C62A08A4A9AE711DF56EC807AA3261BB447A4F4440B2EE8C476F5DFBCD985C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: AddressProc$HandleLibraryLoadModule
                                  • String ID: SystemFunction036$advapi32.dll$msvcrt.dll$rand_s
                                  • API String ID: 384173800-4041758303
                                  • Opcode ID: 92bec230b7dd7ae9f9bbc3669ca63d39642e77e1892d4597da22ddc72aded575
                                  • Instruction ID: 7cce4256d6f118e77d888f341d8e11fac6d8ad7ad3a950615f142ba8a30c51b1
                                  • Opcode Fuzzy Hash: 92bec230b7dd7ae9f9bbc3669ca63d39642e77e1892d4597da22ddc72aded575
                                  • Instruction Fuzzy Hash: 92F0D464E1AE17D1EE0ADF13FC544A827A5BF487B4B8405B2C80D163B4EEACA54AC300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: CopyErrorFileLastfflushfwrite
                                  • String ID: NULL$[E] (%s) -> CopyFileA failed(src=%s,dst=%s,overwrite=%d,gle=%lu)$[E] (%s) -> Failed(src=%s,dst=%s,overwrite=%d,err=%08x)$[I] (%s) -> Done(src=%s,dst=%s,overwrite=%d)$fs_file_copy
                                  • API String ID: 2887799713-3464183404
                                  • Opcode ID: 47aa78f9715c757d15418383cbf686b7e332c4a858e1d6338a5e6343c50d03d1
                                  • Instruction ID: 94cc95ee4d22d14174d6177db4900e53d7e79064e0aa32fb53aa7e596a031ffe
                                  • Opcode Fuzzy Hash: 47aa78f9715c757d15418383cbf686b7e332c4a858e1d6338a5e6343c50d03d1
                                  • Instruction Fuzzy Hash: 3E416069D0CD9E8BFA208A17BC0037915547F05BB8F2401B2C99E476F1EEDCAE458716
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: CopyErrorFileLastfflushfwrite
                                  • String ID: NULL$[E] (%s) -> CopyFileA failed(src=%s,dst=%s,overwrite=%d,gle=%lu)$[E] (%s) -> Failed(src=%s,dst=%s,overwrite=%d,err=%08x)$[I] (%s) -> Done(src=%s,dst=%s,overwrite=%d)$fs_file_copy
                                  • API String ID: 2887799713-3464183404
                                  • Opcode ID: d66d8130dc3d6d4f1d99bbc469e587a231d8cd05d92920e517c8e77ecd8b0f49
                                  • Instruction ID: 2ae9264ddbf07f1ca1ae578de85eec1be6f4c0b2cbf83455d4e56e9eca78f90e
                                  • Opcode Fuzzy Hash: d66d8130dc3d6d4f1d99bbc469e587a231d8cd05d92920e517c8e77ecd8b0f49
                                  • Instruction Fuzzy Hash: 59416A61D0CE1795FB614AD7E80037D665D7F04BF8F5840BAC90F0AAF4EEACAA818701
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: DeleteErrorFileLast
                                  • String ID: NULL$[E] (%s) -> DeleteFileA failed(path=%s,gle=%lu)$[E] (%s) -> Failed(path=%s,err=%08x)$[I] (%s) -> Done(path=%s)$fs_file_delete
                                  • API String ID: 2018770650-4119452840
                                  • Opcode ID: 7dcf710799abc44ddf9b1729ff8e4c79730672ce58fc48c80c262d61a60e784d
                                  • Instruction ID: a0b456f0846c1d35f7af6f7149ac89aeb28bc2a1cd0c96c9bd54ff646d9d9ccb
                                  • Opcode Fuzzy Hash: 7dcf710799abc44ddf9b1729ff8e4c79730672ce58fc48c80c262d61a60e784d
                                  • Instruction Fuzzy Hash: E3311D51E0CE4F8BFA60A65ABD4037C22415F557B4F9500B6C99E172F2EDDDAC8A9302
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastsend
                                  • String ID: [E] (%s) -> !!!WTF!!!(sock=0x%llx,l=%d,n=%d)$[E] (%s) -> Invalid arguments(sock=0x%llx,p=0x%p,l=%d)$[E] (%s) -> send failed(sock=0x%llx,WSAgle=%d)$tcp_recv$tcp_send
                                  • API String ID: 1802528911-690514478
                                  • Opcode ID: f5ed6a7e91a2a29f0ed113ceb27407fee5528338d24d9cfe335694d9ee608d87
                                  • Instruction ID: 2ff763cbaeae98dbdb81a8029af1da10622498828f97481690761be680439ce4
                                  • Opcode Fuzzy Hash: f5ed6a7e91a2a29f0ed113ceb27407fee5528338d24d9cfe335694d9ee608d87
                                  • Instruction Fuzzy Hash: 2221AE55B18D4A83FA208B2BAD806B85241BF18BF4F5443B0DDBD4BAF1DEACA9558300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastsend
                                  • String ID: [E] (%s) -> !!!WTF!!!(sock=0x%llx,l=%d,n=%d)$[E] (%s) -> Invalid arguments(sock=0x%llx,p=0x%p,l=%d)$[E] (%s) -> send failed(sock=0x%llx,WSAgle=%d)$tcp_recv$tcp_send
                                  • API String ID: 1802528911-690514478
                                  • Opcode ID: c9f19f32b5df819760338bec0d2a147b920345362efdfe3d7456cba7c5dbbd7a
                                  • Instruction ID: a81efd7b30064c1e5f96c4f9dd31861cf8146e5baf60e7bd43f2c73ccaf9d45e
                                  • Opcode Fuzzy Hash: c9f19f32b5df819760338bec0d2a147b920345362efdfe3d7456cba7c5dbbd7a
                                  • Instruction Fuzzy Hash: E621DE65B08E0341EB214FA7A9806BC525AAF097F0F5803B8DC2C8B6F2FE2DA5458300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: CloseErrorHandleLastProcess$OpenTerminatestrcmp
                                  • String ID: [E] (%s) -> TerminateProcess failed(gle=%lu)$process_kill
                                  • API String ID: 1221532209-1116693529
                                  • Opcode ID: 6f4592497d5f64ef2bbb820cb7689dfd57b1a9d751fb8f01230840f11b2ddb6a
                                  • Instruction ID: a7e4cc8ca7edfc6897539c73f7becb6b11b92f97657dae8a29a38d1e819d2703
                                  • Opcode Fuzzy Hash: 6f4592497d5f64ef2bbb820cb7689dfd57b1a9d751fb8f01230840f11b2ddb6a
                                  • Instruction Fuzzy Hash: 76117C15E1AF0B47FB659B97ACC037A2392AF55775F1400B5C88E066F1EEEEE8498200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: CloseErrorHandleLastProcess$OpenTerminatestrcmp
                                  • String ID: [E] (%s) -> TerminateProcess failed(gle=%lu)$process_kill
                                  • API String ID: 1221532209-1116693529
                                  • Opcode ID: 93fc96329f73007c35746c868cfb508d14210149105aa23a18dee84d4ea970eb
                                  • Instruction ID: a5cb12af1a6d1604919bf24f773c16ce3ada4229474d448dfd1f62d99700df28
                                  • Opcode Fuzzy Hash: 93fc96329f73007c35746c868cfb508d14210149105aa23a18dee84d4ea970eb
                                  • Instruction Fuzzy Hash: 2B117F15E1AF0F47FB659B97ACD037A2392AF55775F1400B5C88E062F1EEEEE8498200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: CloseErrorHandleLastProcess$OpenTerminatestrcmp
                                  • String ID: [E] (%s) -> TerminateProcess failed(gle=%lu)$process_kill
                                  • API String ID: 1221532209-1116693529
                                  • Opcode ID: d7a0d7f5a7b2a4e3d400a787d61450851b263e017d5bd8201c9c34e13afcf3dd
                                  • Instruction ID: 658427271041e55cedc357951787912004ddc9a77b9385e894096a9b19ba9030
                                  • Opcode Fuzzy Hash: d7a0d7f5a7b2a4e3d400a787d61450851b263e017d5bd8201c9c34e13afcf3dd
                                  • Instruction Fuzzy Hash: FC117C15E1AF0B47FB659B97ACD037A2392AF55775F1400B5C88E062F1EEEEE8498200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: CloseErrorHandleLastProcess$OpenTerminatestrcmp
                                  • String ID: [E] (%s) -> TerminateProcess failed(gle=%lu)$process_kill
                                  • API String ID: 1221532209-1116693529
                                  • Opcode ID: f74b715ccb6925c361faf0dc0f44663209a238fdca931a3afb68363d493b3dfd
                                  • Instruction ID: c93d6ad777fddae2c8314393a477b1491b82584603a727603ff8325330a00e69
                                  • Opcode Fuzzy Hash: f74b715ccb6925c361faf0dc0f44663209a238fdca931a3afb68363d493b3dfd
                                  • Instruction Fuzzy Hash: 9E117C15E1AF0B47FB659B97ACC037A2292AF55775F1440B5C88E062F1EEEEE8498200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: CloseErrorHandleLastProcess$OpenTerminatestrcmp
                                  • String ID: [E] (%s) -> TerminateProcess failed(gle=%lu)$process_kill
                                  • API String ID: 1221532209-1116693529
                                  • Opcode ID: 6b2bf3dba12848de8549e9a6170e6c7b27bbc81ec1cc257075f236f2d8ffd292
                                  • Instruction ID: 761cb948efcb60f6e1969ce9e34a7f5bb361f38d695cbd8467bf9a86e88a4d19
                                  • Opcode Fuzzy Hash: 6b2bf3dba12848de8549e9a6170e6c7b27bbc81ec1cc257075f236f2d8ffd292
                                  • Instruction Fuzzy Hash: 3B118112A0DF1396FB554BC7909033E1699FF057A5F1800BDCC0E4A2B1DF6EF849A201
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: CloseErrorHandleLastProcess$OpenTerminatestrcmp
                                  • String ID: [E] (%s) -> TerminateProcess failed(gle=%lu)$process_kill
                                  • API String ID: 1221532209-1116693529
                                  • Opcode ID: 2170fb843dc9024c7a72dd777fd7c8e8f87c2e469e68bf6523431c34d069a559
                                  • Instruction ID: 954152c7cb4bb720f8c84544127936eb4b10c0f8ce2c156cdb1ee48b504f0e47
                                  • Opcode Fuzzy Hash: 2170fb843dc9024c7a72dd777fd7c8e8f87c2e469e68bf6523431c34d069a559
                                  • Instruction Fuzzy Hash: CA117F12A0DF1396FB554BC7949033E1699FF057A5F1840BDCC0E462B1DF6EE889A201
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: strlen
                                  • String ID: ((match == NULL) || (match_len != NULL))$(needle != NULL)$(pattern != NULL)$C:/Projects/rdp/bot/codebase/utils.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$str_match
                                  • API String ID: 39653677-892027187
                                  • Opcode ID: dda567349ec99dcddd5be3e3eef9e17723494d5e456f79aab727309c5bcd18ac
                                  • Instruction ID: a9ec1131fb016230743accf0a0949d9a656f5ea61ea71e29c8e60fbbcdc0328a
                                  • Opcode Fuzzy Hash: dda567349ec99dcddd5be3e3eef9e17723494d5e456f79aab727309c5bcd18ac
                                  • Instruction Fuzzy Hash: 9751D751B0CD8F92FE208B57AD197B91651BF017A8F8840B2D98D0B6F1EEBDA916C300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: CriticalHeapSection$EnterFreeLeaveProcessfflushfwrite
                                  • String ID: [D] (%s) -> Requested(handler=0x%p)$[E] (%s) -> Failed(handler=0x%p)$[I] (%s) -> Done(handler=0x%p)$ebus_unsubscribe
                                  • API String ID: 2011334650-1527096901
                                  • Opcode ID: 60dbd24cb8195e753da08d34ad23b942db4597d253108ddfd3f1a4b75fba148a
                                  • Instruction ID: 024db4204976cf9b7a67ec58b0f0045c28f2bfae6964a67674c316fcc09cb1f2
                                  • Opcode Fuzzy Hash: 60dbd24cb8195e753da08d34ad23b942db4597d253108ddfd3f1a4b75fba148a
                                  • Instruction Fuzzy Hash: 2F21DC50A0AE0F96FE159F23EC911B82391AF54FB4F4894B5C94D0A7F6EEECE4468310
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: strlen$strcat
                                  • String ID: (file_path != NULL)$C:/Projects/rdp/bot/codebase/fs.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$fs_module_file
                                  • API String ID: 2335785903-2423714266
                                  • Opcode ID: 98633d643f2fa153ff4bd1d2eb28ca78fc1e22ebfa149f2c4a083f6ca115ba09
                                  • Instruction ID: 4e47b20e507a6278607cdedd3c45640a9ba070e0d8e213a962163445689c0b38
                                  • Opcode Fuzzy Hash: 98633d643f2fa153ff4bd1d2eb28ca78fc1e22ebfa149f2c4a083f6ca115ba09
                                  • Instruction Fuzzy Hash: 03119691A0CE4F85FB559B179D087B957515F11BE4F4C41B0DE8D0A2F2EEBC941AC340
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: AttributesErrorFileLast
                                  • String ID: (path != NULL)$C:/Projects/rdp/bot/codebase/fs.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$fs_path_exists
                                  • API String ID: 1799206407-4111913120
                                  • Opcode ID: 3e653d2a1f3f8e34072ed63f7c5697a327472162f466aec2d27c6ce9d0a95ad8
                                  • Instruction ID: 7436161436954d5e76f944176e2c5c1daff75c5bf67788e0e36ba8b6b9346c57
                                  • Opcode Fuzzy Hash: 3e653d2a1f3f8e34072ed63f7c5697a327472162f466aec2d27c6ce9d0a95ad8
                                  • Instruction Fuzzy Hash: E321B761E0CCDF83FB2A466AAC5437D11415F04336F6445B2D09E8D1F4DEDDE9855243
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: inet_addr
                                  • String ID: (s != NULL)$(v != NULL)$C:/Projects/rdp/bot/codebase/net.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$ip4_from_str
                                  • API String ID: 1393076350-1216860922
                                  • Opcode ID: 620f199b0a00be557768cdf46eda07ecd77f5febd471f9397a369252cefe9704
                                  • Instruction ID: fe93699486878787bd7e56d33af10ef822c59ff296fe7dcb41f0198d79a2be89
                                  • Opcode Fuzzy Hash: 620f199b0a00be557768cdf46eda07ecd77f5febd471f9397a369252cefe9704
                                  • Instruction Fuzzy Hash: B51130A1A08E4FD3FB11DB23AC503B85360AF10328F4441B2D59D4A1F0EFFDA9668B41
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: AddressErrorLastLibraryLoadProc
                                  • String ID: Done$Wow64RevertWow64FsRedirection$[E] (%s) -> Wow64RevertWow64FsRedirection failed(gle=%lu)$[I] (%s) -> %s$fs_wow_redir_revert$kernel32
                                  • API String ID: 3511525774-1584720945
                                  • Opcode ID: e8dd00e081f08df5f59cc19417fbb6108acdd2fa6c1e8984d2d542c1b529ee79
                                  • Instruction ID: ed1036e94a6adde977fc777685f334fb4ecc99350cddf3999dc783deafa01bda
                                  • Opcode Fuzzy Hash: e8dd00e081f08df5f59cc19417fbb6108acdd2fa6c1e8984d2d542c1b529ee79
                                  • Instruction Fuzzy Hash: 7E11A560E1EE4B82FB11DB17AC513B42260AF44764F9400B2D48E862F5EEEDE994C750
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Service$CloseControlErrorHandleLastOpen
                                  • String ID: [E] (%s) -> ControlService(SERVICE_CONTROL_STOP) failed(lpServiceName=%s,gle=%lu)$scm_stop
                                  • API String ID: 3311966420-638458398
                                  • Opcode ID: 39d226b17c5d19a97b0f081be26e22e7528f54a1ea2593885e11c26f739b76bf
                                  • Instruction ID: c991bcb21e4ecb6f72219ee7f5797a14c6bb703f6697aff61ec7dc96b0d058ac
                                  • Opcode Fuzzy Hash: 39d226b17c5d19a97b0f081be26e22e7528f54a1ea2593885e11c26f739b76bf
                                  • Instruction Fuzzy Hash: 53018C62F08E0382FF509B87A48467913A9BF49BA4F0454BAC90E433B5EE7CE4448300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Service$CloseControlErrorHandleLastOpen
                                  • String ID: [E] (%s) -> ControlService(SERVICE_CONTROL_STOP) failed(lpServiceName=%s,gle=%lu)$scm_stop
                                  • API String ID: 3311966420-638458398
                                  • Opcode ID: 1354183fb5f3b1a4a496faa34c4fce142fe0e3d090115fcd85ed68cc77a5d5cb
                                  • Instruction ID: 7b7e5c504f72f9387ffadabbaab48cafe37409aaf43e332e85c81da85efd1e36
                                  • Opcode Fuzzy Hash: 1354183fb5f3b1a4a496faa34c4fce142fe0e3d090115fcd85ed68cc77a5d5cb
                                  • Instruction Fuzzy Hash: 6F018C62F08E0381FF509B87A88467913A9BF49BA4F0454BAC90E433B5EE7CE5448301
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Service$CloseControlErrorHandleLastOpen
                                  • String ID: [E] (%s) -> ControlService(SERVICE_CONTROL_STOP) failed(lpServiceName=%s,gle=%lu)$scm_stop
                                  • API String ID: 3311966420-638458398
                                  • Opcode ID: d755a79ff02b9631c0372abdcf40374a3b633505cadf7dddc6cc8c77f0f91b2d
                                  • Instruction ID: b0bc9b315e9999d16610045f74d64bedf4f84c3c9afb88e4c44de4a55c209bcc
                                  • Opcode Fuzzy Hash: d755a79ff02b9631c0372abdcf40374a3b633505cadf7dddc6cc8c77f0f91b2d
                                  • Instruction Fuzzy Hash: DE018C62F08E0381FF509B87A48467913A9BF49BA5F0454B9C90E433B6EE7CE4448300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Service$CloseControlErrorHandleLastOpen
                                  • String ID: [E] (%s) -> ControlService(SERVICE_CONTROL_STOP) failed(lpServiceName=%s,gle=%lu)$scm_stop
                                  • API String ID: 3311966420-638458398
                                  • Opcode ID: 1354183fb5f3b1a4a496faa34c4fce142fe0e3d090115fcd85ed68cc77a5d5cb
                                  • Instruction ID: 7b7e5c504f72f9387ffadabbaab48cafe37409aaf43e332e85c81da85efd1e36
                                  • Opcode Fuzzy Hash: 1354183fb5f3b1a4a496faa34c4fce142fe0e3d090115fcd85ed68cc77a5d5cb
                                  • Instruction Fuzzy Hash: 6F018C62F08E0381FF509B87A88467913A9BF49BA4F0454BAC90E433B5EE7CE5448301
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Service$CloseControlErrorHandleLastOpen
                                  • String ID: [E] (%s) -> ControlService(SERVICE_CONTROL_STOP) failed(lpServiceName=%s,gle=%lu)$scm_stop
                                  • API String ID: 3311966420-638458398
                                  • Opcode ID: d755a79ff02b9631c0372abdcf40374a3b633505cadf7dddc6cc8c77f0f91b2d
                                  • Instruction ID: b0bc9b315e9999d16610045f74d64bedf4f84c3c9afb88e4c44de4a55c209bcc
                                  • Opcode Fuzzy Hash: d755a79ff02b9631c0372abdcf40374a3b633505cadf7dddc6cc8c77f0f91b2d
                                  • Instruction Fuzzy Hash: DE018C62F08E0381FF509B87A48467913A9BF49BA5F0454B9C90E433B6EE7CE4448300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Service$CloseControlErrorHandleLastOpen
                                  • String ID: [E] (%s) -> ControlService(SERVICE_CONTROL_STOP) failed(lpServiceName=%s,gle=%lu)$scm_stop
                                  • API String ID: 3311966420-638458398
                                  • Opcode ID: 39d226b17c5d19a97b0f081be26e22e7528f54a1ea2593885e11c26f739b76bf
                                  • Instruction ID: c991bcb21e4ecb6f72219ee7f5797a14c6bb703f6697aff61ec7dc96b0d058ac
                                  • Opcode Fuzzy Hash: 39d226b17c5d19a97b0f081be26e22e7528f54a1ea2593885e11c26f739b76bf
                                  • Instruction Fuzzy Hash: 53018C62F08E0382FF509B87A48467913A9BF49BA4F0454BAC90E433B5EE7CE4448300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Service$CloseControlErrorHandleLastOpen
                                  • String ID: [E] (%s) -> ControlService(SERVICE_CONTROL_STOP) failed(lpServiceName=%s,gle=%lu)$scm_stop
                                  • API String ID: 3311966420-638458398
                                  • Opcode ID: c33561d12d3229e8870e97e301ee69838ae1b1f69a4fb9fb7f5ba37d45c04149
                                  • Instruction ID: 5abbb35e846caa1a36decf62a35e7d5f08d7df47bb41201d694f7f7c15a6e3a4
                                  • Opcode Fuzzy Hash: c33561d12d3229e8870e97e301ee69838ae1b1f69a4fb9fb7f5ba37d45c04149
                                  • Instruction Fuzzy Hash: 62018C62F08E0381FF509B87E88467913A9BF49BA4F0454B9C90E433B5EE7CE4888300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Service$CloseControlErrorHandleLastOpen
                                  • String ID: [E] (%s) -> ControlService(SERVICE_CONTROL_STOP) failed(lpServiceName=%s,gle=%lu)$scm_stop
                                  • API String ID: 3311966420-638458398
                                  • Opcode ID: c33561d12d3229e8870e97e301ee69838ae1b1f69a4fb9fb7f5ba37d45c04149
                                  • Instruction ID: 5abbb35e846caa1a36decf62a35e7d5f08d7df47bb41201d694f7f7c15a6e3a4
                                  • Opcode Fuzzy Hash: c33561d12d3229e8870e97e301ee69838ae1b1f69a4fb9fb7f5ba37d45c04149
                                  • Instruction Fuzzy Hash: 62018C62F08E0381FF509B87E88467913A9BF49BA4F0454B9C90E433B5EE7CE4888300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: AddressErrorLastLibraryLoadProcfflushfwrite
                                  • String ID: Done$Wow64DisableWow64FsRedirection$[E] (%s) -> Wow64DisableWow64FsRedirection failed(gle=%lu)$[I] (%s) -> %s$fs_wow_redir_disable$kernel32
                                  • API String ID: 1533789296-1853374401
                                  • Opcode ID: 3c6fde57ad9de5adf9d03fa5379e8ba19824a2bc27a12cabdc5cee2dc70506b6
                                  • Instruction ID: 9426e6b0476af6cd5e6be2e71c912db7edf5eb14f289f401f0f656c9336504da
                                  • Opcode Fuzzy Hash: 3c6fde57ad9de5adf9d03fa5379e8ba19824a2bc27a12cabdc5cee2dc70506b6
                                  • Instruction Fuzzy Hash: 1D019360E1EE4FD2FB10DB17AC913B81260AF04B64F8404F2D44E866F1EEECE9958750
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: LibraryLoadResource$FindFree
                                  • String ID: (ver != NULL)$C:/Projects/rdp/bot/rpd-controller/rdp.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$rdp_version$termsrv.dll
                                  • API String ID: 3272429154-2519045969
                                  • Opcode ID: 1ae8dc0e7033f0d680bada044a56bc459b1fd35c778bb9db268845c80eb1e7a7
                                  • Instruction ID: 058ac08102e3c122b928f1fbcc5fda0b60bb0022b91d66ba3e3dd75e41024c8e
                                  • Opcode Fuzzy Hash: 1ae8dc0e7033f0d680bada044a56bc459b1fd35c778bb9db268845c80eb1e7a7
                                  • Instruction Fuzzy Hash: 69F0E760E0DE0791FF21DB93A8945B81259AF48774F9801BAD90E063B2EE2CB94AC314
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: CriticalSection$Heap$CloseDeleteEnterFreeHandleLeaveObjectProcessSingleWait
                                  • String ID: Done$[I] (%s) -> %s$ebus_cleanup
                                  • API String ID: 3198640931-3713968270
                                  • Opcode ID: 70793c2a016fe52366cf0e1d994800624d52a6a0fdbe5a5cf153969d17cf4d9a
                                  • Instruction ID: 00bcafb46d81632830885a0b2ebe78316228f601134c4471db21db5bb138be76
                                  • Opcode Fuzzy Hash: 70793c2a016fe52366cf0e1d994800624d52a6a0fdbe5a5cf153969d17cf4d9a
                                  • Instruction Fuzzy Hash: 28019320A08E8A81FA14DB23EC953B42361BF80774F5447F5D47D4A2F5EFEDA9899710
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Heap_errno$ErrorFreeLastProcessfopenfseeksendstrcpy
                                  • String ID: ($-RGMLWD-$ORRE
                                  • API String ID: 1421482426-2390005167
                                  • Opcode ID: 9bd85fb98a04c2d7f282292f880e28581716fbf9b3cf189157d077e1d52ab63c
                                  • Instruction ID: 47aff7d7aa583c1aa84ec27c7082726885dc1862b62f97dcd095154204c36db3
                                  • Opcode Fuzzy Hash: 9bd85fb98a04c2d7f282292f880e28581716fbf9b3cf189157d077e1d52ab63c
                                  • Instruction Fuzzy Hash: A7719572A0CE9E83EA609B26A9403BD6751DB41BB4F500271EADD077F5CEADDC468B40
                                  APIs
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Sleep_amsg_exit$_initterm
                                  • String ID:
                                  • API String ID: 2193611136-0
                                  • Opcode ID: 0d59a9bbdadfa98793d80cd63363695fbedac232d6db2798325d0230d2e31b90
                                  • Instruction ID: 93001bf90636edd9fde984d994cc379f50f5db709080a3a5a870018aabd16685
                                  • Opcode Fuzzy Hash: 0d59a9bbdadfa98793d80cd63363695fbedac232d6db2798325d0230d2e31b90
                                  • Instruction Fuzzy Hash: 3A413821A09E8EC6FB55DB13EC5027922A1BF58BA4F5844F1CA4D973F5EEECE8418310
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: CloseHandle
                                  • String ID: (pi != NULL)$C:/Projects/rdp/bot/codebase/process.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$process_free
                                  • API String ID: 2962429428-1801624891
                                  • Opcode ID: 48091f2a0962f079f29521df7b3f5c81ad1906a3e722640791fc8fab62d4ab0b
                                  • Instruction ID: 9b3e67fc830fc9dc4b1b52fa6217c8ec5f40dcd821d133a0453ad98b0febf6c1
                                  • Opcode Fuzzy Hash: 48091f2a0962f079f29521df7b3f5c81ad1906a3e722640791fc8fab62d4ab0b
                                  • Instruction Fuzzy Hash: 61F0F861A18D9F85FA00DB26FC501B82720AF50768F8441B2D94D176F0DEACD946C340
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: _stricmp
                                  • String ID: (name != NULL)$C:/Projects/rdp/bot/codebase/scm.c$[E] (%s) -> Assertation failed: %s, file %s, line %d$scm_find
                                  • API String ID: 2884411883-2863218139
                                  • Opcode ID: c277aa45597e2b8e077a23331a0580097456e195fb04bf7e1bf7432c4daca58d
                                  • Instruction ID: 07112cd2ae8dcf238d1434ddeb6a737f2202b1e0816597cbf402d3fab3e16768
                                  • Opcode Fuzzy Hash: c277aa45597e2b8e077a23331a0580097456e195fb04bf7e1bf7432c4daca58d
                                  • Instruction Fuzzy Hash: 1F014B61E0EE0790FF559BA2E4447BA63A9EF447A4F4810B9E94F062B0EF7CE545C701
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastfflushfwriteshutdown
                                  • String ID: [D] (%s) -> Done(sock=0x%llx)$[E] (%s) -> shutdown failed(sock=0x%llx,chan=%d,WSAgle=%d)$sock_shutdown
                                  • API String ID: 2143829457-932964775
                                  • Opcode ID: 593188122a7cfa4796afd97ec4a7eab56fafb39927c9130e4034bde85502587f
                                  • Instruction ID: f1a169f60b4b8f903f4230d02fb9e23d24c9de2bb1a0edb871cd35dcae2bef55
                                  • Opcode Fuzzy Hash: 593188122a7cfa4796afd97ec4a7eab56fafb39927c9130e4034bde85502587f
                                  • Instruction Fuzzy Hash: 6DF05E21E0CC4BD2FA20A72BEC450F92650AF10BB0F9445B2E94C462F5EFECA95A8301
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastclosesocketfflushfwrite
                                  • String ID: [D] (%s) -> Done(sock=0x%llx)$[E] (%s) -> closesocket failed(sock=0x%llx,WSAgle=%d)$sock_close
                                  • API String ID: 152032778-2221966578
                                  • Opcode ID: f7103db33014c39b255244beb88c324541c5afc457535d89a7f2c5182b634700
                                  • Instruction ID: 20f52e4dd9314662cc152839a4144e9ad441ba68c692d37feabdcfcba603feea
                                  • Opcode Fuzzy Hash: f7103db33014c39b255244beb88c324541c5afc457535d89a7f2c5182b634700
                                  • Instruction Fuzzy Hash: 68F05E50E08D8F82FA10AB67EC410F922509F14BB0F9413B5D57D462F5ADECA9598301
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastclosesocketfflushfwrite
                                  • String ID: [D] (%s) -> Done(sock=0x%llx)$[E] (%s) -> closesocket failed(sock=0x%llx,WSAgle=%d)$sock_close
                                  • API String ID: 152032778-2221966578
                                  • Opcode ID: bb115bf1a3de3cb7bfef1c94fb363b858f8f74bf0ac96ec09b59a5527da0d493
                                  • Instruction ID: efaa5d3860f74aaa780615935d8ac2eb26afb7d541f01594bdcf37e2b6f404c1
                                  • Opcode Fuzzy Hash: bb115bf1a3de3cb7bfef1c94fb363b858f8f74bf0ac96ec09b59a5527da0d493
                                  • Instruction Fuzzy Hash: D4F05E61E4CD0392FB116BE7E8514B823299F15B71F1403F9D53D062F2AF1CA5458301
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: CriticalDeleteSectionfclose
                                  • String ID: Done$[I] (%s) -> %s$debug_cleanup
                                  • API String ID: 3387974148-4247581856
                                  • Opcode ID: aeb4f1ca7e14951c31381153f3446be483603443577fafeadf4f5bda74db2a5f
                                  • Instruction ID: c60917ecea395240720e1a285ede7a52164eda40bc31b7337444f8f72057a0f0
                                  • Opcode Fuzzy Hash: aeb4f1ca7e14951c31381153f3446be483603443577fafeadf4f5bda74db2a5f
                                  • Instruction Fuzzy Hash: B1F03A21E0AE03C5FB419BD3E8A53B4236EAF58324F5414F9C44D06671CF7DB0498782
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Heap$FreeProcess$CloseCriticalDeleteHandleSectionService
                                  • String ID: Done$[I] (%s) -> %s$scm_cleanup
                                  • API String ID: 3170896351-2182690050
                                  • Opcode ID: 57e7b2d492cb600557f65335f972399dcba93579e55ec1ad9c8988fd1aa638ab
                                  • Instruction ID: d1ef011f8f3d36b79dcdda82a86073aee6a82100e2b93b130586ca2e96be8127
                                  • Opcode Fuzzy Hash: 57e7b2d492cb600557f65335f972399dcba93579e55ec1ad9c8988fd1aa638ab
                                  • Instruction Fuzzy Hash: 2CF0152AE0AE03C4FB95DBD3E891778236AAF48768F9401B9C44D022719F3CB108C346
                                  APIs
                                  • VirtualProtect.KERNEL32(?,?,?,?,?,00007FFE126E1034,?,?,00007FFE126D11A1), ref: 00007FFE126DCC32
                                  Strings
                                  • Unknown pseudo relocation bit size %d., xrefs: 00007FFE126DCB5B
                                  • Unknown pseudo relocation protocol version %d., xrefs: 00007FFE126DCAD2
                                  • %d bit pseudo relocation at %p out of range, targeting %p, yielding the value %p., xrefs: 00007FFE126DCBCD
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ProtectVirtual
                                  • String ID: Unknown pseudo relocation bit size %d.$ Unknown pseudo relocation protocol version %d.$%d bit pseudo relocation at %p out of range, targeting %p, yielding the value %p.
                                  • API String ID: 544645111-1286557213
                                  • Opcode ID: d0f3fb6da05cc254e0b3ff34542b3f475c5facd6cc65ea65544b784f58289625
                                  • Instruction ID: 977d30ace46e557ae45daabc20291fe0d9671979d396078e6617abc2733fdda4
                                  • Opcode Fuzzy Hash: d0f3fb6da05cc254e0b3ff34542b3f475c5facd6cc65ea65544b784f58289625
                                  • Instruction Fuzzy Hash: 55615C61F18E5E86EA14CB27ED4067827A0AB44BB4F1481B1DA9D477F9DEBCE541C700
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorLastsetsockopt
                                  • String ID: [E] (%s) -> setsockopt(SO_KEEPALIVE) failed(sock=0x%llx,value=%d,WSAgle=%d)$tcp_set_keepalive
                                  • API String ID: 1729277954-536111009
                                  • Opcode ID: 7ecc009d2ed3ae8a9b0078967a05074eb7a03867f61cbee3818ba73ef7baa526
                                  • Instruction ID: 9ca48767a09735fb6c125a33d88d11c99f6e244442e039ee69068fc429061078
                                  • Opcode Fuzzy Hash: 7ecc009d2ed3ae8a9b0078967a05074eb7a03867f61cbee3818ba73ef7baa526
                                  • Instruction Fuzzy Hash: 67F0BB61A1894587F3509F27BC044756690FF98774F508271ED6D837F4DEBCD90A8B00
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: CriticalDeleteSection
                                  • String ID: Done$[I] (%s) -> %s$debug_cleanup
                                  • API String ID: 166494926-4247581856
                                  • Opcode ID: b2552b2603190d3dfbcad6e125bc77a0089a5f81a6dfc14119ca7b5ee64b6f79
                                  • Instruction ID: d25525f88869d45f18f4bd3af347a3f613f0743399556c0f5d66edbf5accee36
                                  • Opcode Fuzzy Hash: b2552b2603190d3dfbcad6e125bc77a0089a5f81a6dfc14119ca7b5ee64b6f79
                                  • Instruction Fuzzy Hash: AFF09D20A19E8BC5FA05DB23ECA43B52260BF51734F8405B5C04D162F5EFED6189C360
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: CriticalDeleteSection
                                  • String ID: Done$[I] (%s) -> %s$proxy_init
                                  • API String ID: 166494926-991486753
                                  • Opcode ID: 2975420c0a3c075b2e3cd463d9d46d928e6aae1cded662ae34a472e4de050931
                                  • Instruction ID: 2147b4f76176b156395331e248f6f51a92f425106298825dd9bfc9df838f7cca
                                  • Opcode Fuzzy Hash: 2975420c0a3c075b2e3cd463d9d46d928e6aae1cded662ae34a472e4de050931
                                  • Instruction Fuzzy Hash: A0F0D425D0BE47C4FB419B93E8457B822AABF54774F8041BAC10E02271DF3CA589C301
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: ErrorHandleLastModule
                                  • String ID: [E] (%s) -> GetModuleHandleExA failed(gle=%lu)$module_current
                                  • API String ID: 4242514867-2427012484
                                  • Opcode ID: d11d240018aab1f42355d239cf3f525ac66d3e20a7cc312227a91e68f9aaca59
                                  • Instruction ID: 727ed38fd280d448bc0d1197106782500d1f3816ed164268b456b32ad2572b44
                                  • Opcode Fuzzy Hash: d11d240018aab1f42355d239cf3f525ac66d3e20a7cc312227a91e68f9aaca59
                                  • Instruction Fuzzy Hash: 91F03061A08E0A91F720DB12EC403792760EB447B8F9800B5D58D466F4DEACD258CB40
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: ErrorHandleLastModule
                                  • String ID: [E] (%s) -> GetModuleHandleExA failed(gle=%lu)$module_current
                                  • API String ID: 4242514867-2427012484
                                  • Opcode ID: a689698aadfcd3d6d4072a0834da6b3aa0b2ec0d04f59930c527e4dd69370b82
                                  • Instruction ID: c4ce05d2fb2088309d5da4feb2ed910a20efedc867f9a1bbb4d50ee1a3681dcd
                                  • Opcode Fuzzy Hash: a689698aadfcd3d6d4072a0834da6b3aa0b2ec0d04f59930c527e4dd69370b82
                                  • Instruction Fuzzy Hash: 33F06D65A1CE07D0EB219F92E8803AD2769FF487B8F8801B9C58D026B4CF3CE248C741
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Cleanupfflushfwrite
                                  • String ID: Done$[I] (%s) -> %s$net_cleanup
                                  • API String ID: 1441811225-3926276259
                                  • Opcode ID: 11f392ae5c464eb5dd1a1c6ad7e6d60bc081ecf5e2099df0fbf8ecaee2072699
                                  • Instruction ID: 5cf7221b79ff1cfb1792b86ca8609ca795c17aed758dcd0e658af0fe644f3053
                                  • Opcode Fuzzy Hash: 11f392ae5c464eb5dd1a1c6ad7e6d60bc081ecf5e2099df0fbf8ecaee2072699
                                  • Instruction Fuzzy Hash: B8D0C964D59C4BD1EA00E716DC460B51320AB50764F9050B1C00D010F09EACA1AA8710
                                  APIs
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Byte$CharMultiWide$Lead_errno
                                  • String ID:
                                  • API String ID: 2766522060-0
                                  • Opcode ID: f125edc36d3b8c8eb07748e4d7d74821e8797b385320d5e951b27f540b9cdcff
                                  • Instruction ID: 109220707c275adeea440b88ed8447feccaf87edf1f69e555df53fcc34d850e3
                                  • Opcode Fuzzy Hash: f125edc36d3b8c8eb07748e4d7d74821e8797b385320d5e951b27f540b9cdcff
                                  • Instruction Fuzzy Hash: A431F872A0CA828AF7708F22AC4037D6A50FB657A8F149171DA9C637E5DBBDD445CB00
                                  APIs
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: _unlock$_lockrealloc
                                  • String ID:
                                  • API String ID: 4047297157-0
                                  • Opcode ID: 2a7e4f9ecfc54b828ce2ac12068c354f055dfaff74910f07e8cc230d271ba141
                                  • Instruction ID: 7d6d495d1294f7e7a02d01100bfe5ed0e4107d7c0e2b7d86542e45f094ac4a5b
                                  • Opcode Fuzzy Hash: 2a7e4f9ecfc54b828ce2ac12068c354f055dfaff74910f07e8cc230d271ba141
                                  • Instruction Fuzzy Hash: DA118E22A0AF4185EF45DF62EC1136862D5EF44BA8F188074DA4C5B3D5EEBCE891C310
                                  APIs
                                  Strings
                                  • [D] (%s) -> Done(size=%u,code=%08x(%.4s),sender=%016llx(%.8s),receiver=%016llx(%.8s),td=%lld,err=%08x), xrefs: 00007FFE126D2706
                                  • ebus_dispatch, xrefs: 00007FFE126D26FF
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: CriticalSection$EnterLeave
                                  • String ID: [D] (%s) -> Done(size=%u,code=%08x(%.4s),sender=%016llx(%.8s),receiver=%016llx(%.8s),td=%lld,err=%08x)$ebus_dispatch
                                  • API String ID: 3168844106-1717220914
                                  • Opcode ID: 49ea56a97abc367d7c5f7885a608cb66da50d361340aeccd66cb374a8bf68df5
                                  • Instruction ID: f97910d40bbfa7153639cf1656318922ec349d8087c621fd43606b1a2ba81e1e
                                  • Opcode Fuzzy Hash: 49ea56a97abc367d7c5f7885a608cb66da50d361340aeccd66cb374a8bf68df5
                                  • Instruction Fuzzy Hash: 4D213B32A08F8A86EB25CF16EC505696360FB54BB4F144171DA9D476F8EFBCE852C710
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: CloseHandleService
                                  • String ID: [E] (%s) -> Service stop failed(lpServiceName=%s,pid=%lu,err=%08x)$scm_stop
                                  • API String ID: 1725840886-2743387298
                                  • Opcode ID: eada9341f7b65974e50c900dd1b2d16e4aafaf64b06467ad1ef1277b257a6ef0
                                  • Instruction ID: af47cd3a9b5031e1cc9d54d09e6604a69786aa327bbdd5b1f372774d2c335cb0
                                  • Opcode Fuzzy Hash: eada9341f7b65974e50c900dd1b2d16e4aafaf64b06467ad1ef1277b257a6ef0
                                  • Instruction Fuzzy Hash: A3018062F08E4342F7716AD76880BBE128D6F91774F0801BECE5D462B1DE6CE9858300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: CloseHandleService
                                  • String ID: [E] (%s) -> Service stop failed(lpServiceName=%s,pid=%lu,err=%08x)$scm_stop
                                  • API String ID: 1725840886-2743387298
                                  • Opcode ID: d37e6684921ac6afd3a3190e2d155180c18594454b0321776bc693f2bf8bce3a
                                  • Instruction ID: 83d24077f4e352ae021f9e17cc4bc3d0f1f1529a9da8b8ec40b72199107f0578
                                  • Opcode Fuzzy Hash: d37e6684921ac6afd3a3190e2d155180c18594454b0321776bc693f2bf8bce3a
                                  • Instruction Fuzzy Hash: 98018062F08E4342F7716AD76880BBE128D6F91774F0801BECE5D462B1DE6CE9858300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: CloseHandleService
                                  • String ID: [E] (%s) -> Service stop failed(lpServiceName=%s,pid=%lu,err=%08x)$scm_stop
                                  • API String ID: 1725840886-2743387298
                                  • Opcode ID: b0e45bea8efca1ee1d99ad525f4bd780d33b18cb6567acc56d3d14e090869979
                                  • Instruction ID: c4616ab93f2b0cdeee9b96dcd730f7a7ee220cf68bf280633d207ce7e33d3654
                                  • Opcode Fuzzy Hash: b0e45bea8efca1ee1d99ad525f4bd780d33b18cb6567acc56d3d14e090869979
                                  • Instruction Fuzzy Hash: 18018062F08E4342F7716AD76880BBE128DAF91774F0801BECE5D462B1DE6CE9858300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: CloseHandleService
                                  • String ID: [E] (%s) -> Service stop failed(lpServiceName=%s,pid=%lu,err=%08x)$scm_stop
                                  • API String ID: 1725840886-2743387298
                                  • Opcode ID: 9e9aaee555912c83f6fc53b451cab8b2b66ab17b373ff7a645e401c1bf3bdc3c
                                  • Instruction ID: c4616ab93f2b0cdeee9b96dcd730f7a7ee220cf68bf280633d207ce7e33d3654
                                  • Opcode Fuzzy Hash: 9e9aaee555912c83f6fc53b451cab8b2b66ab17b373ff7a645e401c1bf3bdc3c
                                  • Instruction Fuzzy Hash: 18018062F08E4342F7716AD76880BBE128DAF91774F0801BECE5D462B1DE6CE9858300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: CloseHandleService
                                  • String ID: [E] (%s) -> Service stop failed(lpServiceName=%s,pid=%lu,err=%08x)$scm_stop
                                  • API String ID: 1725840886-2743387298
                                  • Opcode ID: 0093b8fea805837825659e0f3e0aaf3ff064e882623dd3e4ab1f24279e994d2e
                                  • Instruction ID: d62fab5ed4393aec4aa7f16f19e33d5ec39d2d2071d8f95867a889a37fd1ec39
                                  • Opcode Fuzzy Hash: 0093b8fea805837825659e0f3e0aaf3ff064e882623dd3e4ab1f24279e994d2e
                                  • Instruction Fuzzy Hash: EB019E62F0CE4382F7716AD76880BBE128DAF91774F0801BECE5D462B1DE6CE9858300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: ecb2b89b5e7aa1af6933886f6cd76dfa94bf214193f3cb43210aadc99fb1fce7
                                  • Instruction ID: c0c41f5fb2c4bc762a7f0244a4523a8c1b9dd32c9d4aa43145c6f5ac81d66c16
                                  • Opcode Fuzzy Hash: ecb2b89b5e7aa1af6933886f6cd76dfa94bf214193f3cb43210aadc99fb1fce7
                                  • Instruction Fuzzy Hash: ABF08913B08A0F83F9529A067D417BD12416F41775F4D05F6DD8D0FAE1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 651b008547de0a0734efe05499035938bc8e2b426924568dcd9034468eb89c87
                                  • Instruction ID: b5f6e1fac01226c58b96aeb1285064e8eaf43227bd4e81bb52d6b2c958242a92
                                  • Opcode Fuzzy Hash: 651b008547de0a0734efe05499035938bc8e2b426924568dcd9034468eb89c87
                                  • Instruction Fuzzy Hash: 31F08913B08A0F83F9539A067D417BD12416F41775F4D05F6DD8D0F6E1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 651b008547de0a0734efe05499035938bc8e2b426924568dcd9034468eb89c87
                                  • Instruction ID: b5f6e1fac01226c58b96aeb1285064e8eaf43227bd4e81bb52d6b2c958242a92
                                  • Opcode Fuzzy Hash: 651b008547de0a0734efe05499035938bc8e2b426924568dcd9034468eb89c87
                                  • Instruction Fuzzy Hash: 31F08913B08A0F83F9539A067D417BD12416F41775F4D05F6DD8D0F6E1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 651b008547de0a0734efe05499035938bc8e2b426924568dcd9034468eb89c87
                                  • Instruction ID: b5f6e1fac01226c58b96aeb1285064e8eaf43227bd4e81bb52d6b2c958242a92
                                  • Opcode Fuzzy Hash: 651b008547de0a0734efe05499035938bc8e2b426924568dcd9034468eb89c87
                                  • Instruction Fuzzy Hash: 31F08913B08A0F83F9539A067D417BD12416F41775F4D05F6DD8D0F6E1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: b0a2e04803684ab1046b6b72119038998ad8c3b2f1bd8de1f186fb5461de7af0
                                  • Instruction ID: 1c4432cd7b6349f1d0135f06d10094f50be44377df4a723f55965e3104b563b7
                                  • Opcode Fuzzy Hash: b0a2e04803684ab1046b6b72119038998ad8c3b2f1bd8de1f186fb5461de7af0
                                  • Instruction Fuzzy Hash: F4F05413B0890F82F9529A067C417BD12416F41775F4D05F2DD8D0FAE1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: ecb2b89b5e7aa1af6933886f6cd76dfa94bf214193f3cb43210aadc99fb1fce7
                                  • Instruction ID: c0c41f5fb2c4bc762a7f0244a4523a8c1b9dd32c9d4aa43145c6f5ac81d66c16
                                  • Opcode Fuzzy Hash: ecb2b89b5e7aa1af6933886f6cd76dfa94bf214193f3cb43210aadc99fb1fce7
                                  • Instruction Fuzzy Hash: ABF08913B08A0F83F9529A067D417BD12416F41775F4D05F6DD8D0FAE1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 52bddc3ceb909860e75a6136755f9cccd486d613cc30ae5d59a6bec256897139
                                  • Instruction ID: 2c09301333e7e061ff2ce14073a043598c22f75f565642e3daa76c52bd7e28b4
                                  • Opcode Fuzzy Hash: 52bddc3ceb909860e75a6136755f9cccd486d613cc30ae5d59a6bec256897139
                                  • Instruction Fuzzy Hash: D5F08913B08A0F83F9529A06BD417BD12416F41775F4D05F6DD8D0F6E1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 7027c4c35489a5b710680c362744ee6bbf84f9fee4b5875ad56ece3a20df7e47
                                  • Instruction ID: cd0b7b99f5b08b9c63f518d502ab92a4dacaf1fbac4244d3dd0f5201ea5d18c4
                                  • Opcode Fuzzy Hash: 7027c4c35489a5b710680c362744ee6bbf84f9fee4b5875ad56ece3a20df7e47
                                  • Instruction Fuzzy Hash: A8F08913B08A0F83F9529A067D417BD12416F41775F4D05F6DD9D0F6E1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: e6c6f4eb72822a7a18e31b5cbf2feec447158e6a93172f1e437b3715734c4219
                                  • Instruction ID: af28dc0a987c5eadfa041dc712e54d4abdeccfdd358ab17c276472c7c83d9d62
                                  • Opcode Fuzzy Hash: e6c6f4eb72822a7a18e31b5cbf2feec447158e6a93172f1e437b3715734c4219
                                  • Instruction Fuzzy Hash: EDF08913B08A0F87F9529A067D417BD12416F41775F4D05F6DD8D0F6E1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 5224d5ab997a7560d73d6d6af1e78d01773b4518d5cb3d20f5b7b8dad6205f8b
                                  • Instruction ID: f7e991e140601f4d8eeafeb0af900d11b7f935d8084fce3191abeb8a2445a14e
                                  • Opcode Fuzzy Hash: 5224d5ab997a7560d73d6d6af1e78d01773b4518d5cb3d20f5b7b8dad6205f8b
                                  • Instruction Fuzzy Hash: 2CF08913B08A0F83F9529A06BD417BD12416F41775F4D05F6DD8C0F6E1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: ecb2b89b5e7aa1af6933886f6cd76dfa94bf214193f3cb43210aadc99fb1fce7
                                  • Instruction ID: c0c41f5fb2c4bc762a7f0244a4523a8c1b9dd32c9d4aa43145c6f5ac81d66c16
                                  • Opcode Fuzzy Hash: ecb2b89b5e7aa1af6933886f6cd76dfa94bf214193f3cb43210aadc99fb1fce7
                                  • Instruction Fuzzy Hash: ABF08913B08A0F83F9529A067D417BD12416F41775F4D05F6DD8D0FAE1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 52bddc3ceb909860e75a6136755f9cccd486d613cc30ae5d59a6bec256897139
                                  • Instruction ID: 2c09301333e7e061ff2ce14073a043598c22f75f565642e3daa76c52bd7e28b4
                                  • Opcode Fuzzy Hash: 52bddc3ceb909860e75a6136755f9cccd486d613cc30ae5d59a6bec256897139
                                  • Instruction Fuzzy Hash: D5F08913B08A0F83F9529A06BD417BD12416F41775F4D05F6DD8D0F6E1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 7027c4c35489a5b710680c362744ee6bbf84f9fee4b5875ad56ece3a20df7e47
                                  • Instruction ID: cd0b7b99f5b08b9c63f518d502ab92a4dacaf1fbac4244d3dd0f5201ea5d18c4
                                  • Opcode Fuzzy Hash: 7027c4c35489a5b710680c362744ee6bbf84f9fee4b5875ad56ece3a20df7e47
                                  • Instruction Fuzzy Hash: A8F08913B08A0F83F9529A067D417BD12416F41775F4D05F6DD9D0F6E1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: e6c6f4eb72822a7a18e31b5cbf2feec447158e6a93172f1e437b3715734c4219
                                  • Instruction ID: af28dc0a987c5eadfa041dc712e54d4abdeccfdd358ab17c276472c7c83d9d62
                                  • Opcode Fuzzy Hash: e6c6f4eb72822a7a18e31b5cbf2feec447158e6a93172f1e437b3715734c4219
                                  • Instruction Fuzzy Hash: EDF08913B08A0F87F9529A067D417BD12416F41775F4D05F6DD8D0F6E1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 5224d5ab997a7560d73d6d6af1e78d01773b4518d5cb3d20f5b7b8dad6205f8b
                                  • Instruction ID: f7e991e140601f4d8eeafeb0af900d11b7f935d8084fce3191abeb8a2445a14e
                                  • Opcode Fuzzy Hash: 5224d5ab997a7560d73d6d6af1e78d01773b4518d5cb3d20f5b7b8dad6205f8b
                                  • Instruction Fuzzy Hash: 2CF08913B08A0F83F9529A06BD417BD12416F41775F4D05F6DD8C0F6E1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: ecb2b89b5e7aa1af6933886f6cd76dfa94bf214193f3cb43210aadc99fb1fce7
                                  • Instruction ID: c0c41f5fb2c4bc762a7f0244a4523a8c1b9dd32c9d4aa43145c6f5ac81d66c16
                                  • Opcode Fuzzy Hash: ecb2b89b5e7aa1af6933886f6cd76dfa94bf214193f3cb43210aadc99fb1fce7
                                  • Instruction Fuzzy Hash: ABF08913B08A0F83F9529A067D417BD12416F41775F4D05F6DD8D0FAE1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 52bddc3ceb909860e75a6136755f9cccd486d613cc30ae5d59a6bec256897139
                                  • Instruction ID: 2c09301333e7e061ff2ce14073a043598c22f75f565642e3daa76c52bd7e28b4
                                  • Opcode Fuzzy Hash: 52bddc3ceb909860e75a6136755f9cccd486d613cc30ae5d59a6bec256897139
                                  • Instruction Fuzzy Hash: D5F08913B08A0F83F9529A06BD417BD12416F41775F4D05F6DD8D0F6E1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 7027c4c35489a5b710680c362744ee6bbf84f9fee4b5875ad56ece3a20df7e47
                                  • Instruction ID: cd0b7b99f5b08b9c63f518d502ab92a4dacaf1fbac4244d3dd0f5201ea5d18c4
                                  • Opcode Fuzzy Hash: 7027c4c35489a5b710680c362744ee6bbf84f9fee4b5875ad56ece3a20df7e47
                                  • Instruction Fuzzy Hash: A8F08913B08A0F83F9529A067D417BD12416F41775F4D05F6DD9D0F6E1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: e6c6f4eb72822a7a18e31b5cbf2feec447158e6a93172f1e437b3715734c4219
                                  • Instruction ID: af28dc0a987c5eadfa041dc712e54d4abdeccfdd358ab17c276472c7c83d9d62
                                  • Opcode Fuzzy Hash: e6c6f4eb72822a7a18e31b5cbf2feec447158e6a93172f1e437b3715734c4219
                                  • Instruction Fuzzy Hash: EDF08913B08A0F87F9529A067D417BD12416F41775F4D05F6DD8D0F6E1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 5224d5ab997a7560d73d6d6af1e78d01773b4518d5cb3d20f5b7b8dad6205f8b
                                  • Instruction ID: f7e991e140601f4d8eeafeb0af900d11b7f935d8084fce3191abeb8a2445a14e
                                  • Opcode Fuzzy Hash: 5224d5ab997a7560d73d6d6af1e78d01773b4518d5cb3d20f5b7b8dad6205f8b
                                  • Instruction Fuzzy Hash: 2CF08913B08A0F83F9529A06BD417BD12416F41775F4D05F6DD8C0F6E1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 52bddc3ceb909860e75a6136755f9cccd486d613cc30ae5d59a6bec256897139
                                  • Instruction ID: 2c09301333e7e061ff2ce14073a043598c22f75f565642e3daa76c52bd7e28b4
                                  • Opcode Fuzzy Hash: 52bddc3ceb909860e75a6136755f9cccd486d613cc30ae5d59a6bec256897139
                                  • Instruction Fuzzy Hash: D5F08913B08A0F83F9529A06BD417BD12416F41775F4D05F6DD8D0F6E1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 7027c4c35489a5b710680c362744ee6bbf84f9fee4b5875ad56ece3a20df7e47
                                  • Instruction ID: cd0b7b99f5b08b9c63f518d502ab92a4dacaf1fbac4244d3dd0f5201ea5d18c4
                                  • Opcode Fuzzy Hash: 7027c4c35489a5b710680c362744ee6bbf84f9fee4b5875ad56ece3a20df7e47
                                  • Instruction Fuzzy Hash: A8F08913B08A0F83F9529A067D417BD12416F41775F4D05F6DD9D0F6E1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: e6c6f4eb72822a7a18e31b5cbf2feec447158e6a93172f1e437b3715734c4219
                                  • Instruction ID: af28dc0a987c5eadfa041dc712e54d4abdeccfdd358ab17c276472c7c83d9d62
                                  • Opcode Fuzzy Hash: e6c6f4eb72822a7a18e31b5cbf2feec447158e6a93172f1e437b3715734c4219
                                  • Instruction Fuzzy Hash: EDF08913B08A0F87F9529A067D417BD12416F41775F4D05F6DD8D0F6E1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 5224d5ab997a7560d73d6d6af1e78d01773b4518d5cb3d20f5b7b8dad6205f8b
                                  • Instruction ID: f7e991e140601f4d8eeafeb0af900d11b7f935d8084fce3191abeb8a2445a14e
                                  • Opcode Fuzzy Hash: 5224d5ab997a7560d73d6d6af1e78d01773b4518d5cb3d20f5b7b8dad6205f8b
                                  • Instruction Fuzzy Hash: 2CF08913B08A0F83F9529A06BD417BD12416F41775F4D05F6DD8C0F6E1AEBD6C868200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 5709c0765b6f8496f8df3a7eccd76d6d0a261959c6e34066c548116b593456d8
                                  • Instruction ID: 5cc0175fb2c42c4725221c9bc5a0f6358e1db8c89ccdb41a7118a0f19a9e5e80
                                  • Opcode Fuzzy Hash: 5709c0765b6f8496f8df3a7eccd76d6d0a261959c6e34066c548116b593456d8
                                  • Instruction Fuzzy Hash: 48F08263B09E0341FB539A46B9517BD124A2F817B5E4A05B9CD5D0E6F1EF3DA8869200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 21e72524f4de20b60197deac3f47e72fc40ad3756a2ba98f2743e3b9b0231261
                                  • Instruction ID: 385a699bc1e65567d4f59795ce288a04c013e145004f3b635dfbf8b976148e1a
                                  • Opcode Fuzzy Hash: 21e72524f4de20b60197deac3f47e72fc40ad3756a2ba98f2743e3b9b0231261
                                  • Instruction Fuzzy Hash: 69F08C63F09E0341FB539A46B9517BD128A2F817B5E4A05BACD5C0E6F1EF3DA8869200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 1ef5e7788548105050074cc7d457cb1886e5be0a844f57c89e2bed23bb7e37e0
                                  • Instruction ID: 158e8e66602e835f204b1aab700f6c55d453a605df66dc88a44eee78b4727910
                                  • Opcode Fuzzy Hash: 1ef5e7788548105050074cc7d457cb1886e5be0a844f57c89e2bed23bb7e37e0
                                  • Instruction Fuzzy Hash: 12F0EC23B08E0341FB539A46B8507BD028A2F807B4E4A05BACD4C0E2F1EF3DA8828200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 1ef5e7788548105050074cc7d457cb1886e5be0a844f57c89e2bed23bb7e37e0
                                  • Instruction ID: 158e8e66602e835f204b1aab700f6c55d453a605df66dc88a44eee78b4727910
                                  • Opcode Fuzzy Hash: 1ef5e7788548105050074cc7d457cb1886e5be0a844f57c89e2bed23bb7e37e0
                                  • Instruction Fuzzy Hash: 12F0EC23B08E0341FB539A46B8507BD028A2F807B4E4A05BACD4C0E2F1EF3DA8828200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 1ef5e7788548105050074cc7d457cb1886e5be0a844f57c89e2bed23bb7e37e0
                                  • Instruction ID: 158e8e66602e835f204b1aab700f6c55d453a605df66dc88a44eee78b4727910
                                  • Opcode Fuzzy Hash: 1ef5e7788548105050074cc7d457cb1886e5be0a844f57c89e2bed23bb7e37e0
                                  • Instruction Fuzzy Hash: 12F0EC23B08E0341FB539A46B8507BD028A2F807B4E4A05BACD4C0E2F1EF3DA8828200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 5709c0765b6f8496f8df3a7eccd76d6d0a261959c6e34066c548116b593456d8
                                  • Instruction ID: 5cc0175fb2c42c4725221c9bc5a0f6358e1db8c89ccdb41a7118a0f19a9e5e80
                                  • Opcode Fuzzy Hash: 5709c0765b6f8496f8df3a7eccd76d6d0a261959c6e34066c548116b593456d8
                                  • Instruction Fuzzy Hash: 48F08263B09E0341FB539A46B9517BD124A2F817B5E4A05B9CD5D0E6F1EF3DA8869200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 21e72524f4de20b60197deac3f47e72fc40ad3756a2ba98f2743e3b9b0231261
                                  • Instruction ID: 385a699bc1e65567d4f59795ce288a04c013e145004f3b635dfbf8b976148e1a
                                  • Opcode Fuzzy Hash: 21e72524f4de20b60197deac3f47e72fc40ad3756a2ba98f2743e3b9b0231261
                                  • Instruction Fuzzy Hash: 69F08C63F09E0341FB539A46B9517BD128A2F817B5E4A05BACD5C0E6F1EF3DA8869200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 3dea84561a08eda02289668b5a23641fe69872ad0f932d5545ca6a8a00d9cad3
                                  • Instruction ID: b53a2962233827cbdf3ef57d6807b30313552aa38b22123fc0d0bb676225770d
                                  • Opcode Fuzzy Hash: 3dea84561a08eda02289668b5a23641fe69872ad0f932d5545ca6a8a00d9cad3
                                  • Instruction Fuzzy Hash: 25F08263B09E0341FB539A46B9517BD124A2F817B5E4A05BACD5D0E6F1EF3DA8869200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 04483584c3d709d6abb3ad9167d0459b9fcb057600e22160db0457c365a132de
                                  • Instruction ID: 1a14a1b171110b43eb99972a0218b7405ffe3b76348b4cf5b14245e5ec41c090
                                  • Opcode Fuzzy Hash: 04483584c3d709d6abb3ad9167d0459b9fcb057600e22160db0457c365a132de
                                  • Instruction Fuzzy Hash: AAF08C63F09E0341FB539A46B9517BD128A2F817B5E4A05BACD5D0E6F1EF3DA8869200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: fclose
                                  • String ID: [E] (%s) -> Failed(path=%s,err=%08x)$fs_file_read
                                  • API String ID: 3125558077-1073242539
                                  • Opcode ID: 4ff5b688d0eeb14e3199faf831a151054604e1485ebc29b41b24802f0f268173
                                  • Instruction ID: bcae75193750e0b87704b3810a703e7f105d74078f01733b97a0ad8dcf8cced5
                                  • Opcode Fuzzy Hash: 4ff5b688d0eeb14e3199faf831a151054604e1485ebc29b41b24802f0f268173
                                  • Instruction Fuzzy Hash: 60F08C63B09E0341FB539A46B9517BD128A2F817B5E4A05BACD5D0F6F1EF3DA8869200
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: CloseHandleService
                                  • String ID: [E] (%s) -> Service start failed(lpServiceName=%s,err=%08x)$scm_start
                                  • API String ID: 1725840886-2678404757
                                  • Opcode ID: 519a86a81fc24fe0f0d928815388edf54c40d8e89bece97ed147f38440b7f34e
                                  • Instruction ID: d492b5ba31d4f7af08dfb2a4710081c8a33d8002a05717de6f3ede8c1a32feee
                                  • Opcode Fuzzy Hash: 519a86a81fc24fe0f0d928815388edf54c40d8e89bece97ed147f38440b7f34e
                                  • Instruction Fuzzy Hash: 30F05432E0CD1382FB625B96A5409BC12595F01BB8F0901FDCDAE576F0DD2CAC86D381
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: CloseHandleService
                                  • String ID: [E] (%s) -> Service start failed(lpServiceName=%s,err=%08x)$scm_start
                                  • API String ID: 1725840886-2678404757
                                  • Opcode ID: c39ec0f83fba0b7bb5aab92eed5ff1988cfd920119d1b498418e2ae0e516b84a
                                  • Instruction ID: ddbb000c03f675914780a7a1b62dd919bfafaa354e6b0b61771f34263f63f186
                                  • Opcode Fuzzy Hash: c39ec0f83fba0b7bb5aab92eed5ff1988cfd920119d1b498418e2ae0e516b84a
                                  • Instruction Fuzzy Hash: 1FF05432E0CD1382FB725B96A5409BC12595F01BB8F0911FCCDAE576F1ED2DA881D381
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: CloseHandleService
                                  • String ID: [E] (%s) -> Service start failed(lpServiceName=%s,err=%08x)$scm_start
                                  • API String ID: 1725840886-2678404757
                                  • Opcode ID: a7ee9a9b2b16f88340efb8a0b2b52e36d0927bfe179ea8e4806cd418094a4123
                                  • Instruction ID: aa6c6e224b2280a7d44b4ef257fbceb28c4ef4d18a2f248c3da1fe7365e5f4e7
                                  • Opcode Fuzzy Hash: a7ee9a9b2b16f88340efb8a0b2b52e36d0927bfe179ea8e4806cd418094a4123
                                  • Instruction Fuzzy Hash: 9DF05432E0CD1382FB625B96A5409BC12595F01BB8F0911FDCDAE576F1ED2CAC81D381
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: CloseHandleService
                                  • String ID: [E] (%s) -> Service start failed(lpServiceName=%s,err=%08x)$scm_start
                                  • API String ID: 1725840886-2678404757
                                  • Opcode ID: d49c7b6acef5f8fc4d26a5d8f535081e48d87aeb39909334141a3080d2214463
                                  • Instruction ID: 518bfeb42af71910a2d1474d6b0f49af8833513620aceb7e0b6ca521c6b89580
                                  • Opcode Fuzzy Hash: d49c7b6acef5f8fc4d26a5d8f535081e48d87aeb39909334141a3080d2214463
                                  • Instruction Fuzzy Hash: C6F05432E0CD1382FB625B96A5409BC12595F01BB8F0911FDCDAE576F1ED2CAC81D391
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: CloseHandleService
                                  • String ID: [E] (%s) -> Service start failed(lpServiceName=%s,err=%08x)$scm_start
                                  • API String ID: 1725840886-2678404757
                                  • Opcode ID: 519a86a81fc24fe0f0d928815388edf54c40d8e89bece97ed147f38440b7f34e
                                  • Instruction ID: d492b5ba31d4f7af08dfb2a4710081c8a33d8002a05717de6f3ede8c1a32feee
                                  • Opcode Fuzzy Hash: 519a86a81fc24fe0f0d928815388edf54c40d8e89bece97ed147f38440b7f34e
                                  • Instruction Fuzzy Hash: 30F05432E0CD1382FB625B96A5409BC12595F01BB8F0901FDCDAE576F0DD2CAC86D381
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [I] (%s) -> Done(root=0x%p,key=%s,param=%s)$registry_set_value
                                  • API String ID: 1001908780-3542721600
                                  • Opcode ID: cc422ce8ee68a8959793c21b2fdc4b79ac324035df3c0b44995fd49cc8f8ba1c
                                  • Instruction ID: 5d1746f5e6f1740753d032d398d0aba7f0e1f5a4d897220eebd0f80c710d1574
                                  • Opcode Fuzzy Hash: cc422ce8ee68a8959793c21b2fdc4b79ac324035df3c0b44995fd49cc8f8ba1c
                                  • Instruction Fuzzy Hash: FDE01252A0CE0E82F651DF56FC000792214EF90BB5F4411F5DD8E425F5EEACE9899305
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [I] (%s) -> Done(root=0x%p,key=%s,param=%s)$registry_set_value
                                  • API String ID: 1001908780-3542721600
                                  • Opcode ID: d0c45932989ffefb138983b759f83f943f427ff6741bc40ce204d7911cdd7924
                                  • Instruction ID: faee86d66b4b3fcab3f7e3d9db735c0cebb954268fd1cee8a6e1561bcd0e963d
                                  • Opcode Fuzzy Hash: d0c45932989ffefb138983b759f83f943f427ff6741bc40ce204d7911cdd7924
                                  • Instruction Fuzzy Hash: 46E04852A0CD0E82F651DF57FC001792214EF90BB0F4411F5DD8E425F4DEACE5899304
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [I] (%s) -> Done(root=0x%p,key=%s,param=%s)$registry_set_value
                                  • API String ID: 1001908780-3542721600
                                  • Opcode ID: e7af9f531cdda218fbdddf15989a8a8fcdeb87563891bd7e896eacbffbfd5397
                                  • Instruction ID: 80a96f12aa45f2a6dd2bba5545d98aee7e5f76fd834fcf770fbc095c5ecd1b3e
                                  • Opcode Fuzzy Hash: e7af9f531cdda218fbdddf15989a8a8fcdeb87563891bd7e896eacbffbfd5397
                                  • Instruction Fuzzy Hash: 63E01252A0CE0E82F651DF56FC000782214EF907B4F4451F5DD8E425F4DEACE9899305
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [I] (%s) -> Done(root=0x%p,key=%s,param=%s)$registry_set_value
                                  • API String ID: 1001908780-3542721600
                                  • Opcode ID: 52ec67bb2cd6948e4ba0fba69181c63a6a7864344478762952f3758870e9c4cc
                                  • Instruction ID: 78ad7917269a87940544a9760024406708de67ea74e96a91883473f551451555
                                  • Opcode Fuzzy Hash: 52ec67bb2cd6948e4ba0fba69181c63a6a7864344478762952f3758870e9c4cc
                                  • Instruction Fuzzy Hash: E1E01252A0CE0E82F651DF56FC001796214EF90BB4F4411F5DD8E425F4DEACE9899305
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [I] (%s) -> Done(root=0x%p,key=%s,param=%s)$registry_set_value
                                  • API String ID: 1001908780-3542721600
                                  • Opcode ID: 50fdb24fed43a9ced9cc134ccbb0a60065d76e948486d6e738506ef65be9f7f6
                                  • Instruction ID: 087f8fd927027f5d72cd827a7642a4149258c8efa8d0813c73eb4ce9f97eb244
                                  • Opcode Fuzzy Hash: 50fdb24fed43a9ced9cc134ccbb0a60065d76e948486d6e738506ef65be9f7f6
                                  • Instruction Fuzzy Hash: 9AE01252A0CE0E82F651DF56FC000792214EF90BB4F4411F5DD8E425F4DEACEA899305
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [I] (%s) -> Done(root=0x%p,key=%s,param=%s)$registry_set_value
                                  • API String ID: 1001908780-3542721600
                                  • Opcode ID: f30cd13dbcdb34b275e08cb9c0a1b4bf37e0cf362818ecba85d79cd8ea6bc73c
                                  • Instruction ID: f067f8b056b94eb08f7a6060986198247fe4cc850beed6a37cd0adead82d78a8
                                  • Opcode Fuzzy Hash: f30cd13dbcdb34b275e08cb9c0a1b4bf37e0cf362818ecba85d79cd8ea6bc73c
                                  • Instruction Fuzzy Hash: 08E01262A1CF0681F762AB82FC400BD2358EF807B9F4441B9DD4E466B19E7CDAC9D305
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [I] (%s) -> Done(root=0x%p,key=%s,param=%s)$registry_del_value
                                  • API String ID: 1001908780-1337547089
                                  • Opcode ID: 4e5aa02ca7c9843f842698dd8ece679557bb6567bdaef6c7e70fa2f570dc5ecf
                                  • Instruction ID: 04cb1e8ae5bccaa847565cdd91169dd3d2473a7b2950a74dfb62ffa45a931eaa
                                  • Opcode Fuzzy Hash: 4e5aa02ca7c9843f842698dd8ece679557bb6567bdaef6c7e70fa2f570dc5ecf
                                  • Instruction Fuzzy Hash: C8E04F61A4CE4E82F522AF56FC402B92214FF90BB4F4400B5ED8E465F49EADEA899340
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [I] (%s) -> Done(root=0x%p,key=%s,param=%s)$registry_del_value
                                  • API String ID: 1001908780-1337547089
                                  • Opcode ID: 7034be72048aec7c00143ac9ce14abb55da6642a4719b0dcd64bb02a88672d65
                                  • Instruction ID: f82dfc34e9502e031b1669e1d486613813471c975e860acc0399e13397d569d1
                                  • Opcode Fuzzy Hash: 7034be72048aec7c00143ac9ce14abb55da6642a4719b0dcd64bb02a88672d65
                                  • Instruction Fuzzy Hash: B2E0D861A4CE0E82F521DF12FC001792204FF80BB4F4400B1ED8E025F49DACE9899300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [I] (%s) -> Done(root=0x%p,key=%s,param=%s)$registry_del_value
                                  • API String ID: 1001908780-1337547089
                                  • Opcode ID: da65e3582d5bee4f70acca21ab3bed44824ff8daa4ea177b503a265cbcb84fb9
                                  • Instruction ID: cd2449a0878862abbc280cb895daa7037d9eeedcc88fbe5b4b02c50032be36ea
                                  • Opcode Fuzzy Hash: da65e3582d5bee4f70acca21ab3bed44824ff8daa4ea177b503a265cbcb84fb9
                                  • Instruction Fuzzy Hash: BCE04F61A4CE4E82F522EF56FC401B92214FF90BB4F4400B5ED8E466F49EADEA899341
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [I] (%s) -> Done(root=0x%p,key=%s,param=%s)$registry_del_value
                                  • API String ID: 1001908780-1337547089
                                  • Opcode ID: 4f5cfa6df5a0aa0a7afd4c4dee5a8abe4dc35c94694f4bfeac8150aeffe7ff31
                                  • Instruction ID: 63c04419a6fef277f67dae1c786f24770d0c7e40c6972a654a71796817561398
                                  • Opcode Fuzzy Hash: 4f5cfa6df5a0aa0a7afd4c4dee5a8abe4dc35c94694f4bfeac8150aeffe7ff31
                                  • Instruction Fuzzy Hash: F5E0D861A4CE0E82F521DF12FC401792204FF80BB4F4400B1ED8E025F49DADE9899300
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2484217372.00007FFE126D1000.00000020.00000001.01000000.00000008.sdmp, Offset: 00007FFE126D0000, based on PE: true
                                  • Associated: 0000000E.00000002.2484179322.00007FFE126D0000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484275825.00007FFE126E2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484307514.00007FFE126EB000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484396562.00007FFE126EE000.00000004.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484448384.00007FFE126EF000.00000008.00000001.01000000.00000008.sdmpDownload File
                                  • Associated: 0000000E.00000002.2484498239.00007FFE126F2000.00000002.00000001.01000000.00000008.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe126d0000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [I] (%s) -> Done(root=0x%p,key=%s,param=%s)$registry_del_value
                                  • API String ID: 1001908780-1337547089
                                  • Opcode ID: 795eca84448f132f94cc4907e02e8ff1cd009b933e2d03c3c54d4f87f65ecc77
                                  • Instruction ID: a1e28a8f34adce67b16de0b7ce68fbd231c532172eb6135026162bf5d751e3f5
                                  • Opcode Fuzzy Hash: 795eca84448f132f94cc4907e02e8ff1cd009b933e2d03c3c54d4f87f65ecc77
                                  • Instruction Fuzzy Hash: 2DE04F61A4CE4E83F522EF56FC401B96214FF90BB4F4400B5ED8E466F49EADEA899350
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [I] (%s) -> Done(root=0x%p,key=%s,param=%s)$registry_del_value
                                  • API String ID: 1001908780-1337547089
                                  • Opcode ID: 5d6129e3ec844c67532fc437771ab920fdd01362ef31499ba0784a8a643b47c4
                                  • Instruction ID: 83b66e03a39f1ea9110847a67411b0a4320cf4ce3280c8b2564764374cd9af0a
                                  • Opcode Fuzzy Hash: 5d6129e3ec844c67532fc437771ab920fdd01362ef31499ba0784a8a643b47c4
                                  • Instruction Fuzzy Hash: 6DE04862A1CE0681F7625B92FC000BD321CFF407F8F4400B9DD4E466719E2CE7C99241
                                  APIs
                                  Strings
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Closefflushfwrite
                                  • String ID: [I] (%s) -> Done(root=0x%p,key=%s,param=%s)$registry_del_value
                                  • API String ID: 1001908780-1337547089
                                  • Opcode ID: 0f759002f524cc00935ec0c9206375d4caee05aa24c77603e7d1fbd4b10431a4
                                  • Instruction ID: fe9ddc353c504cfaa3d9e922c11ed661fdb5a4f18b3ab56317a649dc9fda0a0e
                                  • Opcode Fuzzy Hash: 0f759002f524cc00935ec0c9206375d4caee05aa24c77603e7d1fbd4b10431a4
                                  • Instruction Fuzzy Hash: 81E04862A1CE0681F7625B92FC001BD721CFF407F8F4400B9DD4E466719E2CE6C99650
                                  APIs
                                  Memory Dump Source
                                  • Source File: 0000000E.00000002.2483588049.00007FFE11501000.00000020.00000001.01000000.0000000C.sdmp, Offset: 00007FFE11500000, based on PE: true
                                  • Associated: 0000000E.00000002.2483515591.00007FFE11500000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483632071.00007FFE11516000.00000002.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483680951.00007FFE11520000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483730130.00007FFE11523000.00000004.00000001.01000000.0000000C.sdmpDownload File
                                  • Associated: 0000000E.00000002.2483779800.00007FFE11524000.00000008.00000001.01000000.0000000C.sdmpDownload File
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_14_2_7ffe11500000_main.jbxd
                                  Similarity
                                  • API ID: Heap$FreeProcess
                                  • String ID:
                                  • API String ID: 3859560861-0
                                  • Opcode ID: 52071573abfc37b688244c61e326d04804cb9da7333af29a775557c74bcfae91
                                  • Instruction ID: f0dc974a7bb283af8f010e42ec9d1b12c1d65f1c7ddbecae145bbdfbfd482eb3
                                  • Opcode Fuzzy Hash: 52071573abfc37b688244c61e326d04804cb9da7333af29a775557c74bcfae91
                                  • Instruction Fuzzy Hash: 7901FF6290EE42D1FF945B97E85437822A9AF48BB5F4C04B8CA8E467B1DF3CA544C612