Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
qsKo.ps1

Overview

General Information

Sample name:qsKo.ps1
Analysis ID:1511454
MD5:668884aeb66c4d344622dcd0dc087b8c
SHA1:0d8a0e61e56313a745a0a7862ecc2fedbf12abbc
SHA256:01c3e4114427cce7ab6bf90cfa72164a8cfd37dcadddb69817c31679e12fd263
Tags:APTdeadmunky-nlKimsukyoshi-atps1rhadamanthys
Infos:

Detection

RHADAMANTHYS
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for dropped file
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected RHADAMANTHYS Stealer
.NET source code contains potential unpacker
AI detected suspicious sample
Allocates memory in foreign processes
C2 URLs / IPs found in malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Machine Learning detection for dropped file
Powershell drops PE file
Sigma detected: Execution from Suspicious Folder
Sigma detected: Windows Shell/Scripting Application File Write to Suspicious Folder
Switches to a custom stack to bypass stack traces
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Writes to foreign memory regions
AV process strings found (often used to terminate AV products)
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains functionality to query network adapater information
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a DirectInput object (often for capturing keystrokes)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Drops files with a non-matching file extension (content does not match file extension)
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
Installs a raw input device (often for capturing keystrokes)
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries information about the installed CPU (vendor, model number etc)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Searches for user specific document files
Sigma detected: Change PowerShell Policies to an Insecure Level
Sigma detected: Dllhost Internet Connection
Suricata IDS alerts with low severity for network traffic
Uses Microsoft's Enhanced Cryptographic Provider
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer
Yara detected Keylogger Generic
Yara signature match

Classification

  • System is w10x64
  • powershell.exe (PID: 7316 cmdline: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -noLogo -ExecutionPolicy unrestricted -file "C:\Users\user\Desktop\qsKo.ps1" MD5: 04029E121A0CFA5991749937DD22A1D9)
    • conhost.exe (PID: 7344 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • conhost.exe (PID: 736 cmdline: "C:\Windows\system32\conhost.exe" C:\Users\Public\Documents\nUCp.exe MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • nUCp.exe (PID: 6328 cmdline: C:\Users\Public\Documents\nUCp.exe MD5: FFFAAB9CB76179E7C9CC424C7519F8AB)
        • OpenWith.exe (PID: 5860 cmdline: "C:\Windows\system32\openwith.exe" MD5: 0ED31792A7FFF811883F80047CBCFC91)
          • OpenWith.exe (PID: 5952 cmdline: "C:\Windows\system32\openwith.exe" MD5: E4A834784FA08C17D47A1E72429C5109)
            • setup_wm.exe (PID: 5452 cmdline: "C:\Program Files\Windows Media Player\setup_wm.exe" MD5: F32C225D11A5AF5906CF7C15FDA955E4)
              • dllhost.exe (PID: 7468 cmdline: "C:\Windows\system32\dllhost.exe" MD5: 08EB78E5BE019DF044C26B14703BD1FA)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
RhadamanthysAccording to PCrisk, Rhadamanthys is a stealer-type malware, and as its name implies - it is designed to extract data from infected machines.At the time of writing, this malware is spread through malicious websites mirroring those of genuine software such as AnyDesk, Zoom, Notepad++, and others. Rhadamanthys is downloaded alongside the real program, thus diminishing immediate user suspicion. These sites were promoted through Google ads, which superseded the legitimate search results on the Google search engine.
  • Sandworm
https://malpedia.caad.fkie.fraunhofer.de/details/win.rhadamanthys
{"C2 url": "https://deadmunky.nl:3736/083f339e93162/kuegsocf.6wn8t"}
SourceRuleDescriptionAuthorStrings
00000005.00000003.1419467605.0000000004D19000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_RHADAMANTHYSYara detected RHADAMANTHYS StealerJoe Security
    00000006.00000003.1766148892.0000011F7B611000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_RHADAMANTHYSYara detected RHADAMANTHYS StealerJoe Security
      00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmpJoeSecurity_RHADAMANTHYSYara detected RHADAMANTHYS StealerJoe Security
        00000005.00000002.1463969465.0000000004550000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_RHADAMANTHYSYara detected RHADAMANTHYS StealerJoe Security
          00000006.00000003.1511743151.0000011F7B4C4000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_RHADAMANTHYSYara detected RHADAMANTHYS StealerJoe Security
            Click to see the 12 entries
            SourceRuleDescriptionAuthorStrings
            4.2.nUCp.exe.fa0000.0.unpackJoeSecurity_RHADAMANTHYSYara detected RHADAMANTHYS StealerJoe Security
              4.3.nUCp.exe.4760000.7.raw.unpackJoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
                4.3.nUCp.exe.4540000.6.raw.unpackJoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
                  5.3.OpenWith.exe.4db0000.6.raw.unpackJoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
                    5.3.OpenWith.exe.4fd0000.7.raw.unpackJoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
                      SourceRuleDescriptionAuthorStrings
                      amsi64_7316.amsi.csvINDICATOR_SUSPICIOUS_PWSH_B64Encoded_Concatenated_FileEXECDetects PowerShell scripts containing patterns of base64 encoded files, concatenation and executionditekSHen
                      • 0x719a2:$b1: ::WriteAllBytes(
                      • 0x7ddae:$s1: -join
                      • 0x7755a:$s4: +=
                      • 0x7761c:$s4: +=
                      • 0x7b843:$s4: +=
                      • 0x7d960:$s4: +=
                      • 0x7dc4a:$s4: +=
                      • 0x7dd90:$s4: +=
                      • 0x7f529:$s4: +=
                      • 0x7f5a9:$s4: +=
                      • 0x7f66f:$s4: +=
                      • 0x7f6ef:$s4: +=
                      • 0x7f8c5:$s4: +=
                      • 0x7f949:$s4: +=
                      • 0x71a2a:$e4: Start-Process
                      • 0x755df:$e4: Get-WmiObject
                      • 0x757ce:$e4: Get-Process
                      • 0x75826:$e4: Start-Process

                      System Summary

                      barindex
                      Source: Process startedAuthor: Florian Roth (Nextron Systems), Tim Shelton: Data: Command: C:\Users\Public\Documents\nUCp.exe, CommandLine: C:\Users\Public\Documents\nUCp.exe, CommandLine|base64offset|contains: , Image: C:\Users\Public\Documents\nUCp.exe, NewProcessName: C:\Users\Public\Documents\nUCp.exe, OriginalFileName: C:\Users\Public\Documents\nUCp.exe, ParentCommandLine: "C:\Windows\system32\conhost.exe" C:\Users\Public\Documents\nUCp.exe , ParentImage: C:\Windows\System32\conhost.exe, ParentProcessId: 736, ParentProcessName: conhost.exe, ProcessCommandLine: C:\Users\Public\Documents\nUCp.exe, ProcessId: 6328, ProcessName: nUCp.exe
                      Source: File createdAuthor: Florian Roth (Nextron Systems): Data: EventID: 11, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ProcessId: 7316, TargetFilename: C:\Users\Public\Documents\nUCp.mp3
                      Source: Process startedAuthor: frack113: Data: Command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -noLogo -ExecutionPolicy unrestricted -file "C:\Users\user\Desktop\qsKo.ps1", CommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -noLogo -ExecutionPolicy unrestricted -file "C:\Users\user\Desktop\qsKo.ps1", CommandLine|base64offset|contains: z, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 3968, ProcessCommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -noLogo -ExecutionPolicy unrestricted -file "C:\Users\user\Desktop\qsKo.ps1", ProcessId: 7316, ProcessName: powershell.exe
                      Source: Network ConnectionAuthor: bartblaze: Data: DestinationIp: 194.113.106.180, DestinationIsIpv6: false, DestinationPort: 443, EventID: 3, Image: C:\Windows\System32\dllhost.exe, Initiated: true, ProcessId: 7468, Protocol: tcp, SourceIp: 192.168.2.10, SourceIsIpv6: false, SourcePort: 49708
                      Source: Process startedAuthor: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): Data: Command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -noLogo -ExecutionPolicy unrestricted -file "C:\Users\user\Desktop\qsKo.ps1", CommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -noLogo -ExecutionPolicy unrestricted -file "C:\Users\user\Desktop\qsKo.ps1", CommandLine|base64offset|contains: z, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 3968, ProcessCommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -noLogo -ExecutionPolicy unrestricted -file "C:\Users\user\Desktop\qsKo.ps1", ProcessId: 7316, ProcessName: powershell.exe
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-09-15T15:02:38.427859+020028548242Potentially Bad Traffic194.113.106.1803736192.168.2.1049706TCP
                      2024-09-15T15:02:48.917706+020028548242Potentially Bad Traffic194.113.106.1803736192.168.2.1049707TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-09-15T15:02:25.993182+020028548021Domain Observed Used for C2 Detected194.113.106.1803736192.168.2.1049701TCP
                      2024-09-15T15:02:38.427859+020028548021Domain Observed Used for C2 Detected194.113.106.1803736192.168.2.1049706TCP
                      2024-09-15T15:02:48.917706+020028548021Domain Observed Used for C2 Detected194.113.106.1803736192.168.2.1049707TCP
                      2024-09-15T15:02:55.097704+020028548021Domain Observed Used for C2 Detected194.113.106.180443192.168.2.1049708TCP
                      2024-09-15T15:03:01.712920+020028548021Domain Observed Used for C2 Detected194.113.106.180443192.168.2.1049709TCP
                      2024-09-15T15:03:08.193359+020028548021Domain Observed Used for C2 Detected194.113.106.180443192.168.2.1049710TCP
                      2024-09-15T15:03:14.921005+020028548021Domain Observed Used for C2 Detected194.113.106.180443192.168.2.1049712TCP
                      2024-09-15T15:03:21.402407+020028548021Domain Observed Used for C2 Detected194.113.106.180443192.168.2.1049713TCP
                      2024-09-15T15:03:28.139413+020028548021Domain Observed Used for C2 Detected194.113.106.180443192.168.2.1049714TCP
                      2024-09-15T15:03:34.627622+020028548021Domain Observed Used for C2 Detected194.113.106.180443192.168.2.1049715TCP
                      2024-09-15T15:03:41.361518+020028548021Domain Observed Used for C2 Detected194.113.106.180443192.168.2.1049716TCP
                      2024-09-15T15:03:47.962486+020028548021Domain Observed Used for C2 Detected194.113.106.180443192.168.2.1049717TCP
                      2024-09-15T15:03:54.468063+020028548021Domain Observed Used for C2 Detected194.113.106.180443192.168.2.1049718TCP
                      2024-09-15T15:04:01.074588+020028548021Domain Observed Used for C2 Detected194.113.106.180443192.168.2.1049719TCP
                      2024-09-15T15:04:07.823659+020028548021Domain Observed Used for C2 Detected194.113.106.180443192.168.2.1049720TCP
                      2024-09-15T15:04:14.623754+020028548021Domain Observed Used for C2 Detected194.113.106.180443192.168.2.1049721TCP
                      2024-09-15T15:04:20.901754+020028548021Domain Observed Used for C2 Detected194.113.106.180443192.168.2.1049722TCP

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection

                      barindex
                      Source: C:\Users\Public\Documents\nUCp.mp3Avira: detection malicious, Label: TR/Crypt.ZPACK.Gen8
                      Source: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmpMalware Configuration Extractor: Rhadamanthys {"C2 url": "https://deadmunky.nl:3736/083f339e93162/kuegsocf.6wn8t"}
                      Source: deadmunky.nlVirustotal: Detection: 12%Perma Link
                      Source: https://deadmunky.nl:3736/083f339e93162/kuegsocf.6wn8tkernelbasentdllkernel32GetProcessMitigationPolVirustotal: Detection: 16%Perma Link
                      Source: https://deadmunky.nl:3736/083f339e93162/kuegsocf.6wn8tVirustotal: Detection: 14%Perma Link
                      Source: https://deadmunky.nl:3736/083f339e93162/kuegsocf.6wn8t(Virustotal: Detection: 16%Perma Link
                      Source: C:\Users\Public\Documents\nUCp.exe (copy)ReversingLabs: Detection: 60%
                      Source: C:\Users\Public\Documents\nUCp.exe (copy)Virustotal: Detection: 81%Perma Link
                      Source: C:\Users\Public\Documents\nUCp.mp3ReversingLabs: Detection: 60%
                      Source: C:\Users\Public\Documents\nUCp.mp3Virustotal: Detection: 81%Perma Link
                      Source: qsKo.ps1ReversingLabs: Detection: 21%
                      Source: qsKo.ps1Virustotal: Detection: 19%Perma Link
                      Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
                      Source: C:\Users\Public\Documents\nUCp.mp3Joe Sandbox ML: detected
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4D2258 CryptUnprotectData,6_3_00007DF46E4D2258
                      Source: unknownHTTPS traffic detected: 104.21.82.103:443 -> 192.168.2.10:49700 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49708 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49709 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49710 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49712 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49713 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49714 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49715 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49716 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49717 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49718 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49719 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49720 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49721 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49722 version: TLS 1.2
                      Source: Binary string: softy.pdb source: powershell.exe, 00000000.00000002.1402300584.00000177EEAFC000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831 source: OpenWith.exe, 00000006.00000002.1767169425.0000011F79208000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: *on.pdb> source: powershell.exe, 00000000.00000002.1402300584.00000177EEAFC000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: System.Management.Automation.pdb source: powershell.exe, 00000000.00000002.1401134083.00000177EE833000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: wkernel32.pdb source: nUCp.exe, 00000004.00000003.1391779587.00000000045C0000.00000004.00000001.00020000.00000000.sdmp, nUCp.exe, 00000004.00000003.1391701123.0000000000E50000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1394843323.0000000004DB0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1394938485.0000000004ED0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wkernelbase.pdb source: nUCp.exe, 00000004.00000003.1391976687.0000000004540000.00000004.00000001.00020000.00000000.sdmp, nUCp.exe, 00000004.00000003.1392146550.0000000004760000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1395128336.0000000004DB0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1395438185.0000000004FD0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: ntdll.pdb source: nUCp.exe, 00000004.00000003.1390959056.0000000004540000.00000004.00000001.00020000.00000000.sdmp, nUCp.exe, 00000004.00000003.1391125502.0000000004730000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1393989753.0000000004DB0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1394224065.0000000004FA0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\winload_prod.pdb source: OpenWith.exe, 00000006.00000002.1767169425.0000011F79208000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: wntdll.pdbUGP source: nUCp.exe, 00000004.00000003.1391365646.0000000004540000.00000004.00000001.00020000.00000000.sdmp, nUCp.exe, 00000004.00000003.1391513023.00000000046E0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1394664846.0000000004F50000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1394483982.0000000004DB0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: ntdll.pdbUGP source: nUCp.exe, 00000004.00000003.1390959056.0000000004540000.00000004.00000001.00020000.00000000.sdmp, nUCp.exe, 00000004.00000003.1391125502.0000000004730000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1393989753.0000000004DB0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1394224065.0000000004FA0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wntdll.pdb source: nUCp.exe, 00000004.00000003.1391365646.0000000004540000.00000004.00000001.00020000.00000000.sdmp, nUCp.exe, 00000004.00000003.1391513023.00000000046E0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1394664846.0000000004F50000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1394483982.0000000004DB0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: Microsoft.PowerShell.Commands.Utility.pdb source: powershell.exe, 00000000.00000002.1402300584.00000177EEAFC000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.pdb source: powershell.exe, 00000000.00000002.1402300584.00000177EEAFC000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: ntkrnlmp.pdb4-Xz source: OpenWith.exe, 00000006.00000003.1538253921.0000011F7B75D000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: ion.pdb^ source: powershell.exe, 00000000.00000002.1402300584.00000177EEAFC000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb source: OpenWith.exe, 00000006.00000002.1767169425.0000011F79208000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2 source: OpenWith.exe, 00000006.00000002.1767169425.0000011F79208000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: n.pdb9 source: powershell.exe, 00000000.00000002.1401134083.00000177EE833000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: wkernel32.pdbUGP source: nUCp.exe, 00000004.00000003.1391779587.00000000045C0000.00000004.00000001.00020000.00000000.sdmp, nUCp.exe, 00000004.00000003.1391701123.0000000000E50000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1394843323.0000000004DB0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1394938485.0000000004ED0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wkernelbase.pdbUGP source: nUCp.exe, 00000004.00000003.1391976687.0000000004540000.00000004.00000001.00020000.00000000.sdmp, nUCp.exe, 00000004.00000003.1392146550.0000000004760000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1395128336.0000000004DB0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1395438185.0000000004FD0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: winload_prod.pdb source: OpenWith.exe, 00000006.00000003.1538253921.0000011F7B75D000.00000004.00000020.00020000.00000000.sdmp
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_2_00FFA165 FindFirstFileExW,4_2_00FFA165
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.iniJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppDataJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\RoamingJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\WindowsJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\userJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\Roaming\MicrosoftJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeCode function: 4x nop then dec esp6_3_00007DF46E4DE261
                      Source: C:\Windows\System32\OpenWith.exeCode function: 4x nop then dec esp6_2_0000011F791B0511
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 4x nop then dec esp8_2_0000021CE78E5641

                      Networking

                      barindex
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 194.113.106.180:3736 -> 192.168.2.10:49701
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 194.113.106.180:3736 -> 192.168.2.10:49707
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 194.113.106.180:3736 -> 192.168.2.10:49706
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 194.113.106.180:443 -> 192.168.2.10:49710
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 194.113.106.180:443 -> 192.168.2.10:49713
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 194.113.106.180:443 -> 192.168.2.10:49709
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 194.113.106.180:443 -> 192.168.2.10:49712
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 194.113.106.180:443 -> 192.168.2.10:49708
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 194.113.106.180:443 -> 192.168.2.10:49714
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 194.113.106.180:443 -> 192.168.2.10:49721
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 194.113.106.180:443 -> 192.168.2.10:49722
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 194.113.106.180:443 -> 192.168.2.10:49715
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 194.113.106.180:443 -> 192.168.2.10:49719
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 194.113.106.180:443 -> 192.168.2.10:49717
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 194.113.106.180:443 -> 192.168.2.10:49718
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 194.113.106.180:443 -> 192.168.2.10:49716
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 194.113.106.180:443 -> 192.168.2.10:49720
                      Source: Malware configuration extractorURLs: https://deadmunky.nl:3736/083f339e93162/kuegsocf.6wn8t
                      Source: global trafficTCP traffic: 192.168.2.10:49701 -> 194.113.106.180:3736
                      Source: Joe Sandbox ViewASN Name: RACKTECHRU RACKTECHRU
                      Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
                      Source: Joe Sandbox ViewJA3 fingerprint: caec7ddf6889590d999d7ca1b76373b6
                      Source: Network trafficSuricata IDS: 2854824 - Severity 2 - ETPRO JA3 HASH Suspected Malware Related Response : 194.113.106.180:3736 -> 192.168.2.10:49707
                      Source: Network trafficSuricata IDS: 2854824 - Severity 2 - ETPRO JA3 HASH Suspected Malware Related Response : 194.113.106.180:3736 -> 192.168.2.10:49706
                      Source: global trafficHTTP traffic detected: POST /98aa7e1ce731c6206ebbe457e9f2dc7088adc3c628bee08/verify HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1682Content-Type: application/x-www-form-urlencodedHost: captcha.serverprotect.onlineContent-Length: 0Connection: Keep-Alive
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E504D8C WSARecv,6_3_00007DF46E504D8C
                      Source: global trafficDNS traffic detected: DNS query: captcha.serverprotect.online
                      Source: global trafficDNS traffic detected: DNS query: deadmunky.nl
                      Source: unknownHTTP traffic detected: POST /98aa7e1ce731c6206ebbe457e9f2dc7088adc3c628bee08/verify HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1682Content-Type: application/x-www-form-urlencodedHost: captcha.serverprotect.onlineContent-Length: 0Connection: Keep-Alive
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Sun, 15 Sep 2024 13:02:19 GMTContent-Type: text/html; charset=utf-8Transfer-Encoding: chunkedConnection: closeContent-Security-Policy: script-src 'self' 'unsafe-inline' 'unsafe-eval';img-src 'self' cdn.discordapp.com;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requestsCross-Origin-Opener-Policy: same-originCross-Origin-Resource-Policy: same-originOrigin-Agent-Cluster: ?1Referrer-Policy: no-referrerStrict-Transport-Security: max-age=15552000; includeSubDomainsX-Content-Type-Options: nosniffX-DNS-Prefetch-Control: offX-Download-Options: noopenX-Frame-Options: SAMEORIGINX-Permitted-Cross-Domain-Policies: noneX-XSS-Protection: 0CF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2FuF43JeoqhMAqUT5LOSzO%2Bz9h%2By3fEAHk625AHJJQmuTlnrGf%2F%2FKSw770iowiD983krP0KPpLapaLsdWPF4WpjHEvZscp7GjHELFjKx3u6E2OiRG8%2Bl9YssPG6EiXpwnTOZHITt%2Bj2AqxaXxVMBn"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c38cf795b637d06-EWRalt-svc: h3=":443"; ma=86400
                      Source: powershell.exe, 00000000.00000002.1371224256.00000177D7CE5000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://captcha.serverprotect.online
                      Source: powershell.exe, 00000000.00000002.1403260797.00000177EEBDE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.micro
                      Source: powershell.exe, 00000000.00000002.1403260797.00000177EEBDE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.microsoft
                      Source: powershell.exe, 00000000.00000002.1403260797.00000177EEBDE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://microsoft.co
                      Source: powershell.exe, 00000000.00000002.1396196856.00000177E6818000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://nuget.org/NuGet.exe
                      Source: powershell.exe, 00000000.00000002.1371224256.00000177D69C8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://pesterbdd.com/images/Pester.png
                      Source: powershell.exe, 00000000.00000002.1371224256.00000177D67A1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
                      Source: powershell.exe, 00000000.00000002.1371224256.00000177D69C8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html
                      Source: powershell.exe, 00000000.00000002.1403260797.00000177EEBDE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.microsoft.co
                      Source: powershell.exe, 00000000.00000002.1403260797.00000177EEBDE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.microsoft.czl
                      Source: OpenWith.exe, 00000006.00000003.1542052579.0000011F7B725000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ac.ecosia.org/autocomplete?q=
                      Source: powershell.exe, 00000000.00000002.1371224256.00000177D67A1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://aka.ms/pscore68
                      Source: powershell.exe, 00000000.00000002.1371224256.00000177D787B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://captcha.serverprotect.online
                      Source: powershell.exe, 00000000.00000002.1371224256.00000177D7EA4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.1371224256.00000177D787B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://captcha.serverprotect.online/98aa7e1c
                      Source: powershell.exe, 00000000.00000002.1371224256.00000177D787B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.1396196856.00000177E6818000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://captcha.serverprotect.online/98aa7e1ce731c6206ebbe457e9f2dc7088adc3c628bee08/verify
                      Source: OpenWith.exe, 00000006.00000003.1542052579.0000011F7B725000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
                      Source: OpenWith.exe, 00000006.00000003.1542052579.0000011F7B725000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
                      Source: OpenWith.exe, 00000006.00000003.1542052579.0000011F7B725000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
                      Source: powershell.exe, 00000000.00000002.1396196856.00000177E6818000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/
                      Source: powershell.exe, 00000000.00000002.1396196856.00000177E6818000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/Icon
                      Source: powershell.exe, 00000000.00000002.1396196856.00000177E6818000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/License
                      Source: OpenWith.exe, 00000006.00000003.1514008533.0000011F7AE19000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://deadmunky.nl:3736/083f339e93162/kuegsocf.6wn8t
                      Source: OpenWith.exe, 00000005.00000002.1462963482.00000000027BC000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: https://deadmunky.nl:3736/083f339e93162/kuegsocf.6wn8t(
                      Source: OpenWith.exe, 00000005.00000003.1462414332.0000000005184000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://deadmunky.nl:3736/083f339e93162/kuegsocf.6wn8tkernelbasentdllkernel32GetProcessMitigationPol
                      Source: OpenWith.exe, 00000006.00000003.1549035844.0000011F7B715000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://discord.com
                      Source: OpenWith.exe, 00000006.00000003.1549035844.0000011F7B715000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://discordapp.com
                      Source: OpenWith.exe, 00000006.00000003.1542052579.0000011F7B725000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/ac/?q=
                      Source: OpenWith.exe, 00000006.00000003.1542052579.0000011F7B725000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/chrome_newtab
                      Source: OpenWith.exe, 00000006.00000003.1542052579.0000011F7B725000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
                      Source: powershell.exe, 00000000.00000002.1371224256.00000177D69C8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/Pester/Pester
                      Source: powershell.exe, 00000000.00000002.1371224256.00000177D787B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://go.micro
                      Source: powershell.exe, 00000000.00000002.1396196856.00000177E6818000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://nuget.org/nuget.exe
                      Source: OpenWith.exe, 00000006.00000003.1542052579.0000011F7B725000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.ecosia.org/newtab/
                      Source: OpenWith.exe, 00000006.00000003.1542052579.0000011F7B725000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
                      Source: unknownHTTPS traffic detected: 104.21.82.103:443 -> 192.168.2.10:49700 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49708 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49709 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49710 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49712 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49713 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49714 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49715 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49716 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49717 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49718 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49719 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49720 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49721 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 194.113.106.180:443 -> 192.168.2.10:49722 version: TLS 1.2
                      Source: nUCp.exe, 00000004.00000003.1391976687.0000000004540000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: DirectInput8Creatememstr_520f4a7b-2
                      Source: nUCp.exe, 00000004.00000003.1391976687.0000000004540000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: GetRawInputDatamemstr_c9e0cf07-5
                      Source: Yara matchFile source: 4.3.nUCp.exe.4760000.7.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 4.3.nUCp.exe.4540000.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.3.OpenWith.exe.4db0000.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 5.3.OpenWith.exe.4fd0000.7.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000004.00000003.1391976687.0000000004540000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000003.1395128336.0000000004DB0000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000004.00000003.1392146550.0000000004760000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000003.1395438185.0000000004FD0000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: nUCp.exe PID: 6328, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: OpenWith.exe PID: 5860, type: MEMORYSTR

                      System Summary

                      barindex
                      Source: amsi64_7316.amsi.csv, type: OTHERMatched rule: Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution Author: ditekSHen
                      Source: Process Memory Space: powershell.exe PID: 7316, type: MEMORYSTRMatched rule: Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution Author: ditekSHen
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\Public\Documents\nUCp.mp3Jump to dropped file
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\Public\Documents\nUCp.exe (copy)Jump to dropped file
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_0000011F7ABB30C7 NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,RtlFreeHeap,RtlFreeHeap,6_3_0000011F7ABB30C7
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4DADD4 NtAcceptConnectPort,6_3_00007DF46E4DADD4
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4DBE6C NtAcceptConnectPort,6_3_00007DF46E4DBE6C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4DAE5C NtAcceptConnectPort,6_3_00007DF46E4DAE5C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4DAF40 NtAcceptConnectPort,6_3_00007DF46E4DAF40
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4DAF60 NtAcceptConnectPort,6_3_00007DF46E4DAF60
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4DAC0C NtAcceptConnectPort,6_3_00007DF46E4DAC0C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4DACC8 NtAcceptConnectPort,6_3_00007DF46E4DACC8
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4DBCC0 malloc,NtAcceptConnectPort,NtAcceptConnectPort,free,6_3_00007DF46E4DBCC0
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4DACE8 NtAcceptConnectPort,6_3_00007DF46E4DACE8
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4DAD14 NtAcceptConnectPort,6_3_00007DF46E4DAD14
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4DC7CC NtAcceptConnectPort,6_3_00007DF46E4DC7CC
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4DC70C NtAcceptConnectPort,6_3_00007DF46E4DC70C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4DD3C0 NtAcceptConnectPort,NtAcceptConnectPort,6_3_00007DF46E4DD3C0
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4DC47C NtAcceptConnectPort,6_3_00007DF46E4DC47C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4DB498 NtAcceptConnectPort,calloc,DuplicateHandle,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,NtAcceptConnectPort,6_3_00007DF46E4DB498
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4DD2F4 NtAcceptConnectPort,NtAcceptConnectPort,6_3_00007DF46E4DD2F4
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4DC10C NtAcceptConnectPort,6_3_00007DF46E4DC10C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_2_0000011F791B15AC NtAcceptConnectPort,6_2_0000011F791B15AC
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_2_0000011F791B1A90 NtAcceptConnectPort,NtAcceptConnectPort,6_2_0000011F791B1A90
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_2_0000011F791B0AC8 NtAcceptConnectPort,NtAcceptConnectPort,6_2_0000011F791B0AC8
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_2_0000011F791B1CD0 NtAcceptConnectPort,CloseHandle,6_2_0000011F791B1CD0
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_00007DF4B9901CE8 calloc,CreateProcessW,NtResumeThread,CloseHandle,free,8_3_00007DF4B9901CE8
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_00007DF4B9901958 calloc,NtAllocateVirtualMemory,NtWriteVirtualMemory,NtQueryInformationProcess,NtReadVirtualMemory,NtReadVirtualMemory,NtReadVirtualMemory,NtReadVirtualMemory,NtProtectVirtualMemory,NtProtectVirtualMemory,NtWriteVirtualMemory,NtProtectVirtualMemory,8_3_00007DF4B9901958
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78F252C NtAcceptConnectPort,8_2_0000021CE78F252C
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78F2C64 NtAcceptConnectPort,8_2_0000021CE78F2C64
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78F2418 NtAcceptConnectPort,8_2_0000021CE78F2418
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78F29D4 NtAcceptConnectPort,8_2_0000021CE78F29D4
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78F2990 NtAcceptConnectPort,8_2_0000021CE78F2990
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78F28B8 NtAcceptConnectPort,8_2_0000021CE78F28B8
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78F28E8 NtAcceptConnectPort,8_2_0000021CE78F28E8
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78F288C NtAcceptConnectPort,8_2_0000021CE78F288C
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78F27B8 NtAcceptConnectPort,8_2_0000021CE78F27B8
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_00007DF4B9901E64 CreateProcessW,NtResumeThread,CloseHandle,8_2_00007DF4B9901E64
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_00007DF4B990199C calloc,NtQueryInformationProcess,NtReadVirtualMemory,NtProtectVirtualMemory,NtWriteVirtualMemory,8_2_00007DF4B990199C
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_00007DF4B9912704 NtQuerySystemInformation,malloc,NtQuerySystemInformation,8_2_00007DF4B9912704
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4B385C NtQuerySystemInformation,9_2_0000022FAA4B385C
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 0_2_00007FF7C0CC20B80_2_00007FF7C0CC20B8
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_2_01000BC14_2_01000BC1
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_0000011F7ABB24F76_3_0000011F7ABB24F7
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_0000011F7ABB5E7C6_3_0000011F7ABB5E7C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_0000011F7ABB557C6_3_0000011F7ABB557C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_0000011F7ABB58FC6_3_0000011F7ABB58FC
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_0000011F7ABB4A386_3_0000011F7ABB4A38
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_0000011F7ABB2C3C6_3_0000011F7ABB2C3C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_0000011F7ABB1BA66_3_0000011F7ABB1BA6
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_0000011F7ABB279C6_3_0000011F7ABB279C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4B26346_3_00007DF46E4B2634
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4FFDE06_3_00007DF46E4FFDE0
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E5A6DAC6_3_00007DF46E5A6DAC
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E593D846_3_00007DF46E593D84
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4C1E546_3_00007DF46E4C1E54
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E59AE006_3_00007DF46E59AE00
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4E9F4C6_3_00007DF46E4E9F4C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E599F686_3_00007DF46E599F68
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4E0F046_3_00007DF46E4E0F04
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E58EBE46_3_00007DF46E58EBE4
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E51DC546_3_00007DF46E51DC54
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E556C606_3_00007DF46E556C60
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4B5C246_3_00007DF46E4B5C24
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4CD9F06_3_00007DF46E4CD9F0
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E5969A86_3_00007DF46E5969A8
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E50CA386_3_00007DF46E50CA38
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E529AE06_3_00007DF46E529AE0
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4FFA946_3_00007DF46E4FFA94
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E509B706_3_00007DF46E509B70
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E519B386_3_00007DF46E519B38
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4CFB246_3_00007DF46E4CFB24
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E59FB046_3_00007DF46E59FB04
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E5ACB046_3_00007DF46E5ACB04
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E50B7B86_3_00007DF46E50B7B8
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E59A8BC6_3_00007DF46E59A8BC
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4D996C6_3_00007DF46E4D996C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4CF95C6_3_00007DF46E4CF95C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E5075E46_3_00007DF46E5075E4
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E5195D06_3_00007DF46E5195D0
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E50D5946_3_00007DF46E50D594
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4BF6246_3_00007DF46E4BF624
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E5196E06_3_00007DF46E5196E0
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E58A3D46_3_00007DF46E58A3D4
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4FF3B86_3_00007DF46E4FF3B8
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4F43F86_3_00007DF46E4F43F8
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E5193F46_3_00007DF46E5193F4
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E50A4306_3_00007DF46E50A430
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E59A4A06_3_00007DF46E59A4A0
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E5984746_3_00007DF46E598474
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E5025246_3_00007DF46E502524
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E54E24C6_3_00007DF46E54E24C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E5A72C86_3_00007DF46E5A72C8
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E59B3186_3_00007DF46E59B318
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E52CFB46_3_00007DF46E52CFB4
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E5ABFCC6_3_00007DF46E5ABFCC
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E59AF806_3_00007DF46E59AF80
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4B10586_3_00007DF46E4B1058
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4FF02C6_3_00007DF46E4FF02C
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E5220BC6_3_00007DF46E5220BC
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E57A1686_3_00007DF46E57A168
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E50B1046_3_00007DF46E50B104
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_2_0000011F791B0C5C6_2_0000011F791B0C5C
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A01F408_3_0000021CE7A01F40
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A01F408_3_0000021CE7A01F40
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A01F408_3_0000021CE7A01F40
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A0170E8_3_0000021CE7A0170E
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A0170E8_3_0000021CE7A0170E
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A0170E8_3_0000021CE7A0170E
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A036608_3_0000021CE7A03660
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A036608_3_0000021CE7A03660
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A036608_3_0000021CE7A03660
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A0027B8_3_0000021CE7A0027B
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A0027B8_3_0000021CE7A0027B
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A0027B8_3_0000021CE7A0027B
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_00007DF4B99022048_3_00007DF4B9902204
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_00007DF4B9904EFC8_3_00007DF4B9904EFC
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_00007DF4B990392C8_3_00007DF4B990392C
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A01F408_3_0000021CE7A01F40
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A01F408_3_0000021CE7A01F40
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A01F408_3_0000021CE7A01F40
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A0170E8_3_0000021CE7A0170E
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A0170E8_3_0000021CE7A0170E
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A0170E8_3_0000021CE7A0170E
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A036608_3_0000021CE7A03660
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A036608_3_0000021CE7A03660
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A036608_3_0000021CE7A03660
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A0027B8_3_0000021CE7A0027B
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A0027B8_3_0000021CE7A0027B
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A0027B8_3_0000021CE7A0027B
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A01F408_3_0000021CE7A01F40
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A01F408_3_0000021CE7A01F40
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A01F408_3_0000021CE7A01F40
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A0170E8_3_0000021CE7A0170E
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A0170E8_3_0000021CE7A0170E
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A0170E8_3_0000021CE7A0170E
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A036608_3_0000021CE7A03660
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A036608_3_0000021CE7A03660
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A036608_3_0000021CE7A03660
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A0027B8_3_0000021CE7A0027B
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A0027B8_3_0000021CE7A0027B
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_3_0000021CE7A0027B8_3_0000021CE7A0027B
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78E26288_2_0000021CE78E2628
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78F2D248_2_0000021CE78F2D24
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78EC25C8_2_0000021CE78EC25C
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE79076848_2_0000021CE7907684
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE79155B08_2_0000021CE79155B0
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE79195D48_2_0000021CE79195D4
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE7914DE88_2_0000021CE7914DE8
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78FF6188_2_0000021CE78FF618
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE7920D908_2_0000021CE7920D90
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78E14D08_2_0000021CE78E14D0
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78FDCE48_2_0000021CE78FDCE4
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE791ECE48_2_0000021CE791ECE4
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE7906D188_2_0000021CE7906D18
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE79264348_2_0000021CE7926434
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE79104788_2_0000021CE7910478
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE791CC008_2_0000021CE791CC00
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78FE3988_2_0000021CE78FE398
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78F5ADC8_2_0000021CE78F5ADC
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE7913A388_2_0000021CE7913A38
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE7923A4D8_2_0000021CE7923A4D
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE7914A508_2_0000021CE7914A50
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE79202708_2_0000021CE7920270
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78F72708_2_0000021CE78F7270
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE791F1D08_2_0000021CE791F1D0
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE791F9408_2_0000021CE791F940
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE79001748_2_0000021CE7900174
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE791E9848_2_0000021CE791E984
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE79148D08_2_0000021CE79148D0
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE79159188_2_0000021CE7915918
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE791A81C8_2_0000021CE791A81C
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE790D8548_2_0000021CE790D854
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE79208748_2_0000021CE7920874
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE79070948_2_0000021CE7907094
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78FD0108_2_0000021CE78FD010
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78F6F248_2_0000021CE78F6F24
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78FC7508_2_0000021CE78FC750
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE7913F708_2_0000021CE7913F70
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE79086B48_2_0000021CE79086B4
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78FBEB88_2_0000021CE78FBEB8
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE7903EA48_2_0000021CE7903EA4
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE7915EC88_2_0000021CE7915EC8
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_00007DF4B99022CC8_2_00007DF4B99022CC
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4C6E949_2_0000022FAA4C6E94
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4C8EB89_2_0000022FAA4C8EB8
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4DC6689_2_0000022FAA4DC668
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4D46609_2_0000022FAA4D4660
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4C27A49_2_0000022FAA4C27A4
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4CF76C9_2_0000022FAA4CF76C
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4C98189_2_0000022FAA4C9818
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4BBFE49_2_0000022FAA4BBFE4
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4BBC689_2_0000022FAA4BBC68
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4CE51C9_2_0000022FAA4CE51C
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4C9D309_2_0000022FAA4C9D30
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4CA4F89_2_0000022FAA4CA4F8
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4DC5009_2_0000022FAA4DC500
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4D25B49_2_0000022FAA4D25B4
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4CAE109_2_0000022FAA4CAE10
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4BC5D49_2_0000022FAA4BC5D4
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4B8DF49_2_0000022FAA4B8DF4
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4E1E089_2_0000022FAA4E1E08
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4BD6049_2_0000022FAA4BD604
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4D2AA09_2_0000022FAA4D2AA0
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4D22549_2_0000022FAA4D2254
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4D3B409_2_0000022FAA4D3B40
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4C92D49_2_0000022FAA4C92D4
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4C53C89_2_0000022FAA4C53C8
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4B737C9_2_0000022FAA4B737C
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4CA8609_2_0000022FAA4CA860
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4D41449_2_0000022FAA4D4144
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4C99989_2_0000022FAA4C9998
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4C89809_2_0000022FAA4C8980
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4D32109_2_0000022FAA4D3210
                      Source: amsi64_7316.amsi.csv, type: OTHERMatched rule: INDICATOR_SUSPICIOUS_PWSH_B64Encoded_Concatenated_FileEXEC author = ditekSHen, description = Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution
                      Source: Process Memory Space: powershell.exe PID: 7316, type: MEMORYSTRMatched rule: INDICATOR_SUSPICIOUS_PWSH_B64Encoded_Concatenated_FileEXEC author = ditekSHen, description = Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution
                      Source: nUCp.mp3.0.drStatic PE information: Section: UPX1 ZLIB complexity 0.9950352536848073
                      Source: 6.3.OpenWith.exe.11f7b45d970.4.raw.unpack, CallWrapper.csSuspicious method names: .CallWrapper.GetPayload
                      Source: 6.3.OpenWith.exe.11f7b45d970.0.raw.unpack, CallWrapper.csSuspicious method names: .CallWrapper.GetPayload
                      Source: 6.3.OpenWith.exe.11f7b45d970.2.raw.unpack, CallWrapper.csSuspicious method names: .CallWrapper.GetPayload
                      Source: 6.3.OpenWith.exe.11f7b45d970.1.raw.unpack, CallWrapper.csSuspicious method names: .CallWrapper.GetPayload
                      Source: 6.3.OpenWith.exe.11f7b45d970.5.raw.unpack, CallWrapper.csSuspicious method names: .CallWrapper.GetPayload
                      Source: classification engineClassification label: mal100.troj.spyw.evad.winPS1@14/7@2/2
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4B2634 CreateToolhelp32Snapshot,Thread32First,Thread32Next,CloseHandle,SuspendThread,6_3_00007DF46E4B2634
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\Public\Documents\nUCp.mp3Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMutant created: NULL
                      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7344:120:WilError_03
                      Source: C:\Windows\SysWOW64\OpenWith.exeMutant created: \Sessions\1\BaseNamedObjects\MSCTF.Asm.{00000009-4fb3f26-9d18-66b568-627b8a85e4b6}
                      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:736:120:WilError_03
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_m051kwi2.pse.ps1Jump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\SysWOW64\OpenWith.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile read: C:\Users\desktop.iniJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CAJump to behavior
                      Source: OpenWith.exe, 00000006.00000003.1766778822.00007DF46E5B2000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1766148892.0000011F7B611000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1764862654.0000011F7B2C6000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1510500387.0000011F7ABE3000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1511532978.0000011F7B411000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
                      Source: OpenWith.exe, 00000006.00000003.1766778822.00007DF46E5B2000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1766148892.0000011F7B611000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1764862654.0000011F7B2C6000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1510500387.0000011F7ABE3000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1511532978.0000011F7B411000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
                      Source: OpenWith.exe, 00000006.00000003.1766778822.00007DF46E5B2000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1766148892.0000011F7B611000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1764862654.0000011F7B2C6000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1510500387.0000011F7ABE3000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1511532978.0000011F7B411000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND coalesce(rootpage,1)>0
                      Source: OpenWith.exe, 00000006.00000003.1766778822.00007DF46E5B2000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1766148892.0000011F7B611000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1764862654.0000011F7B2C6000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1510500387.0000011F7ABE3000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1511532978.0000011F7B411000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
                      Source: OpenWith.exe, 00000006.00000003.1766778822.00007DF46E5B2000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1766148892.0000011F7B611000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1764862654.0000011F7B2C6000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1510500387.0000011F7ABE3000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1511532978.0000011F7B411000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
                      Source: OpenWith.exe, 00000006.00000003.1766778822.00007DF46E5B2000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1766148892.0000011F7B611000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1764862654.0000011F7B2C6000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1510500387.0000011F7ABE3000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1511532978.0000011F7B411000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
                      Source: OpenWith.exe, 00000006.00000003.1542391088.0000011F7B74E000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1544938979.0000011F7B521000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1542498034.0000011F7B75D000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1544938979.0000011F7B4FD000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
                      Source: OpenWith.exe, 00000006.00000003.1766778822.00007DF46E5B2000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1766148892.0000011F7B611000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1764862654.0000011F7B2C6000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1510500387.0000011F7ABE3000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000003.1511532978.0000011F7B411000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
                      Source: qsKo.ps1ReversingLabs: Detection: 21%
                      Source: qsKo.ps1Virustotal: Detection: 19%
                      Source: unknownProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -noLogo -ExecutionPolicy unrestricted -file "C:\Users\user\Desktop\qsKo.ps1"
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe "C:\Windows\system32\conhost.exe" C:\Users\Public\Documents\nUCp.exe
                      Source: C:\Windows\System32\conhost.exeProcess created: C:\Users\Public\Documents\nUCp.exe C:\Users\Public\Documents\nUCp.exe
                      Source: C:\Users\Public\Documents\nUCp.exeProcess created: C:\Windows\SysWOW64\OpenWith.exe "C:\Windows\system32\openwith.exe"
                      Source: C:\Windows\SysWOW64\OpenWith.exeProcess created: C:\Windows\System32\OpenWith.exe "C:\Windows\system32\openwith.exe"
                      Source: C:\Windows\System32\OpenWith.exeProcess created: C:\Program Files\Windows Media Player\setup_wm.exe "C:\Program Files\Windows Media Player\setup_wm.exe"
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeProcess created: C:\Windows\System32\dllhost.exe "C:\Windows\system32\dllhost.exe"
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe "C:\Windows\system32\conhost.exe" C:\Users\Public\Documents\nUCp.exe Jump to behavior
                      Source: C:\Windows\System32\conhost.exeProcess created: C:\Users\Public\Documents\nUCp.exe C:\Users\Public\Documents\nUCp.exeJump to behavior
                      Source: C:\Users\Public\Documents\nUCp.exeProcess created: C:\Windows\SysWOW64\OpenWith.exe "C:\Windows\system32\openwith.exe"Jump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeProcess created: C:\Windows\System32\OpenWith.exe "C:\Windows\system32\openwith.exe"Jump to behavior
                      Source: C:\Windows\System32\OpenWith.exeProcess created: C:\Program Files\Windows Media Player\setup_wm.exe "C:\Program Files\Windows Media Player\setup_wm.exe"Jump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeProcess created: C:\Windows\System32\dllhost.exe "C:\Windows\system32\dllhost.exe"Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appresolver.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: bcp47langs.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: slc.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sppc.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: linkinfo.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ntshrui.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cscapi.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: policymanager.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msvcp110_win.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: taskflowdataengine.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wintypes.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cdp.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: umpdc.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dsreg.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: onecorecommonproxystub.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iphlpapi.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dnsapi.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dhcpcsvc6.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dhcpcsvc.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: winnsi.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rasapi32.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rasman.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rtutils.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mswsock.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: winhttp.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rasadhlp.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: fwpuclnt.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: schannel.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mskeyprotect.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ntasn1.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ncrypt.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ncryptsslp.dllJump to behavior
                      Source: C:\Users\Public\Documents\nUCp.exeSection loaded: apphelp.dllJump to behavior
                      Source: C:\Users\Public\Documents\nUCp.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: wbemcomn.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: amsi.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: userenv.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: profapi.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: version.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: uxtheme.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: sspicli.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: mpr.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: powrprof.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: umpdc.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: wbemcomn.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: wbemcomn.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: mswsock.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: dnsapi.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: iphlpapi.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: rasadhlp.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeSection loaded: fwpuclnt.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: cryptbase.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: netapi32.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: netutils.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: mswsock.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: dpapi.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: uxtheme.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: wkscli.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: cscapi.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: dnsapi.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: iphlpapi.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: rasadhlp.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: fwpuclnt.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeSection loaded: atl.dllJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeSection loaded: pdh.dllJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeSection loaded: wininet.dllJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeSection loaded: urlmon.dllJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeSection loaded: userenv.dllJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeSection loaded: secur32.dllJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeSection loaded: mfplat.dllJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeSection loaded: version.dllJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeSection loaded: iertutil.dllJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeSection loaded: srvcli.dllJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeSection loaded: netutils.dllJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeSection loaded: sspicli.dllJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeSection loaded: msasn1.dllJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeSection loaded: rtworkq.dllJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeSection loaded: cryptbase.dllJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeSection loaded: mswsock.dllJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeSection loaded: uxtheme.dllJump to behavior
                      Source: C:\Windows\System32\dllhost.exeSection loaded: cryptbase.dllJump to behavior
                      Source: C:\Windows\System32\dllhost.exeSection loaded: iphlpapi.dllJump to behavior
                      Source: C:\Windows\System32\dllhost.exeSection loaded: mswsock.dllJump to behavior
                      Source: C:\Windows\System32\dllhost.exeSection loaded: dhcpcsvc.dllJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dllJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\7.0\Outlook\Profiles\OutlookJump to behavior
                      Source: Binary string: softy.pdb source: powershell.exe, 00000000.00000002.1402300584.00000177EEAFC000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831 source: OpenWith.exe, 00000006.00000002.1767169425.0000011F79208000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: *on.pdb> source: powershell.exe, 00000000.00000002.1402300584.00000177EEAFC000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: System.Management.Automation.pdb source: powershell.exe, 00000000.00000002.1401134083.00000177EE833000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: wkernel32.pdb source: nUCp.exe, 00000004.00000003.1391779587.00000000045C0000.00000004.00000001.00020000.00000000.sdmp, nUCp.exe, 00000004.00000003.1391701123.0000000000E50000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1394843323.0000000004DB0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1394938485.0000000004ED0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wkernelbase.pdb source: nUCp.exe, 00000004.00000003.1391976687.0000000004540000.00000004.00000001.00020000.00000000.sdmp, nUCp.exe, 00000004.00000003.1392146550.0000000004760000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1395128336.0000000004DB0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1395438185.0000000004FD0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: ntdll.pdb source: nUCp.exe, 00000004.00000003.1390959056.0000000004540000.00000004.00000001.00020000.00000000.sdmp, nUCp.exe, 00000004.00000003.1391125502.0000000004730000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1393989753.0000000004DB0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1394224065.0000000004FA0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\winload_prod.pdb source: OpenWith.exe, 00000006.00000002.1767169425.0000011F79208000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: wntdll.pdbUGP source: nUCp.exe, 00000004.00000003.1391365646.0000000004540000.00000004.00000001.00020000.00000000.sdmp, nUCp.exe, 00000004.00000003.1391513023.00000000046E0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1394664846.0000000004F50000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1394483982.0000000004DB0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: ntdll.pdbUGP source: nUCp.exe, 00000004.00000003.1390959056.0000000004540000.00000004.00000001.00020000.00000000.sdmp, nUCp.exe, 00000004.00000003.1391125502.0000000004730000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1393989753.0000000004DB0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1394224065.0000000004FA0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wntdll.pdb source: nUCp.exe, 00000004.00000003.1391365646.0000000004540000.00000004.00000001.00020000.00000000.sdmp, nUCp.exe, 00000004.00000003.1391513023.00000000046E0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1394664846.0000000004F50000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1394483982.0000000004DB0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: Microsoft.PowerShell.Commands.Utility.pdb source: powershell.exe, 00000000.00000002.1402300584.00000177EEAFC000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.pdb source: powershell.exe, 00000000.00000002.1402300584.00000177EEAFC000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: ntkrnlmp.pdb4-Xz source: OpenWith.exe, 00000006.00000003.1538253921.0000011F7B75D000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: ion.pdb^ source: powershell.exe, 00000000.00000002.1402300584.00000177EEAFC000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb source: OpenWith.exe, 00000006.00000002.1767169425.0000011F79208000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2 source: OpenWith.exe, 00000006.00000002.1767169425.0000011F79208000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: n.pdb9 source: powershell.exe, 00000000.00000002.1401134083.00000177EE833000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: wkernel32.pdbUGP source: nUCp.exe, 00000004.00000003.1391779587.00000000045C0000.00000004.00000001.00020000.00000000.sdmp, nUCp.exe, 00000004.00000003.1391701123.0000000000E50000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1394843323.0000000004DB0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1394938485.0000000004ED0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wkernelbase.pdbUGP source: nUCp.exe, 00000004.00000003.1391976687.0000000004540000.00000004.00000001.00020000.00000000.sdmp, nUCp.exe, 00000004.00000003.1392146550.0000000004760000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1395128336.0000000004DB0000.00000004.00000001.00020000.00000000.sdmp, OpenWith.exe, 00000005.00000003.1395438185.0000000004FD0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: winload_prod.pdb source: OpenWith.exe, 00000006.00000003.1538253921.0000011F7B75D000.00000004.00000020.00020000.00000000.sdmp

                      Data Obfuscation

                      barindex
                      Source: 6.3.OpenWith.exe.11f7b45d970.2.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                      Source: 6.3.OpenWith.exe.11f7b45d970.2.raw.unpack, Runtime.cs.Net Code: CoreMain
                      Source: 6.3.OpenWith.exe.11f7b45d970.0.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                      Source: 6.3.OpenWith.exe.11f7b45d970.0.raw.unpack, Runtime.cs.Net Code: CoreMain
                      Source: 6.3.OpenWith.exe.11f7b45d970.5.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                      Source: 6.3.OpenWith.exe.11f7b45d970.5.raw.unpack, Runtime.cs.Net Code: CoreMain
                      Source: 6.2.OpenWith.exe.11f7b459d60.1.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                      Source: 6.2.OpenWith.exe.11f7b459d60.1.raw.unpack, Runtime.cs.Net Code: CoreMain
                      Source: 6.3.OpenWith.exe.11f7b459d60.3.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                      Source: 6.3.OpenWith.exe.11f7b459d60.3.raw.unpack, Runtime.cs.Net Code: CoreMain
                      Source: 6.3.OpenWith.exe.11f7b45d970.1.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                      Source: 6.3.OpenWith.exe.11f7b45d970.1.raw.unpack, Runtime.cs.Net Code: CoreMain
                      Source: 6.3.OpenWith.exe.11f7b45d970.4.raw.unpack, Runtime.cs.Net Code: CoreMain System.Reflection.Assembly.Load(byte[])
                      Source: 6.3.OpenWith.exe.11f7b45d970.4.raw.unpack, Runtime.cs.Net Code: CoreMain
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 0_2_00007FF7C0CC815D push ebx; ret 0_2_00007FF7C0CC816A
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 0_2_00007FF7C0CC126D pushad ; retf 0_2_00007FF7C0CC1272
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 0_2_00007FF7C0CC6C00 push eax; ret 0_2_00007FF7C0CC6C0D
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 0_2_00007FF7C0CC5CBD push eax; iretd 0_2_00007FF7C0CC5D21
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 0_2_00007FF7C0D90566 push esi; retf 0_2_00007FF7C0D90567
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_3_01004130 pushad ; ret 4_3_01004138
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_3_01002F50 push eax; retf 4_3_01002F51
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_3_01004170 push ecx; iretd 4_3_0100417C
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_3_01006777 push esi; ret 4_3_01006782
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_3_010047A2 push ebp; iretd 4_3_010047A3
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_3_010061E2 push eax; retf 4_3_010061F1
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_3_01004C62 push es; retf 4_3_01004C91
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_3_01005E69 push ebx; iretd 4_3_01005E6A
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_3_01006A80 push edx; ret 4_3_01006A81
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_2_00FAC01A push ds; iretd 4_2_00FAC036
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_2_010012F4 push ecx; ret 4_2_01001307
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_2_00FA1436 push ds; retf 4_2_00FA143B
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_2_00FAE5F8 push ebx; ret 4_2_00FAE5F9
                      Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 5_3_027F4262 push eax; retf 5_3_027F4271
                      Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 5_3_027F2822 push ebp; iretd 5_3_027F2823
                      Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 5_3_027F3EE9 push ebx; iretd 5_3_027F3EEA
                      Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 5_3_027F2CE2 push es; retf 5_3_027F2D11
                      Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 5_3_027F4B00 push edx; ret 5_3_027F4B01
                      Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 5_3_027F47F7 push esi; ret 5_3_027F4802
                      Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 5_3_027F21F0 push ecx; iretd 5_3_027F21FC
                      Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 5_3_027F0FD0 push eax; retf 5_3_027F0FD1
                      Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 5_3_027F21B0 pushad ; ret 5_3_027F21B8
                      Source: C:\Windows\System32\dllhost.exeCode function: 9_2_0000022FAA4E3590 push ebx; retf 9_2_0000022FAA4E3592
                      Source: initial sampleStatic PE information: section name: UPX0
                      Source: initial sampleStatic PE information: section name: UPX1
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\Public\Documents\nUCp.mp3Jump to dropped file
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\Public\Documents\nUCp.exe (copy)Jump to dropped file
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\Public\Documents\nUCp.mp3Jump to dropped file
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\Public\Documents\nUCp.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\dllhost.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\dllhost.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior

                      Malware Analysis System Evasion

                      barindex
                      Source: C:\Users\Public\Documents\nUCp.exeAPI/Special instruction interceptor: Address: 7FF8418CD044
                      Source: C:\Windows\SysWOW64\OpenWith.exeAPI/Special instruction interceptor: Address: 7FF8418CD044
                      Source: C:\Windows\SysWOW64\OpenWith.exeAPI/Special instruction interceptor: Address: 511A83A
                      Source: OpenWith.exe, 00000005.00000002.1463804330.0000000004540000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: PROCMON.EXE
                      Source: OpenWith.exe, 00000005.00000002.1463804330.0000000004540000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OCEXP64.EXETCPVIEW.EXETCPVIEW64.EXEPROCMON.EXE33
                      Source: C:\Windows\System32\dllhost.exeCode function: GetAdaptersInfo,9_2_0000022FAA4B2AC4
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 6166Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 3683Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 3644Thread sleep time: -6456360425798339s >= -30000sJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 892Thread sleep time: -922337203685477s >= -30000sJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\SysWOW64\OpenWith.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_Processor
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_2_00FFA165 FindFirstFileExW,4_2_00FFA165
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E539F04 GetSystemInfo,6_3_00007DF46E539F04
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.iniJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppDataJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\RoamingJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\WindowsJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\userJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Users\user\AppData\Roaming\MicrosoftJump to behavior
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive userers - NDCDYNVMware20,11696501413z
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: tasks.office.comVMware20,11696501413o
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: trackpan.utiitsl.comVMware20,11696501413h
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: netportal.hdfcbank.comVMware20,11696501413
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: www.interactiveuserers.co.inVMware20,11696501413~
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: dev.azure.comVMware20,11696501413j
                      Source: OpenWith.exe, 00000006.00000003.1514008533.0000011F7AE19000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}SymbolicLinkLinkcLinkSymbolicLink
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive userers - COM.HKVMware20,11696501413
                      Source: OpenWith.exe, 00000006.00000003.1514008533.0000011F7AE19000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: VMCIDevSymbol
                      Source: OpenWith.exe, 00000005.00000002.1463429475.0000000002BC8000.00000004.00000020.00020000.00000000.sdmp, OpenWith.exe, 00000006.00000002.1767169425.0000011F79208000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Test URL for global passwords blocklistVMware20,11696501413
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: secure.bankofamerica.comVMware20,11696501413|UE
                      Source: OpenWith.exe, 00000006.00000003.1541323666.0000011F7ADA8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SCSI#Disk&Ven_VMware&Prod_Virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}SymbolicLinkymbolicLinkcLinkSymbolicLinkmc
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: bankofamerica.comVMware20,11696501413x
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Canara Transaction PasswordVMware20,11696501413}
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive userers - non-EU EuropeVMware20,11696501413
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Canara Transaction PasswordVMware20,11696501413x
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: turbotax.intuit.comVMware20,11696501413t
                      Source: powershell.exe, 00000000.00000002.1402300584.00000177EEB5B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive userers - HKVMware20,11696501413]
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: outlook.office.comVMware20,11696501413s
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive userers - EU East & CentralVMware20,11696501413
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: account.microsoft.com/profileVMware20,11696501413u
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive userers - GDCDYNVMware20,11696501413p
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive userers - EU WestVMware20,11696501413n
                      Source: OpenWith.exe, 00000006.00000002.1767169425.0000011F79208000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWP
                      Source: OpenWith.exe, 00000005.00000003.1395438185.0000000004FD0000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: DisableGuestVmNetworkConnectivity
                      Source: OpenWith.exe, 00000006.00000003.1514008533.0000011F7AE19000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}SymbolicLinkmbolicLinkSymbolicLink+QO
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: ms.portal.azure.comVMware20,11696501413
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Canara Change Transaction PasswordVMware20,11696501413
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: www.interactiveuserers.comVMware20,11696501413}
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: interactiveuserers.co.inVMware20,11696501413d
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: microsoft.visualstudio.comVMware20,11696501413x
                      Source: OpenWith.exe, 00000005.00000003.1395438185.0000000004FD0000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: EnableGuestVmNetworkConnectivity
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: global block list test formVMware20,11696501413
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: outlook.office365.comVMware20,11696501413t
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Canara Change Transaction PasswordVMware20,11696501413^
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: interactiveuserers.comVMware20,11696501413
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: discord.comVMware20,11696501413f
                      Source: OpenWith.exe, 00000006.00000003.1543394834.0000011F7B502000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: AMC password management pageVMware20,11696501413
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information queried: ProcessInformationJump to behavior
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_2_00FF9AB4 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,4_2_00FF9AB4
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_3_01002277 mov eax, dword ptr fs:[00000030h]4_3_01002277
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_2_01002277 mov eax, dword ptr fs:[00000030h]4_2_01002277
                      Source: C:\Windows\SysWOW64\OpenWith.exeCode function: 5_3_027F0283 mov eax, dword ptr fs:[00000030h]5_3_027F0283
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_2_00FF4E5A GetProcessHeap,RtlAllocateHeap,GetModuleFileNameW,_wcsrchr,lstrlenW,GetProcessHeap,RtlFreeHeap,MulDiv,4_2_00FF4E5A
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: DebugJump to behavior
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_2_00FF9AB4 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,4_2_00FF9AB4
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_2_00FF5A33 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,4_2_00FF5A33
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_2_00FF55A9 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,4_2_00FF55A9

                      HIPS / PFW / Operating System Protection Evasion

                      barindex
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeMemory allocated: C:\Windows\System32\dllhost.exe base: 22FAA4B0000 protect: page read and writeJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeMemory written: C:\Windows\System32\dllhost.exe base: 22FAA4B0000Jump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeMemory written: C:\Windows\System32\dllhost.exe base: 7FF6F7FC14E0Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe "C:\Windows\system32\conhost.exe" C:\Users\Public\Documents\nUCp.exe Jump to behavior
                      Source: C:\Windows\System32\conhost.exeProcess created: C:\Users\Public\Documents\nUCp.exe C:\Users\Public\Documents\nUCp.exeJump to behavior
                      Source: C:\Users\Public\Documents\nUCp.exeProcess created: C:\Windows\SysWOW64\OpenWith.exe "C:\Windows\system32\openwith.exe"Jump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeProcess created: C:\Windows\System32\OpenWith.exe "C:\Windows\system32\openwith.exe"Jump to behavior
                      Source: C:\Windows\System32\OpenWith.exeProcess created: C:\Program Files\Windows Media Player\setup_wm.exe "C:\Program Files\Windows Media Player\setup_wm.exe"Jump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeProcess created: C:\Windows\System32\dllhost.exe "C:\Windows\system32\dllhost.exe"Jump to behavior
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_2_00FF5845 cpuid 4_2_00FF5845
                      Source: C:\Windows\System32\OpenWith.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                      Source: C:\Windows\SysWOW64\OpenWith.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Windows\System32\dllhost.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4D1B18 CreateNamedPipeW,BindIoCompletionCallback,ConnectNamedPipe,6_3_00007DF46E4D1B18
                      Source: C:\Users\Public\Documents\nUCp.exeCode function: 4_2_00FF5490 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,4_2_00FF5490
                      Source: C:\Windows\SysWOW64\OpenWith.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
                      Source: OpenWith.exe, 00000005.00000002.1463804330.0000000004540000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: tcpview.exe
                      Source: OpenWith.exe, 00000005.00000002.1463804330.0000000004540000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Procmon.exe

                      Stealing of Sensitive Information

                      barindex
                      Source: Yara matchFile source: 4.2.nUCp.exe.fa0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000005.00000003.1419467605.0000000004D19000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.1766148892.0000011F7B611000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.1463969465.0000000004550000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.1511743151.0000011F7B4C4000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.1511532978.0000011F7B411000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000004.00000003.1389217701.0000000000E50000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000003.1393293145.00000000044F0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000004.00000003.1393080101.0000000003BC0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: OpenWith.exe, 00000006.00000003.1540218988.0000011F7AE19000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: um-Electrum\conf
                      Source: OpenWith.exe, 00000006.00000003.1606135234.0000011F7AE10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: %AppData%\ElectronCash\config
                      Source: OpenWith.exe, 00000006.00000003.1540218988.0000011F7AE19000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: %AppData%\com.liberty.jaxx
                      Source: OpenWith.exe, 00000006.00000003.1540218988.0000011F7AE19000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: passphrase.json
                      Source: OpenWith.exe, 00000006.00000003.1540218988.0000011F7AE19000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: %AppData%\Exodus
                      Source: OpenWith.exe, 00000006.00000003.1540218988.0000011F7AE19000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: %AppData%\Coinomi\Coinomi\wallets
                      Source: powershell.exe, 00000000.00000002.1406806497.00007FF7C0E90000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: sqlcolumnencryptionkeystoreprovider
                      Source: OpenWith.exe, 00000006.00000002.1767169425.0000011F79208000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: \??\C:\Users\user\AppData\Roaming\Ledger Live
                      Source: C:\Windows\System32\OpenWith.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Bitcoin\Bitcoin-QtJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\monero-project\monero-coreJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeKey opened: HKEY_CURRENT_USER\Software\Martin Prikryl\WinSCP 2\Configuration\SecurityJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storageJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM StoreJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\fhihpiojkbmbpdjeoajapmgkhlnakfjf\Icons MaskableJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDBJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download ServiceJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\aghbiahbpaijignceidepookljebhfak\Icons MaskableJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache\js\index-dirJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension StateJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\091tobv5.default-release\safebrowsing\google4Jump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmiedaJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web ApplicationsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\aghbiahbpaijignceidepookljebhfakJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\mpnpojknpmmopombnjdcgaaiekajbnjbJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\NetworkJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\agimnkijcaahngcdmfeangaknmldooml\Icons MonochromeJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\091tobv5.default-release\cache2Jump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadataJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension ScriptsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\aghbiahbpaijignceidepookljebhfak\Icons MonochromeJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\aghbiahbpaijignceidepookljebhfak\IconsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\EncryptionJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\DawnCacheJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\kefjledonklijopmnomlcbpllchaibag\IconsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\GPUCacheJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\agimnkijcaahngcdmfeangaknmldooml\Icons MaskableJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDBJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local StorageJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldbJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\mpnpojknpmmopombnjdcgaaiekajbnjb\Icons MaskableJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\091tobv5.default-release\settings\main\ms-language-packs\browser\newtabJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_metadata_storeJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_storeJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDBJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\kefjledonklijopmnomlcbpllchaibag\Icons MonochromeJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache\wasmJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\091tobv5.default-release\settingsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\defJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local StorageJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension SettingsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\DefaultJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GPUCacheJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalStorageConfigDBJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync DataJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session StorageJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\mpnpojknpmmopombnjdcgaaiekajbnjb\IconsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\091tobv5.default-release\settings\main\ms-language-packsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Cache\Cache_DataJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\TempJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\fmgjjmmmlfnkbppncabfkddbjimcfncm\Icons MonochromeJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest ResourcesJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\FilesJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics DatabaseJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage\025af778-db9d-49f0-b172-4eb563717cb5Jump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\mpnpojknpmmopombnjdcgaaiekajbnjb\Icons MonochromeJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\091tobv5.default-release\cache2\entriesJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\extJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync App SettingsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\fmgjjmmmlfnkbppncabfkddbjimcfncm\Icons MaskableJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\index-dirJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\fhihpiojkbmbpdjeoajapmgkhlnakfjfJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache\jsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation PlatformJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_dbJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\SessionsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabaseJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\091tobv5.default-release\settings\main\ms-language-packs\browserJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session StorageJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDBJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\WebStorageJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code CacheJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\091tobv5.default-releaseJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension RulesJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\dtbqpus9.defaultJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabaseJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\StorageJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\kefjledonklijopmnomlcbpllchaibag\Icons MaskableJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldbJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache\wasm\index-dirJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\kefjledonklijopmnomlcbpllchaibagJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\fhihpiojkbmbpdjeoajapmgkhlnakfjf\Icons MonochromeJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dirJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\091tobv5.default-release\thumbnailsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\DawnCacheJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\NetworkJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\agimnkijcaahngcdmfeangaknmldooml\IconsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code CacheJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_dbJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\091tobv5.default-release\cache2\doomedJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\fmgjjmmmlfnkbppncabfkddbjimcfncmJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\coupon_dbJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\fmgjjmmmlfnkbppncabfkddbjimcfncm\IconsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\091tobv5.default-release\settings\mainJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\CacheJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalDBJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDBJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\ProfilesJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement TrackerJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\agimnkijcaahngcdmfeangaknmldoomlJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\091tobv5.default-release\startupCacheJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrialsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\jsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasmJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\091tobv5.default-release\safebrowsingJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\databasesJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\CacheJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources\fhihpiojkbmbpdjeoajapmgkhlnakfjf\IconsJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\OutlookJump to behavior
                      Source: C:\Windows\System32\OpenWith.exeDirectory queried: C:\Users\user\Documents\AQRFEVRTGLJump to behavior
                      Source: Yara matchFile source: Process Memory Space: OpenWith.exe PID: 5952, type: MEMORYSTR

                      Remote Access Functionality

                      barindex
                      Source: Yara matchFile source: 4.2.nUCp.exe.fa0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000005.00000003.1419467605.0000000004D19000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.1766148892.0000011F7B611000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000002.1463969465.0000000004550000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.1511743151.0000011F7B4C4000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000006.00000003.1511532978.0000011F7B411000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000004.00000003.1389217701.0000000000E50000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000005.00000003.1393293145.00000000044F0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000004.00000003.1393080101.0000000003BC0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E4D1B18 CreateNamedPipeW,BindIoCompletionCallback,ConnectNamedPipe,6_3_00007DF46E4D1B18
                      Source: C:\Windows\System32\OpenWith.exeCode function: 6_3_00007DF46E504088 socket,bind,6_3_00007DF46E504088
                      Source: C:\Program Files\Windows Media Player\setup_wm.exeCode function: 8_2_0000021CE78ECDF4 CreateNamedPipeW,BindIoCompletionCallback,ConnectNamedPipe,8_2_0000021CE78ECDF4
                      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                      Gather Victim Identity InformationAcquire InfrastructureValid Accounts11
                      Windows Management Instrumentation
                      1
                      DLL Side-Loading
                      1
                      DLL Side-Loading
                      21
                      Obfuscated Files or Information
                      1
                      OS Credential Dumping
                      1
                      System Time Discovery
                      Remote Services1
                      Archive Collected Data
                      3
                      Ingress Tool Transfer
                      Exfiltration Over Other Network MediumAbuse Accessibility Features
                      CredentialsDomainsDefault Accounts1
                      PowerShell
                      Boot or Logon Initialization Scripts212
                      Process Injection
                      111
                      Software Packing
                      21
                      Input Capture
                      13
                      File and Directory Discovery
                      Remote Desktop Protocol21
                      Data from Local System
                      21
                      Encrypted Channel
                      Exfiltration Over BluetoothNetwork Denial of Service
                      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
                      DLL Side-Loading
                      1
                      Credentials in Registry
                      136
                      System Information Discovery
                      SMB/Windows Admin Shares1
                      Email Collection
                      1
                      Non-Standard Port
                      Automated ExfiltrationData Encrypted for Impact
                      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook11
                      Masquerading
                      NTDS341
                      Security Software Discovery
                      Distributed Component Object Model21
                      Input Capture
                      3
                      Non-Application Layer Protocol
                      Traffic DuplicationData Destruction
                      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script31
                      Virtualization/Sandbox Evasion
                      LSA Secrets31
                      Virtualization/Sandbox Evasion
                      SSHKeylogging114
                      Application Layer Protocol
                      Scheduled TransferData Encrypted for Impact
                      Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts212
                      Process Injection
                      Cached Domain Credentials2
                      Process Discovery
                      VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                      DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup ItemsCompile After DeliveryDCSync1
                      Application Window Discovery
                      Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                      Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/JobIndicator Removal from ToolsProc Filesystem1
                      System Network Configuration Discovery
                      Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
                      Hide Legend

                      Legend:

                      • Process
                      • Signature
                      • Created File
                      • DNS/IP Info
                      • Is Dropped
                      • Is Windows Process
                      • Number of created Registry Values
                      • Number of created Files
                      • Visual Basic
                      • Delphi
                      • Java
                      • .Net C# or VB.NET
                      • C, C++ or other language
                      • Is malicious
                      • Internet
                      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1511454 Sample: qsKo.ps1 Startdate: 15/09/2024 Architecture: WINDOWS Score: 100 40 deadmunky.nl 2->40 42 captcha.serverprotect.online 2->42 48 Multi AV Scanner detection for domain / URL 2->48 50 Suricata IDS alerts for network traffic 2->50 52 Found malware configuration 2->52 54 11 other signatures 2->54 12 powershell.exe 14 20 2->12         started        signatures3 process4 dnsIp5 46 captcha.serverprotect.online 104.21.82.103, 443, 49700 CLOUDFLARENETUS United States 12->46 36 C:\Users\Public\Documents\nUCp.mp3, PE32 12->36 dropped 38 C:\Users\Public\Documents\nUCp.exe (copy), PE32 12->38 dropped 70 Found many strings related to Crypto-Wallets (likely being stolen) 12->70 72 Powershell drops PE file 12->72 17 conhost.exe 12->17         started        19 conhost.exe 12->19         started        file6 signatures7 process8 process9 21 nUCp.exe 1 17->21         started        signatures10 56 Switches to a custom stack to bypass stack traces 21->56 24 OpenWith.exe 21->24         started        process11 dnsIp12 44 deadmunky.nl 194.113.106.180, 3736, 443, 49701 RACKTECHRU Russian Federation 24->44 58 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 24->58 60 Switches to a custom stack to bypass stack traces 24->60 28 OpenWith.exe 24->28         started        signatures13 process14 signatures15 62 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 28->62 64 Tries to steal Mail credentials (via file / registry access) 28->64 66 Found many strings related to Crypto-Wallets (likely being stolen) 28->66 68 2 other signatures 28->68 31 setup_wm.exe 28->31         started        process16 signatures17 74 Writes to foreign memory regions 31->74 76 Allocates memory in foreign processes 31->76 34 dllhost.exe 31->34         started        process18

                      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                      windows-stand
                      SourceDetectionScannerLabelLink
                      qsKo.ps121%ReversingLabsWin32.Trojan.Generic
                      qsKo.ps119%VirustotalBrowse
                      SourceDetectionScannerLabelLink
                      C:\Users\Public\Documents\nUCp.mp3100%AviraTR/Crypt.ZPACK.Gen8
                      C:\Users\Public\Documents\nUCp.mp3100%Joe Sandbox ML
                      C:\Users\Public\Documents\nUCp.exe (copy)61%ReversingLabsWin32.Trojan.Generic
                      C:\Users\Public\Documents\nUCp.exe (copy)82%VirustotalBrowse
                      C:\Users\Public\Documents\nUCp.mp361%ReversingLabsWin32.Trojan.Generic
                      C:\Users\Public\Documents\nUCp.mp382%VirustotalBrowse
                      No Antivirus matches
                      SourceDetectionScannerLabelLink
                      captcha.serverprotect.online0%VirustotalBrowse
                      deadmunky.nl12%VirustotalBrowse
                      SourceDetectionScannerLabelLink
                      https://duckduckgo.com/chrome_newtab0%URL Reputationsafe
                      https://duckduckgo.com/chrome_newtab0%URL Reputationsafe
                      http://nuget.org/NuGet.exe0%URL Reputationsafe
                      http://nuget.org/NuGet.exe0%URL Reputationsafe
                      https://duckduckgo.com/ac/?q=0%URL Reputationsafe
                      http://pesterbdd.com/images/Pester.png0%URL Reputationsafe
                      https://contoso.com/License0%URL Reputationsafe
                      https://contoso.com/Icon0%URL Reputationsafe
                      https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=0%URL Reputationsafe
                      https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=0%URL Reputationsafe
                      https://www.ecosia.org/newtab/0%URL Reputationsafe
                      https://ac.ecosia.org/autocomplete?q=0%URL Reputationsafe
                      https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search0%URL Reputationsafe
                      https://contoso.com/0%URL Reputationsafe
                      https://nuget.org/nuget.exe0%URL Reputationsafe
                      https://aka.ms/pscore680%URL Reputationsafe
                      http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name0%URL Reputationsafe
                      https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=0%URL Reputationsafe
                      https://www.google.com/images/branding/product/ico/googleg_lodp.ico0%Avira URL Cloudsafe
                      https://discord.com0%Avira URL Cloudsafe
                      http://www.apache.org/licenses/LICENSE-2.0.html0%Avira URL Cloudsafe
                      https://captcha.serverprotect.online0%Avira URL Cloudsafe
                      http://crl.microsoft0%Avira URL Cloudsafe
                      http://microsoft.co0%Avira URL Cloudsafe
                      https://deadmunky.nl:3736/083f339e93162/kuegsocf.6wn8tkernelbasentdllkernel32GetProcessMitigationPol0%Avira URL Cloudsafe
                      https://go.micro0%Avira URL Cloudsafe
                      https://captcha.serverprotect.online0%VirustotalBrowse
                      https://discord.com0%VirustotalBrowse
                      http://www.apache.org/licenses/LICENSE-2.0.html0%VirustotalBrowse
                      https://captcha.serverprotect.online/98aa7e1c0%Avira URL Cloudsafe
                      http://crl.microsoft0%VirustotalBrowse
                      http://www.microsoft.co0%Avira URL Cloudsafe
                      https://deadmunky.nl:3736/083f339e93162/kuegsocf.6wn8tkernelbasentdllkernel32GetProcessMitigationPol17%VirustotalBrowse
                      https://discordapp.com0%Avira URL Cloudsafe
                      http://captcha.serverprotect.online0%Avira URL Cloudsafe
                      https://captcha.serverprotect.online/98aa7e1ce731c6206ebbe457e9f2dc7088adc3c628bee08/verify0%Avira URL Cloudsafe
                      http://captcha.serverprotect.online0%VirustotalBrowse
                      http://microsoft.co1%VirustotalBrowse
                      http://www.microsoft.co1%VirustotalBrowse
                      https://www.google.com/images/branding/product/ico/googleg_lodp.ico0%VirustotalBrowse
                      https://captcha.serverprotect.online/98aa7e1ce731c6206ebbe457e9f2dc7088adc3c628bee08/verify0%VirustotalBrowse
                      https://github.com/Pester/Pester0%Avira URL Cloudsafe
                      https://discordapp.com0%VirustotalBrowse
                      http://www.microsoft.czl0%Avira URL Cloudsafe
                      http://crl.micro0%Avira URL Cloudsafe
                      https://deadmunky.nl:3736/083f339e93162/kuegsocf.6wn8t0%Avira URL Cloudsafe
                      https://deadmunky.nl:3736/083f339e93162/kuegsocf.6wn8t(0%Avira URL Cloudsafe
                      https://deadmunky.nl:3736/083f339e93162/kuegsocf.6wn8t15%VirustotalBrowse
                      https://deadmunky.nl:3736/083f339e93162/kuegsocf.6wn8t(17%VirustotalBrowse
                      https://github.com/Pester/Pester1%VirustotalBrowse
                      NameIPActiveMaliciousAntivirus DetectionReputation
                      captcha.serverprotect.online
                      104.21.82.103
                      truefalseunknown
                      deadmunky.nl
                      194.113.106.180
                      truetrueunknown
                      NameMaliciousAntivirus DetectionReputation
                      https://captcha.serverprotect.online/98aa7e1ce731c6206ebbe457e9f2dc7088adc3c628bee08/verifyfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://deadmunky.nl:3736/083f339e93162/kuegsocf.6wn8ttrue
                      • 15%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      NameSourceMaliciousAntivirus DetectionReputation
                      https://duckduckgo.com/chrome_newtabOpenWith.exe, 00000006.00000003.1542052579.0000011F7B725000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      • URL Reputation: safe
                      unknown
                      http://nuget.org/NuGet.exepowershell.exe, 00000000.00000002.1396196856.00000177E6818000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      • URL Reputation: safe
                      unknown
                      https://discord.comOpenWith.exe, 00000006.00000003.1549035844.0000011F7B715000.00000004.00000020.00020000.00000000.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://duckduckgo.com/ac/?q=OpenWith.exe, 00000006.00000003.1542052579.0000011F7B725000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://captcha.serverprotect.onlinepowershell.exe, 00000000.00000002.1371224256.00000177D787B000.00000004.00000800.00020000.00000000.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://www.google.com/images/branding/product/ico/googleg_lodp.icoOpenWith.exe, 00000006.00000003.1542052579.0000011F7B725000.00000004.00000020.00020000.00000000.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://pesterbdd.com/images/Pester.pngpowershell.exe, 00000000.00000002.1371224256.00000177D69C8000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://crl.microsoftpowershell.exe, 00000000.00000002.1403260797.00000177EEBDE000.00000004.00000020.00020000.00000000.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://www.apache.org/licenses/LICENSE-2.0.htmlpowershell.exe, 00000000.00000002.1371224256.00000177D69C8000.00000004.00000800.00020000.00000000.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://microsoft.copowershell.exe, 00000000.00000002.1403260797.00000177EEBDE000.00000004.00000020.00020000.00000000.sdmpfalse
                      • 1%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://deadmunky.nl:3736/083f339e93162/kuegsocf.6wn8tkernelbasentdllkernel32GetProcessMitigationPolOpenWith.exe, 00000005.00000003.1462414332.0000000005184000.00000004.00000020.00020000.00000000.sdmptrue
                      • 17%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://go.micropowershell.exe, 00000000.00000002.1371224256.00000177D787B000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://captcha.serverprotect.online/98aa7e1cpowershell.exe, 00000000.00000002.1371224256.00000177D7EA4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.1371224256.00000177D787B000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://www.microsoft.copowershell.exe, 00000000.00000002.1403260797.00000177EEBDE000.00000004.00000020.00020000.00000000.sdmpfalse
                      • 1%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://contoso.com/Licensepowershell.exe, 00000000.00000002.1396196856.00000177E6818000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://discordapp.comOpenWith.exe, 00000006.00000003.1549035844.0000011F7B715000.00000004.00000020.00020000.00000000.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://captcha.serverprotect.onlinepowershell.exe, 00000000.00000002.1371224256.00000177D7CE5000.00000004.00000800.00020000.00000000.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://contoso.com/Iconpowershell.exe, 00000000.00000002.1396196856.00000177E6818000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=OpenWith.exe, 00000006.00000003.1542052579.0000011F7B725000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=OpenWith.exe, 00000006.00000003.1542052579.0000011F7B725000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://www.ecosia.org/newtab/OpenWith.exe, 00000006.00000003.1542052579.0000011F7B725000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://github.com/Pester/Pesterpowershell.exe, 00000000.00000002.1371224256.00000177D69C8000.00000004.00000800.00020000.00000000.sdmpfalse
                      • 1%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://www.microsoft.czlpowershell.exe, 00000000.00000002.1403260797.00000177EEBDE000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://ac.ecosia.org/autocomplete?q=OpenWith.exe, 00000006.00000003.1542052579.0000011F7B725000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://crl.micropowershell.exe, 00000000.00000002.1403260797.00000177EEBDE000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/searchOpenWith.exe, 00000006.00000003.1542052579.0000011F7B725000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://contoso.com/powershell.exe, 00000000.00000002.1396196856.00000177E6818000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://nuget.org/nuget.exepowershell.exe, 00000000.00000002.1396196856.00000177E6818000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://aka.ms/pscore68powershell.exe, 00000000.00000002.1371224256.00000177D67A1000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://deadmunky.nl:3736/083f339e93162/kuegsocf.6wn8t(OpenWith.exe, 00000005.00000002.1462963482.00000000027BC000.00000004.00000010.00020000.00000000.sdmptrue
                      • 17%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://schemas.xmlsoap.org/ws/2005/05/identity/claims/namepowershell.exe, 00000000.00000002.1371224256.00000177D67A1000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=OpenWith.exe, 00000006.00000003.1542052579.0000011F7B725000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      104.21.82.103
                      captcha.serverprotect.onlineUnited States
                      13335CLOUDFLARENETUSfalse
                      194.113.106.180
                      deadmunky.nlRussian Federation
                      208861RACKTECHRUtrue
                      Joe Sandbox version:40.0.0 Tourmaline
                      Analysis ID:1511454
                      Start date and time:2024-09-15 15:01:15 +02:00
                      Joe Sandbox product:CloudBasic
                      Overall analysis duration:0h 7m 48s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:default.jbs
                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                      Number of analysed new started processes analysed:13
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Sample name:qsKo.ps1
                      Detection:MAL
                      Classification:mal100.troj.spyw.evad.winPS1@14/7@2/2
                      EGA Information:
                      • Successful, ratio: 66.7%
                      HCA Information:
                      • Successful, ratio: 63%
                      • Number of executed functions: 168
                      • Number of non-executed functions: 22
                      Cookbook Comments:
                      • Found application associated with file extension: .ps1
                      • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
                      • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                      • Execution Graph export aborted for target OpenWith.exe, PID 5860 because there are no executed function
                      • Execution Graph export aborted for target powershell.exe, PID 7316 because it is empty
                      • Not all processes where analyzed, report is missing behavior information
                      • Report size exceeded maximum capacity and may have missing behavior information.
                      • Report size getting too big, too many NtOpenFile calls found.
                      • Report size getting too big, too many NtOpenKeyEx calls found.
                      • Report size getting too big, too many NtQueryValueKey calls found.
                      • Report size getting too big, too many NtReadVirtualMemory calls found.
                      TimeTypeDescription
                      09:02:16API Interceptor15x Sleep call for process: powershell.exe modified
                      09:02:52API Interceptor1x Sleep call for process: setup_wm.exe modified
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      194.113.106.180GsrDwm0DJG.ps1Get hashmaliciousRHADAMANTHYSBrowse
                        HeggBkMoYE.ps1Get hashmaliciousRHADAMANTHYSBrowse
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          deadmunky.nlGsrDwm0DJG.ps1Get hashmaliciousRHADAMANTHYSBrowse
                          • 194.113.106.180
                          HeggBkMoYE.ps1Get hashmaliciousRHADAMANTHYSBrowse
                          • 194.113.106.180
                          rsDymE.vbsGet hashmaliciousRHADAMANTHYSBrowse
                          • 63.141.252.2
                          ji2OQQH0ei.exeGet hashmaliciousRHADAMANTHYSBrowse
                          • 63.141.252.2
                          Wg2icM1Vjd.exeGet hashmaliciousRHADAMANTHYSBrowse
                          • 63.141.252.2
                          mz4hWuLng5.exeGet hashmaliciousRHADAMANTHYSBrowse
                          • 63.141.252.2
                          3fFuN58APW.exeGet hashmaliciousRHADAMANTHYSBrowse
                          • 63.141.252.2
                          C6hvgnDXwW.exeGet hashmaliciousRHADAMANTHYSBrowse
                          • 63.141.252.2
                          drZ7xATGIg.exeGet hashmaliciousRHADAMANTHYSBrowse
                          • 63.141.252.2
                          zaD1vaze6V.ps1Get hashmaliciousRHADAMANTHYSBrowse
                          • 63.141.252.2
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          CLOUDFLARENETUSSecuriteInfo.com.FileRepMalware.32268.950.exeGet hashmaliciousUnknownBrowse
                          • 162.159.61.4
                          https://nnwdryn4me2.typeform.com/to/vzxAdnuI?utm_source=www.thedeepview.co&utm_medium=newsletter&utm_campaign=u-s-hospital-teams-up-with-suki-for-an-ai-assistant&_bhlid=899a446fb8590c3f4dab42c864907d7822828cadGet hashmaliciousUnknownBrowse
                          • 104.16.117.116
                          ATH0000878718.pdf.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                          • 188.114.97.3
                          Frozen_Slotted.exeGet hashmaliciousUnknownBrowse
                          • 104.26.1.5
                          IM5Ov6yzm3CzKUodDTWqZSXo.exeGet hashmaliciousLummaC, Stealc, VidarBrowse
                          • 172.67.136.135
                          aNj1aFSOxohqZwe847hVpx4K.exeGet hashmaliciousLummaC, Stealc, VidarBrowse
                          • 104.21.26.150
                          SecuriteInfo.com.Variant.Tedy.640280.26081.14300.exeGet hashmaliciousUnknownBrowse
                          • 172.67.72.57
                          SecuriteInfo.com.Variant.Tedy.640280.26081.14300.exeGet hashmaliciousUnknownBrowse
                          • 104.26.0.5
                          Setup.exeGet hashmaliciousLummaCBrowse
                          • 188.114.97.3
                          YjtJRRgm3O.lnkGet hashmaliciousUnknownBrowse
                          • 172.67.198.33
                          RACKTECHRUGsrDwm0DJG.ps1Get hashmaliciousRHADAMANTHYSBrowse
                          • 194.113.106.180
                          HeggBkMoYE.ps1Get hashmaliciousRHADAMANTHYSBrowse
                          • 194.113.106.180
                          b2J6hgvd51.elfGet hashmaliciousUnknownBrowse
                          • 45.128.232.191
                          TbFoReHi2v.elfGet hashmaliciousMiraiBrowse
                          • 45.128.232.235
                          gmA11dfzc2.elfGet hashmaliciousMiraiBrowse
                          • 45.128.232.235
                          naoen3DFXE.elfGet hashmaliciousMiraiBrowse
                          • 45.128.232.235
                          BrKoH01YHR.elfGet hashmaliciousMiraiBrowse
                          • 45.128.232.235
                          JV1eMPUdHV.elfGet hashmaliciousMiraiBrowse
                          • 45.128.232.235
                          O1OSOtRYWN.elfGet hashmaliciousMiraiBrowse
                          • 45.128.232.235
                          EuK5PNhZyK.elfGet hashmaliciousMiraiBrowse
                          • 45.128.232.235
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          3b5074b1b5d032e5620f69f9f700ff0eATH0000878718.pdf.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                          • 104.21.82.103
                          SfXgy8lFUR.lnkGet hashmaliciousUnknownBrowse
                          • 104.21.82.103
                          YjtJRRgm3O.lnkGet hashmaliciousUnknownBrowse
                          • 104.21.82.103
                          PjkFCWhi.exeGet hashmaliciousXWormBrowse
                          • 104.21.82.103
                          i1XtJZAi.posh.ps1Get hashmaliciousUnknownBrowse
                          • 104.21.82.103
                          E78jryaJ.posh.ps1Get hashmaliciousPoshC2Browse
                          • 104.21.82.103
                          http://duckduckgogg42xjoc72x3sjasowoarfbgcmvfimaftt6twagswzczad.onionGet hashmaliciousUnknownBrowse
                          • 104.21.82.103
                          https://saltlakeinsider.com/wp-content/themes/travel/ghgh/red.htmlGet hashmaliciousUnknownBrowse
                          • 104.21.82.103
                          https://qrco.de/bfOaLJGet hashmaliciousUnknownBrowse
                          • 104.21.82.103
                          http://worker-ancient-butterfly-29b6.fokkoyarka.workers.dev/Get hashmaliciousHTMLPhisherBrowse
                          • 104.21.82.103
                          caec7ddf6889590d999d7ca1b76373b6DCF368HPtv.exeGet hashmaliciousRHADAMANTHYSBrowse
                          • 194.113.106.180
                          ji2OQQH0ei.exeGet hashmaliciousRHADAMANTHYSBrowse
                          • 194.113.106.180
                          zaD1vaze6V.ps1Get hashmaliciousRHADAMANTHYSBrowse
                          • 194.113.106.180
                          1kfRGncRyD.exeGet hashmaliciousRHADAMANTHYSBrowse
                          • 194.113.106.180
                          5qckfVuvzX.exeGet hashmaliciousRHADAMANTHYSBrowse
                          • 194.113.106.180
                          file.exeGet hashmaliciousRHADAMANTHYS, XWormBrowse
                          • 194.113.106.180
                          QIkZ7aeVBV.msiGet hashmaliciousDanaBot, RHADAMANTHYSBrowse
                          • 194.113.106.180
                          SensApi.dllGet hashmaliciousRHADAMANTHYSBrowse
                          • 194.113.106.180
                          s6K4JjTwtz.exeGet hashmaliciousRHADAMANTHYSBrowse
                          • 194.113.106.180
                          IrJIw2lsaB.msiGet hashmaliciousRHADAMANTHYSBrowse
                          • 194.113.106.180
                          No context
                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                          File Type:PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
                          Category:dropped
                          Size (bytes):232448
                          Entropy (8bit):7.973684967690312
                          Encrypted:false
                          SSDEEP:6144:OpYKhXNlVtQGZAu2vUq5TRMfdhlijTA0ymoS:OpYWxrZARBqxscmoS
                          MD5:FFFAAB9CB76179E7C9CC424C7519F8AB
                          SHA1:9DD9E92A87BDDAFDA67224C444CE2CA84E4254AA
                          SHA-256:EC71CE039F5E01D02F2EE60C0B01DD0B623790EB2C2CED4F525FC8A606FEC61E
                          SHA-512:FE154E45CBED150D9871F7122855BEA7F1BE8E78506D3A9305C5CD56FF3FD2B815E2534D9621CB71770501E0ED82210D6D0DE98D218A163AEE8717716DDBD4E6
                          Malicious:true
                          Antivirus:
                          • Antivirus: ReversingLabs, Detection: 61%
                          • Antivirus: Virustotal, Detection: 82%, Browse
                          Reputation:low
                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......UP.|.1@/.1@/.1@/ZIC..1@/ZIE..1@/ZID..1@/.NE.71@/.ND..1@/.NC..1@/ZIA..1@/.1A/v1@/+.D..1@/.1@/.1@/+../.1@/+.B..1@/Rich.1@/........................PE..L..._{_d...............%..... ......`.............@..........................0............@..................................$...............................%......................................,...............................................UPX0....................................UPX1.............r..................@....rsrc.... ...........v..............@..............................................................................................................................................................................................................................................................................................................................................................4.10.UPX!....
                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                          File Type:PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
                          Category:dropped
                          Size (bytes):232448
                          Entropy (8bit):7.973684967690312
                          Encrypted:false
                          SSDEEP:6144:OpYKhXNlVtQGZAu2vUq5TRMfdhlijTA0ymoS:OpYWxrZARBqxscmoS
                          MD5:FFFAAB9CB76179E7C9CC424C7519F8AB
                          SHA1:9DD9E92A87BDDAFDA67224C444CE2CA84E4254AA
                          SHA-256:EC71CE039F5E01D02F2EE60C0B01DD0B623790EB2C2CED4F525FC8A606FEC61E
                          SHA-512:FE154E45CBED150D9871F7122855BEA7F1BE8E78506D3A9305C5CD56FF3FD2B815E2534D9621CB71770501E0ED82210D6D0DE98D218A163AEE8717716DDBD4E6
                          Malicious:true
                          Antivirus:
                          • Antivirus: Avira, Detection: 100%
                          • Antivirus: Joe Sandbox ML, Detection: 100%
                          • Antivirus: ReversingLabs, Detection: 61%
                          • Antivirus: Virustotal, Detection: 82%, Browse
                          Reputation:low
                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......UP.|.1@/.1@/.1@/ZIC..1@/ZIE..1@/ZID..1@/.NE.71@/.ND..1@/.NC..1@/ZIA..1@/.1A/v1@/+.D..1@/.1@/.1@/+../.1@/+.B..1@/Rich.1@/........................PE..L..._{_d...............%..... ......`.............@..........................0............@..................................$...............................%......................................,...............................................UPX0....................................UPX1.............r..................@....rsrc.... ...........v..............@..............................................................................................................................................................................................................................................................................................................................................................4.10.UPX!....
                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                          File Type:data
                          Category:dropped
                          Size (bytes):64
                          Entropy (8bit):1.1940658735648508
                          Encrypted:false
                          SSDEEP:3:NlllulpgztZ:NllUO
                          MD5:ADB67D140C904AFBF0D2C47FCFC73086
                          SHA1:CAA1973FC7AB5367DC2007487049041C6D0AC54E
                          SHA-256:BA09CC360CD10629A32D8E84392BAD452284123893B0792F6417340A72E3B951
                          SHA-512:85BE6449222EAA096A6F84E051D16DB1147498DA621BDB6C7B5D11CF6C306DB4DE90CEB457EDE22CCA53BC94CF4D1E6D0FAE203D196AF7AF225AF87464E1286E
                          Malicious:false
                          Preview:@...e.................................x..............@..........
                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                          File Type:ASCII text, with no line terminators
                          Category:dropped
                          Size (bytes):60
                          Entropy (8bit):4.038920595031593
                          Encrypted:false
                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                          Malicious:false
                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                          File Type:ASCII text, with no line terminators
                          Category:dropped
                          Size (bytes):60
                          Entropy (8bit):4.038920595031593
                          Encrypted:false
                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                          Malicious:false
                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                          File Type:data
                          Category:dropped
                          Size (bytes):6220
                          Entropy (8bit):3.7190960432981486
                          Encrypted:false
                          SSDEEP:96:YSOUyhPOCgO6b4bkvhkvCCthwtQJfJHCwtQJfXHB:0UyhPeO6bI6tQptQz
                          MD5:B73BCD4FA134D8FF6AFA9FBCE3E31912
                          SHA1:0D78D65CD5A7158FC21BAE613B9898A3F3F2B1BA
                          SHA-256:73D61EA626D4DDBE5FE20149362B9FF4F626746B79E5B5BD39F6D102165FA0C1
                          SHA-512:258CE5BE9E56D6C80C877547698D408A4FCBB3B49524A9E831CEB4AC3EF33FFE0CA22E6D6828A6CED92404C09AD94B3A09DC8EB8C5C8350F6FF6EB379BB2C2B8
                          Malicious:false
                          Preview:...................................FL..................F.".. ....N.5q....m.{o...z.:{.............................:..DG..Yr?.D..U..k0.&...&.........5q......vo...#..{o.......t...CFSF..1.....EW)N..AppData...t.Y^...H.g.3..(.....gVA.G..k...@......EW)N/YEh...........................c..A.p.p.D.a.t.a...B.V.1...../YCh..Roaming.@......EW)N/YCh..............................R.o.a.m.i.n.g.....\.1.....EW.R..MICROS~1..D......EW)N/Y@h..........................O~X.M.i.c.r.o.s.o.f.t.....V.1.....EW.S..Windows.@......EW)N/Y@h..........................j...W.i.n.d.o.w.s.......1.....EW+N..STARTM~1..n......EW)N/Y@h....................D......H..S.t.a.r.t. .M.e.n.u...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.6.......1.....EW#O..Programs..j......EW)N/Y@h....................@.......|.P.r.o.g.r.a.m.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.2.....n.1......O.K..WINDOW~1..V......EW)NEW)N..........................d...W.i.n.d.o.w.s. .P.o.w.e.r.S.h.e.l.l.....z.2......O.I .WINDOW~2.LNK..^......EW)N/YGh................
                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                          File Type:data
                          Category:dropped
                          Size (bytes):6220
                          Entropy (8bit):3.7190960432981486
                          Encrypted:false
                          SSDEEP:96:YSOUyhPOCgO6b4bkvhkvCCthwtQJfJHCwtQJfXHB:0UyhPeO6bI6tQptQz
                          MD5:B73BCD4FA134D8FF6AFA9FBCE3E31912
                          SHA1:0D78D65CD5A7158FC21BAE613B9898A3F3F2B1BA
                          SHA-256:73D61EA626D4DDBE5FE20149362B9FF4F626746B79E5B5BD39F6D102165FA0C1
                          SHA-512:258CE5BE9E56D6C80C877547698D408A4FCBB3B49524A9E831CEB4AC3EF33FFE0CA22E6D6828A6CED92404C09AD94B3A09DC8EB8C5C8350F6FF6EB379BB2C2B8
                          Malicious:false
                          Preview:...................................FL..................F.".. ....N.5q....m.{o...z.:{.............................:..DG..Yr?.D..U..k0.&...&.........5q......vo...#..{o.......t...CFSF..1.....EW)N..AppData...t.Y^...H.g.3..(.....gVA.G..k...@......EW)N/YEh...........................c..A.p.p.D.a.t.a...B.V.1...../YCh..Roaming.@......EW)N/YCh..............................R.o.a.m.i.n.g.....\.1.....EW.R..MICROS~1..D......EW)N/Y@h..........................O~X.M.i.c.r.o.s.o.f.t.....V.1.....EW.S..Windows.@......EW)N/Y@h..........................j...W.i.n.d.o.w.s.......1.....EW+N..STARTM~1..n......EW)N/Y@h....................D......H..S.t.a.r.t. .M.e.n.u...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.6.......1.....EW#O..Programs..j......EW)N/Y@h....................@.......|.P.r.o.g.r.a.m.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.2.....n.1......O.K..WINDOW~1..V......EW)NEW)N..........................d...W.i.n.d.o.w.s. .P.o.w.e.r.S.h.e.l.l.....z.2......O.I .WINDOW~2.LNK..^......EW)N/YGh................
                          File type:ASCII text, with very long lines (65534), with CRLF line terminators
                          Entropy (8bit):4.010420672236651
                          TrID:
                            File name:qsKo.ps1
                            File size:465'550 bytes
                            MD5:668884aeb66c4d344622dcd0dc087b8c
                            SHA1:0d8a0e61e56313a745a0a7862ecc2fedbf12abbc
                            SHA256:01c3e4114427cce7ab6bf90cfa72164a8cfd37dcadddb69817c31679e12fd263
                            SHA512:5282e820aae2f62d54b9da87ca5fa6e49605490fe8bee1d193b0c3fa89ce575bb0045549f5b3b766b546166273f5bac8e8ea0c9aeed4a79f4729a6eae09d2011
                            SSDEEP:6144:pnyEjQ3UHJ+SNbvDnVoC3OOeFZRjHvsufB0VGtsrvCBJ8JUBm9aedJM2dQyP0RPt:VyEjvpTbzVoCEfHj6xrQ8J4ledTmvt
                            TLSH:62A49EBC75042DD5E66E565BDA9BFCD80376F6729DC7A8C840A4FBE30563362EE02804
                            File Content Preview:..$encodedData = '4d5a90000300000004000000ffff0000b800000000000000400000000000000000000000000000000000000000000000000000000000000000000000100100000e1fba0e00b409cd21b8014ccd21546869732070726f6772616d2063616e6e6f742062652072756e20696e20444f53206d6f64652e0d0
                            Icon Hash:3270d6baae77db44
                            TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                            2024-09-15T15:02:25.993182+02002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1194.113.106.1803736192.168.2.1049701TCP
                            2024-09-15T15:02:38.427859+02002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1194.113.106.1803736192.168.2.1049706TCP
                            2024-09-15T15:02:38.427859+02002854824ETPRO JA3 HASH Suspected Malware Related Response2194.113.106.1803736192.168.2.1049706TCP
                            2024-09-15T15:02:48.917706+02002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1194.113.106.1803736192.168.2.1049707TCP
                            2024-09-15T15:02:48.917706+02002854824ETPRO JA3 HASH Suspected Malware Related Response2194.113.106.1803736192.168.2.1049707TCP
                            2024-09-15T15:02:55.097704+02002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1194.113.106.180443192.168.2.1049708TCP
                            2024-09-15T15:03:01.712920+02002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1194.113.106.180443192.168.2.1049709TCP
                            2024-09-15T15:03:08.193359+02002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1194.113.106.180443192.168.2.1049710TCP
                            2024-09-15T15:03:14.921005+02002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1194.113.106.180443192.168.2.1049712TCP
                            2024-09-15T15:03:21.402407+02002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1194.113.106.180443192.168.2.1049713TCP
                            2024-09-15T15:03:28.139413+02002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1194.113.106.180443192.168.2.1049714TCP
                            2024-09-15T15:03:34.627622+02002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1194.113.106.180443192.168.2.1049715TCP
                            2024-09-15T15:03:41.361518+02002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1194.113.106.180443192.168.2.1049716TCP
                            2024-09-15T15:03:47.962486+02002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1194.113.106.180443192.168.2.1049717TCP
                            2024-09-15T15:03:54.468063+02002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1194.113.106.180443192.168.2.1049718TCP
                            2024-09-15T15:04:01.074588+02002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1194.113.106.180443192.168.2.1049719TCP
                            2024-09-15T15:04:07.823659+02002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1194.113.106.180443192.168.2.1049720TCP
                            2024-09-15T15:04:14.623754+02002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1194.113.106.180443192.168.2.1049721TCP
                            2024-09-15T15:04:20.901754+02002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1194.113.106.180443192.168.2.1049722TCP
                            TimestampSource PortDest PortSource IPDest IP
                            Sep 15, 2024 15:02:18.323926926 CEST49700443192.168.2.10104.21.82.103
                            Sep 15, 2024 15:02:18.323988914 CEST44349700104.21.82.103192.168.2.10
                            Sep 15, 2024 15:02:18.324057102 CEST49700443192.168.2.10104.21.82.103
                            Sep 15, 2024 15:02:18.374741077 CEST49700443192.168.2.10104.21.82.103
                            Sep 15, 2024 15:02:18.374763012 CEST44349700104.21.82.103192.168.2.10
                            Sep 15, 2024 15:02:18.855271101 CEST44349700104.21.82.103192.168.2.10
                            Sep 15, 2024 15:02:18.855691910 CEST49700443192.168.2.10104.21.82.103
                            Sep 15, 2024 15:02:19.026925087 CEST49700443192.168.2.10104.21.82.103
                            Sep 15, 2024 15:02:19.026952982 CEST44349700104.21.82.103192.168.2.10
                            Sep 15, 2024 15:02:19.027762890 CEST44349700104.21.82.103192.168.2.10
                            Sep 15, 2024 15:02:19.044518948 CEST49700443192.168.2.10104.21.82.103
                            Sep 15, 2024 15:02:19.091403008 CEST44349700104.21.82.103192.168.2.10
                            Sep 15, 2024 15:02:19.233074903 CEST44349700104.21.82.103192.168.2.10
                            Sep 15, 2024 15:02:19.233544111 CEST44349700104.21.82.103192.168.2.10
                            Sep 15, 2024 15:02:19.233617067 CEST49700443192.168.2.10104.21.82.103
                            Sep 15, 2024 15:02:19.245007038 CEST49700443192.168.2.10104.21.82.103
                            Sep 15, 2024 15:02:24.947691917 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:24.956653118 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:24.956835985 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:24.957122087 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:24.962146997 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:25.661312103 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:25.664262056 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:25.976260900 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:25.993181944 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:25.993284941 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:25.993530989 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:25.993541002 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.205554008 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.214368105 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.219255924 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.460568905 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.460593939 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.460603952 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.460692883 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.460793018 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.460841894 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.460877895 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.460889101 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.460942984 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.460954905 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.460988998 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.461033106 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.461106062 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.461374998 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.461427927 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.461451054 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.461461067 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.461507082 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.465723991 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.465737104 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.465791941 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.472315073 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.472402096 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.472450018 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.475990057 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.476061106 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.476103067 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.551347971 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.581917048 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.581957102 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.582016945 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.582055092 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.582154036 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.585937977 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.585974932 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.586009979 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.586049080 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.632498026 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.795106888 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.795129061 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.795197010 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.795211077 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.795224905 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.795273066 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.795286894 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.795299053 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.795310974 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.795324087 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.795336008 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.795344114 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.795350075 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.795367002 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.795367956 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.795380116 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.795398951 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.795420885 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.795511961 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.795523882 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.795536041 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.795547962 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.795557976 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.795584917 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.795592070 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.795677900 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.795689106 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.795722961 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.795995951 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.796015978 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.796025991 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.796046019 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.796060085 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.796098948 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.796206951 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.796245098 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.796267033 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.796323061 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.796361923 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.796451092 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.796509027 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.796554089 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.796555042 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.796569109 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.796611071 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.797003031 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.797230959 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.797250032 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.797262907 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.797281027 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.797307014 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.797328949 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.797580004 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.797626972 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.801949978 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.802839041 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.802850008 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.802862883 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.802895069 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.802898884 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.802906036 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.802917004 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.802917957 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.802938938 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.802946091 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.802952051 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.802964926 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.802993059 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.803014994 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.803419113 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.803458929 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.803469896 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.803494930 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.803498983 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.803512096 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.803566933 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.804434061 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.804460049 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.804474115 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.804485083 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.804486036 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.804501057 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.804514885 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.804542065 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.805238962 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.805257082 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.805269957 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.805279970 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.805293083 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.805309057 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.805335045 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.806077003 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.806092024 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.806103945 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.806123972 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.806139946 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.806181908 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.806194067 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.806233883 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.806862116 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.806898117 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.806910038 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.806921959 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.806934118 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.806956053 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.806986094 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.807758093 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.807775974 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.807787895 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.807817936 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.807818890 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.807851076 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.808307886 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.808353901 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.808429956 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.808517933 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.808527946 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.808568954 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.815481901 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.815498114 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.815510035 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.815540075 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.815557003 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.819559097 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.819571972 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.819582939 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.819618940 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.824685097 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.824698925 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.824709892 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.824767113 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.824789047 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.830410004 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.830421925 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.830435038 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.830485106 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.833688974 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.833719969 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.833729982 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.833758116 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.833758116 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.837296963 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.837347031 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.837403059 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.837503910 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.837528944 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.837573051 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.841428041 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.841439962 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.841450930 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.841496944 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.843616962 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.843628883 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.843640089 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.843683958 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.843713999 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.847107887 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.847203970 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.847214937 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.847245932 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.847261906 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.847276926 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.852557898 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.852569103 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.852579117 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.852623940 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.855074883 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.855122089 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.855128050 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.855133057 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.855175018 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.856528997 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.856554985 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.856565952 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.856606960 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.859627008 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.859637976 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.859647989 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.859677076 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.859689951 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.862651110 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.862663031 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.862672091 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.862694979 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.865782976 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.865828037 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.865890026 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.865900993 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.865931988 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.865977049 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.868727922 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.868772984 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.868840933 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.868850946 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.868859053 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.868886948 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.872167110 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.872208118 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.872365952 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.872375965 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.872404099 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.872406006 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.874727011 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.874766111 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.874771118 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.874784946 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.874859095 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.877705097 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.877716064 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.877721071 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.877774000 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.881014109 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.881026030 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.881035089 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.881081104 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.883600950 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.883614063 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.883682966 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.883692026 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.883768082 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.883768082 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.886837006 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.886847973 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.886857986 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.886887074 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.889803886 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.889816999 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.889827967 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.889914989 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.892796993 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.892880917 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.892890930 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.892930031 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.899199009 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.899218082 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.899229050 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.899280071 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.899734974 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.901953936 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.901973009 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.901984930 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.902045012 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.904597998 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.904609919 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.904620886 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.904658079 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.904687881 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.904727936 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.904759884 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.904772043 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.904800892 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.907557011 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.907608032 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.907614946 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.907618999 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.907663107 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.910118103 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.910129070 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.910140991 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.910190105 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.912971973 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.913033962 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.913058043 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.913068056 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.913078070 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.913104057 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.915530920 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.915541887 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.915551901 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.915563107 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.915585995 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.915612936 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.918718100 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.918755054 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.918764114 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.918765068 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.918802023 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.921145916 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.921158075 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.921166897 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.921176910 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.921201944 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.921228886 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.923806906 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.923818111 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.923827887 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.923858881 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.926497936 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.926507950 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.926532030 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.926543951 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.926565886 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.926570892 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.929408073 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.929471970 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.929630041 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.929646015 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.929656029 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.929681063 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.931658983 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.931669950 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.931679964 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.931711912 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.931745052 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.934422970 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.934442997 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.934453011 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.934490919 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.937026024 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.937113047 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.937123060 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.937134981 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.937185049 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.937185049 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.940254927 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.940265894 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.940275908 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.940310001 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.940325022 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.945204020 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.945216894 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.945226908 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.945301056 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.946089029 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.946134090 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.946162939 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.946173906 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.946212053 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.947516918 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.947549105 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.947559118 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.947590113 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.951067924 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.951128006 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.951222897 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.951234102 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.951267958 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.954500914 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.954608917 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.954619884 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.954655886 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.955502987 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.955514908 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.955524921 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.955553055 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.955571890 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.958599091 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.958610058 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.958621979 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.958669901 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.959274054 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.959315062 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.959544897 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.959572077 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:26.959613085 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:26.959656954 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.007467985 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.178952932 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179002047 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179066896 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179078102 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.179097891 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179141998 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.179150105 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179186106 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179218054 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179227114 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.179251909 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179280996 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179307938 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.179332972 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179367065 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179378986 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.179419994 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179464102 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.179470062 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179502964 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179536104 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179544926 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.179590940 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179621935 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179634094 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.179653883 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179687023 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179693937 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.179721117 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179755926 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179763079 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.179789066 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179821014 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179831982 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.179852009 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179882050 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179889917 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.179914951 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179949045 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.179955959 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.179981947 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.180012941 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.180017948 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.180048943 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.180079937 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.180079937 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.180115938 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.180150032 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.180155039 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.180186987 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.180219889 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.180227995 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.180253983 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.180284977 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.180289984 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.180320024 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.180352926 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.180357933 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.180386066 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.180428982 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.180670977 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.180716038 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.180881023 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.180954933 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181001902 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.181004047 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181072950 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181092024 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181107044 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181118965 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181132078 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.181133032 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181148052 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181148052 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.181174040 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.181180954 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181195021 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181209087 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181220055 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.181222916 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181235075 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181247950 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181248903 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.181277990 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.181477070 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181510925 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181524038 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.181548119 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181591034 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.181591034 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181673050 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181705952 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181714058 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.181759119 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181792974 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181802988 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.181828976 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181971073 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.181981087 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.182005882 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.182040930 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.182045937 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.182243109 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.182286024 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.182295084 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.182348013 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.182383060 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.182391882 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.182415962 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.182454109 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.182466030 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.182499886 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.182534933 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.182540894 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.182568073 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.182601929 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.182607889 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.182636023 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.182672024 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.182676077 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.183079958 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.183306932 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.183341026 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.183351994 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.183413029 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.183444977 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.183454037 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.183480024 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.183511972 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.183523893 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.183564901 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.183598042 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.183602095 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.183634996 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.183669090 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.183675051 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.183703899 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.183739901 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.183748960 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.184201002 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.184246063 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.184253931 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.184288979 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.184322119 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.184329033 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.184356928 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.184391022 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.184415102 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.184425116 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.184461117 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.184464931 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.186274052 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.186326027 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.186333895 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.186362982 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.186408043 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.186415911 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.186459064 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.186508894 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.186510086 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.186544895 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.186578035 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.186587095 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.186611891 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.186651945 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.186657906 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.186666965 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.186676979 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.186702013 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.186711073 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.186753988 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.186763048 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.187149048 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.187186956 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.187294960 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.187306881 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.187319040 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.187330961 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.187340975 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.187344074 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.187352896 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.187362909 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.187400103 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.187483072 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.187494993 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.187505960 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.187516928 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.187529087 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.187545061 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.187570095 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.188013077 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.188208103 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.188218117 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.188230991 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.188244104 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.188246012 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.188277960 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.188277960 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.188291073 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.188303947 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.188313961 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.188314915 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.188328028 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.188342094 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.188345909 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.188359976 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.188369036 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.188371897 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.188406944 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.188985109 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.189027071 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.189101934 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.189237118 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.189249992 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.189261913 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.189274073 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.189279079 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.189292908 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.189296961 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.189307928 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.189320087 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.189330101 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.189337969 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.189349890 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.189357042 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.189362049 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.189373970 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.189383984 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.189384937 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.189408064 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.190105915 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.190145969 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.190336943 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.190347910 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.190360069 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.190371037 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.190382004 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.190385103 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.190399885 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.190402031 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.190414906 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.190433025 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.190444946 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.190449953 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.190457106 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.190469027 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.190469980 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.190481901 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.190495014 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.190495968 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.190520048 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.191234112 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.191246033 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.191257954 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.191277981 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.191283941 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.191296101 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.191296101 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.191307068 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.191319942 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.191329956 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.191334963 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.191345930 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.191354990 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.191356897 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.191370010 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.191380024 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.191387892 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.191409111 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.192169905 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.192188025 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.192198992 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.192224026 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.192229986 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.192240953 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.192241907 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.192255020 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.192265987 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.192286968 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.192311049 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.192328930 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.192341089 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.192352057 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.192363024 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.192374945 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.192382097 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.192404985 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.193156958 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.193167925 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.193178892 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.193196058 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.193217039 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.193283081 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.193294048 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.193305016 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.193315983 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.193326950 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.193336964 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.193341970 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.193348885 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.193365097 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.193381071 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.193443060 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.193454027 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.193476915 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.194057941 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.194097996 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.194158077 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.194205046 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.194237947 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.194288969 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.194300890 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.194333076 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.194407940 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.194418907 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.194430113 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.194439888 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.194456100 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.194475889 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.194565058 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.194576979 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.194586992 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.194592953 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.194603920 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.194622040 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.194645882 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.195183992 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.195220947 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.195292950 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.195307016 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.195317984 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.195328951 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.195339918 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.195350885 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.195350885 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.195377111 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.195410013 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.195415020 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.195425987 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.195437908 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.195444107 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.195453882 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.195466995 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.195492983 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.196141958 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196152925 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196165085 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196182013 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.196201086 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196203947 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.196213961 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196228027 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196237087 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.196238995 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196266890 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.196285963 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196296930 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196341038 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.196358919 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.196373940 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196387053 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196398020 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196408987 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196422100 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196432114 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.196433067 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196444988 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.196469069 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.196528912 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196541071 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196552038 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196561098 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.196567059 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196584940 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.196595907 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196614981 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196631908 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196633101 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.196651936 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196666956 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.196671963 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196690083 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196706057 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.196711063 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196729898 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196744919 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.196748972 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.196784973 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.197068930 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197159052 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197176933 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197195053 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197199106 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.197223902 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197232008 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.197243929 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197263002 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197278976 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.197283030 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197302103 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197319031 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.197331905 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197351933 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197367907 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.197371006 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197391033 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197407007 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.197410107 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197431087 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197448015 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.197448969 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197479010 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197482109 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.197498083 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197519064 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197529078 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.197539091 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197557926 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197575092 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.197577000 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197597027 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197609901 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.197614908 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197633028 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197649956 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.197652102 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197671890 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197685957 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.197690964 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197710037 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197724104 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.197730064 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.197765112 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.198043108 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.198061943 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.198080063 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.198096991 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.198097944 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.198118925 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.198151112 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.198203087 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.198223114 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.198241949 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.198244095 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.198261023 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.198273897 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.198287010 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.198313951 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.198323965 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.198334932 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.198354006 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.198369026 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.198373079 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.198391914 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.198409081 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.198410988 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.198431969 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.198446989 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.198463917 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.198483944 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.198498964 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.198503971 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.198523998 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.198539019 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.201209068 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.201247931 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.201262951 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.201281071 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.201318026 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.201335907 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.201351881 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.201364040 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.201374054 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.201381922 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.201386929 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.201409101 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.219688892 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.219702005 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.219712019 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.219723940 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.219736099 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.219747066 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.219748020 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.219762087 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.219774008 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.219779015 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.219793081 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.220930099 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.220984936 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.220990896 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.221023083 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.221064091 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.221072912 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.221107960 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.221142054 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.221149921 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.221178055 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.221213102 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.221216917 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.229581118 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.229610920 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.229645967 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.229662895 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.229700089 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.229707956 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.229734898 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.229768991 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.229778051 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.229804993 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.229837894 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.229846954 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.234276056 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.234306097 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.234328985 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.234360933 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.234394073 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.234405041 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.234427929 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.234462023 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.234468937 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.234496117 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.234529972 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.234538078 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.240967989 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.241020918 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.241030931 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.241055965 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.241101980 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.241107941 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.241142035 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.241174936 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.241179943 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.241209984 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.241251945 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.251158953 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.251353979 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.251409054 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.251413107 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.251488924 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.251535892 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.251538992 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.251595974 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.251636028 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.251640081 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.251682043 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.251713991 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.251724005 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.251764059 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.251805067 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.251816034 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.251852989 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.251888990 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.251892090 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.251923084 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.251974106 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.251981020 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.252008915 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.252043962 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.252052069 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.254215956 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.254272938 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.254323959 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.254359007 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.254403114 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.254481077 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.254511118 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.254543066 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.254549980 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.254595995 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.254626036 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.254637003 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.254738092 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.254767895 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.254779100 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.254971027 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.255012989 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.259689093 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.259721041 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.259769917 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.259772062 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.259805918 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.259840012 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.259857893 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.259875059 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.259907961 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.259917974 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.259943008 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.259984016 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.267147064 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.267241001 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.267277002 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.267303944 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.267313957 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.267349005 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.267362118 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.267411947 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.267456055 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.267457962 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.267496109 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.267538071 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.270529032 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.270565987 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.270602942 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.270620108 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.270657063 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.270692110 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.270701885 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.270729065 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.270765066 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.270771980 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.274858952 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.274893999 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.274919987 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.274930000 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.274966002 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.275002003 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.275007010 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.275036097 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.275041103 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.275072098 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.275115967 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.276922941 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.276974916 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.277009964 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.277025938 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.277045012 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.277079105 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.277086020 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.277112961 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.277148962 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.277153015 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.283073902 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.283128977 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.283130884 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.283164978 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.283205986 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.283272028 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.283282042 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.283318043 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.283344030 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.283353090 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.283405066 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.289012909 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.289047003 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.289082050 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.289102077 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.289156914 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.289191961 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.289206982 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.289227962 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.289262056 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.289273024 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.292025089 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.292068958 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.292079926 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.292134047 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.292167902 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.292176008 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.292205095 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.292239904 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.292254925 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.292265892 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.292275906 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.292310953 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.292349100 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.292360067 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.322144032 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.322171926 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.322184086 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.322195053 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.322206020 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.322217941 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.322215080 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.322254896 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.322258949 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.322259903 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.322290897 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.322324991 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.322334051 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.322359085 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.322398901 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.322408915 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.322443008 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.322479010 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.322483063 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.322511911 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.322555065 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.322633028 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.322668076 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.322700977 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.322707891 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.322737932 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.322772980 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.322782993 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.322807074 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.322844028 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.322868109 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.325638056 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.325670958 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.325690985 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.325727940 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.325761080 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.325773001 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.325798035 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.325831890 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.325839996 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.325867891 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.325907946 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.332391977 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.332426071 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.332461119 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.332479954 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.332494020 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.332529068 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.332535982 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.332562923 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.332596064 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.332606077 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.343827963 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.343871117 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.343878031 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.343888998 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.343905926 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.343924046 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.343930006 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.343940020 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.343956947 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.343959093 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.343971014 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.343981981 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.343993902 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.343998909 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.344008923 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.344021082 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.344022036 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.344034910 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.344048977 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.344053030 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.344068050 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.345815897 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.345865965 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.345869064 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.345906019 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.345937967 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.345947981 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.345993042 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.346028090 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.346038103 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.346065998 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.346103907 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.350411892 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.350466967 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.350506067 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.350513935 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.350574017 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.350609064 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.350615978 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.350658894 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.350693941 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.350704908 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.365103960 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.365173101 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.365183115 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.365221977 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.365257025 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.365269899 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.365293026 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.365329027 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.365334988 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.365364075 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.365396976 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.365402937 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.365432978 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.365473032 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.365488052 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.365523100 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.365557909 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.365561962 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.365609884 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.365643024 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.365648985 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.365721941 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.365756989 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.365761995 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.365797043 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.365834951 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.365834951 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.365871906 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.365906000 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.365912914 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.365942955 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.365977049 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.368251085 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.368287086 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.368323088 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.368344069 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.368432999 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.368467093 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.368483067 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.368501902 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.368537903 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.368544102 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.376549959 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.376600981 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.376604080 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.376672029 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.376708031 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.376717091 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.376745939 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.376780987 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.376806974 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.376815081 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.376857042 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.380688906 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.380749941 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.380796909 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.380800962 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.380836964 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.380880117 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.380887985 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.380923986 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.380960941 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.380966902 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.384844065 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.384891987 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.384901047 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.384936094 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.384975910 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.384989023 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.385024071 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.385059118 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.385085106 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.385093927 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.385135889 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.401299000 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.401369095 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.401382923 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.401400089 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.401426077 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.401439905 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.401453972 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.401463032 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.401463032 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.401504993 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.402579069 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.402591944 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.402602911 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.402621031 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.402647018 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.402673960 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.402687073 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.402699947 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.402713060 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.402724028 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.402724028 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.402744055 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.406533003 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.406610966 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.410830975 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.410886049 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.410902023 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.410912991 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.410924911 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.410938025 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.410950899 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.410954952 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.410964966 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.410990953 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.410996914 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.411019087 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.415626049 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.415640116 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.415651083 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.415673018 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.415694952 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.415712118 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.415725946 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.415736914 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.415751934 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.415761948 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.415787935 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.422751904 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.422775030 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.422785044 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.422817945 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.422862053 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.422873020 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.422884941 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.422897100 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.422900915 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.422909975 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.422916889 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.422955036 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.433111906 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.433163881 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.433198929 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.433218956 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.433233976 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.433280945 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.433289051 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.433322906 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.433357000 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.433366060 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.433389902 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.433423996 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.433429003 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.433458090 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.433492899 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.433504105 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.433526993 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.433561087 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.433568001 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.433595896 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.433640957 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.436717987 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.436773062 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.436806917 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.436820030 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.436861038 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.436894894 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.436904907 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.436928988 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.436963081 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.436970949 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.440906048 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.440957069 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.440958977 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.440994978 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.441029072 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.441039085 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.441065073 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.441099882 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.441102982 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.441287041 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.441329002 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.452816963 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.452852964 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.452884912 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.452910900 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.452919960 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.452955008 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.452965975 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.453008890 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.453042984 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.453052044 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.453078985 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.453119040 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.454971075 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.455005884 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.455039978 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.455051899 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.455092907 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.455127001 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.455133915 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.455163002 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.455194950 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.455199003 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.455229998 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.455271006 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.460189104 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.460220098 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.460297108 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.461262941 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.461299896 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.461333990 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.461353064 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.461366892 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.461402893 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.461409092 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.461438894 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.461481094 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.463027000 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.463066101 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.463099003 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.463114977 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.463151932 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.463184118 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.463193893 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.463219881 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.463253021 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.463259935 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.463289022 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.463326931 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.477878094 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.477894068 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.477905989 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.477945089 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.477957010 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.477967978 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.477967024 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.477979898 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.477993011 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.478007078 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.478034019 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.481014967 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.481041908 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.481049061 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.481054068 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.481066942 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.481106997 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.481121063 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.481161118 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.481389046 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.481878042 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.481898069 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.481911898 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.481920004 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.481957912 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.482012033 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.482023954 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.482034922 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.482047081 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.482053995 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.482079983 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.503246069 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.503345966 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.503360033 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.503397942 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.503434896 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.503447056 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.503482103 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.503557920 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.503568888 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.503595114 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.503596067 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.503607988 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.503635883 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.507066965 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.507124901 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.507127047 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.507142067 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.507175922 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.507308960 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.507323027 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.507337093 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.507348061 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.507360935 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.507392883 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.516386032 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.516463041 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.516474962 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.516510963 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.516562939 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.516575098 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.516587973 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.516601086 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.516606092 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.516619921 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.516633034 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.516652107 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.525043011 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.525167942 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.525182962 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.525213003 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.525326967 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.525342941 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.525352955 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.525363922 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.525367022 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.525373936 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.525387049 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.525403023 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.528518915 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.528553963 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.528589010 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.528597116 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.528691053 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.528724909 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.528733969 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.528759956 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.528795004 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.528805017 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.533802032 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.533835888 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.533854008 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.533924103 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.533965111 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.533974886 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.534009933 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.534045935 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.534054041 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.534079075 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.534117937 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.534118891 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.534156084 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.534188032 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.534194946 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.534221888 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.534255981 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.534262896 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.534290075 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.534324884 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.534331083 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.535067081 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.535100937 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.535103083 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.535155058 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.535187006 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.535187960 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.535223961 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.535257101 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.535264015 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.535294056 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.535321951 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.535334110 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.536519051 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.536560059 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.536628962 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.536664009 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.536699057 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.536761045 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.536794901 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.536829948 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.536838055 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.536864042 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.536905050 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.543685913 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.543740034 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.543772936 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.543787003 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.543875933 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.543885946 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.543899059 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.543914080 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.543939114 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.543946981 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.545691013 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.545722008 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.545739889 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.545754910 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.545789003 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.545799017 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.545820951 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.545855045 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.545866013 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.545891047 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.545923948 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.545928955 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.550838947 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.550868988 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.550887108 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.550920963 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.550956964 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.550971031 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.551004887 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.551045895 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.551054955 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.551089048 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.551120996 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.551124096 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.553662062 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.553710938 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.553745985 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.553776026 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.553808928 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.553821087 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.553843021 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.553874969 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.553884983 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.553910017 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.553942919 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.553951025 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.567775011 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.567819118 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.568563938 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.568617105 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.568773985 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.568804979 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.568849087 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.568856001 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.568888903 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.568921089 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.568926096 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.568957090 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.568989992 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.568993092 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.572282076 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.572330952 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.572349072 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.572385073 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.572417021 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.572423935 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.572449923 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.572482109 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.572489023 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.572516918 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.572552919 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.572797060 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.572849035 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.572884083 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.572887897 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.572916031 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.572949886 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.572957039 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.572983980 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.573019028 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.573045969 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.597150087 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.597207069 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.597229958 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.597239971 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.597275972 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.597285986 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.597310066 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.597349882 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.597352982 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.597362041 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.597404957 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.598490953 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.598587990 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.598620892 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.598630905 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.598695040 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.598730087 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.598756075 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.598764896 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.598800898 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.598803997 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.607208014 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.607249975 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.607265949 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.607278109 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.607316017 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.607316971 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.607327938 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.607336998 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.607347965 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.607364893 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.607394934 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.615823030 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.615833998 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.615844965 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.615875006 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.615952015 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.615962982 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.615978003 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.615988016 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.615989923 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.616012096 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.619259119 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.619270086 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.619280100 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.619301081 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.619328022 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.619436979 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.619447947 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.619458914 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.619468927 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.619488955 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.619507074 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.624269962 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.624279976 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.624321938 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.624407053 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.624460936 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.624471903 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.624499083 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.624521017 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.624557972 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.624591112 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.624602079 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.624613047 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.624636889 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.624855042 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.624893904 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.624962091 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.624973059 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.624983072 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.625009060 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.625298977 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.625339985 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.625344992 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.625500917 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.625539064 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.625554085 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.625659943 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.625696898 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.625888109 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.626597881 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.626642942 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.626645088 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.626710892 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.626754045 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.626787901 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.626837969 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.626872063 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.626880884 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.626904964 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.626940966 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.626966953 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.629848003 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.629898071 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.629901886 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.629936934 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.629970074 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.629976034 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.630021095 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.630054951 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.630059958 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.630091906 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.630136967 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.634339094 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.634372950 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.634413004 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.634427071 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.634480953 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.634516001 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.634546995 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.634551048 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.634596109 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.634603977 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.636365891 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.636399031 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.636413097 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.636434078 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.636473894 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.636486053 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.636519909 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.636553049 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.636559010 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.636601925 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.636642933 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.641468048 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.641541004 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.641592026 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.641611099 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.641644955 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.641675949 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.641685963 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.641711950 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.641746044 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.641756058 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.641779900 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.641824007 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.644324064 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.644359112 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.644395113 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.644402981 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.644428968 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.644464016 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.644470930 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.644500017 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.644537926 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.644583941 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.659187078 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.659236908 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.659327984 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.659360886 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.659409046 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.659420967 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.659455061 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.659490108 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.659492970 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.659523010 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.659555912 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.659563065 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.662870884 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.662919998 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.662924051 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.662961006 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.662992954 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.663002968 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.663028955 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.663069010 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.663079023 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.663115025 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.663145065 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.663153887 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.663213968 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.663249016 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.663255930 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.663283110 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.663316011 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.663321972 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.663350105 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.663398027 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.663402081 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.663436890 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.663470984 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.663476944 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.668977976 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.675554991 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.687736034 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.687788963 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.687788010 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.687824965 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.687858105 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.687865973 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.687892914 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.687925100 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.687933922 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.687963963 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.688004971 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.689563990 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.689615011 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.689650059 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.689662933 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.689683914 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.689719915 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.689726114 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.689752102 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.689785957 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.689791918 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.697813988 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.697844028 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.697863102 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.697896957 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.697930098 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.697937965 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.697966099 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.698000908 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.698008060 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.698035002 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.698071003 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.698075056 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.706383944 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.706396103 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.706408978 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.706428051 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.706438065 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.706450939 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.706454039 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.706464052 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.706475973 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.706501961 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.706523895 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.709856033 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.709867954 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.709883928 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.709896088 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.709906101 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.709912062 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.709920883 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.709929943 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.709934950 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.709948063 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.709955931 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.709963083 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.709995985 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.715167046 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.715177059 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.715194941 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.715207100 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.715209007 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.715218067 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.715235949 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.715240002 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.715254068 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.715259075 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.715265036 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.715276957 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.715286970 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.715323925 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.716186047 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.716203928 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.716213942 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.716242075 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.716268063 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.716289043 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.716301918 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.716312885 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.716315031 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.716325998 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.716341019 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.716367006 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.717168093 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.717230082 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.717276096 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.717309952 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.717320919 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.717333078 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.717344046 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.717355967 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.717355967 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.717366934 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.717387915 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.717406988 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.720587015 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.720597982 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.720622063 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.720623970 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.720633984 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.720638037 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.720642090 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.720654011 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.720662117 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.720668077 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.720696926 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.720716953 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.724796057 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.724813938 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.724819899 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.724855900 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.724858999 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.724870920 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.724896908 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.724904060 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.724915028 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.724925041 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.724944115 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.724961042 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.726818085 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.726830006 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.726843119 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.726852894 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.726875067 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.726876974 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.726885080 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.726895094 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.726896048 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.726908922 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.726921082 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.726927996 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.726963043 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.732155085 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.732202053 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.732209921 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.732261896 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.732295036 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.732304096 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.732328892 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.732362032 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.732368946 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.732397079 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.732429981 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.732433081 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.735266924 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.735313892 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.735317945 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.735353947 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.735402107 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.735404015 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.735439062 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.735471010 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.735477924 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.735503912 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.735537052 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.735546112 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.739392042 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.739425898 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.763441086 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.763506889 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.763514042 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.763551950 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.763585091 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.763597965 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.763621092 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.763653994 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.763667107 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.763689995 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.763726950 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.763736010 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.764494896 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.764525890 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.764545918 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.764561892 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.764609098 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.764628887 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.764672995 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.764714003 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.764729977 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.764781952 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.764810085 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.764822960 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.764843941 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.764879942 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.764882088 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.764914036 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.764946938 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.764977932 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.764993906 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.765026093 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.765032053 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.765060902 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.765088081 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.765103102 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.765124083 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.765156984 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.765166998 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.765188932 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.765225887 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.765228033 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.778300047 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.778331995 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.778358936 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.778383970 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.778419018 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.778430939 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.778453112 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.778486013 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.778493881 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.778523922 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.778568983 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.778578997 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.779416084 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.779438019 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.779921055 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.779969931 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.779978991 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.780015945 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.780050039 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.780061007 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.780086040 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.780118942 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.780128956 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.780154943 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.780205011 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.788455963 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.788525105 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.788558960 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.788590908 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.788625002 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.788656950 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.788666964 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.788667917 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.788691998 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.788714886 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.788731098 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.788777113 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.796540022 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.796590090 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.797070026 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.797105074 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.797158003 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.797229052 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.797262907 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.797296047 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.797311068 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.797331095 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.797364950 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.797377110 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.797399998 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.797446966 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.800527096 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.800576925 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.800611019 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.800628901 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.800646067 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.800679922 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.800689936 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.800714970 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.800760031 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.800764084 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.805247068 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.805294991 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.805759907 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.805780888 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.805792093 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.805850983 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.805850983 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.805855989 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.805869102 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.805881023 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.805895090 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.805921078 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.805952072 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.806817055 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.806916952 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.806926966 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.806935072 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.806941032 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.806947947 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.806955099 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.806962013 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.806969881 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.807002068 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.807940960 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.807951927 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.807971001 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.807981014 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.807991982 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.808001041 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.808012962 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.808020115 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.808031082 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.808041096 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.808058023 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.808082104 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.811249971 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.811280012 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.811335087 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.811389923 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.811402082 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.811414003 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.811424971 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.811435938 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.811440945 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.811446905 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.811460972 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.811480999 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.815582037 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.815598965 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.815612078 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.815623045 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.815635920 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.815648079 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.815651894 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.815660000 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.815681934 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.815694094 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.815764904 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.817522049 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.817559004 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.817573071 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.817600965 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.817636967 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.817648888 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.817661047 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.817672014 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.817682981 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.817718983 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.820265055 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.820301056 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.822815895 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.822837114 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.822846889 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.822860956 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.822886944 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.822905064 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.822922945 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.822936058 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.822946072 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.822957039 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.822972059 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.822985888 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.825907946 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.825921059 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.825938940 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.825949907 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.825958967 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.825961113 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.825973988 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.825978994 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.825988054 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.825999022 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.826000929 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.826035976 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.850738049 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.850774050 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.853924036 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.853965998 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.853975058 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.854011059 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.854043961 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.854055882 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.854079008 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.854110956 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.854140043 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.854161978 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.854195118 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.854201078 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.855334044 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.855380058 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.855402946 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.855458021 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.855498075 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.855505943 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.855540037 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.855576038 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.855587006 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.855619907 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.855652094 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.855660915 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.855684042 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.855717897 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.855720997 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.855771065 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.855803967 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.855812073 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.855839014 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.855870962 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.855880022 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.855906010 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.855946064 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.859396935 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.859425068 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.869205952 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.869266033 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.869317055 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.869327068 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.869410992 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.869458914 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.869469881 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.869496107 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.869532108 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.869537115 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.870446920 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.870479107 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.870487928 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.870515108 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.870551109 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.870768070 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.870817900 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.870852947 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.870858908 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.870887041 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.870927095 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.876699924 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.876729965 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.879148006 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.879201889 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.879239082 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.879241943 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.879291058 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.879323006 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.879331112 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.879375935 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.879422903 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.879436016 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.883627892 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.883655071 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.887696981 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.887733936 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.887761116 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.887767076 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.887814999 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.887819052 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.887952089 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.887984991 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.887990952 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.888020039 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.888052940 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.888062954 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.891185999 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.891242981 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.891253948 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.891311884 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.891361952 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.891366959 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.891415119 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.891448021 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.891462088 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.891503096 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.891541004 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.896446943 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.896480083 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.896512985 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.896536112 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.896547079 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.896583080 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.896595955 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.896617889 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.896651983 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.896662951 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.896686077 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.896732092 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.897669077 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.897723913 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.897737980 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.897770882 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.897772074 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.897808075 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.897814035 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.897840977 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.897954941 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.897963047 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.898271084 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.898296118 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.898541927 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.898593903 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.898627043 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.898638964 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.898659945 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.898672104 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.898695946 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.898730993 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.898736954 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.898766994 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.898801088 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.898839951 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.901958942 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.902030945 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.902065992 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.902081966 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.902098894 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.902133942 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.902141094 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.902168036 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.902175903 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.902201891 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.902245045 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.905744076 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.905771971 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.906210899 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.906222105 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.906233072 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.906264067 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.906374931 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.906387091 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.906398058 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.906408072 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.906425953 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.906451941 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.907964945 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.907968044 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.908000946 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.908013105 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.908013105 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.908032894 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.908041954 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.908046961 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.908058882 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.908070087 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.908070087 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.908128977 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.913856983 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.914246082 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.914258003 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.914268970 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.914279938 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.914292097 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.914294004 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.914303064 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.914315939 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.914319992 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.914340973 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.914357901 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.916480064 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.916598082 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.916608095 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.916632891 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.916663885 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.916676044 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.916686058 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.916697025 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.916699886 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.916723013 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.921717882 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.921749115 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.953011990 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953042030 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953077078 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.953094959 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953145027 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.953164101 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953221083 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953273058 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953305006 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953320026 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.953340054 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953345060 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.953393936 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953433990 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.953444958 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953480959 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953515053 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953547001 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953557014 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.953581095 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953613997 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953624010 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.953651905 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953654051 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.953681946 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953716040 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953717947 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.953751087 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953783035 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953814983 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953823090 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.953850031 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953886032 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953896999 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.953916073 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.953927994 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.959795952 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.959846020 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.959851027 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.959881067 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.959913969 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.959928036 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.959949017 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.959983110 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.959995985 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.960017920 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.960051060 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.960067034 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.961018085 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.961061001 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.961071968 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.961112976 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.961146116 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.961152077 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.961179972 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.961225986 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.961234093 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.961261034 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.961294889 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.961307049 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.971024990 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.971080065 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.971085072 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.971116066 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.971165895 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.971168041 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.971201897 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.971237898 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.971249104 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.971251965 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.971296072 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.978210926 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.978245020 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.978276968 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.978308916 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.978357077 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.978452921 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.978486061 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.978502989 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.978522062 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.978526115 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.978555918 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.978604078 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.982343912 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.982395887 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.982431889 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.982451916 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.982465029 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.982500076 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.982508898 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.982532978 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.982568979 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.982583046 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.987308979 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.987359047 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.987413883 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.987422943 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.987456083 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.987488985 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.987507105 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.987524033 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.987529039 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.987560034 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.987602949 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.988296032 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.988348007 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.988379955 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.988405943 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.988547087 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.988580942 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.988616943 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.988632917 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.988650084 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.988658905 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.988682985 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.988733053 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.989007950 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.989078999 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.989228964 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.989283085 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.989284039 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.989332914 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.989368916 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.989382982 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.989403963 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.989439011 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.989444017 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.989468098 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.989514112 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.992484093 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.992533922 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.992585897 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.992607117 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.992619991 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.992662907 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.992671967 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.992705107 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.992742062 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.992754936 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.992774963 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.992821932 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.996799946 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.996859074 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.996876955 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.996927977 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.996962070 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.996977091 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.996995926 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.997030020 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.997062922 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.997088909 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.997539043 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.998682022 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.998738050 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.998771906 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.998796940 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.998805046 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.998840094 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.998852968 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.998872995 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.998908997 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.998946905 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:27.998969078 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:27.998997927 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.004075050 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.004143000 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.004174948 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.004225969 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.004235983 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.004261017 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.004282951 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.004293919 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.004309893 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.004324913 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.004347086 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.004369974 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.015084028 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.015320063 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.015330076 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.015340090 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.015345097 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.015356064 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.015366077 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.015446901 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.015448093 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.043886900 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.043963909 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.043973923 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.044030905 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.044064999 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.044085026 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.044125080 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.044158936 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.044171095 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.044214010 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.044265032 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.044266939 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.044301033 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.044337034 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.044372082 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.044384003 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.044405937 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.044410944 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.044442892 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.044476986 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.044483900 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.044496059 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.044528008 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.044534922 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.044586897 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.044620991 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.044648886 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.044656038 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.044699907 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.044708967 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.044749022 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.044790030 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.050380945 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.050434113 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.050487041 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.050487995 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.050522089 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.050560951 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.050563097 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.050574064 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.050611019 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.050623894 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.050642014 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.050697088 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.051690102 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.051743984 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.051779985 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.051814079 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.051831007 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.051848888 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.051856041 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.051883936 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.051918983 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.051948071 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.051959991 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.052870989 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.061681986 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.061738014 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.061791897 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.061798096 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.061889887 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.061923981 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.061959028 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.061969042 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.061994076 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.062028885 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.062043905 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.062076092 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.069125891 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.069158077 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.069214106 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.069250107 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.069263935 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.069284916 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.069319963 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.069328070 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.069359064 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.069364071 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.069400072 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.069442034 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.072837114 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.072871923 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.072922945 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.072925091 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.072961092 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.072995901 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.073004007 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.073031902 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.073067904 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.073111057 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.077909946 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.077939987 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.077974081 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.077994108 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.078028917 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.078062057 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.078072071 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.078097105 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.078097105 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.078145981 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.078181982 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.078195095 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.079153061 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.079186916 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.079209089 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.079240084 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.079273939 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.079308987 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.079314947 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.079343081 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.079361916 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.079420090 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.079437971 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.079782963 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.079835892 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.079869986 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.079886913 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.079922915 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.079957008 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.079966068 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.079992056 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.080028057 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.080035925 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.083203077 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.083255053 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.083261013 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.083290100 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.083323956 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.083340883 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.083374977 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.083422899 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.083457947 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.083462954 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.083493948 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.083507061 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.090714931 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.090765953 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.090836048 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.090871096 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.090924978 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.091006041 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.091110945 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.091145992 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.091159105 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.091186047 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.091213942 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.091232061 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.091926098 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.091958046 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.091980934 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.092010975 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.092058897 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.092077971 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.092112064 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.092147112 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.092155933 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.092181921 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.092220068 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.092231035 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.094754934 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.094808102 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.094809055 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.094842911 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.094877005 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.094890118 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.094913006 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.094948053 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.094975948 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.094983101 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.095016956 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.095030069 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.105876923 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.105907917 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.105942965 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.105964899 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.106003046 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.106014013 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.106036901 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.106040955 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.106044054 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.106059074 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.106084108 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.106122017 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.134514093 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.134535074 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.134547949 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.134558916 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.134571075 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.134586096 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.134598017 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.134601116 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.134613991 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.134623051 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.134629965 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.134644032 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.134650946 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.134656906 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.134670019 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.134674072 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.134682894 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.134690046 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.134697914 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.134716988 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.134733915 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.134741068 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.134808064 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.134884119 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.134927034 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.134943008 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.134978056 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.135087967 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.135118961 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.135155916 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.135163069 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.135191917 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.135236025 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.140947104 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.141107082 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.141140938 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.141175985 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.141200066 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.141220093 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.141227961 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.141267061 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.141300917 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.141345024 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.142597914 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.142648935 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.142649889 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.142700911 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.142719984 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.142736912 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.142765999 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.142772913 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.142787933 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.142808914 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.142843008 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.142910004 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.154544115 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.154601097 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.154616117 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.154637098 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.154689074 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.154725075 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.154733896 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.154761076 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.154808998 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.154818058 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.154850006 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.159821033 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.159874916 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.159909964 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.159960032 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.160027027 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.160062075 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.160096884 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.160108089 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.160132885 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.160142899 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.166220903 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.166276932 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.166277885 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.166310072 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.166361094 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.166366100 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.166399956 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.166435003 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.166450024 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.166469097 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.166501999 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.166515112 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.169873953 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.169907093 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.169964075 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.169974089 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.169998884 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.170007944 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.170056105 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.170089006 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.170097113 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.170125961 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.170167923 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.170502901 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.170557976 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.170593023 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.170639992 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.170726061 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.170743942 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.170762062 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.170797110 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.170815945 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.170825958 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.170896053 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.170914888 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.170948982 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.170964003 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.170968056 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.170986891 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.171005011 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.171008110 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.171032906 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.173858881 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.173877954 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.173912048 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.173935890 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.174017906 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.174037933 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.174072027 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.174082994 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.174092054 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.174105883 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.184228897 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.184284925 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.184350967 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.184386969 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.184406042 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.184422970 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.184425116 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.184442997 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.184457064 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.184465885 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.184493065 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.184504032 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.185597897 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.185642004 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.185693979 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.185702085 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.185714006 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.185733080 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.185751915 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.185760021 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.185765982 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.185774088 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.185827971 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.185873032 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.187783957 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.187844038 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.187844038 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.187884092 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.187902927 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.187922001 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.187925100 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.187957048 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.187989950 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.188009024 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.188055038 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.196609020 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.196629047 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.196685076 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.196690083 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.196703911 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.196738958 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.196748972 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.196758032 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.196777105 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.196806908 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.196821928 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.196846962 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.225047112 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225054979 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225061893 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225112915 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225121021 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225136042 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225142002 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225156069 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225162029 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225167990 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225233078 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.225269079 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225270033 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.225275993 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225287914 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225296974 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225302935 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225310087 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225322008 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.225338936 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.225353956 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.225599051 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225661993 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225667000 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225711107 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.225713015 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225720882 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225733995 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225740910 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225754023 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.225754976 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225763083 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225768089 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.225770950 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.225800991 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.231643915 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.231651068 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.231668949 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.231678963 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.231686115 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.231703043 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.231738091 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.231749058 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.231777906 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.231786013 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.233141899 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.233182907 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.233189106 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.233205080 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.233232021 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.233243942 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.233249903 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.233262062 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.233274937 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.233282089 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.233295918 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.233325958 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.248043060 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.248083115 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.248116970 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.248142958 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.248168945 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.248217106 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.248234987 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.248253107 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.248270988 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.248275042 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.248368025 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.250534058 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.250586987 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.250621080 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.250636101 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.250703096 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.250720978 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.250737906 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.250751972 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.250756025 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.250791073 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.257132053 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.257209063 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.257210016 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.257226944 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.257246017 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.257273912 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.257337093 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.257354021 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.257386923 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.257436037 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.257466078 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.260448933 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.260531902 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.260545969 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.260564089 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.260581970 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.260596037 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.260617018 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.260628939 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.260636091 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.260653019 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.260657072 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.260683060 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.260896921 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.261007071 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.261020899 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.261049986 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.261059046 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.261079073 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.261111021 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.261125088 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.261128902 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.261148930 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.261149883 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.261167049 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.261182070 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.261183023 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.261203051 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.261221886 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.261240005 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.261243105 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.261275053 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.261346102 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.261363029 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.261394978 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.261410952 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.261437893 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.264653921 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.264667988 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.264702082 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.264723063 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.264743090 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.264764071 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.264780998 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.264801979 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.264820099 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.264822960 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.264838934 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.264882088 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.275708914 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.275727034 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.275782108 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.275793076 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.275821924 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.275839090 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.275856972 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.275891066 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.275902987 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.277472019 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.277533054 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.277559042 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.277574062 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.277623892 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.277640104 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.277657032 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.277690887 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.277699947 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.277709007 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.277728081 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.277759075 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.278779030 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.278798103 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.278815031 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.278846979 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.278870106 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.278934002 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.278951883 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.278969049 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.278985977 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.278989077 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.279068947 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.287084103 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.287168026 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.287182093 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.287233114 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.287240982 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.287250042 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.287283897 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.287293911 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.287302017 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.287319899 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.287321091 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.287354946 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.315851927 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.315874100 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.315879107 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.315958977 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.315973997 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.315980911 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.315987110 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.315993071 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.316025972 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.316035986 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.316041946 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.316054106 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.316062927 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.316068888 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.316085100 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.316085100 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.316092014 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.316109896 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.316127062 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.316139936 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.316536903 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.316543102 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.316555023 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.316591978 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.316651106 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.316658020 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.316669941 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.316675901 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.316698074 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.316720963 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.322993994 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.322999954 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.323019981 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.323062897 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.323102951 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.323117018 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.323124886 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.323132038 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.323148966 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.323174000 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.324629068 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.324636936 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.324651957 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.324702978 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.324774027 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.324779987 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.324791908 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.324796915 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.324824095 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.324848890 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.341228962 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.341248035 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.341283083 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.341315985 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.341326952 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.341345072 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.341377020 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.341394901 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.341397047 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.341437101 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.342448950 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.342468023 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.342502117 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.342521906 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.342550993 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.342622042 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.342638969 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.342679024 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.342689037 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.342700005 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.342736006 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.347907066 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.347982883 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.347996950 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.348033905 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.348036051 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.348073959 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.348088026 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.348093033 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.348109961 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.348128080 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.348134995 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.348170996 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.351241112 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.351255894 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.351309061 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.351315022 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.351322889 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.351342916 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.351358891 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.351361990 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.351376057 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.351397991 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.351414919 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.351694107 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.351735115 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.351751089 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.351756096 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.351787090 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.351917982 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.351932049 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.351969957 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.352003098 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.352045059 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.352049112 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.352251053 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.352267981 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.352303028 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.352307081 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.352324963 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.352341890 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.352360964 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.352374077 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.352406025 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.352459908 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.352478027 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.352494955 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.352515936 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.352530003 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.358865976 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.358887911 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.358942032 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.358952999 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.358961105 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.358978987 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.358994961 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.358998060 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.359013081 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.359036922 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.366549015 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.366575956 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.366609097 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.366617918 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.366661072 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.366678953 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.366678953 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.366698027 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.366713047 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.366714001 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.366733074 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.366764069 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.368520975 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.368550062 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.368570089 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.368587017 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.368597984 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.368624926 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.368638992 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.368643045 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.368665934 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.368678093 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.368716002 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.369337082 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.369381905 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.369415998 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.369440079 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.369682074 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.369705915 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.369720936 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.369740963 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.369754076 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.369785070 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.377799034 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.377856016 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.377897024 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.377897024 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.377917051 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.377949953 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.377974987 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.377990961 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.377996922 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.378010035 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.378010988 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.378025055 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.378036976 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.378070116 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.411701918 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.411737919 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.411753893 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.411767006 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.411773920 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.411781073 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.411787033 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.411794901 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.411854029 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.411859989 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.411861897 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.411875963 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.411884069 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.411899090 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.411905050 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.411911964 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.411922932 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.411947966 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.411947966 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.412398100 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.412498951 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.412503958 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.412527084 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.412549973 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.412580967 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.412664890 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.412672043 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.412684917 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.412692070 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.412698984 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.412713051 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.412738085 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.427791119 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.427812099 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.427818060 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.427879095 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.427922964 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.427959919 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.427967072 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.427980900 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.427988052 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.428018093 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.428047895 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.428163052 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.428169966 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.428181887 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.428219080 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.428252935 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.428260088 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.428273916 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.428280115 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.428309917 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.428334951 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.438852072 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.438869953 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.438904047 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.438920975 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.438961029 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.438978910 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.438981056 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.439013958 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.439019918 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.439038992 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.439055920 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.439089060 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.439101934 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.439107895 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.439125061 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.439126015 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.439143896 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.439160109 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.439165115 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.439177036 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.439212084 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.439232111 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.439241886 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.439249992 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.439263105 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.439268112 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.439285994 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.439301968 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.439302921 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.439321995 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.439341068 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.439367056 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.442076921 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.442095041 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.442128897 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.442146063 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.442209005 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.442225933 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.442244053 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.442257881 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.442277908 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.442290068 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.442735910 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.442775011 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.442789078 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.442795038 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.442811966 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.442831039 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.442847013 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.442857981 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.442866087 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.442868948 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.442915916 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.442935944 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.442951918 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.442971945 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.442992926 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.442997932 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.443048954 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.443049908 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.443087101 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.443105936 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.443150043 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.449521065 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.449538946 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.449594021 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.449596882 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.449610949 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.449630022 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.449646950 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.449661970 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.449666977 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.449677944 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.449704885 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.452292919 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.452311039 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.457140923 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.457155943 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.457231998 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.457248926 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.457288027 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.457307100 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.457323074 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.457336903 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.457341909 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.457359076 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.457375050 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.457528114 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.458821058 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.458898067 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.458913088 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.458955050 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.458965063 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.458992958 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.459028006 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.459039927 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.459047079 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.459067106 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.459115028 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.460175037 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.460241079 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.460275888 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.460293055 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.460294962 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.460314035 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.460330963 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.460365057 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.460377932 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.460382938 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.460459948 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.468564034 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.468605042 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.468622923 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.468638897 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.468657017 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.468661070 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.468673944 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.468693018 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.468703985 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.468710899 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.468724012 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.468748093 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.474126101 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.474150896 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.502522945 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.502552986 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.502567053 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.502602100 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.502608061 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.502620935 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.502669096 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.502696991 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.502711058 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.502722025 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.502744913 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.502767086 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.502784014 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.502801895 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.502801895 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.502821922 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.502830982 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.502840996 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.502860069 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.502872944 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.502911091 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.503309011 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.503323078 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.503375053 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.503396034 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.503429890 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.503446102 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.503463030 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.503511906 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.503513098 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.503539085 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.503552914 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.503593922 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.505604029 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.505630970 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.518651009 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.518657923 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.518671036 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.518752098 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.518758059 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.518770933 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.518775940 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.518783092 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.518793106 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.518810987 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.518815994 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.518835068 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.518841028 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.518853903 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.518857002 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.518857956 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.518918991 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.524507046 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.524549961 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.529376030 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529382944 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529397011 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529449940 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.529458046 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529465914 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529476881 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529483080 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529500961 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529506922 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529512882 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529519081 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529520988 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.529553890 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.529582024 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529588938 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529593945 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529601097 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529642105 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.529661894 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529668093 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529679060 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529685020 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529690027 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529701948 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529706955 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.529715061 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.529735088 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.529762983 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.532640934 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.532656908 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.532663107 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.532708883 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.532748938 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.532754898 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.532768011 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.532773972 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.532778978 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.532799006 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.532815933 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.533298016 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.533303976 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.533314943 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.533375025 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.533386946 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.533394098 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.533405066 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.533411026 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.533416986 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.533447027 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.533526897 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.533569098 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.533608913 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.533648968 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.533673048 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.533679008 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.533684969 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.533709049 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.533715010 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.533745050 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.533761978 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.538337946 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.538362026 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.539995909 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.540071011 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.540086031 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.540119886 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.540138006 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.540143967 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.540154934 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.540182114 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.540196896 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.540208101 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.540215015 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.540261984 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.547805071 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.547869921 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.547907114 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.547946930 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.547965050 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.547974110 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.547982931 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.547997952 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.548001051 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.548018932 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.548024893 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.548059940 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.549604893 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.549623013 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.549658060 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.549676895 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.549679041 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.549696922 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.549715042 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.549736023 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.549745083 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.549772978 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.550805092 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.550873041 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.550888062 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.550905943 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.550921917 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.550939083 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.550939083 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.550957918 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.550967932 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.550995111 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.551009893 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.559179068 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.559243917 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.559334993 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.559350014 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.559400082 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.559418917 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.559425116 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.559442997 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.559461117 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.559478045 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.559478998 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.559503078 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.580079079 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.593144894 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.593211889 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.593220949 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.593280077 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.593317986 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.593329906 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.593337059 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.593355894 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.593393087 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.593394041 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.593415976 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.593432903 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.593446016 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.593451977 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.593466997 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.593468904 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.593483925 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.593502045 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.593513012 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.593518972 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.593538046 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.593538046 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.593602896 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.593898058 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.593913078 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.593964100 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.593981028 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.593981981 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.593998909 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.594032049 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.594053984 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.594053984 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.594074965 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.594080925 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.594089031 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.594144106 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.606148958 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.609380007 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.609400034 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.609436989 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:28.609538078 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.633290052 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.655925035 CEST497013736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:28.661194086 CEST373649701194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:37.609853029 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:37.614797115 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:37.614869118 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:37.614962101 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:37.620100021 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:38.415060997 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:38.415079117 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:38.415092945 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:38.415183067 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:38.423051119 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:38.427859068 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:38.642474890 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:38.642779112 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:38.647700071 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:38.869421959 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:38.872231007 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:38.879429102 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:38.879494905 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:38.884306908 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.250111103 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.252820015 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.257600069 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.257679939 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.262419939 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.626204014 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.626215935 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.626380920 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.820885897 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.820939064 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.821042061 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.821109056 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.829794884 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.830029964 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.830039978 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.830049038 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.830120087 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.830120087 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.830171108 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.830192089 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.830200911 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.830209970 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.830221891 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.830281973 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.830285072 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.830291986 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.830285072 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.830296040 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.830312014 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.830319881 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.830384016 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.830384016 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.835011959 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.835067034 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.835175991 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.835186958 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.835216999 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.835235119 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.835256100 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.835290909 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.835294008 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.835350990 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.835429907 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.835561991 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.840285063 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.840411901 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.840456009 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.840465069 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.840513945 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.840523005 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.840591908 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.840600967 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.840610027 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.840647936 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.840656996 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.840673923 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.840682983 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.840759993 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.840769053 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.840785980 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.840832949 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.860440969 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.860500097 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.860511065 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.860586882 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.860635996 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:39.865890980 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.865901947 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.865911007 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.865925074 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.866408110 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.866417885 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.866463900 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.866487026 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.866497040 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.866571903 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.866995096 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:39.867003918 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:40.301387072 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:40.351222038 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:40.645185947 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:40.645309925 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:40.645428896 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:40.645535946 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:40.650104046 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:40.650157928 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:40.650278091 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:40.650324106 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:40.650335073 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:40.650345087 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:40.650466919 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:40.650476933 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:40.650482893 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:40.650543928 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:40.650552988 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:40.650597095 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:40.650605917 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:40.650641918 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:40.655039072 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:40.978401899 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:41.023085117 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:41.551896095 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:41.551987886 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:41.552078962 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:41.552186966 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:41.552262068 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:41.552323103 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:41.630671024 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:41.630681992 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:41.630916119 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:41.631256104 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:41.631397009 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:41.631438017 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:41.631469965 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:41.631519079 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:41.631527901 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:41.631541014 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:41.631578922 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:41.631622076 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:41.631711006 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:41.631733894 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:41.631742001 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:41.631769896 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:41.631778955 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:41.631788015 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:41.631798029 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:41.850979090 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:41.898103952 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:42.835799932 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:42.840543032 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:42.840639114 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:42.848665953 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:43.213006973 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:43.213054895 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:43.213092089 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:43.213161945 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:43.213196993 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:43.213387966 CEST497063736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:43.220911980 CEST373649706194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:48.211024046 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:48.215958118 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:48.216093063 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:48.216156960 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:48.221234083 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:48.904556036 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:48.904591084 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:48.904850006 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:48.912951946 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:48.917706013 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:49.131944895 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:49.132245064 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:49.137129068 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:49.344996929 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:49.347806931 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:49.352720976 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:49.352797985 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:49.358134985 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:49.722347021 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:49.725127935 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:49.730602026 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:49.730693102 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:49.735842943 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.098115921 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.113125086 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.113192081 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.113238096 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.113260984 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.113262892 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.113313913 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.113362074 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.113428116 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.113470078 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.113564968 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.113574982 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.113625050 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.121746063 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.121777058 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.121788979 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.121824980 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.121871948 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.129595041 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.129610062 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.129621029 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.130191088 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.139170885 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.139190912 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.139202118 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.139234066 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.139252901 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.146691084 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.146739006 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.146807909 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.199951887 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.199980021 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.200042963 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.234133959 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.234181881 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.234201908 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.234213114 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.234253883 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.234253883 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.238569975 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.238601923 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.238614082 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.238642931 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.246743917 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.246804953 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.246817112 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.246819973 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.246925116 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.255558968 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.255575895 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.255589008 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.255651951 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.264029980 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.264049053 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.264060974 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.264110088 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.264156103 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.271934986 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.271953106 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.271964073 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.272021055 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.280339003 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.280371904 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.280383110 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.280409098 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.280478001 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.289604902 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.289629936 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.289674997 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.289745092 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.298634052 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.298681974 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.298691988 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.298712015 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.298743963 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.298816919 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:50.320789099 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:50.321090937 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.396007061 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.400907040 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.401005983 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.405766010 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.777798891 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.778040886 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.778053999 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.778065920 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.778148890 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.778150082 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.785739899 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.785752058 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.785763025 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.785824060 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.785962105 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.786031008 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.791229963 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.791241884 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.791251898 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.791307926 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.796859980 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.796873093 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.796883106 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.796968937 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.796968937 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.984344006 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984358072 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984369993 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984383106 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984401941 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984477043 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984488964 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984532118 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.984532118 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.984680891 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984692097 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984703064 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984751940 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.984751940 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.984783888 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984797001 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984807968 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984827042 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984838963 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984849930 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984853983 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.984868050 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984879971 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984889030 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984899998 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984900951 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.984900951 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.984913111 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984922886 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984935045 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984947920 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984958887 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.984977961 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.984977961 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.985018969 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.986766100 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.986779928 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.986866951 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.988028049 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.988099098 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.989577055 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.989588976 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.989602089 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.989614010 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.989666939 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.989666939 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.989749908 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.989789009 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.989801884 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.989860058 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.989872932 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.989911079 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.989911079 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.990648985 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.990659952 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.990673065 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.990711927 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.990724087 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.990726948 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.990776062 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.990776062 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.991512060 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.991523027 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.991534948 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.991545916 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.991559982 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.991578102 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.991612911 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.992362022 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.992379904 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.992393017 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.992403984 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.992415905 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.992434978 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.992434978 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.992470980 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.993191957 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.994797945 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.994810104 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.994834900 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.994882107 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.994882107 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.994986057 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.995049953 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.995165110 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.995342970 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.995418072 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.995486021 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.995685101 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.995790958 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.995913982 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.996017933 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.996046066 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.996057987 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.996104002 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.996527910 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.996556997 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.996579885 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.996978998 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.996990919 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.997003078 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.997039080 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.997138023 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.997430086 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.997489929 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.997656107 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.997656107 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.997731924 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.997803926 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.998083115 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.998095989 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.998173952 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.998367071 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.998532057 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.998662949 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.998711109 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.998748064 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.998821974 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.999751091 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.999763012 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.999775887 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.999809027 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.999820948 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.999829054 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.999835014 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:52.999871016 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:52.999871016 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.000490904 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.000502110 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.000513077 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.000547886 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.000559092 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.000569105 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.000586033 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.000593901 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.000595093 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.000598907 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.000612020 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.000631094 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.000639915 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.000673056 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.000711918 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.000813961 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.000849962 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.001002073 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.003863096 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.003928900 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.003940105 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.004072905 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.007911921 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.007925987 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.007936954 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.008001089 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.008001089 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.017263889 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.017344952 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.017362118 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.017374992 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.017385960 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.017405033 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.017429113 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.019579887 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.019592047 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.019602060 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.019665956 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.019666910 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.022942066 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.022952080 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.023039103 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.023041010 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.023049116 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.023178101 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.026849985 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.026859999 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.026874065 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.026927948 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.026976109 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.026977062 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.030771971 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.030798912 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.030808926 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.030821085 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.030893087 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.030893087 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.032454967 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.032480955 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.032517910 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.032527924 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.032547951 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.032593012 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.034157991 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.034169912 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.034183025 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.034281015 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.036166906 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.036186934 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.036197901 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.036253929 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.036253929 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.037861109 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.037911892 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.037921906 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.037933111 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.037965059 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.037996054 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.039830923 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.039843082 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.039854050 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.039901972 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.043107986 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.043178082 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.043188095 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.043234110 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.043234110 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.043780088 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.043790102 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.043816090 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.043874025 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.045685053 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.045722961 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.045733929 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.045757055 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.045808077 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.047739983 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.047753096 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.047763109 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.047852039 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.049694061 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.049711943 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.049721956 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.049761057 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.049797058 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.051451921 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.051481009 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.051584959 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.051597118 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.051611900 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.051644087 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.053343058 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.053353071 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.053364038 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.053420067 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.055457115 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.055515051 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.055522919 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.055526018 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.055537939 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.055569887 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.057216883 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.057291031 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.057301044 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.057311058 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.057333946 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.057333946 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.059178114 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.059199095 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.059210062 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.059252977 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.059252977 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.062423944 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.062482119 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.062494040 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.062542915 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.063532114 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.063549995 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.063611031 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.063652039 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.063668013 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.063745975 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.064884901 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.064897060 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.064908028 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.064958096 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.064958096 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.066788912 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.066801071 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.066812038 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.066845894 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.069037914 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.069092989 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.069204092 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.069215059 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.069294930 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.071821928 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.071890116 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.071901083 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.071912050 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.071963072 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.071963072 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.072694063 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.072803974 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.072839022 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.072863102 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.072875977 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.072982073 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.075115919 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.075135946 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.075148106 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.075216055 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.077409029 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.077420950 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.077430964 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.077480078 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.077480078 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.078387022 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.078430891 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.078442097 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.078551054 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.082581043 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.082653999 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.284050941 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.288997889 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.289060116 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.294069052 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.658864975 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.658958912 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.658974886 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.658986092 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.659008026 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.659060955 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.660561085 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.660578966 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.660590887 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.660602093 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.660654068 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.660674095 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.661490917 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.661503077 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.661513090 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.661580086 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.662514925 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.662564993 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.662580967 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.662591934 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.662697077 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.663568020 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.663621902 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.663631916 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.663642883 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.663681984 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.663732052 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.664560080 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.664581060 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.664591074 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.664601088 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.664625883 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.664671898 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.665669918 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.665673018 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.665678024 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.665724993 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.666595936 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.666618109 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.666627884 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.666646957 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.666681051 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.762804985 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.767663956 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:53.767721891 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:53.773205042 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:54.135236025 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:54.135507107 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:54.135507107 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:54.136024952 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:54.136094093 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:54.136358976 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:54.136437893 CEST497073736192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:54.140620947 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:54.140633106 CEST373649707194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:54.227015972 CEST49708443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:54.227054119 CEST44349708194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:54.227253914 CEST49708443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:54.227253914 CEST49708443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:54.227282047 CEST44349708194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:55.092993975 CEST44349708194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:55.093199968 CEST49708443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:55.097696066 CEST49708443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:55.097703934 CEST44349708194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:55.098084927 CEST44349708194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:55.099797964 CEST49708443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:55.147407055 CEST44349708194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:59.852535963 CEST44349708194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:59.852700949 CEST44349708194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:59.852817059 CEST49708443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:59.852852106 CEST49708443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:59.852871895 CEST44349708194.113.106.180192.168.2.10
                            Sep 15, 2024 15:02:59.852927923 CEST49708443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:02:59.852935076 CEST44349708194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:00.851676941 CEST49709443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:00.851722002 CEST44349709194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:00.851902962 CEST49709443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:00.851969004 CEST49709443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:00.851974964 CEST44349709194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:01.676474094 CEST44349709194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:01.676734924 CEST49709443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:01.712893963 CEST49709443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:01.712919950 CEST44349709194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:01.713862896 CEST44349709194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:01.714553118 CEST49709443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:01.759413004 CEST44349709194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:06.456831932 CEST44349709194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:06.456909895 CEST44349709194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:06.456980944 CEST49709443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:06.457175970 CEST49709443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:06.457194090 CEST44349709194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:06.457240105 CEST49709443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:06.457245111 CEST44349709194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:07.461769104 CEST49710443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:07.461838007 CEST44349710194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:07.461951971 CEST49710443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:07.462275028 CEST49710443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:07.462290049 CEST44349710194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:08.189023018 CEST44349710194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:08.189258099 CEST49710443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:08.193345070 CEST49710443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:08.193358898 CEST44349710194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:08.193643093 CEST44349710194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:08.194391012 CEST49710443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:08.239403963 CEST44349710194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:13.097177982 CEST44349710194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:13.097275972 CEST44349710194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:13.097419024 CEST49710443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:13.097687006 CEST49710443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:13.097708941 CEST44349710194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:14.086066008 CEST49712443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:14.086159945 CEST44349712194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:14.086291075 CEST49712443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:14.086352110 CEST49712443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:14.086369038 CEST44349712194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:14.914966106 CEST44349712194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:14.915064096 CEST49712443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:14.920995951 CEST49712443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:14.921005011 CEST44349712194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:14.921241045 CEST44349712194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:14.922149897 CEST49712443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:14.963397980 CEST44349712194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:19.693538904 CEST44349712194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:19.693695068 CEST44349712194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:19.693852901 CEST49712443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:19.693964958 CEST49712443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:19.694006920 CEST44349712194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:20.679893017 CEST49713443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:20.679929018 CEST44349713194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:20.680008888 CEST49713443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:20.680114985 CEST49713443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:20.680124998 CEST44349713194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:21.397773027 CEST44349713194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:21.397897005 CEST49713443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:21.402395010 CEST49713443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:21.402406931 CEST44349713194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:21.402673006 CEST44349713194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:21.403403997 CEST49713443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:21.447428942 CEST44349713194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:26.285810947 CEST44349713194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:26.285897970 CEST44349713194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:26.285945892 CEST49713443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:26.286014080 CEST49713443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:26.286036968 CEST44349713194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:27.273864031 CEST49714443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:27.273920059 CEST44349714194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:27.274045944 CEST49714443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:27.274118900 CEST49714443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:27.274131060 CEST44349714194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:28.135008097 CEST44349714194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:28.135101080 CEST49714443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:28.139404058 CEST49714443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:28.139413118 CEST44349714194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:28.140175104 CEST44349714194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:28.140897989 CEST49714443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:28.187397957 CEST44349714194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:32.901952982 CEST44349714194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:32.902040005 CEST44349714194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:32.902194023 CEST49714443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:32.902194023 CEST49714443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:32.910686016 CEST49714443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:32.910702944 CEST44349714194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:33.914660931 CEST49715443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:33.914719105 CEST44349715194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:33.914825916 CEST49715443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:33.914922953 CEST49715443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:33.914935112 CEST44349715194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:34.614497900 CEST44349715194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:34.614701986 CEST49715443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:34.627546072 CEST49715443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:34.627621889 CEST44349715194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:34.628423929 CEST44349715194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:34.629206896 CEST49715443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:34.671436071 CEST44349715194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:39.518693924 CEST44349715194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:39.518862963 CEST44349715194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:39.518933058 CEST49715443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:39.518974066 CEST49715443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:39.518995047 CEST44349715194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:40.508490086 CEST49716443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:40.508569956 CEST44349716194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:40.508672953 CEST49716443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:40.508749008 CEST49716443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:40.508771896 CEST44349716194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:41.357152939 CEST44349716194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:41.357261896 CEST49716443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:41.361504078 CEST49716443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:41.361517906 CEST44349716194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:41.362390995 CEST44349716194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:41.363122940 CEST49716443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:41.407402039 CEST44349716194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:46.124522924 CEST44349716194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:46.124685049 CEST44349716194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:46.124897957 CEST49716443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:46.124897957 CEST49716443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:46.124990940 CEST49716443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:46.125025988 CEST44349716194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:47.133379936 CEST49717443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:47.133430958 CEST44349717194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:47.133559942 CEST49717443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:47.133611917 CEST49717443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:47.133621931 CEST44349717194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:47.958138943 CEST44349717194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:47.958250046 CEST49717443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:47.962470055 CEST49717443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:47.962486029 CEST44349717194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:47.962807894 CEST44349717194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:47.963499069 CEST49717443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:48.011396885 CEST44349717194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:52.733151913 CEST44349717194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:52.733247995 CEST44349717194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:52.733383894 CEST49717443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:52.733383894 CEST49717443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:52.733491898 CEST49717443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:52.733513117 CEST44349717194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:53.727063894 CEST49718443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:53.727114916 CEST44349718194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:53.727202892 CEST49718443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:53.727268934 CEST49718443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:53.727278948 CEST44349718194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:54.443918943 CEST44349718194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:54.444072008 CEST49718443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:54.468029976 CEST49718443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:54.468063116 CEST44349718194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:54.468409061 CEST44349718194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:54.469126940 CEST49718443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:54.511404991 CEST44349718194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:59.347956896 CEST44349718194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:59.348050117 CEST44349718194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:59.348110914 CEST49718443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:59.348134041 CEST49718443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:59.348151922 CEST44349718194.113.106.180192.168.2.10
                            Sep 15, 2024 15:03:59.348172903 CEST49718443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:03:59.348179102 CEST44349718194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:00.372951984 CEST49719443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:00.373013973 CEST44349719194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:00.373100996 CEST49719443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:00.373148918 CEST49719443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:00.373157978 CEST44349719194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:01.066612005 CEST44349719194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:01.066833973 CEST49719443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:01.074573994 CEST49719443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:01.074588060 CEST44349719194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:01.074825048 CEST44349719194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:01.076432943 CEST49719443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:01.123399019 CEST44349719194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:05.973757982 CEST44349719194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:05.973849058 CEST44349719194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:05.973901033 CEST49719443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:05.990833044 CEST49719443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:05.990875959 CEST44349719194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:05.990895987 CEST49719443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:05.990904093 CEST44349719194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:06.992726088 CEST49720443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:06.992783070 CEST44349720194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:06.992908001 CEST49720443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:06.992975950 CEST49720443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:06.993001938 CEST44349720194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:07.818010092 CEST44349720194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:07.818099976 CEST49720443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:07.823620081 CEST49720443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:07.823658943 CEST44349720194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:07.824018002 CEST44349720194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:07.824771881 CEST49720443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:07.867396116 CEST44349720194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:12.598639965 CEST44349720194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:12.598727942 CEST44349720194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:12.598786116 CEST49720443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:12.598891020 CEST49720443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:12.598915100 CEST44349720194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:13.586472034 CEST49721443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:13.586519003 CEST44349721194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:13.586577892 CEST49721443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:13.586636066 CEST49721443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:13.586642027 CEST44349721194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:14.618195057 CEST44349721194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:14.618320942 CEST49721443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:14.623734951 CEST49721443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:14.623754025 CEST44349721194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:14.624097109 CEST44349721194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:14.630269051 CEST49721443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:14.675401926 CEST44349721194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:19.189392090 CEST44349721194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:19.189572096 CEST44349721194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:19.189640999 CEST49721443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:19.189735889 CEST49721443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:19.189757109 CEST44349721194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:20.195909977 CEST49722443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:20.195964098 CEST44349722194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:20.196073055 CEST49722443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:20.196161032 CEST49722443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:20.196170092 CEST44349722194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:20.894500017 CEST44349722194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:20.894634962 CEST49722443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:20.901726007 CEST49722443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:20.901753902 CEST44349722194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:20.902075052 CEST44349722194.113.106.180192.168.2.10
                            Sep 15, 2024 15:04:20.924421072 CEST49722443192.168.2.10194.113.106.180
                            Sep 15, 2024 15:04:20.967406988 CEST44349722194.113.106.180192.168.2.10
                            TimestampSource PortDest PortSource IPDest IP
                            Sep 15, 2024 15:02:18.281922102 CEST5397253192.168.2.101.1.1.1
                            Sep 15, 2024 15:02:18.305391073 CEST53539721.1.1.1192.168.2.10
                            Sep 15, 2024 15:02:24.919368029 CEST6191153192.168.2.101.1.1.1
                            Sep 15, 2024 15:02:24.945310116 CEST53619111.1.1.1192.168.2.10
                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                            Sep 15, 2024 15:02:18.281922102 CEST192.168.2.101.1.1.10x3e54Standard query (0)captcha.serverprotect.onlineA (IP address)IN (0x0001)false
                            Sep 15, 2024 15:02:24.919368029 CEST192.168.2.101.1.1.10xc10aStandard query (0)deadmunky.nlA (IP address)IN (0x0001)false
                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                            Sep 15, 2024 15:02:18.305391073 CEST1.1.1.1192.168.2.100x3e54No error (0)captcha.serverprotect.online104.21.82.103A (IP address)IN (0x0001)false
                            Sep 15, 2024 15:02:18.305391073 CEST1.1.1.1192.168.2.100x3e54No error (0)captcha.serverprotect.online172.67.200.41A (IP address)IN (0x0001)false
                            Sep 15, 2024 15:02:24.945310116 CEST1.1.1.1192.168.2.100xc10aNo error (0)deadmunky.nl194.113.106.180A (IP address)IN (0x0001)false
                            • captcha.serverprotect.online
                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                            0192.168.2.1049700104.21.82.1034437316C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                            TimestampBytes transferredDirectionData
                            2024-09-15 13:02:19 UTC296OUTPOST /98aa7e1ce731c6206ebbe457e9f2dc7088adc3c628bee08/verify HTTP/1.1
                            User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1682
                            Content-Type: application/x-www-form-urlencoded
                            Host: captcha.serverprotect.online
                            Content-Length: 0
                            Connection: Keep-Alive
                            2024-09-15 13:02:19 UTC1309INHTTP/1.1 404 Not Found
                            Date: Sun, 15 Sep 2024 13:02:19 GMT
                            Content-Type: text/html; charset=utf-8
                            Transfer-Encoding: chunked
                            Connection: close
                            Content-Security-Policy: script-src 'self' 'unsafe-inline' 'unsafe-eval';img-src 'self' cdn.discordapp.com;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
                            Cross-Origin-Opener-Policy: same-origin
                            Cross-Origin-Resource-Policy: same-origin
                            Origin-Agent-Cluster: ?1
                            Referrer-Policy: no-referrer
                            Strict-Transport-Security: max-age=15552000; includeSubDomains
                            X-Content-Type-Options: nosniff
                            X-DNS-Prefetch-Control: off
                            X-Download-Options: noopen
                            X-Frame-Options: SAMEORIGIN
                            X-Permitted-Cross-Domain-Policies: none
                            X-XSS-Protection: 0
                            CF-Cache-Status: DYNAMIC
                            Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2FuF43JeoqhMAqUT5LOSzO%2Bz9h%2By3fEAHk625AHJJQmuTlnrGf%2F%2FKSw770iowiD983krP0KPpLapaLsdWPF4WpjHEvZscp7GjHELFjKx3u6E2OiRG8%2Bl9YssPG6EiXpwnTOZHITt%2Bj2AqxaXxVMBn"}],"group":"cf-nel","max_age":604800}
                            NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                            Server: cloudflare
                            CF-RAY: 8c38cf795b637d06-EWR
                            alt-svc: h3=":443"; ma=86400
                            2024-09-15 13:02:19 UTC18INData Raw: 64 0d 0a 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0d 0a
                            Data Ascii: d404 Not Found
                            2024-09-15 13:02:19 UTC5INData Raw: 30 0d 0a 0d 0a
                            Data Ascii: 0


                            Click to jump to process

                            Click to jump to process

                            Click to dive into process behavior distribution

                            Click to jump to process

                            Target ID:0
                            Start time:09:02:13
                            Start date:15/09/2024
                            Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                            Wow64 process (32bit):false
                            Commandline:"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -noLogo -ExecutionPolicy unrestricted -file "C:\Users\user\Desktop\qsKo.ps1"
                            Imagebase:0x7ff7b2bb0000
                            File size:452'608 bytes
                            MD5 hash:04029E121A0CFA5991749937DD22A1D9
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Reputation:high
                            Has exited:true

                            Target ID:1
                            Start time:09:02:13
                            Start date:15/09/2024
                            Path:C:\Windows\System32\conhost.exe
                            Wow64 process (32bit):false
                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                            Imagebase:0x7ff620390000
                            File size:862'208 bytes
                            MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Reputation:high
                            Has exited:true

                            Target ID:3
                            Start time:09:02:16
                            Start date:15/09/2024
                            Path:C:\Windows\System32\conhost.exe
                            Wow64 process (32bit):false
                            Commandline:"C:\Windows\system32\conhost.exe" C:\Users\Public\Documents\nUCp.exe
                            Imagebase:0x7ff620390000
                            File size:862'208 bytes
                            MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Reputation:high
                            Has exited:true

                            Target ID:4
                            Start time:09:02:16
                            Start date:15/09/2024
                            Path:C:\Users\Public\Documents\nUCp.exe
                            Wow64 process (32bit):true
                            Commandline:C:\Users\Public\Documents\nUCp.exe
                            Imagebase:0xfa0000
                            File size:232'448 bytes
                            MD5 hash:FFFAAB9CB76179E7C9CC424C7519F8AB
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Yara matches:
                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Author: Joe Security
                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000004.00000003.1389217701.0000000000E50000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                            • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: 00000004.00000003.1391976687.0000000004540000.00000004.00000001.00020000.00000000.sdmp, Author: Joe Security
                            • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: 00000004.00000003.1392146550.0000000004760000.00000004.00000001.00020000.00000000.sdmp, Author: Joe Security
                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000004.00000003.1393080101.0000000003BC0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                            Reputation:low
                            Has exited:true

                            Target ID:5
                            Start time:09:02:20
                            Start date:15/09/2024
                            Path:C:\Windows\SysWOW64\OpenWith.exe
                            Wow64 process (32bit):true
                            Commandline:"C:\Windows\system32\openwith.exe"
                            Imagebase:0x70000
                            File size:107'368 bytes
                            MD5 hash:0ED31792A7FFF811883F80047CBCFC91
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Yara matches:
                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000005.00000003.1419467605.0000000004D19000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000005.00000002.1463969465.0000000004550000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000005.00000003.1393293145.00000000044F0000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                            • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: 00000005.00000003.1395128336.0000000004DB0000.00000004.00000001.00020000.00000000.sdmp, Author: Joe Security
                            • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: 00000005.00000003.1395438185.0000000004FD0000.00000004.00000001.00020000.00000000.sdmp, Author: Joe Security
                            Reputation:moderate
                            Has exited:true

                            Target ID:6
                            Start time:09:02:27
                            Start date:15/09/2024
                            Path:C:\Windows\System32\OpenWith.exe
                            Wow64 process (32bit):false
                            Commandline:"C:\Windows\system32\openwith.exe"
                            Imagebase:0x7ff69b6a0000
                            File size:123'984 bytes
                            MD5 hash:E4A834784FA08C17D47A1E72429C5109
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Yara matches:
                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000006.00000003.1766148892.0000011F7B611000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000006.00000003.1511743151.0000011F7B4C4000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                            • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000006.00000003.1511532978.0000011F7B411000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                            Reputation:high
                            Has exited:true

                            Target ID:8
                            Start time:09:02:49
                            Start date:15/09/2024
                            Path:C:\Program Files\Windows Media Player\setup_wm.exe
                            Wow64 process (32bit):false
                            Commandline:"C:\Program Files\Windows Media Player\setup_wm.exe"
                            Imagebase:0x7ff7df220000
                            File size:1'857'024 bytes
                            MD5 hash:F32C225D11A5AF5906CF7C15FDA955E4
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Reputation:moderate
                            Has exited:false

                            Target ID:9
                            Start time:09:02:51
                            Start date:15/09/2024
                            Path:C:\Windows\System32\dllhost.exe
                            Wow64 process (32bit):false
                            Commandline:"C:\Windows\system32\dllhost.exe"
                            Imagebase:0x7ff6f7fc0000
                            File size:21'312 bytes
                            MD5 hash:08EB78E5BE019DF044C26B14703BD1FA
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Reputation:moderate
                            Has exited:false

                            Reset < >
                              Strings
                              Memory Dump Source
                              • Source File: 00000000.00000002.1405199053.00007FF7C0D90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF7C0D90000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_0_2_7ff7c0d90000_powershell.jbxd
                              Similarity
                              • API ID:
                              • String ID: x6z$x6z
                              • API String ID: 0-2525929240
                              • Opcode ID: 8ad8594278eeda71995464ee89be59a5fc159a7a0e3032db0ebdc0d3fd738dbd
                              • Instruction ID: 5f84a44a75ffa69eaeb2a9bffac3a3b1dd732de394b236cce40deeda17a04242
                              • Opcode Fuzzy Hash: 8ad8594278eeda71995464ee89be59a5fc159a7a0e3032db0ebdc0d3fd738dbd
                              • Instruction Fuzzy Hash: 5F22387190DBC94FE356EB6898556B5BFE0EF56270B4801FEC08DC7293DE28A806C791
                              Memory Dump Source
                              • Source File: 00000000.00000002.1405199053.00007FF7C0D90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF7C0D90000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_0_2_7ff7c0d90000_powershell.jbxd
                              Similarity
                              • API ID:
                              • String ID:
                              • API String ID:
                              • Opcode ID: d52c00d0fe77f237f2091e2c42fa9a0bd2b5c3633ba4f967793c77e7f81ded77
                              • Instruction ID: 19e568acad4eaed87fbe5b5a6f2ddc200cdf2f3cf44dc4b46a088f237413c6d8
                              • Opcode Fuzzy Hash: d52c00d0fe77f237f2091e2c42fa9a0bd2b5c3633ba4f967793c77e7f81ded77
                              • Instruction Fuzzy Hash: 3A82BE70A0CA898FDB99EF288855678B7E2FF55724B9401BDC00EC7292DF25BC46C791
                              Memory Dump Source
                              • Source File: 00000000.00000002.1405199053.00007FF7C0D90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF7C0D90000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_0_2_7ff7c0d90000_powershell.jbxd
                              Similarity
                              • API ID:
                              • String ID:
                              • API String ID:
                              • Opcode ID: 981960e03ab117e2f33bc72c66b8f9e8951ae9881750349936055c9510e3430e
                              • Instruction ID: f4cdfad74c058f6e9184ee39b1b9fbf749bfec228a9c61162b2c067e88eca441
                              • Opcode Fuzzy Hash: 981960e03ab117e2f33bc72c66b8f9e8951ae9881750349936055c9510e3430e
                              • Instruction Fuzzy Hash: C7621721A0DB894FE756AB3858556B4BFE1EF56330B4901FBD18EC7293DE18AC05C3A1
                              Memory Dump Source
                              • Source File: 00000000.00000002.1405199053.00007FF7C0D90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF7C0D90000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_0_2_7ff7c0d90000_powershell.jbxd
                              Similarity
                              • API ID:
                              • String ID:
                              • API String ID:
                              • Opcode ID: 14a03c900578c2aa78faea2a8e69337c22ca4f7c2f0b31af7e15ea49ec21eea3
                              • Instruction ID: 0dd775e9e42aa0ed0db32d2a25fd9c807b4cc141fe3cc539bfc02d3dcecd4683
                              • Opcode Fuzzy Hash: 14a03c900578c2aa78faea2a8e69337c22ca4f7c2f0b31af7e15ea49ec21eea3
                              • Instruction Fuzzy Hash: 33D1167190DA894FE796AF6888556B9BBE0FF46360B5801FED04DC7293DF18B805C391
                              Memory Dump Source
                              • Source File: 00000000.00000002.1405199053.00007FF7C0D90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF7C0D90000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_0_2_7ff7c0d90000_powershell.jbxd
                              Similarity
                              • API ID:
                              • String ID:
                              • API String ID:
                              • Opcode ID: 8a1f9488278d621440cfbc6215321f7f159a4d505a0e59afe0e40b5e892efc61
                              • Instruction ID: 163681d7acb618b904e24783342483ed0125d56fe6943749c65c7b235a798e9a
                              • Opcode Fuzzy Hash: 8a1f9488278d621440cfbc6215321f7f159a4d505a0e59afe0e40b5e892efc61
                              • Instruction Fuzzy Hash: AC11A722E1D9064BB2A8BA1864D61BDA2C1EF44731BD802B9E64FC3782DF08BC1152D1
                              Memory Dump Source
                              • Source File: 00000000.00000002.1404752992.00007FF7C0CC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF7C0CC0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_0_2_7ff7c0cc0000_powershell.jbxd
                              Similarity
                              • API ID:
                              • String ID:
                              • API String ID:
                              • Opcode ID: 344ae550aa189cfee030fe5dad0be6a80d281401a7062d5ced25e02183c3b3df
                              • Instruction ID: df6d40b2d7e358816a083606dfc8a12fc05045bbe92da24e6dc442652641567e
                              • Opcode Fuzzy Hash: 344ae550aa189cfee030fe5dad0be6a80d281401a7062d5ced25e02183c3b3df
                              • Instruction Fuzzy Hash: 1501447111CB084FDB44EF0CE451AA6B7E0FB99364F50056DE58AC3651D626E881CB45
                              Memory Dump Source
                              • Source File: 00000000.00000002.1404752992.00007FF7C0CC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF7C0CC0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_0_2_7ff7c0cc0000_powershell.jbxd
                              Similarity
                              • API ID:
                              • String ID:
                              • API String ID:
                              • Opcode ID: 2396290656bea5cd6dc50c813f07ebbf23bb15a112c66a8f0aafa9b99dba0d60
                              • Instruction ID: c34d4a8b3ba5de9a2e8200d4f6f197d91c5c20523a54797931965f2c6e469ac5
                              • Opcode Fuzzy Hash: 2396290656bea5cd6dc50c813f07ebbf23bb15a112c66a8f0aafa9b99dba0d60
                              • Instruction Fuzzy Hash: 66129967A0E6C64FE3225A3C9C650E5BFA0DF5367574D12F7C2C4CB193EE19284A83A1

                              Execution Graph

                              Execution Coverage:1.9%
                              Dynamic/Decrypted Code Coverage:0%
                              Signature Coverage:2.3%
                              Total number of Nodes:1708
                              Total number of Limit Nodes:27
                              execution_graph 8519 ffb3fc 8520 ffb407 8519->8520 8522 ffb430 8520->8522 8523 ffb42c 8520->8523 8525 ffc3f4 8520->8525 8530 ffb454 8522->8530 8526 ffc211 __dosmaperr 5 API calls 8525->8526 8527 ffc410 8526->8527 8528 ffc42e InitializeCriticalSectionAndSpinCount 8527->8528 8529 ffc419 8527->8529 8528->8529 8529->8520 8531 ffb480 8530->8531 8532 ffb461 8530->8532 8531->8523 8533 ffb46b RtlDeleteCriticalSection 8532->8533 8533->8531 8533->8533 6711 ff8a7b 6714 ff88af 6711->6714 6715 ff88ee 6714->6715 6716 ff88dc 6714->6716 6726 ff875f 6715->6726 6741 ff56fa GetModuleHandleW 6716->6741 6721 ff892b 6725 ff8940 6727 ff876b __FrameHandler3::FrameUnwindToState 6726->6727 6749 ffb43d RtlEnterCriticalSection 6727->6749 6729 ff8775 6750 ff87c7 6729->6750 6731 ff8782 6754 ff87a0 6731->6754 6734 ff8946 6833 ff8977 6734->6833 6736 ff8950 6737 ff8964 6736->6737 6738 ff8954 GetCurrentProcess TerminateProcess 6736->6738 6739 ff8990 __FrameHandler3::FrameUnwindToState 3 API calls 6737->6739 6738->6737 6740 ff896c ExitProcess 6739->6740 6742 ff5706 6741->6742 6742->6715 6743 ff8990 GetModuleHandleExW 6742->6743 6744 ff89cf GetProcAddress 6743->6744 6745 ff89f0 6743->6745 6744->6745 6746 ff89e3 6744->6746 6747 ff88ed 6745->6747 6748 ff89f6 FreeLibrary 6745->6748 6746->6745 6747->6715 6748->6747 6749->6729 6751 ff87d3 __FrameHandler3::FrameUnwindToState 6750->6751 6752 ff8837 __FrameHandler3::FrameUnwindToState 6751->6752 6757 ff8eb4 6751->6757 6752->6731 6832 ffb485 RtlLeaveCriticalSection 6754->6832 6756 ff878e 6756->6721 6756->6734 6758 ff8ec0 __EH_prolog3 6757->6758 6761 ff8c0c 6758->6761 6760 ff8ee7 __FrameHandler3::FrameUnwindToState 6760->6752 6762 ff8c18 __FrameHandler3::FrameUnwindToState 6761->6762 6769 ffb43d RtlEnterCriticalSection 6762->6769 6764 ff8c26 6770 ff8dc4 6764->6770 6769->6764 6771 ff8de3 6770->6771 6772 ff8c33 6770->6772 6771->6772 6777 ff9e01 6771->6777 6774 ff8c5b 6772->6774 6831 ffb485 RtlLeaveCriticalSection 6774->6831 6776 ff8c44 6776->6760 6778 ff9e0c HeapFree 6777->6778 6782 ff9e36 6777->6782 6779 ff9e21 GetLastError 6778->6779 6778->6782 6780 ff9e2e __dosmaperr 6779->6780 6783 ff9d91 6780->6783 6782->6772 6786 ff98f1 GetLastError 6783->6786 6785 ff9d96 6785->6782 6787 ff9907 6786->6787 6788 ff990d 6786->6788 6809 ffc373 6787->6809 6792 ff9911 SetLastError 6788->6792 6814 ffc3b2 6788->6814 6792->6785 6796 ff9957 6799 ffc3b2 __dosmaperr 6 API calls 6796->6799 6797 ff9946 6798 ffc3b2 __dosmaperr 6 API calls 6797->6798 6801 ff9954 6798->6801 6800 ff9963 6799->6800 6802 ff997e 6800->6802 6803 ff9967 6800->6803 6804 ff9e01 ___free_lconv_mon 12 API calls 6801->6804 6826 ff95ce 6802->6826 6806 ffc3b2 __dosmaperr 6 API calls 6803->6806 6804->6792 6806->6801 6808 ff9e01 ___free_lconv_mon 12 API calls 6808->6792 6810 ffc211 __dosmaperr 5 API calls 6809->6810 6811 ffc38f 6810->6811 6812 ffc3aa TlsGetValue 6811->6812 6813 ffc398 6811->6813 6813->6788 6815 ffc211 __dosmaperr 5 API calls 6814->6815 6816 ffc3ce 6815->6816 6817 ffc3ec TlsSetValue 6816->6817 6818 ff9929 6816->6818 6818->6792 6819 ff9da4 6818->6819 6824 ff9db1 __dosmaperr 6819->6824 6820 ff9df1 6823 ff9d91 __dosmaperr 13 API calls 6820->6823 6821 ff9ddc RtlAllocateHeap 6822 ff993e 6821->6822 6821->6824 6822->6796 6822->6797 6823->6822 6824->6820 6824->6821 6825 ffc647 __dosmaperr RtlEnterCriticalSection RtlLeaveCriticalSection 6824->6825 6825->6824 6827 ff9462 __dosmaperr RtlEnterCriticalSection RtlLeaveCriticalSection 6826->6827 6828 ff963c 6827->6828 6829 ff9574 __dosmaperr 14 API calls 6828->6829 6830 ff9665 6829->6830 6830->6808 6831->6776 6832->6756 6836 ffb4c1 6833->6836 6835 ff897c __FrameHandler3::FrameUnwindToState 6835->6736 6837 ffb4d0 __FrameHandler3::FrameUnwindToState 6836->6837 6838 ffb4dd 6837->6838 6840 ffc296 6837->6840 6838->6835 6843 ffc211 6840->6843 6844 ffc241 6843->6844 6845 ffc23d 6843->6845 6844->6845 6850 ffc146 6844->6850 6845->6838 6848 ffc25b GetProcAddress 6848->6845 6849 ffc26b __dosmaperr 6848->6849 6849->6845 6856 ffc157 ___vcrt_FlsFree 6850->6856 6851 ffc1ed 6851->6845 6851->6848 6852 ffc175 LoadLibraryExW 6853 ffc1f4 6852->6853 6854 ffc190 GetLastError 6852->6854 6853->6851 6855 ffc206 FreeLibrary 6853->6855 6854->6856 6855->6851 6856->6851 6856->6852 6857 ffc1c3 LoadLibraryExW 6856->6857 6857->6853 6857->6856 6968 ff547b 6971 ff544e 6968->6971 6972 ff545d 6971->6972 6973 ff5464 6971->6973 6977 ff8e9e 6972->6977 6980 ff8f1b 6973->6980 6976 ff5462 6978 ff8f1b 32 API calls 6977->6978 6979 ff8eb0 6978->6979 6979->6976 6983 ff8c67 6980->6983 6984 ff8c73 __FrameHandler3::FrameUnwindToState 6983->6984 6991 ffb43d RtlEnterCriticalSection 6984->6991 6986 ff8c81 6992 ff8cc2 6986->6992 6988 ff8c8e 7002 ff8cb6 6988->7002 6991->6986 6993 ff8cdd 6992->6993 6994 ff8d50 __dosmaperr 6992->6994 6993->6994 6995 ff8d30 6993->6995 7005 ffc517 6993->7005 6994->6988 6995->6994 6997 ffc517 32 API calls 6995->6997 6999 ff8d46 6997->6999 6998 ff8d26 7000 ff9e01 ___free_lconv_mon 14 API calls 6998->7000 7001 ff9e01 ___free_lconv_mon 14 API calls 6999->7001 7000->6995 7001->6994 7054 ffb485 RtlLeaveCriticalSection 7002->7054 7004 ff8c9f 7004->6976 7006 ffc53f 7005->7006 7007 ffc524 7005->7007 7008 ffc54e 7006->7008 7014 ffddc6 7006->7014 7007->7006 7009 ffc530 7007->7009 7021 ffddf9 7008->7021 7011 ff9d91 __dosmaperr 14 API calls 7009->7011 7013 ffc535 __FrameHandler3::FrameUnwindToState 7011->7013 7013->6998 7015 ffdde6 RtlSizeHeap 7014->7015 7016 ffddd1 7014->7016 7015->7008 7017 ff9d91 __dosmaperr 14 API calls 7016->7017 7018 ffddd6 7017->7018 7019 ff9cb0 ___std_exception_copy 29 API calls 7018->7019 7020 ffdde1 7019->7020 7020->7008 7022 ffde06 7021->7022 7023 ffde11 7021->7023 7033 ffbbef 7022->7033 7024 ffde19 7023->7024 7031 ffde22 __dosmaperr 7023->7031 7026 ff9e01 ___free_lconv_mon 14 API calls 7024->7026 7029 ffde0e 7026->7029 7027 ffde4c RtlReAllocateHeap 7027->7029 7027->7031 7028 ffde27 7030 ff9d91 __dosmaperr 14 API calls 7028->7030 7029->7013 7030->7029 7031->7027 7031->7028 7040 ffc647 7031->7040 7034 ffbc2d 7033->7034 7038 ffbbfd __dosmaperr 7033->7038 7035 ff9d91 __dosmaperr 14 API calls 7034->7035 7037 ffbc2b 7035->7037 7036 ffbc18 RtlAllocateHeap 7036->7037 7036->7038 7037->7029 7038->7034 7038->7036 7039 ffc647 __dosmaperr 2 API calls 7038->7039 7039->7038 7043 ffc673 7040->7043 7044 ffc67f __FrameHandler3::FrameUnwindToState 7043->7044 7049 ffb43d RtlEnterCriticalSection 7044->7049 7046 ffc68a __FrameHandler3::FrameUnwindToState 7050 ffc6c1 7046->7050 7049->7046 7053 ffb485 RtlLeaveCriticalSection 7050->7053 7052 ffc652 7052->7031 7053->7052 7054->7004 7363 ff783a 7364 ff7848 ___except_validate_context_record 7363->7364 7372 ff6913 7364->7372 7366 ff784e 7367 ff788d 7366->7367 7369 ff78b3 7366->7369 7371 ff78ab 7366->7371 7367->7371 7385 ff7c59 7367->7385 7369->7371 7388 ff72d1 7369->7388 7439 ff6921 7372->7439 7374 ff6918 7374->7366 7453 ffc79c 7374->7453 7377 ff91b7 7379 ff91e0 7377->7379 7380 ff91c1 IsProcessorFeaturePresent 7377->7380 7489 ff8a3f 7379->7489 7381 ff91cd 7380->7381 7383 ff9ab4 __FrameHandler3::FrameUnwindToState 8 API calls 7381->7383 7383->7379 7602 ff7c71 7385->7602 7387 ff7c6c 7387->7371 7392 ff72f1 __FrameHandler3::FrameUnwindToState 7388->7392 7389 ff7604 7390 ff91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7389->7390 7400 ff760a 7389->7400 7391 ff7675 7390->7391 7392->7389 7394 ff73d3 7392->7394 7395 ff6913 __InternalCxxFrameHandler 78 API calls 7392->7395 7393 ff75d9 7393->7389 7415 ff75d7 7393->7415 7636 ff7676 7393->7636 7394->7393 7396 ff745c 7394->7396 7437 ff73d9 type_info::operator== 7394->7437 7398 ff7353 7395->7398 7403 ff7573 __InternalCxxFrameHandler 7396->7403 7621 ff6cc4 7396->7621 7397 ff6913 __InternalCxxFrameHandler 78 API calls 7397->7389 7398->7400 7402 ff6913 __InternalCxxFrameHandler 78 API calls 7398->7402 7400->7371 7405 ff7361 7402->7405 7404 ff75a3 7403->7404 7406 ff75c8 7403->7406 7407 ff75ad 7403->7407 7403->7415 7404->7407 7404->7415 7408 ff6913 __InternalCxxFrameHandler 78 API calls 7405->7408 7409 ff7d59 __InternalCxxFrameHandler 68 API calls 7406->7409 7410 ff6913 __InternalCxxFrameHandler 78 API calls 7407->7410 7414 ff7369 7408->7414 7412 ff75d1 7409->7412 7411 ff75b8 7410->7411 7413 ff6913 __InternalCxxFrameHandler 78 API calls 7411->7413 7412->7415 7416 ff7634 7412->7416 7413->7437 7414->7389 7417 ff6913 __InternalCxxFrameHandler 78 API calls 7414->7417 7415->7397 7418 ff6913 __InternalCxxFrameHandler 78 API calls 7416->7418 7419 ff73b2 7417->7419 7420 ff7639 7418->7420 7419->7394 7424 ff6913 __InternalCxxFrameHandler 78 API calls 7419->7424 7423 ff6913 __InternalCxxFrameHandler 78 API calls 7420->7423 7422 ff747d ___TypeMatch 7422->7403 7626 ff7251 7422->7626 7425 ff7641 7423->7425 7426 ff73bc 7424->7426 7662 ff6eb7 RtlUnwind 7425->7662 7427 ff6913 __InternalCxxFrameHandler 78 API calls 7426->7427 7432 ff73c7 7427->7432 7430 ff7655 7433 ff7c59 __InternalCxxFrameHandler 78 API calls 7430->7433 7431 ff7614 __InternalCxxFrameHandler 7659 ff7f46 7431->7659 7616 ff7d59 7432->7616 7435 ff7661 __InternalCxxFrameHandler 7433->7435 7663 ff7bd0 7435->7663 7437->7431 7653 ff90eb 7437->7653 7440 ff692d GetLastError 7439->7440 7441 ff692a 7439->7441 7492 ff6c04 7440->7492 7441->7374 7444 ff69a7 SetLastError 7444->7374 7446 ff695b __InternalCxxFrameHandler 7447 ff6983 7446->7447 7448 ff6c3f ___vcrt_FlsSetValue 6 API calls 7446->7448 7452 ff6961 7446->7452 7449 ff6c3f ___vcrt_FlsSetValue 6 API calls 7447->7449 7450 ff6997 7447->7450 7448->7447 7449->7450 7451 ff9127 ___std_exception_copy 14 API calls 7450->7451 7451->7452 7452->7444 7514 ffc6ca 7453->7514 7456 ffc7e1 7457 ffc7ed __FrameHandler3::FrameUnwindToState 7456->7457 7458 ff98f1 __dosmaperr 14 API calls 7457->7458 7459 ffc83d 7457->7459 7460 ffc84f __FrameHandler3::FrameUnwindToState 7457->7460 7466 ffc81e __FrameHandler3::FrameUnwindToState 7457->7466 7458->7466 7461 ff9d91 __dosmaperr 14 API calls 7459->7461 7462 ffc885 __FrameHandler3::FrameUnwindToState 7460->7462 7525 ffb43d RtlEnterCriticalSection 7460->7525 7463 ffc842 7461->7463 7470 ffc8c2 7462->7470 7472 ffc9bf 7462->7472 7480 ffc8f0 7462->7480 7464 ff9cb0 ___std_exception_copy 29 API calls 7463->7464 7467 ffc827 7464->7467 7466->7459 7466->7460 7466->7467 7467->7377 7475 ff97a0 _unexpected 68 API calls 7470->7475 7470->7480 7471 ffc9ca 7474 ff8a3f __FrameHandler3::FrameUnwindToState 21 API calls 7471->7474 7472->7471 7530 ffb485 RtlLeaveCriticalSection 7472->7530 7479 ffc9d2 __FrameHandler3::FrameUnwindToState 7474->7479 7477 ffc8e5 7475->7477 7476 ff97a0 _unexpected 68 API calls 7482 ffc945 7476->7482 7478 ff97a0 _unexpected 68 API calls 7477->7478 7478->7480 7531 ffcd97 RtlEnterCriticalSection 7479->7531 7526 ffc96b 7480->7526 7482->7467 7483 ff97a0 _unexpected 68 API calls 7482->7483 7483->7467 7484 ffca22 7543 ffca53 7484->7543 7485 ffc9e9 __FrameHandler3::FrameUnwindToState 7485->7484 7532 ffcc15 7485->7532 7490 ff88af __FrameHandler3::FrameUnwindToState 21 API calls 7489->7490 7491 ff8a50 7490->7491 7502 ff6aa3 7492->7502 7495 ff6c36 TlsGetValue 7496 ff6942 7495->7496 7496->7444 7496->7452 7497 ff6c3f 7496->7497 7498 ff6aa3 ___vcrt_FlsFree 5 API calls 7497->7498 7499 ff6c59 7498->7499 7500 ff6c74 TlsSetValue 7499->7500 7501 ff6c68 7499->7501 7500->7501 7501->7446 7503 ff6ac4 7502->7503 7504 ff6ac0 7502->7504 7503->7504 7505 ff6b2c GetProcAddress 7503->7505 7507 ff6b1d 7503->7507 7509 ff6b43 LoadLibraryExW 7503->7509 7504->7495 7504->7496 7505->7504 7507->7505 7508 ff6b25 FreeLibrary 7507->7508 7508->7505 7510 ff6b5a GetLastError 7509->7510 7511 ff6b8a 7509->7511 7510->7511 7512 ff6b65 ___vcrt_FlsFree 7510->7512 7511->7503 7512->7511 7513 ff6b7b LoadLibraryExW 7512->7513 7513->7503 7515 ffc6d6 __FrameHandler3::FrameUnwindToState 7514->7515 7520 ffb43d RtlEnterCriticalSection 7515->7520 7517 ffc6e4 7521 ffc726 7517->7521 7520->7517 7524 ffb485 RtlLeaveCriticalSection 7521->7524 7523 ff91ac 7523->7377 7523->7456 7524->7523 7525->7462 7527 ffc96f 7526->7527 7529 ffc937 7526->7529 7546 ffb485 RtlLeaveCriticalSection 7527->7546 7529->7467 7529->7476 7529->7482 7530->7471 7531->7485 7533 ffcc2a __FrameHandler3::FrameUnwindToState 7532->7533 7534 ffcc3c 7533->7534 7535 ffcc31 7533->7535 7536 ffcbac __FrameHandler3::FrameUnwindToState 68 API calls 7534->7536 7547 ffcb0b 7535->7547 7538 ffcc46 7536->7538 7539 ffd3f4 __FrameHandler3::FrameUnwindToState 29 API calls 7538->7539 7540 ffcc37 __FrameHandler3::FrameUnwindToState 7538->7540 7541 ffcc5d 7539->7541 7540->7484 7550 ffdf04 7541->7550 7601 ffcdab RtlLeaveCriticalSection 7543->7601 7545 ffca41 7545->7377 7546->7529 7561 ffca5f 7547->7561 7551 ffdf15 7550->7551 7552 ffdf22 7550->7552 7553 ff9d91 __dosmaperr 14 API calls 7551->7553 7554 ffdf6b 7552->7554 7557 ffdf49 7552->7557 7560 ffdf1a 7553->7560 7555 ff9d91 __dosmaperr 14 API calls 7554->7555 7556 ffdf70 7555->7556 7559 ff9cb0 ___std_exception_copy 29 API calls 7556->7559 7583 ffde62 7557->7583 7559->7560 7560->7540 7562 ffca6b __FrameHandler3::FrameUnwindToState 7561->7562 7569 ffb43d RtlEnterCriticalSection 7562->7569 7564 ffcae1 7578 ffcaff 7564->7578 7565 ffca75 __FrameHandler3::FrameUnwindToState 7565->7564 7570 ffc9d3 7565->7570 7569->7565 7571 ffc9df __FrameHandler3::FrameUnwindToState 7570->7571 7581 ffcd97 RtlEnterCriticalSection 7571->7581 7573 ffca22 7575 ffca53 __FrameHandler3::FrameUnwindToState RtlLeaveCriticalSection 7573->7575 7574 ffc9e9 __FrameHandler3::FrameUnwindToState 7574->7573 7577 ffcc15 __FrameHandler3::FrameUnwindToState 68 API calls 7574->7577 7576 ffca41 7575->7576 7576->7565 7577->7573 7582 ffb485 RtlLeaveCriticalSection 7578->7582 7580 ffcaed 7580->7540 7581->7574 7582->7580 7584 ffde6e __FrameHandler3::FrameUnwindToState 7583->7584 7596 ffb636 RtlEnterCriticalSection 7584->7596 7586 ffde7d 7587 ffdec2 7586->7587 7589 ffb70d __FrameHandler3::FrameUnwindToState 29 API calls 7586->7589 7588 ff9d91 __dosmaperr 14 API calls 7587->7588 7591 ffdec9 7588->7591 7590 ffdea9 FlushFileBuffers 7589->7590 7590->7591 7592 ffdeb5 GetLastError 7590->7592 7597 ffdef8 7591->7597 7593 ff9d7e __dosmaperr 14 API calls 7592->7593 7593->7587 7596->7586 7600 ffb659 RtlLeaveCriticalSection 7597->7600 7599 ffdee1 7599->7560 7600->7599 7601->7545 7603 ff7c7d __FrameHandler3::FrameUnwindToState 7602->7603 7604 ff6913 __InternalCxxFrameHandler 78 API calls 7603->7604 7610 ff7c98 __CallSettingFrame@12 CatchIt 7604->7610 7606 ff7d18 7607 ff91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7606->7607 7608 ff7d1d CatchIt 7606->7608 7609 ff7d58 7607->7609 7608->7387 7610->7606 7611 ff7d3f 7610->7611 7612 ff6913 __InternalCxxFrameHandler 78 API calls 7611->7612 7613 ff7d44 7612->7613 7614 ff7d4f 7613->7614 7615 ff6913 __InternalCxxFrameHandler 78 API calls 7613->7615 7614->7606 7615->7614 7617 ff7ded 7616->7617 7620 ff7d6d ___TypeMatch 7616->7620 7618 ff91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7617->7618 7619 ff7df2 7618->7619 7620->7394 7622 ff6ce2 7621->7622 7623 ff6d18 7622->7623 7624 ff91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7622->7624 7623->7422 7625 ff6d33 7624->7625 7627 ff7270 7626->7627 7628 ff7263 7626->7628 7682 ff6eb7 RtlUnwind 7627->7682 7678 ff71b8 7628->7678 7631 ff7285 7632 ff7c71 __FrameHandler3::FrameUnwindToState 78 API calls 7631->7632 7633 ff7296 CatchIt 7632->7633 7683 ff7a01 7633->7683 7635 ff72be CatchIt 7635->7422 7637 ff768c 7636->7637 7648 ff77a1 7636->7648 7638 ff6913 __InternalCxxFrameHandler 78 API calls 7637->7638 7639 ff7693 7638->7639 7640 ff769a RtlEncodePointer 7639->7640 7650 ff76d5 7639->7650 7641 ff6913 __InternalCxxFrameHandler 78 API calls 7640->7641 7647 ff76a8 7641->7647 7642 ff77a6 7644 ff91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7642->7644 7643 ff76f2 7645 ff6cc4 __InternalCxxFrameHandler 68 API calls 7643->7645 7646 ff77ab 7644->7646 7651 ff7709 7645->7651 7649 ff6d91 __InternalCxxFrameHandler 78 API calls 7647->7649 7647->7650 7648->7415 7649->7650 7650->7642 7650->7643 7650->7648 7651->7648 7652 ff7251 CatchIt 79 API calls 7651->7652 7652->7651 7654 ff90f7 __FrameHandler3::FrameUnwindToState 7653->7654 7655 ff97a0 _unexpected 68 API calls 7654->7655 7658 ff90fc 7655->7658 7656 ff91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7657 ff9126 7656->7657 7658->7656 7660 ff7f8d RaiseException 7659->7660 7661 ff7f60 7659->7661 7660->7416 7661->7660 7662->7430 7664 ff7bdc __EH_prolog3_catch 7663->7664 7665 ff6913 __InternalCxxFrameHandler 78 API calls 7664->7665 7666 ff7be1 7665->7666 7667 ff7c04 7666->7667 7743 ff7e7c 7666->7743 7668 ff91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7667->7668 7675 ff7c09 7668->7675 7671 ff7c55 7671->7389 7675->7671 7676 ff6913 __InternalCxxFrameHandler 78 API calls 7675->7676 7677 ff7c4b 7676->7677 7677->7389 7679 ff71c4 __FrameHandler3::FrameUnwindToState 7678->7679 7697 ff707a 7679->7697 7681 ff71ec CatchIt ___AdjustPointer 7681->7627 7682->7631 7684 ff7a0d __FrameHandler3::FrameUnwindToState 7683->7684 7704 ff6f3b 7684->7704 7687 ff6913 __InternalCxxFrameHandler 78 API calls 7688 ff7a39 7687->7688 7689 ff6913 __InternalCxxFrameHandler 78 API calls 7688->7689 7690 ff7a44 7689->7690 7691 ff6913 __InternalCxxFrameHandler 78 API calls 7690->7691 7692 ff7a4f 7691->7692 7693 ff6913 __InternalCxxFrameHandler 78 API calls 7692->7693 7694 ff7a57 CatchIt 7693->7694 7709 ff7b54 7694->7709 7696 ff7b3c 7696->7635 7698 ff7086 __FrameHandler3::FrameUnwindToState 7697->7698 7699 ff91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7698->7699 7700 ff7101 CatchIt ___AdjustPointer 7698->7700 7701 ff71b7 __FrameHandler3::FrameUnwindToState 7699->7701 7700->7681 7702 ff707a CatchIt 68 API calls 7701->7702 7703 ff71ec CatchIt ___AdjustPointer 7702->7703 7703->7681 7705 ff6913 __InternalCxxFrameHandler 78 API calls 7704->7705 7706 ff6f4c 7705->7706 7707 ff6913 __InternalCxxFrameHandler 78 API calls 7706->7707 7708 ff6f57 7707->7708 7708->7687 7718 ff6f5f 7709->7718 7711 ff7b65 7712 ff6913 __InternalCxxFrameHandler 78 API calls 7711->7712 7713 ff7b6b 7712->7713 7714 ff6913 __InternalCxxFrameHandler 78 API calls 7713->7714 7716 ff7b76 7714->7716 7715 ff7bb7 __InternalCxxFrameHandler 7715->7696 7716->7715 7735 ff66a6 7716->7735 7719 ff6913 __InternalCxxFrameHandler 78 API calls 7718->7719 7720 ff6f68 7719->7720 7721 ff6f7e 7720->7721 7722 ff6f70 7720->7722 7724 ff6913 __InternalCxxFrameHandler 78 API calls 7721->7724 7723 ff6913 __InternalCxxFrameHandler 78 API calls 7722->7723 7725 ff6f78 7723->7725 7726 ff6f83 7724->7726 7725->7711 7726->7725 7727 ff91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7726->7727 7728 ff6fa6 7727->7728 7729 ff5a25 _ValidateLocalCookies 5 API calls 7728->7729 7730 ff6fbb ___CxxFrameHandler 7729->7730 7731 ff7015 7730->7731 7734 ff6fc6 7730->7734 7738 ff6eb7 RtlUnwind 7730->7738 7739 ff6d91 7731->7739 7734->7711 7736 ff6913 __InternalCxxFrameHandler 78 API calls 7735->7736 7737 ff66ae 7736->7737 7737->7715 7738->7731 7740 ff6db3 __InternalCxxFrameHandler 7739->7740 7741 ff6da1 7739->7741 7742 ff6913 __InternalCxxFrameHandler 78 API calls 7740->7742 7741->7734 7742->7741 7744 ff6913 __InternalCxxFrameHandler 78 API calls 7743->7744 7746 ff7e82 7744->7746 7745 ff90eb _unexpected 68 API calls 7747 ff7e98 7745->7747 7746->7745 6885 ff68f7 6886 ff690e 6885->6886 6887 ff6901 6885->6887 6887->6886 6889 ff9127 6887->6889 6890 ff9e01 ___free_lconv_mon 14 API calls 6889->6890 6891 ff913f 6890->6891 6891->6886 8208 ffc2f5 8209 ffc211 __dosmaperr 5 API calls 8208->8209 8210 ffc311 8209->8210 8211 ffc329 TlsAlloc 8210->8211 8212 ffc31a 8210->8212 8211->8212 8243 ff52b5 8244 ff52be 8243->8244 8251 ff5845 IsProcessorFeaturePresent 8244->8251 8248 ff52cf 8249 ff52d3 8248->8249 8250 ff654d ___scrt_uninitialize_crt 7 API calls 8248->8250 8250->8249 8252 ff52ca 8251->8252 8253 ff652e 8252->8253 8261 ff6a01 8253->8261 8257 ff654a 8257->8248 8258 ff653f 8258->8257 8259 ff6a3d ___vcrt_uninitialize_locks RtlDeleteCriticalSection 8258->8259 8260 ff6537 8259->8260 8260->8248 8262 ff6a0a 8261->8262 8264 ff6a33 8262->8264 8266 ff6533 8262->8266 8275 ff6c7d 8262->8275 8265 ff6a3d ___vcrt_uninitialize_locks RtlDeleteCriticalSection 8264->8265 8265->8266 8266->8260 8267 ff69b3 8266->8267 8280 ff6b8e 8267->8280 8270 ff69c8 8270->8258 8271 ff6c3f ___vcrt_FlsSetValue 6 API calls 8272 ff69d6 8271->8272 8273 ff69e3 8272->8273 8274 ff69e6 ___vcrt_uninitialize_ptd 6 API calls 8272->8274 8273->8258 8274->8270 8276 ff6aa3 ___vcrt_FlsFree 5 API calls 8275->8276 8277 ff6c97 8276->8277 8278 ff6cb5 InitializeCriticalSectionAndSpinCount 8277->8278 8279 ff6ca0 8277->8279 8278->8279 8279->8262 8281 ff6aa3 ___vcrt_FlsFree 5 API calls 8280->8281 8282 ff6ba8 8281->8282 8283 ff6bc1 TlsAlloc 8282->8283 8284 ff69bd 8282->8284 8284->8270 8284->8271 8678 ff8fb4 8681 ff901c 8678->8681 8682 ff8fc7 8681->8682 8683 ff9030 8681->8683 8683->8682 8684 ff9e01 ___free_lconv_mon 14 API calls 8683->8684 8684->8682 8794 ffc334 8795 ffc211 __dosmaperr 5 API calls 8794->8795 8796 ffc350 8795->8796 8797 ffc36b TlsFree 8796->8797 8798 ffc359 8796->8798 6867 10022cc 6879 1002277 GetPEB 6867->6879 6869 10022e5 6870 1002309 VirtualAlloc 6869->6870 6876 10023fa 6869->6876 6871 1002321 6870->6871 6870->6876 6881 1002098 VirtualAlloc 6871->6881 6874 10023eb VirtualFree 6874->6876 6875 1002359 VirtualAlloc 6875->6874 6877 1002370 6875->6877 6878 10023ae VirtualProtect 6877->6878 6878->6874 6880 1002295 6879->6880 6880->6869 6882 1002270 6881->6882 6884 10020d0 VirtualFree 6881->6884 6882->6874 6882->6875 6884->6882 7812 ff81b1 7813 ff81c8 7812->7813 7835 ff81c1 7812->7835 7814 ff81e9 7813->7814 7816 ff81d3 7813->7816 7842 ffae05 7814->7842 7817 ff9d91 __dosmaperr 14 API calls 7816->7817 7819 ff81d8 7817->7819 7821 ff9cb0 ___std_exception_copy 29 API calls 7819->7821 7821->7835 7827 ff824b 7829 ff9d91 __dosmaperr 14 API calls 7827->7829 7828 ff8257 7830 ff82ee 68 API calls 7828->7830 7831 ff8250 7829->7831 7832 ff826d 7830->7832 7834 ff9e01 ___free_lconv_mon 14 API calls 7831->7834 7832->7831 7833 ff8291 7832->7833 7836 ff82a8 7833->7836 7837 ff82b2 7833->7837 7834->7835 7838 ff9e01 ___free_lconv_mon 14 API calls 7836->7838 7839 ff9e01 ___free_lconv_mon 14 API calls 7837->7839 7840 ff82b0 7838->7840 7839->7840 7841 ff9e01 ___free_lconv_mon 14 API calls 7840->7841 7841->7835 7843 ffae0e 7842->7843 7844 ff81ef 7842->7844 7870 ff985b 7843->7870 7848 ffa7e8 GetModuleFileNameW 7844->7848 7849 ffa828 7848->7849 7850 ffa817 GetLastError 7848->7850 8074 ffa566 7849->8074 8069 ff9d37 7850->8069 7853 ffa823 7856 ff5a25 _ValidateLocalCookies 5 API calls 7853->7856 7857 ff8202 7856->7857 7858 ff82ee 7857->7858 7860 ff8314 7858->7860 7862 ff8372 7860->7862 8113 ffb136 7860->8113 7861 ff8235 7864 ff8462 7861->7864 7862->7861 7863 ffb136 68 API calls 7862->7863 7863->7862 7865 ff8242 7864->7865 7866 ff8473 7864->7866 7865->7827 7865->7828 7866->7865 7867 ff9da4 __dosmaperr 14 API calls 7866->7867 7868 ff849c 7867->7868 7869 ff9e01 ___free_lconv_mon 14 API calls 7868->7869 7869->7865 7871 ff986c 7870->7871 7872 ff9866 7870->7872 7874 ffc3b2 __dosmaperr 6 API calls 7871->7874 7891 ff9872 7871->7891 7873 ffc373 __dosmaperr 6 API calls 7872->7873 7873->7871 7875 ff9886 7874->7875 7877 ff9da4 __dosmaperr 14 API calls 7875->7877 7875->7891 7876 ff91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7879 ff98f0 7876->7879 7878 ff9896 7877->7878 7880 ff989e 7878->7880 7881 ff98b3 7878->7881 7882 ffc3b2 __dosmaperr 6 API calls 7880->7882 7883 ffc3b2 __dosmaperr 6 API calls 7881->7883 7885 ff98aa 7882->7885 7884 ff98bf 7883->7884 7886 ff98c3 7884->7886 7887 ff98d2 7884->7887 7888 ff9e01 ___free_lconv_mon 14 API calls 7885->7888 7889 ffc3b2 __dosmaperr 6 API calls 7886->7889 7890 ff95ce __dosmaperr 14 API calls 7887->7890 7888->7891 7889->7885 7892 ff98dd 7890->7892 7891->7876 7894 ff9877 7891->7894 7893 ff9e01 ___free_lconv_mon 14 API calls 7892->7893 7893->7894 7895 ffac10 7894->7895 7896 ffad65 __FrameHandler3::FrameUnwindToState 68 API calls 7895->7896 7897 ffac3a 7896->7897 7918 ffa997 7897->7918 7900 ffbbef 15 API calls 7901 ffac64 7900->7901 7902 ffac6c 7901->7902 7903 ffac7a 7901->7903 7904 ff9e01 ___free_lconv_mon 14 API calls 7902->7904 7925 ffae60 7903->7925 7906 ffac53 7904->7906 7906->7844 7908 ffacb2 7909 ff9d91 __dosmaperr 14 API calls 7908->7909 7910 ffacb7 7909->7910 7912 ff9e01 ___free_lconv_mon 14 API calls 7910->7912 7911 ffacf9 7914 ffad42 7911->7914 7936 ffa889 7911->7936 7912->7906 7913 ffaccd 7913->7911 7916 ff9e01 ___free_lconv_mon 14 API calls 7913->7916 7915 ff9e01 ___free_lconv_mon 14 API calls 7914->7915 7915->7906 7916->7911 7944 ffa49b 7918->7944 7921 ffa9ca 7923 ffa9cf GetACP 7921->7923 7924 ffa9e1 7921->7924 7922 ffa9b8 GetOEMCP 7922->7924 7923->7924 7924->7900 7924->7906 7926 ffa997 70 API calls 7925->7926 7928 ffae80 7926->7928 7927 ffaf85 7930 ff5a25 _ValidateLocalCookies 5 API calls 7927->7930 7928->7927 7929 ffaebd IsValidCodePage 7928->7929 7932 ffaed8 __FrameHandler3::FrameUnwindToState 7928->7932 7929->7927 7931 ffaecf 7929->7931 7933 ffaca7 7930->7933 7931->7932 7934 ffaef8 GetCPInfo 7931->7934 7960 ffaa6b 7932->7960 7933->7908 7933->7913 7934->7927 7934->7932 7937 ffa895 __FrameHandler3::FrameUnwindToState 7936->7937 8043 ffb43d RtlEnterCriticalSection 7937->8043 7939 ffa89f 8044 ffa8d6 7939->8044 7945 ffa4b9 7944->7945 7951 ffa4b2 7944->7951 7946 ff97a0 _unexpected 68 API calls 7945->7946 7945->7951 7947 ffa4da 7946->7947 7952 ffd205 7947->7952 7951->7921 7951->7922 7953 ffa4f0 7952->7953 7954 ffd218 7952->7954 7956 ffd263 7953->7956 7954->7953 7955 ffc027 __FrameHandler3::FrameUnwindToState 68 API calls 7954->7955 7955->7953 7957 ffd28b 7956->7957 7958 ffd276 7956->7958 7957->7951 7958->7957 7959 ffae4d __FrameHandler3::FrameUnwindToState 68 API calls 7958->7959 7959->7957 7961 ffaa93 GetCPInfo 7960->7961 7970 ffab5c 7960->7970 7966 ffaaab 7961->7966 7961->7970 7963 ff5a25 _ValidateLocalCookies 5 API calls 7965 ffac0e 7963->7965 7965->7927 7971 ffbc3d 7966->7971 7969 ffdca3 70 API calls 7969->7970 7970->7963 7972 ffa49b 68 API calls 7971->7972 7973 ffbc5d 7972->7973 7991 ffb1ff 7973->7991 7975 ffbc8a 7976 ffbd11 7975->7976 7977 ffbd19 7975->7977 7981 ffbbef 15 API calls 7975->7981 7982 ffbcaf __FrameHandler3::FrameUnwindToState 7975->7982 7994 ffbd3e 7976->7994 7978 ff5a25 _ValidateLocalCookies 5 API calls 7977->7978 7979 ffab13 7978->7979 7986 ffdca3 7979->7986 7981->7982 7982->7976 7983 ffb1ff __FrameHandler3::FrameUnwindToState MultiByteToWideChar 7982->7983 7984 ffbcf8 7983->7984 7984->7976 7985 ffbcff GetStringTypeW 7984->7985 7985->7976 7987 ffa49b 68 API calls 7986->7987 7988 ffdcb6 7987->7988 8000 ffdab4 7988->8000 7998 ffb167 7991->7998 7995 ffbd5b 7994->7995 7996 ffbd4a 7994->7996 7995->7977 7996->7995 7997 ff9e01 ___free_lconv_mon 14 API calls 7996->7997 7997->7995 7999 ffb178 MultiByteToWideChar 7998->7999 7999->7975 8001 ffdacf 8000->8001 8002 ffb1ff __FrameHandler3::FrameUnwindToState MultiByteToWideChar 8001->8002 8005 ffdb13 8002->8005 8003 ffdc8e 8004 ff5a25 _ValidateLocalCookies 5 API calls 8003->8004 8006 ffab34 8004->8006 8005->8003 8007 ffbbef 15 API calls 8005->8007 8009 ffdb39 8005->8009 8020 ffdbe1 8005->8020 8006->7969 8007->8009 8008 ffbd3e __freea 14 API calls 8008->8003 8010 ffb1ff __FrameHandler3::FrameUnwindToState MultiByteToWideChar 8009->8010 8009->8020 8011 ffdb82 8010->8011 8011->8020 8028 ffc43f 8011->8028 8014 ffdbb8 8019 ffc43f 6 API calls 8014->8019 8014->8020 8015 ffdbf0 8016 ffdc79 8015->8016 8017 ffbbef 15 API calls 8015->8017 8021 ffdc02 8015->8021 8018 ffbd3e __freea 14 API calls 8016->8018 8017->8021 8018->8020 8019->8020 8020->8008 8021->8016 8022 ffc43f 6 API calls 8021->8022 8023 ffdc45 8022->8023 8023->8016 8024 ffb2b9 __FrameHandler3::FrameUnwindToState WideCharToMultiByte 8023->8024 8025 ffdc5f 8024->8025 8025->8016 8026 ffdc68 8025->8026 8027 ffbd3e __freea 14 API calls 8026->8027 8027->8020 8034 ffc112 8028->8034 8032 ffc450 8032->8014 8032->8015 8032->8020 8033 ffc490 LCMapStringW 8033->8032 8035 ffc211 __dosmaperr 5 API calls 8034->8035 8036 ffc128 8035->8036 8036->8032 8037 ffc49c 8036->8037 8040 ffc12c 8037->8040 8039 ffc4a7 8039->8033 8041 ffc211 __dosmaperr 5 API calls 8040->8041 8042 ffc142 8041->8042 8042->8039 8043->7939 8054 ffb065 8044->8054 8046 ffa8f8 8047 ffb065 29 API calls 8046->8047 8048 ffa917 8047->8048 8049 ffa8ac 8048->8049 8050 ff9e01 ___free_lconv_mon 14 API calls 8048->8050 8051 ffa8ca 8049->8051 8050->8049 8068 ffb485 RtlLeaveCriticalSection 8051->8068 8053 ffa8b8 8053->7914 8055 ffb076 8054->8055 8064 ffb072 CatchIt 8054->8064 8056 ffb07d 8055->8056 8059 ffb090 __FrameHandler3::FrameUnwindToState 8055->8059 8057 ff9d91 __dosmaperr 14 API calls 8056->8057 8058 ffb082 8057->8058 8060 ff9cb0 ___std_exception_copy 29 API calls 8058->8060 8061 ffb0be 8059->8061 8062 ffb0c7 8059->8062 8059->8064 8060->8064 8063 ff9d91 __dosmaperr 14 API calls 8061->8063 8062->8064 8066 ff9d91 __dosmaperr 14 API calls 8062->8066 8065 ffb0c3 8063->8065 8064->8046 8067 ff9cb0 ___std_exception_copy 29 API calls 8065->8067 8066->8065 8067->8064 8068->8053 8070 ff9d7e __dosmaperr 14 API calls 8069->8070 8071 ff9d42 __dosmaperr 8070->8071 8072 ff9d91 __dosmaperr 14 API calls 8071->8072 8073 ff9d55 8072->8073 8073->7853 8075 ffa49b 68 API calls 8074->8075 8076 ffa578 8075->8076 8077 ffa58a 8076->8077 8100 ffc2d6 8076->8100 8079 ffa6eb 8077->8079 8080 ffa6f8 8079->8080 8081 ffa707 8079->8081 8080->7853 8082 ffa70f 8081->8082 8083 ffa734 8081->8083 8082->8080 8106 ffa7ad 8082->8106 8084 ffb2b9 __FrameHandler3::FrameUnwindToState WideCharToMultiByte 8083->8084 8086 ffa744 8084->8086 8087 ffa74b GetLastError 8086->8087 8088 ffa761 8086->8088 8090 ff9d37 __dosmaperr 14 API calls 8087->8090 8089 ffa772 8088->8089 8092 ffa7ad 14 API calls 8088->8092 8089->8080 8110 ffa542 8089->8110 8091 ffa757 8090->8091 8094 ff9d91 __dosmaperr 14 API calls 8091->8094 8092->8089 8094->8080 8096 ffa78c GetLastError 8097 ff9d37 __dosmaperr 14 API calls 8096->8097 8098 ffa798 8097->8098 8099 ff9d91 __dosmaperr 14 API calls 8098->8099 8099->8080 8103 ffc0f8 8100->8103 8104 ffc211 __dosmaperr 5 API calls 8103->8104 8105 ffc10e 8104->8105 8105->8077 8107 ffa7b8 8106->8107 8108 ff9d91 __dosmaperr 14 API calls 8107->8108 8109 ffa7c1 8108->8109 8109->8080 8111 ffb2b9 __FrameHandler3::FrameUnwindToState WideCharToMultiByte 8110->8111 8112 ffa55f 8111->8112 8112->8080 8112->8096 8116 ffb0e6 8113->8116 8117 ffa49b 68 API calls 8116->8117 8118 ffb0f9 8117->8118 8118->7860 8213 ff66f1 8214 ff6715 8213->8214 8215 ff6703 8213->8215 8216 ff6913 __InternalCxxFrameHandler 78 API calls 8214->8216 8215->8214 8217 ff670b 8215->8217 8219 ff671a 8216->8219 8218 ff6713 8217->8218 8220 ff6913 __InternalCxxFrameHandler 78 API calls 8217->8220 8219->8218 8221 ff6913 __InternalCxxFrameHandler 78 API calls 8219->8221 8222 ff6733 8220->8222 8221->8218 8223 ff6913 __InternalCxxFrameHandler 78 API calls 8222->8223 8224 ff673e 8223->8224 8225 ff90eb _unexpected 68 API calls 8224->8225 8226 ff6746 8225->8226 8227 ff52ee 8228 ff52fe 8227->8228 8229 ff52fa 8227->8229 8232 ff530b ___scrt_release_startup_lock 8228->8232 8233 ff55a9 IsProcessorFeaturePresent 8228->8233 8231 ff5374 __FrameHandler3::FrameUnwindToState 8234 ff55bf __FrameHandler3::FrameUnwindToState 8233->8234 8235 ff566a IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 8234->8235 8236 ff56b5 __FrameHandler3::FrameUnwindToState 8235->8236 8236->8231 8735 ff8b6e 8736 ff97a0 _unexpected 68 API calls 8735->8736 8737 ff8b79 8736->8737 8738 ff9d91 __dosmaperr 14 API calls 8737->8738 8741 ff8bb1 8737->8741 8739 ff8ba6 8738->8739 8740 ff9cb0 ___std_exception_copy 29 API calls 8739->8740 8740->8741 8534 ff9fe8 8535 ff9ff8 8534->8535 8538 ffa00e 8534->8538 8536 ff9d91 __dosmaperr 14 API calls 8535->8536 8537 ff9ffd 8536->8537 8539 ff9cb0 ___std_exception_copy 29 API calls 8537->8539 8542 ffa079 8538->8542 8549 ffa08d 8538->8549 8558 ffa165 8538->8558 8541 ffa007 8539->8541 8540 ff8462 14 API calls 8544 ffa0bc 8540->8544 8542->8540 8542->8542 8545 ffa0c5 8544->8545 8553 ffa0db 8544->8553 8546 ff9e01 ___free_lconv_mon 14 API calls 8545->8546 8546->8549 8547 ffa13b 8548 ff9e01 ___free_lconv_mon 14 API calls 8547->8548 8551 ffa148 8548->8551 8576 ffa51d 8549->8576 8552 ffa51d 14 API calls 8551->8552 8552->8541 8553->8547 8555 ffa158 8553->8555 8582 ffd9c5 8553->8582 8556 ff9cc0 ___std_exception_copy 11 API calls 8555->8556 8557 ffa164 8556->8557 8559 ffa171 8558->8559 8559->8559 8560 ff9da4 __dosmaperr 14 API calls 8559->8560 8561 ffa19f 8560->8561 8562 ffd9c5 29 API calls 8561->8562 8563 ffa1cb 8562->8563 8564 ff9cc0 ___std_exception_copy 11 API calls 8563->8564 8565 ffa215 8564->8565 8566 ffa566 68 API calls 8565->8566 8567 ffa2dd 8566->8567 8591 ff9fcb 8567->8591 8570 ffa341 8571 ffa566 68 API calls 8570->8571 8572 ffa37e 8571->8572 8594 ff9f05 8572->8594 8575 ffa165 72 API calls 8580 ffa527 8576->8580 8577 ffa537 8579 ff9e01 ___free_lconv_mon 14 API calls 8577->8579 8578 ff9e01 ___free_lconv_mon 14 API calls 8578->8580 8581 ffa53e 8579->8581 8580->8577 8580->8578 8581->8541 8586 ffd90e 8582->8586 8583 ffd928 8584 ffd93c 8583->8584 8585 ff9d91 __dosmaperr 14 API calls 8583->8585 8584->8553 8587 ffd932 8585->8587 8586->8583 8586->8584 8589 ffd961 8586->8589 8588 ff9cb0 ___std_exception_copy 29 API calls 8587->8588 8588->8584 8589->8584 8590 ff9d91 __dosmaperr 14 API calls 8589->8590 8590->8587 8617 ff9e53 8591->8617 8595 ff9f2f 8594->8595 8596 ff9f13 8594->8596 8598 ff9f36 8595->8598 8599 ff9f52 8595->8599 8597 ffa5a5 14 API calls 8596->8597 8601 ff9f1d 8597->8601 8598->8601 8647 ffa5bf 8598->8647 8600 ffb2b9 __FrameHandler3::FrameUnwindToState WideCharToMultiByte 8599->8600 8602 ff9f62 8600->8602 8601->8575 8604 ff9f7f 8602->8604 8605 ff9f69 GetLastError 8602->8605 8607 ff9f90 8604->8607 8609 ffa5bf 15 API calls 8604->8609 8606 ff9d37 __dosmaperr 14 API calls 8605->8606 8608 ff9f75 8606->8608 8607->8601 8610 ffa542 WideCharToMultiByte 8607->8610 8611 ff9d91 __dosmaperr 14 API calls 8608->8611 8609->8607 8612 ff9fa6 8610->8612 8611->8601 8612->8601 8613 ff9faa GetLastError 8612->8613 8614 ff9d37 __dosmaperr 14 API calls 8613->8614 8615 ff9fb6 8614->8615 8616 ff9d91 __dosmaperr 14 API calls 8615->8616 8616->8601 8618 ff9e7b 8617->8618 8619 ff9e61 8617->8619 8621 ff9ea1 8618->8621 8623 ff9e82 8618->8623 8635 ffa5a5 8619->8635 8622 ffb1ff __FrameHandler3::FrameUnwindToState MultiByteToWideChar 8621->8622 8624 ff9eb0 8622->8624 8627 ff9e6b FindFirstFileExW 8623->8627 8639 ffa5fb 8623->8639 8626 ff9eb7 GetLastError 8624->8626 8629 ff9edd 8624->8629 8631 ffa5fb 15 API calls 8624->8631 8628 ff9d37 __dosmaperr 14 API calls 8626->8628 8627->8570 8630 ff9ec3 8628->8630 8629->8627 8632 ffb1ff __FrameHandler3::FrameUnwindToState MultiByteToWideChar 8629->8632 8633 ff9d91 __dosmaperr 14 API calls 8630->8633 8631->8629 8634 ff9ef4 8632->8634 8633->8627 8634->8626 8634->8627 8636 ffa5b8 8635->8636 8637 ffa5b0 8635->8637 8636->8627 8638 ff9e01 ___free_lconv_mon 14 API calls 8637->8638 8638->8636 8640 ffa5a5 14 API calls 8639->8640 8641 ffa609 8640->8641 8644 ffa63a 8641->8644 8645 ffbbef 15 API calls 8644->8645 8646 ffa61a 8645->8646 8646->8627 8648 ffa5a5 14 API calls 8647->8648 8649 ffa5cd 8648->8649 8650 ffa63a 15 API calls 8649->8650 8651 ffa5db 8650->8651 8651->8601 8292 ff9667 8293 ff9672 8292->8293 8297 ff9682 8292->8297 8298 ff9688 8293->8298 8296 ff9e01 ___free_lconv_mon 14 API calls 8296->8297 8299 ff969d 8298->8299 8300 ff96a3 8298->8300 8301 ff9e01 ___free_lconv_mon 14 API calls 8299->8301 8302 ff9e01 ___free_lconv_mon 14 API calls 8300->8302 8301->8300 8303 ff96af 8302->8303 8304 ff9e01 ___free_lconv_mon 14 API calls 8303->8304 8305 ff96ba 8304->8305 8306 ff9e01 ___free_lconv_mon 14 API calls 8305->8306 8307 ff96c5 8306->8307 8308 ff9e01 ___free_lconv_mon 14 API calls 8307->8308 8309 ff96d0 8308->8309 8310 ff9e01 ___free_lconv_mon 14 API calls 8309->8310 8311 ff96db 8310->8311 8312 ff9e01 ___free_lconv_mon 14 API calls 8311->8312 8313 ff96e6 8312->8313 8314 ff9e01 ___free_lconv_mon 14 API calls 8313->8314 8315 ff96f1 8314->8315 8316 ff9e01 ___free_lconv_mon 14 API calls 8315->8316 8317 ff96fc 8316->8317 8318 ff9e01 ___free_lconv_mon 14 API calls 8317->8318 8319 ff970a 8318->8319 8324 ff94b4 8319->8324 8325 ff94c0 __FrameHandler3::FrameUnwindToState 8324->8325 8340 ffb43d RtlEnterCriticalSection 8325->8340 8327 ff94f4 8341 ff9513 8327->8341 8329 ff94ca 8329->8327 8331 ff9e01 ___free_lconv_mon 14 API calls 8329->8331 8331->8327 8332 ff951f 8333 ff952b __FrameHandler3::FrameUnwindToState 8332->8333 8345 ffb43d RtlEnterCriticalSection 8333->8345 8335 ff9535 8346 ff9755 8335->8346 8337 ff9548 8350 ff9568 8337->8350 8340->8329 8344 ffb485 RtlLeaveCriticalSection 8341->8344 8343 ff9501 8343->8332 8344->8343 8345->8335 8347 ff9764 __dosmaperr 8346->8347 8349 ff978b __dosmaperr 8346->8349 8347->8349 8353 ffbddb 8347->8353 8349->8337 8467 ffb485 RtlLeaveCriticalSection 8350->8467 8352 ff9556 8352->8296 8355 ffbe5b 8353->8355 8356 ffbdf1 8353->8356 8357 ff9e01 ___free_lconv_mon 14 API calls 8355->8357 8380 ffbea9 8355->8380 8356->8355 8361 ff9e01 ___free_lconv_mon 14 API calls 8356->8361 8363 ffbe24 8356->8363 8358 ffbe7d 8357->8358 8359 ff9e01 ___free_lconv_mon 14 API calls 8358->8359 8364 ffbe90 8359->8364 8360 ff9e01 ___free_lconv_mon 14 API calls 8365 ffbe50 8360->8365 8367 ffbe19 8361->8367 8362 ffbeb7 8366 ffbf17 8362->8366 8373 ff9e01 14 API calls ___free_lconv_mon 8362->8373 8368 ff9e01 ___free_lconv_mon 14 API calls 8363->8368 8379 ffbe46 8363->8379 8369 ff9e01 ___free_lconv_mon 14 API calls 8364->8369 8370 ff9e01 ___free_lconv_mon 14 API calls 8365->8370 8371 ff9e01 ___free_lconv_mon 14 API calls 8366->8371 8381 ffb97f 8367->8381 8374 ffbe3b 8368->8374 8375 ffbe9e 8369->8375 8370->8355 8376 ffbf1d 8371->8376 8373->8362 8409 ffba7d 8374->8409 8378 ff9e01 ___free_lconv_mon 14 API calls 8375->8378 8376->8349 8378->8380 8379->8360 8421 ffbf4c 8380->8421 8382 ffb990 8381->8382 8408 ffba79 8381->8408 8383 ffb9a1 8382->8383 8384 ff9e01 ___free_lconv_mon 14 API calls 8382->8384 8385 ff9e01 ___free_lconv_mon 14 API calls 8383->8385 8386 ffb9b3 8383->8386 8384->8383 8385->8386 8387 ff9e01 ___free_lconv_mon 14 API calls 8386->8387 8391 ffb9c5 8386->8391 8387->8391 8388 ff9e01 ___free_lconv_mon 14 API calls 8390 ffb9d7 8388->8390 8389 ffb9e9 8393 ffb9fb 8389->8393 8394 ff9e01 ___free_lconv_mon 14 API calls 8389->8394 8390->8389 8392 ff9e01 ___free_lconv_mon 14 API calls 8390->8392 8391->8388 8391->8390 8392->8389 8395 ffba0d 8393->8395 8397 ff9e01 ___free_lconv_mon 14 API calls 8393->8397 8394->8393 8396 ffba1f 8395->8396 8398 ff9e01 ___free_lconv_mon 14 API calls 8395->8398 8399 ffba31 8396->8399 8400 ff9e01 ___free_lconv_mon 14 API calls 8396->8400 8397->8395 8398->8396 8401 ffba43 8399->8401 8402 ff9e01 ___free_lconv_mon 14 API calls 8399->8402 8400->8399 8403 ffba55 8401->8403 8405 ff9e01 ___free_lconv_mon 14 API calls 8401->8405 8402->8401 8404 ffba67 8403->8404 8406 ff9e01 ___free_lconv_mon 14 API calls 8403->8406 8407 ff9e01 ___free_lconv_mon 14 API calls 8404->8407 8404->8408 8405->8403 8406->8404 8407->8408 8408->8363 8410 ffba8a 8409->8410 8411 ffbae2 8409->8411 8412 ffba9a 8410->8412 8413 ff9e01 ___free_lconv_mon 14 API calls 8410->8413 8411->8379 8414 ffbaac 8412->8414 8415 ff9e01 ___free_lconv_mon 14 API calls 8412->8415 8413->8412 8416 ffbabe 8414->8416 8418 ff9e01 ___free_lconv_mon 14 API calls 8414->8418 8415->8414 8417 ffbad0 8416->8417 8419 ff9e01 ___free_lconv_mon 14 API calls 8416->8419 8417->8411 8420 ff9e01 ___free_lconv_mon 14 API calls 8417->8420 8418->8416 8419->8417 8420->8411 8422 ffbf78 8421->8422 8423 ffbf59 8421->8423 8422->8362 8423->8422 8427 ffbb0b 8423->8427 8426 ff9e01 ___free_lconv_mon 14 API calls 8426->8422 8428 ffbbe9 8427->8428 8429 ffbb1c 8427->8429 8428->8426 8463 ffbae6 8429->8463 8432 ffbae6 __dosmaperr 14 API calls 8433 ffbb2f 8432->8433 8434 ffbae6 __dosmaperr 14 API calls 8433->8434 8435 ffbb3a 8434->8435 8436 ffbae6 __dosmaperr 14 API calls 8435->8436 8437 ffbb45 8436->8437 8438 ffbae6 __dosmaperr 14 API calls 8437->8438 8439 ffbb53 8438->8439 8440 ff9e01 ___free_lconv_mon 14 API calls 8439->8440 8441 ffbb5e 8440->8441 8442 ff9e01 ___free_lconv_mon 14 API calls 8441->8442 8443 ffbb69 8442->8443 8444 ff9e01 ___free_lconv_mon 14 API calls 8443->8444 8445 ffbb74 8444->8445 8446 ffbae6 __dosmaperr 14 API calls 8445->8446 8447 ffbb82 8446->8447 8448 ffbae6 __dosmaperr 14 API calls 8447->8448 8449 ffbb90 8448->8449 8450 ffbae6 __dosmaperr 14 API calls 8449->8450 8451 ffbba1 8450->8451 8452 ffbae6 __dosmaperr 14 API calls 8451->8452 8453 ffbbaf 8452->8453 8454 ffbae6 __dosmaperr 14 API calls 8453->8454 8455 ffbbbd 8454->8455 8456 ff9e01 ___free_lconv_mon 14 API calls 8455->8456 8457 ffbbc8 8456->8457 8458 ff9e01 ___free_lconv_mon 14 API calls 8457->8458 8459 ffbbd3 8458->8459 8460 ff9e01 ___free_lconv_mon 14 API calls 8459->8460 8461 ffbbde 8460->8461 8462 ff9e01 ___free_lconv_mon 14 API calls 8461->8462 8462->8428 8464 ffbaf8 8463->8464 8465 ffbb07 8464->8465 8466 ff9e01 ___free_lconv_mon 14 API calls 8464->8466 8465->8432 8466->8464 8467->8352 8498 ff8627 8499 ff8639 8498->8499 8500 ff863f 8498->8500 8501 ff85f8 14 API calls 8499->8501 8501->8500 7748 ff5426 7749 ff5432 7748->7749 7750 ff5448 7749->7750 7754 ff905c 7749->7754 7752 ff5440 7759 ff654d 7752->7759 7755 ff9079 ___scrt_uninitialize_crt 7754->7755 7756 ff9067 7754->7756 7755->7752 7757 ff9075 7756->7757 7765 ffcc7a 7756->7765 7757->7752 7760 ff6556 7759->7760 7761 ff6560 7759->7761 7768 ff69e6 7760->7768 7761->7750 7766 ffcb0b ___scrt_uninitialize_crt 68 API calls 7765->7766 7767 ffcc81 7766->7767 7767->7757 7769 ff655b 7768->7769 7770 ff69f0 7768->7770 7772 ff6a3d 7769->7772 7776 ff6bc9 7770->7776 7773 ff6a48 7772->7773 7775 ff6a67 7772->7775 7774 ff6a52 RtlDeleteCriticalSection 7773->7774 7774->7774 7774->7775 7775->7761 7777 ff6aa3 ___vcrt_FlsFree 5 API calls 7776->7777 7778 ff6be3 7777->7778 7779 ff6bfb TlsFree 7778->7779 7780 ff6bef 7778->7780 7779->7780 7780->7769 8119 ffb563 8120 ffb592 8119->8120 8121 ffb570 8119->8121 8122 ffb57e RtlDeleteCriticalSection 8121->8122 8123 ffb58c 8121->8123 8122->8122 8122->8123 8124 ff9e01 ___free_lconv_mon 14 API calls 8123->8124 8124->8120 6892 ffc4e1 6893 ffc4ec 6892->6893 6894 ffc512 6892->6894 6893->6894 6895 ffc4fc FreeLibrary 6893->6895 6895->6893 7781 ffd420 7782 ffd45a 7781->7782 7783 ff9d91 __dosmaperr 14 API calls 7782->7783 7788 ffd46e 7782->7788 7784 ffd463 7783->7784 7785 ff9cb0 ___std_exception_copy 29 API calls 7784->7785 7785->7788 7786 ff5a25 _ValidateLocalCookies 5 API calls 7787 ffd47b 7786->7787 7788->7786 8685 1000260 8686 1000280 8685->8686 8689 10006f8 8686->8689 8690 1000737 __startOneArgErrorHandling 8689->8690 8694 10007bf __startOneArgErrorHandling 8690->8694 8697 1000b9e 8690->8697 8692 1000eb2 __startOneArgErrorHandling 14 API calls 8693 10007f4 8692->8693 8695 ff5a25 _ValidateLocalCookies 5 API calls 8693->8695 8694->8692 8694->8693 8696 10002a0 8695->8696 8698 1000bc1 __raise_exc RaiseException 8697->8698 8699 1000bbc 8698->8699 8699->8694 8742 ffb35c GetEnvironmentStringsW 8743 ffb374 8742->8743 8748 ffb3f7 8742->8748 8744 ffb2b9 __FrameHandler3::FrameUnwindToState WideCharToMultiByte 8743->8744 8745 ffb391 8744->8745 8746 ffb39b FreeEnvironmentStringsW 8745->8746 8747 ffb3a6 8745->8747 8746->8748 8749 ffbbef 15 API calls 8747->8749 8750 ffb3ad 8749->8750 8751 ffb3c6 8750->8751 8752 ffb3b5 8750->8752 8754 ffb2b9 __FrameHandler3::FrameUnwindToState WideCharToMultiByte 8751->8754 8753 ff9e01 ___free_lconv_mon 14 API calls 8752->8753 8755 ffb3ba FreeEnvironmentStringsW 8753->8755 8756 ffb3d6 8754->8756 8755->8748 8757 ffb3dd 8756->8757 8758 ffb3e5 8756->8758 8760 ff9e01 ___free_lconv_mon 14 API calls 8757->8760 8759 ff9e01 ___free_lconv_mon 14 API calls 8758->8759 8761 ffb3e3 FreeEnvironmentStringsW 8759->8761 8760->8761 8761->8748 6858 ff4e5a GetProcessHeap RtlAllocateHeap 6859 ff4e84 __FrameHandler3::FrameUnwindToState 6858->6859 6863 ff4f3b 6858->6863 6860 ff4e94 GetModuleFileNameW 6859->6860 6861 ff4f11 GetProcessHeap RtlFreeHeap 6860->6861 6864 ff4eaf _wcsrchr 6860->6864 6862 ff4f27 MulDiv 6861->6862 6861->6863 6862->6863 6864->6861 6865 ff4edb lstrlenW 6864->6865 6866 ff4eea 6865->6866 6866->6861 8468 ffa659 8469 ffa66b 8468->8469 8478 ffa667 8468->8478 8470 ffa696 8469->8470 8471 ffa670 8469->8471 8474 ffc517 32 API calls 8470->8474 8470->8478 8472 ff9da4 __dosmaperr 14 API calls 8471->8472 8473 ffa679 8472->8473 8475 ff9e01 ___free_lconv_mon 14 API calls 8473->8475 8476 ffa6b6 8474->8476 8475->8478 8477 ff9e01 ___free_lconv_mon 14 API calls 8476->8477 8477->8478 8125 10004a7 8126 10004c0 __startOneArgErrorHandling 8125->8126 8127 1000511 __startOneArgErrorHandling 8126->8127 8129 1000850 8126->8129 8130 1000889 __startOneArgErrorHandling 8129->8130 8132 10008b0 __startOneArgErrorHandling 8130->8132 8140 1000bc1 8130->8140 8133 10008f3 8132->8133 8134 10008ce 8132->8134 8152 1000eb2 8133->8152 8144 1000ee3 8134->8144 8137 10008ee __startOneArgErrorHandling 8138 ff5a25 _ValidateLocalCookies 5 API calls 8137->8138 8139 1000917 8138->8139 8139->8127 8141 1000bec __raise_exc 8140->8141 8142 1000de5 RaiseException 8141->8142 8143 1000dfd 8142->8143 8143->8132 8145 1000ef0 8144->8145 8146 1000eff __startOneArgErrorHandling 8145->8146 8149 1000f2e __startOneArgErrorHandling 8145->8149 8147 1000eb2 __startOneArgErrorHandling 14 API calls 8146->8147 8148 1000f18 8147->8148 8148->8137 8150 1000f7c 8149->8150 8151 1000eb2 __startOneArgErrorHandling 14 API calls 8149->8151 8150->8137 8151->8150 8153 1000ed6 8152->8153 8154 1000ebf 8152->8154 8155 ff9d91 __dosmaperr 14 API calls 8153->8155 8156 ff9d91 __dosmaperr 14 API calls 8154->8156 8157 1000edb 8154->8157 8155->8157 8158 1000ece 8156->8158 8157->8137 8158->8137 8180 ff8516 8181 ff852b 8180->8181 8182 ff9da4 __dosmaperr 14 API calls 8181->8182 8183 ff8552 8182->8183 8184 ff855a 8183->8184 8190 ff8564 8183->8190 8185 ff9e01 ___free_lconv_mon 14 API calls 8184->8185 8186 ff8560 8185->8186 8187 ff85c1 8188 ff9e01 ___free_lconv_mon 14 API calls 8187->8188 8188->8186 8189 ff9da4 __dosmaperr 14 API calls 8189->8190 8190->8187 8190->8189 8191 ff85d0 8190->8191 8192 ff914d ___std_exception_copy 29 API calls 8190->8192 8196 ff85eb 8190->8196 8198 ff9e01 ___free_lconv_mon 14 API calls 8190->8198 8202 ff85f8 8191->8202 8192->8190 8195 ff9e01 ___free_lconv_mon 14 API calls 8197 ff85dd 8195->8197 8199 ff9cc0 ___std_exception_copy 11 API calls 8196->8199 8200 ff9e01 ___free_lconv_mon 14 API calls 8197->8200 8198->8190 8201 ff85f7 8199->8201 8200->8186 8203 ff8605 8202->8203 8204 ff85d6 8202->8204 8205 ff861c 8203->8205 8206 ff9e01 ___free_lconv_mon 14 API calls 8203->8206 8204->8195 8207 ff9e01 ___free_lconv_mon 14 API calls 8205->8207 8206->8203 8207->8204 8479 ff8a55 8480 ff8a6b __FrameHandler3::FrameUnwindToState __dosmaperr 8479->8480 8481 ff97a0 _unexpected 68 API calls 8480->8481 8484 ff90fc 8481->8484 8482 ff91a7 __FrameHandler3::FrameUnwindToState 68 API calls 8483 ff9126 8482->8483 8484->8482 7789 ff79d4 7792 ff7f27 7789->7792 7791 ff79e9 7793 ff7f3b 7792->7793 7794 ff7f34 7792->7794 7793->7791 7795 ff9127 ___std_exception_copy 14 API calls 7794->7795 7795->7793 8285 ff8a91 8286 ff8ac3 8285->8286 8287 ff8aa0 8285->8287 8287->8286 8288 ff9d91 __dosmaperr 14 API calls 8287->8288 8289 ff8ab3 8288->8289 8290 ff9cb0 ___std_exception_copy 29 API calls 8289->8290 8291 ff8abe 8290->8291 6896 ff5490 GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter 7796 fff9d0 7799 fff9ee 7796->7799 7798 fff9e6 7802 fff9f3 7799->7802 7800 fffa88 7800->7798 7802->7800 7804 10002b3 7802->7804 7805 10002c6 RtlDecodePointer 7804->7805 7807 10002d6 7804->7807 7805->7807 7806 100031a 7809 ff9d91 __dosmaperr 14 API calls 7806->7809 7811 fffc1f 7806->7811 7807->7806 7808 1000305 7807->7808 7807->7811 7810 ff9d91 __dosmaperr 14 API calls 7808->7810 7808->7811 7809->7811 7810->7811 7811->7798 8502 ffda10 8505 ffda27 8502->8505 8504 ffda22 8506 ffda49 8505->8506 8507 ffda35 8505->8507 8508 ffda63 8506->8508 8509 ffda51 8506->8509 8510 ff9d91 __dosmaperr 14 API calls 8507->8510 8512 ffda61 8508->8512 8515 ffa49b 68 API calls 8508->8515 8511 ff9d91 __dosmaperr 14 API calls 8509->8511 8513 ffda3a 8510->8513 8514 ffda56 8511->8514 8512->8504 8516 ff9cb0 ___std_exception_copy 29 API calls 8513->8516 8517 ff9cb0 ___std_exception_copy 29 API calls 8514->8517 8515->8512 8518 ffda45 8516->8518 8517->8512 8518->8504 8659 ff63d0 8660 ff63ee __InternalCxxFrameHandler 8659->8660 8671 ff6390 8660->8671 8672 ff63af 8671->8672 8673 ff63a2 8671->8673 8674 ff5a25 _ValidateLocalCookies 5 API calls 8673->8674 8674->8672 8485 ff664e 8486 ff6687 8485->8486 8487 ff6657 8485->8487 8487->8486 8488 ff6913 __InternalCxxFrameHandler 78 API calls 8487->8488 8489 ff6692 8488->8489 8490 ff6913 __InternalCxxFrameHandler 78 API calls 8489->8490 8491 ff669d 8490->8491 8492 ff90eb _unexpected 68 API calls 8491->8492 8493 ff66a5 8492->8493 7055 fff04d 7056 fff060 __FrameHandler3::FrameUnwindToState 7055->7056 7059 ffef28 7056->7059 7058 fff06c __FrameHandler3::FrameUnwindToState 7060 ffef34 __FrameHandler3::FrameUnwindToState 7059->7060 7061 ffef3e 7060->7061 7062 ffef61 7060->7062 7063 ff9c33 ___std_exception_copy 29 API calls 7061->7063 7069 ffef59 7062->7069 7070 ffcd97 RtlEnterCriticalSection 7062->7070 7063->7069 7065 ffef7f 7071 ffefbf 7065->7071 7067 ffef8c 7085 ffefb7 7067->7085 7069->7058 7070->7065 7072 ffefef 7071->7072 7073 ffefcc 7071->7073 7083 ffefe7 7072->7083 7088 ffcbac 7072->7088 7074 ff9c33 ___std_exception_copy 29 API calls 7073->7074 7074->7083 7080 fff01b 7105 fff83c 7080->7105 7083->7067 7084 ff9e01 ___free_lconv_mon 14 API calls 7084->7083 7362 ffcdab RtlLeaveCriticalSection 7085->7362 7087 ffefbd 7087->7069 7089 ffcbc5 7088->7089 7093 ffcbec 7088->7093 7090 ffd3f4 __FrameHandler3::FrameUnwindToState 29 API calls 7089->7090 7089->7093 7091 ffcbe1 7090->7091 7112 ffe723 7091->7112 7094 ffeafb 7093->7094 7095 ffeb24 7094->7095 7096 ffeb12 7094->7096 7098 ffd3f4 7095->7098 7096->7095 7097 ff9e01 ___free_lconv_mon 14 API calls 7096->7097 7097->7095 7099 ffd415 7098->7099 7100 ffd400 7098->7100 7099->7080 7101 ff9d91 __dosmaperr 14 API calls 7100->7101 7102 ffd405 7101->7102 7103 ff9cb0 ___std_exception_copy 29 API calls 7102->7103 7104 ffd410 7103->7104 7104->7080 7106 fff865 7105->7106 7111 fff022 7105->7111 7107 fff8b4 7106->7107 7109 fff88c 7106->7109 7108 ff9c33 ___std_exception_copy 29 API calls 7107->7108 7108->7111 7327 fff7ab 7109->7327 7111->7083 7111->7084 7113 ffe72f __FrameHandler3::FrameUnwindToState 7112->7113 7114 ffe770 7113->7114 7116 ffe7b6 7113->7116 7122 ffe737 7113->7122 7115 ff9c33 ___std_exception_copy 29 API calls 7114->7115 7115->7122 7123 ffb636 RtlEnterCriticalSection 7116->7123 7118 ffe7bc 7119 ffe7da 7118->7119 7124 ffe834 7118->7124 7150 ffe82c 7119->7150 7122->7093 7123->7118 7125 ffe85c 7124->7125 7128 ffe87f __FrameHandler3::FrameUnwindToState 7124->7128 7126 ffe860 7125->7126 7129 ffe8bb 7125->7129 7127 ff9c33 ___std_exception_copy 29 API calls 7126->7127 7127->7128 7128->7119 7130 ffe8d9 7129->7130 7153 ffeed8 7129->7153 7156 ffe3b0 7130->7156 7134 ffe938 7138 ffe94c 7134->7138 7139 ffe9a1 WriteFile 7134->7139 7135 ffe8f1 7136 ffe8f9 7135->7136 7137 ffe920 7135->7137 7136->7128 7163 ffe348 7136->7163 7168 ffdf81 GetConsoleOutputCP 7137->7168 7140 ffe98d 7138->7140 7141 ffe954 7138->7141 7139->7128 7143 ffe9c3 GetLastError 7139->7143 7196 ffe42d 7140->7196 7144 ffe979 7141->7144 7145 ffe959 7141->7145 7143->7128 7188 ffe5f1 7144->7188 7145->7128 7181 ffe508 7145->7181 7326 ffb659 RtlLeaveCriticalSection 7150->7326 7152 ffe832 7152->7122 7203 ffee55 7153->7203 7155 ffeef1 7155->7130 7225 ffeb3b 7156->7225 7158 ffe426 7158->7134 7158->7135 7159 ffe3c2 7159->7158 7160 ffe3f0 7159->7160 7234 ff9350 7159->7234 7160->7158 7162 ffe40a GetConsoleMode 7160->7162 7162->7158 7165 ffe36a 7163->7165 7167 ffe39f 7163->7167 7164 ffe3a1 GetLastError 7164->7167 7165->7164 7166 ffeef6 5 API calls __FrameHandler3::FrameUnwindToState 7165->7166 7165->7167 7166->7165 7167->7128 7169 ffdff3 7168->7169 7174 ffdffa CatchIt 7168->7174 7170 ff9350 __FrameHandler3::FrameUnwindToState 64 API calls 7169->7170 7170->7174 7171 ff5a25 _ValidateLocalCookies 5 API calls 7172 ffe341 7171->7172 7172->7128 7173 ffe2b0 7173->7171 7174->7173 7175 ffd2c1 64 API calls __FrameHandler3::FrameUnwindToState 7174->7175 7176 ffed31 5 API calls __FrameHandler3::FrameUnwindToState 7174->7176 7178 ffe229 WriteFile 7174->7178 7180 ffe267 WriteFile 7174->7180 7323 ffb2b9 7174->7323 7175->7174 7176->7174 7178->7174 7179 ffe31f GetLastError 7178->7179 7179->7173 7180->7174 7180->7179 7182 ffe517 __FrameHandler3::FrameUnwindToState 7181->7182 7183 ffe5d6 7182->7183 7185 ffe58c WriteFile 7182->7185 7184 ff5a25 _ValidateLocalCookies 5 API calls 7183->7184 7187 ffe5ef 7184->7187 7185->7182 7186 ffe5d8 GetLastError 7185->7186 7186->7183 7187->7128 7192 ffe600 __FrameHandler3::FrameUnwindToState 7188->7192 7189 ffe708 7190 ff5a25 _ValidateLocalCookies 5 API calls 7189->7190 7191 ffe721 7190->7191 7191->7128 7192->7189 7193 ffb2b9 __FrameHandler3::FrameUnwindToState WideCharToMultiByte 7192->7193 7194 ffe70a GetLastError 7192->7194 7195 ffe6bf WriteFile 7192->7195 7193->7192 7194->7189 7195->7192 7195->7194 7197 ffe43c __FrameHandler3::FrameUnwindToState 7196->7197 7200 ffe4ac WriteFile 7197->7200 7202 ffe4ed 7197->7202 7198 ff5a25 _ValidateLocalCookies 5 API calls 7199 ffe506 7198->7199 7199->7128 7200->7197 7201 ffe4ef GetLastError 7200->7201 7201->7202 7202->7198 7209 ffb70d 7203->7209 7205 ffee67 7206 ffee83 SetFilePointerEx 7205->7206 7208 ffee6f __FrameHandler3::FrameUnwindToState 7205->7208 7207 ffee9b GetLastError 7206->7207 7206->7208 7207->7208 7208->7155 7210 ffb72f 7209->7210 7211 ffb71a 7209->7211 7214 ff9d7e __dosmaperr 14 API calls 7210->7214 7216 ffb754 7210->7216 7222 ff9d7e 7211->7222 7217 ffb75f 7214->7217 7215 ff9d91 __dosmaperr 14 API calls 7218 ffb727 7215->7218 7216->7205 7219 ff9d91 __dosmaperr 14 API calls 7217->7219 7218->7205 7220 ffb767 7219->7220 7221 ff9cb0 ___std_exception_copy 29 API calls 7220->7221 7221->7218 7223 ff98f1 __dosmaperr 14 API calls 7222->7223 7224 ff9d83 7223->7224 7224->7215 7226 ffeb48 7225->7226 7227 ffeb55 7225->7227 7228 ff9d91 __dosmaperr 14 API calls 7226->7228 7230 ffeb61 7227->7230 7231 ff9d91 __dosmaperr 14 API calls 7227->7231 7229 ffeb4d 7228->7229 7229->7159 7230->7159 7232 ffeb82 7231->7232 7233 ff9cb0 ___std_exception_copy 29 API calls 7232->7233 7233->7229 7235 ff9360 7234->7235 7240 ffd232 7235->7240 7241 ffd249 7240->7241 7243 ff937d 7240->7243 7241->7243 7248 ffc027 7241->7248 7244 ffd290 7243->7244 7245 ff938a 7244->7245 7246 ffd2a7 7244->7246 7245->7160 7246->7245 7307 ffae4d 7246->7307 7249 ffc033 __FrameHandler3::FrameUnwindToState 7248->7249 7261 ff97a0 GetLastError 7249->7261 7253 ffc05a 7289 ffc0a8 7253->7289 7258 ffc082 7258->7243 7262 ff97b6 7261->7262 7263 ff97bc 7261->7263 7265 ffc373 __dosmaperr 6 API calls 7262->7265 7264 ffc3b2 __dosmaperr 6 API calls 7263->7264 7267 ff97c0 SetLastError 7263->7267 7266 ff97d8 7264->7266 7265->7263 7266->7267 7269 ff9da4 __dosmaperr 14 API calls 7266->7269 7271 ff9855 7267->7271 7272 ff9850 7267->7272 7270 ff97ed 7269->7270 7273 ff9806 7270->7273 7274 ff97f5 7270->7274 7275 ff91a7 __FrameHandler3::FrameUnwindToState 66 API calls 7271->7275 7272->7258 7288 ffb43d RtlEnterCriticalSection 7272->7288 7277 ffc3b2 __dosmaperr 6 API calls 7273->7277 7276 ffc3b2 __dosmaperr 6 API calls 7274->7276 7278 ff985a 7275->7278 7279 ff9803 7276->7279 7280 ff9812 7277->7280 7283 ff9e01 ___free_lconv_mon 14 API calls 7279->7283 7281 ff982d 7280->7281 7282 ff9816 7280->7282 7284 ff95ce __dosmaperr 14 API calls 7281->7284 7285 ffc3b2 __dosmaperr 6 API calls 7282->7285 7283->7267 7286 ff9838 7284->7286 7285->7279 7287 ff9e01 ___free_lconv_mon 14 API calls 7286->7287 7287->7267 7288->7253 7290 ffc0b6 __dosmaperr 7289->7290 7292 ffc06b 7289->7292 7291 ffbddb __dosmaperr 14 API calls 7290->7291 7290->7292 7291->7292 7293 ffc087 7292->7293 7294 ffb485 __FrameHandler3::FrameUnwindToState RtlLeaveCriticalSection 7293->7294 7295 ffc07e 7294->7295 7295->7258 7296 ff91a7 7295->7296 7297 ffc79c __FrameHandler3::FrameUnwindToState RtlEnterCriticalSection RtlLeaveCriticalSection 7296->7297 7298 ff91ac 7297->7298 7299 ffc7e1 __FrameHandler3::FrameUnwindToState 67 API calls 7298->7299 7302 ff91b7 7298->7302 7299->7302 7300 ff91e0 7304 ff8a3f __FrameHandler3::FrameUnwindToState 21 API calls 7300->7304 7301 ff91c1 IsProcessorFeaturePresent 7303 ff91cd 7301->7303 7302->7300 7302->7301 7305 ff9ab4 __FrameHandler3::FrameUnwindToState 8 API calls 7303->7305 7306 ff91ea 7304->7306 7305->7300 7308 ff97a0 _unexpected 68 API calls 7307->7308 7309 ffae52 7308->7309 7312 ffad65 7309->7312 7313 ffad71 __FrameHandler3::FrameUnwindToState 7312->7313 7314 ffb43d __FrameHandler3::FrameUnwindToState RtlEnterCriticalSection 7313->7314 7315 ffad8b 7313->7315 7321 ffad9b 7314->7321 7316 ffad92 7315->7316 7318 ff91a7 __FrameHandler3::FrameUnwindToState 68 API calls 7315->7318 7316->7245 7317 ffadc7 7319 ffade4 __FrameHandler3::FrameUnwindToState RtlLeaveCriticalSection 7317->7319 7320 ffae04 7318->7320 7319->7315 7321->7317 7322 ff9e01 ___free_lconv_mon 14 API calls 7321->7322 7322->7317 7325 ffb2cc __FrameHandler3::FrameUnwindToState 7323->7325 7324 ffb30a WideCharToMultiByte 7324->7174 7325->7324 7326->7152 7328 fff7b7 __FrameHandler3::FrameUnwindToState 7327->7328 7335 ffb636 RtlEnterCriticalSection 7328->7335 7330 fff7c5 7331 fff7f6 7330->7331 7336 fff8df 7330->7336 7349 fff830 7331->7349 7335->7330 7337 ffb70d __FrameHandler3::FrameUnwindToState 29 API calls 7336->7337 7340 fff8ef 7337->7340 7338 fff8f5 7352 ffb67c 7338->7352 7340->7338 7341 ffb70d __FrameHandler3::FrameUnwindToState 29 API calls 7340->7341 7348 fff927 7340->7348 7344 fff91e 7341->7344 7342 ffb70d __FrameHandler3::FrameUnwindToState 29 API calls 7345 fff933 CloseHandle 7342->7345 7343 fff94d __FrameHandler3::FrameUnwindToState 7343->7331 7346 ffb70d __FrameHandler3::FrameUnwindToState 29 API calls 7344->7346 7345->7338 7347 fff93f GetLastError 7345->7347 7346->7348 7347->7338 7348->7338 7348->7342 7361 ffb659 RtlLeaveCriticalSection 7349->7361 7351 fff819 7351->7111 7353 ffb68b 7352->7353 7354 ffb6f2 7352->7354 7353->7354 7359 ffb6b5 7353->7359 7355 ff9d91 __dosmaperr 14 API calls 7354->7355 7356 ffb6f7 7355->7356 7357 ff9d7e __dosmaperr 14 API calls 7356->7357 7358 ffb6e2 7357->7358 7358->7343 7359->7358 7360 ffb6dc SetStdHandle 7359->7360 7360->7358 7361->7351 7362->7087 8700 ffb78d GetStartupInfoW 8701 ffb7aa 8700->8701 8702 ffb83e 8700->8702 8701->8702 8706 ffb598 8701->8706 8704 ffb7d2 8704->8702 8705 ffb802 GetFileType 8704->8705 8705->8704 8707 ffb5a4 __FrameHandler3::FrameUnwindToState 8706->8707 8708 ffb5ce 8707->8708 8709 ffb5ad 8707->8709 8719 ffb43d RtlEnterCriticalSection 8708->8719 8710 ff9d91 __dosmaperr 14 API calls 8709->8710 8712 ffb5b2 8710->8712 8713 ff9cb0 ___std_exception_copy 29 API calls 8712->8713 8715 ffb5bc 8713->8715 8714 ffb606 8727 ffb62d 8714->8727 8715->8704 8716 ffb5da 8716->8714 8720 ffb4e8 8716->8720 8719->8716 8721 ff9da4 __dosmaperr 14 API calls 8720->8721 8723 ffb4fa 8721->8723 8722 ffb507 8724 ff9e01 ___free_lconv_mon 14 API calls 8722->8724 8723->8722 8725 ffc3f4 6 API calls 8723->8725 8726 ffb55c 8724->8726 8725->8723 8726->8716 8730 ffb485 RtlLeaveCriticalSection 8727->8730 8729 ffb634 8729->8715 8730->8729 6897 ff908c 6898 ff90aa 6897->6898 6900 ff90ca 6897->6900 6899 ff9d91 __dosmaperr 14 API calls 6898->6899 6901 ff90c0 6899->6901 6903 ff9cb0 6901->6903 6906 ff9bfc 6903->6906 6905 ff9cbc 6905->6900 6907 ff9c0e __FrameHandler3::FrameUnwindToState 6906->6907 6910 ff9c33 6907->6910 6909 ff9c26 __FrameHandler3::FrameUnwindToState 6909->6905 6911 ff9c43 6910->6911 6913 ff9c4a 6910->6913 6921 ff92a0 GetLastError 6911->6921 6917 ff9c58 6913->6917 6925 ff9a8b 6913->6925 6915 ff9c7f 6915->6917 6928 ff9cc0 IsProcessorFeaturePresent 6915->6928 6917->6909 6918 ff9caf 6919 ff9bfc ___std_exception_copy 29 API calls 6918->6919 6920 ff9cbc 6919->6920 6920->6909 6922 ff92b9 6921->6922 6932 ff99a2 6922->6932 6926 ff9aaf 6925->6926 6927 ff9a96 GetLastError SetLastError 6925->6927 6926->6915 6927->6915 6929 ff9ccc 6928->6929 6954 ff9ab4 6929->6954 6933 ff99bb 6932->6933 6934 ff99b5 6932->6934 6936 ffc3b2 __dosmaperr 6 API calls 6933->6936 6938 ff92d5 SetLastError 6933->6938 6935 ffc373 __dosmaperr 6 API calls 6934->6935 6935->6933 6937 ff99d5 6936->6937 6937->6938 6939 ff9da4 __dosmaperr 14 API calls 6937->6939 6938->6913 6940 ff99e5 6939->6940 6941 ff99ed 6940->6941 6942 ff9a02 6940->6942 6944 ffc3b2 __dosmaperr 6 API calls 6941->6944 6943 ffc3b2 __dosmaperr 6 API calls 6942->6943 6946 ff9a0e 6943->6946 6945 ff99f9 6944->6945 6949 ff9e01 ___free_lconv_mon 14 API calls 6945->6949 6947 ff9a12 6946->6947 6948 ff9a21 6946->6948 6950 ffc3b2 __dosmaperr 6 API calls 6947->6950 6951 ff95ce __dosmaperr 14 API calls 6948->6951 6949->6938 6950->6945 6952 ff9a2c 6951->6952 6953 ff9e01 ___free_lconv_mon 14 API calls 6952->6953 6953->6938 6955 ff9ad0 __FrameHandler3::FrameUnwindToState 6954->6955 6956 ff9afc IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 6955->6956 6959 ff9bcd __FrameHandler3::FrameUnwindToState 6956->6959 6958 ff9beb GetCurrentProcess TerminateProcess 6958->6918 6960 ff5a25 6959->6960 6961 ff5a2e IsProcessorFeaturePresent 6960->6961 6962 ff5a2d 6960->6962 6964 ff5a70 6961->6964 6962->6958 6967 ff5a33 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 6964->6967 6966 ff5b53 6966->6958 6967->6966 8799 ff6f0a 8800 ff5a25 _ValidateLocalCookies 5 API calls 8799->8800 8801 ff6f1c ___CxxFrameHandler 8800->8801 8731 1000277 8732 1000280 8731->8732 8733 10006f8 __startOneArgErrorHandling 20 API calls 8732->8733 8734 10002a0 8733->8734 8763 ff5748 8764 ff577f 8763->8764 8765 ff575a 8763->8765 8765->8764 8772 ff6747 8765->8772 8770 ff90eb _unexpected 68 API calls 8771 ff579d 8770->8771 8773 ff6913 __InternalCxxFrameHandler 78 API calls 8772->8773 8774 ff578c 8773->8774 8775 ff6750 8774->8775 8776 ff6913 __InternalCxxFrameHandler 78 API calls 8775->8776 8777 ff5796 8776->8777 8777->8770 8778 ff8b47 8781 ff8ace 8778->8781 8782 ff8ada __FrameHandler3::FrameUnwindToState 8781->8782 8789 ffb43d RtlEnterCriticalSection 8782->8789 8784 ff8b12 8790 ff8b30 8784->8790 8785 ff8ae4 8785->8784 8787 ffc0a8 __FrameHandler3::FrameUnwindToState 14 API calls 8785->8787 8787->8785 8789->8785 8793 ffb485 RtlLeaveCriticalSection 8790->8793 8792 ff8b1e 8793->8792 8159 ff7945 8162 ff7978 8159->8162 8165 ff7ec4 8162->8165 8166 ff7953 8165->8166 8168 ff7ed1 ___std_exception_copy 8165->8168 8167 ff7efe 8170 ff9127 ___std_exception_copy 14 API calls 8167->8170 8168->8166 8168->8167 8171 ff914d 8168->8171 8170->8166 8172 ff9169 8171->8172 8173 ff915b 8171->8173 8174 ff9d91 __dosmaperr 14 API calls 8172->8174 8173->8172 8175 ff9181 8173->8175 8179 ff9171 8174->8179 8177 ff917b 8175->8177 8178 ff9d91 __dosmaperr 14 API calls 8175->8178 8176 ff9cb0 ___std_exception_copy 29 API calls 8176->8177 8177->8167 8178->8179 8179->8176 8237 ff56c4 8241 ff60e0 8237->8241 8240 ff56ea 8242 ff56d7 GetStartupInfoW 8241->8242 8242->8240 8675 ff7fc0 8676 ff98f1 __dosmaperr 14 API calls 8675->8676 8677 ff7fcd 8676->8677

                              Control-flow Graph

                              APIs
                              • GetProcessHeap.KERNEL32(00000000,3B9ACA00), ref: 00FF4E6D
                              • RtlAllocateHeap.NTDLL(00000000), ref: 00FF4E74
                              • GetModuleFileNameW.KERNEL32(00000000,?,00000104), ref: 00FF4EA5
                              • _wcsrchr.LIBVCRUNTIME ref: 00FF4EB8
                              • lstrlenW.KERNEL32(-00000002), ref: 00FF4EDD
                              • GetProcessHeap.KERNEL32(00000000,00000000), ref: 00FF4F14
                              • RtlFreeHeap.NTDLL(00000000), ref: 00FF4F1B
                              • MulDiv.KERNEL32(00000001,80000000,80000000), ref: 00FF4F30
                              Strings
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID: Heap$Process$AllocateFileFreeModuleName_wcsrchrlstrlen
                              • String ID: $($@
                              • API String ID: 443335681-2581157662
                              • Opcode ID: 5169fbdad22cc45b85dcffbd38041d0d88b06016d1200044e19a1791bc4cfeee
                              • Instruction ID: 4006ba2a31992ca5a5074df201fdb68f71826ef8fa532fd33378776bc7a7d2f3
                              • Opcode Fuzzy Hash: 5169fbdad22cc45b85dcffbd38041d0d88b06016d1200044e19a1791bc4cfeee
                              • Instruction Fuzzy Hash: EE210472D00308AEE7315264AC8EB7B3668DF45370F210115F709D71E6EB6DAC40EA61

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 26 ffc146-ffc152 27 ffc1e4-ffc1e7 26->27 28 ffc1ed 27->28 29 ffc157-ffc168 27->29 30 ffc1ef-ffc1f3 28->30 31 ffc16a-ffc16d 29->31 32 ffc175-ffc18e LoadLibraryExW 29->32 33 ffc20d-ffc20f 31->33 34 ffc173 31->34 35 ffc1f4-ffc204 32->35 36 ffc190-ffc199 GetLastError 32->36 33->30 38 ffc1e1 34->38 35->33 37 ffc206-ffc207 FreeLibrary 35->37 39 ffc19b-ffc1ad call ff9428 36->39 40 ffc1d2-ffc1df 36->40 37->33 38->27 39->40 43 ffc1af-ffc1c1 call ff9428 39->43 40->38 43->40 46 ffc1c3-ffc1d0 LoadLibraryExW 43->46 46->35 46->40
                              APIs
                              • FreeLibrary.KERNEL32(00000000,?,00FFC255,00FFCAD9,?,00000000,00000000,00000000,?,00FFC3CE,00000022,FlsSetValue,01014078,01014080,00000000), ref: 00FFC207
                              Strings
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID: FreeLibrary
                              • String ID: api-ms-$ext-ms-
                              • API String ID: 3664257935-537541572
                              • Opcode ID: 3d73411b40433042dc8e79aa2bf1cb0adcfb09b9410df000a02f457549b08180
                              • Instruction ID: 8eae847ce8d63314b9fedf00dc2d04643e457661ef27392b2d76858bf8002ab1
                              • Opcode Fuzzy Hash: 3d73411b40433042dc8e79aa2bf1cb0adcfb09b9410df000a02f457549b08180
                              • Instruction Fuzzy Hash: C8212732E4112DABCB328A60DD40A7A7769EF417B0F210214FE55E7296D779EE10D7E0

                              Control-flow Graph

                              APIs
                              • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000004,00000000,?,?), ref: 01002314
                                • Part of subcall function 01002098: VirtualAlloc.KERNELBASE(00000000,00001012,00001000,00000004), ref: 010020C1
                                • Part of subcall function 01002098: VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 0100226D
                              • VirtualAlloc.KERNELBASE(00000000,00400000,00001000,00000004), ref: 01002366
                              • VirtualProtect.KERNELBASE(0000002C,?,00000040,0000002C), ref: 010023C0
                              • VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 010023F3
                              Strings
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID: Virtual$Alloc$Free$Protect
                              • String ID: ,
                              • API String ID: 1004437363-3772416878
                              • Opcode ID: 846e80d9192284de11e110977aaee4205ca63ec1a267e246cbf1a7208dcc7df3
                              • Instruction ID: 24c570a7d23d2d6015eb3944a1f18c7c3fd122eb04dc84d9ee34956988aee8a9
                              • Opcode Fuzzy Hash: 846e80d9192284de11e110977aaee4205ca63ec1a267e246cbf1a7208dcc7df3
                              • Instruction Fuzzy Hash: 8451077590071AAFDB11CFA9C884B9EBBF4FF08344F10851AF959A7280D770E954CBA4
                              APIs
                              • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000004,00000000,?,?), ref: 01002314
                                • Part of subcall function 01002098: VirtualAlloc.KERNELBASE(00000000,00001012,00001000,00000004), ref: 010020C1
                                • Part of subcall function 01002098: VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 0100226D
                              • VirtualAlloc.KERNELBASE(00000000,00400000,00001000,00000004), ref: 01002366
                              • VirtualProtect.KERNELBASE(0000002C,?,00000040,0000002C), ref: 010023C0
                              • VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 010023F3
                              Strings
                              Memory Dump Source
                              • Source File: 00000004.00000003.1390003579.0000000001002000.00000040.00000001.01000000.00000008.sdmp, Offset: 01002000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_3_1002000_nUCp.jbxd
                              Similarity
                              • API ID: Virtual$Alloc$Free$Protect
                              • String ID: ,
                              • API String ID: 1004437363-3772416878
                              • Opcode ID: 846e80d9192284de11e110977aaee4205ca63ec1a267e246cbf1a7208dcc7df3
                              • Instruction ID: 24c570a7d23d2d6015eb3944a1f18c7c3fd122eb04dc84d9ee34956988aee8a9
                              • Opcode Fuzzy Hash: 846e80d9192284de11e110977aaee4205ca63ec1a267e246cbf1a7208dcc7df3
                              • Instruction Fuzzy Hash: 8451077590071AAFDB11CFA9C884B9EBBF4FF08344F10851AF959A7280D770E954CBA4

                              Control-flow Graph

                              APIs
                              • GetCurrentProcess.KERNEL32(00FF8A50,?,00FF8940,00000000,?,?,00FF8A50,BCC996EE,?,00FF8A50), ref: 00FF8957
                              • TerminateProcess.KERNEL32(00000000,?,00FF8940,00000000,?,?,00FF8A50,BCC996EE,?,00FF8A50), ref: 00FF895E
                              • ExitProcess.KERNEL32 ref: 00FF8970
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID: Process$CurrentExitTerminate
                              • String ID:
                              • API String ID: 1703294689-0
                              • Opcode ID: 7c1b751f0508b46633e3e1f467a8555542e0b2220125fe90b4bd807f3c2eef66
                              • Instruction ID: 2843ae4f6a81779ec760341620aec37aa749c09c0579c28eabf6b3bf51234154
                              • Opcode Fuzzy Hash: 7c1b751f0508b46633e3e1f467a8555542e0b2220125fe90b4bd807f3c2eef66
                              • Instruction Fuzzy Hash: 0AD06731400208ABCF226FA0DC099793F27AE40795B244114BA4995026CF7E9952EB81

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 79 1002098-10020ca VirtualAlloc 80 1002270-1002274 79->80 81 10020d0-10020d4 79->81 82 10020dd-10020e4 81->82 83 10020f1-10020f8 82->83 84 10020e6-10020ef 82->84 86 10020fc-100210e 83->86 84->82 87 1002110-1002116 86->87 88 1002133-100213b 86->88 89 1002118 87->89 90 100211d-1002130 87->90 91 100219c-10021a2 88->91 92 100213d-1002143 88->92 93 1002260-100226d VirtualFree 89->93 90->88 96 10021a4 91->96 97 10021a9-10021b0 91->97 94 1002145 92->94 95 100214a-1002167 92->95 93->80 94->93 98 1002169 95->98 99 100216e-1002197 95->99 96->93 100 10021b2 97->100 101 10021b7-10021fa 97->101 98->93 102 100225b 99->102 100->93 103 1002203-1002209 101->103 102->86 103->102 104 100220b-1002238 103->104 105 100223a 104->105 106 100223c-1002259 104->106 105->102 106->103
                              APIs
                              • VirtualAlloc.KERNELBASE(00000000,00001012,00001000,00000004), ref: 010020C1
                              • VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 0100226D
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID: Virtual$AllocFree
                              • String ID:
                              • API String ID: 2087232378-0
                              • Opcode ID: 7dc8e79fde86babc96161718fc4e5f80a5398d7d893a888eaa0e52eee754c683
                              • Instruction ID: 05e0e6d32987452464b69470267e13392ab3d76d345f51dfe85f99ddce2965de
                              • Opcode Fuzzy Hash: 7dc8e79fde86babc96161718fc4e5f80a5398d7d893a888eaa0e52eee754c683
                              • Instruction Fuzzy Hash: B4719C75E04249DFEB42CF98C985BEDBBF0AF09314F144095E5A5F7281C234AA91DF64
                              APIs
                              • VirtualAlloc.KERNELBASE(00000000,00001012,00001000,00000004), ref: 010020C1
                              • VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 0100226D
                              Memory Dump Source
                              • Source File: 00000004.00000003.1390003579.0000000001002000.00000040.00000001.01000000.00000008.sdmp, Offset: 01002000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_3_1002000_nUCp.jbxd
                              Similarity
                              • API ID: Virtual$AllocFree
                              • String ID:
                              • API String ID: 2087232378-0
                              • Opcode ID: 7dc8e79fde86babc96161718fc4e5f80a5398d7d893a888eaa0e52eee754c683
                              • Instruction ID: 05e0e6d32987452464b69470267e13392ab3d76d345f51dfe85f99ddce2965de
                              • Opcode Fuzzy Hash: 7dc8e79fde86babc96161718fc4e5f80a5398d7d893a888eaa0e52eee754c683
                              • Instruction Fuzzy Hash: B4719C75E04249DFEB42CF98C985BEDBBF0AF09314F144095E5A5F7281C234AA91DF64

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 108 ffc211-ffc23b 109 ffc23d-ffc23f 108->109 110 ffc241-ffc243 108->110 111 ffc292-ffc295 109->111 112 ffc249-ffc250 call ffc146 110->112 113 ffc245-ffc247 110->113 115 ffc255-ffc259 112->115 113->111 116 ffc25b-ffc269 GetProcAddress 115->116 117 ffc278-ffc28f 115->117 116->117 119 ffc26b-ffc276 call ff811b 116->119 118 ffc291 117->118 118->111 119->118
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID:
                              • String ID:
                              • API String ID:
                              • Opcode ID: 0370f6c1358a500b0696f779e0fd1533534c94dd10ca3e2d68daceb0ab05d284
                              • Instruction ID: dd5d16481741eba0f0ce138c770493092610af0c1d6d7d7c5c507993d588e6fc
                              • Opcode Fuzzy Hash: 0370f6c1358a500b0696f779e0fd1533534c94dd10ca3e2d68daceb0ab05d284
                              • Instruction Fuzzy Hash: D501F93360023C9F9F228EEDED809763765EFC53307204224FA0497159DA3AD945B7C1
                              APIs
                              • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 00FF55B5
                              • IsDebuggerPresent.KERNEL32 ref: 00FF5681
                              • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 00FF56A1
                              • UnhandledExceptionFilter.KERNEL32(?), ref: 00FF56AB
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID: ExceptionFilterPresentUnhandled$DebuggerFeatureProcessor
                              • String ID:
                              • API String ID: 254469556-0
                              • Opcode ID: 298d95ba064b52277955f8631442407fd961f294bae155874542ea90f3b36ec3
                              • Instruction ID: 2fd32836ef574cacaec3f6f1334c730df70b113c825d2ae10394fb0c22bed304
                              • Opcode Fuzzy Hash: 298d95ba064b52277955f8631442407fd961f294bae155874542ea90f3b36ec3
                              • Instruction Fuzzy Hash: 5E3138B5D0131CDBDB21DFA0D989BCCBBB8AF08704F1041AAE54DAB250EB759A85DF44
                              APIs
                              • IsDebuggerPresent.KERNEL32(?,?,?,?,?,?), ref: 00FF9BAC
                              • SetUnhandledExceptionFilter.KERNEL32(00000000,?,?,?,?,?,?), ref: 00FF9BB6
                              • UnhandledExceptionFilter.KERNEL32(?,?,?,?,?,?,?), ref: 00FF9BC3
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID: ExceptionFilterUnhandled$DebuggerPresent
                              • String ID:
                              • API String ID: 3906539128-0
                              • Opcode ID: d8fd8a2b8283293388fea36bd83e812941463f1ad3a8f6644e92d53f6971870b
                              • Instruction ID: fbd08219332daa5ef7139ef3bbea97b9ddd245add4a8ea0250d0710b3bf53776
                              • Opcode Fuzzy Hash: d8fd8a2b8283293388fea36bd83e812941463f1ad3a8f6644e92d53f6971870b
                              • Instruction Fuzzy Hash: 4F31C27590122C9BCB21DF64DD8979CBBB8BF08310F6042EAE50CA7261EB749B85DF54
                              APIs
                              • IsProcessorFeaturePresent.KERNEL32(0000000A), ref: 00FF585B
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID: FeaturePresentProcessor
                              • String ID:
                              • API String ID: 2325560087-0
                              • Opcode ID: 81528685de541c0badea198b9bb2a6daad8d482d429e33d6b5c531178726574d
                              • Instruction ID: 19d633f2db804db7da422532ff55f7d458a3f2586dd485f60b1c6a2602b4f07c
                              • Opcode Fuzzy Hash: 81528685de541c0badea198b9bb2a6daad8d482d429e33d6b5c531178726574d
                              • Instruction Fuzzy Hash: 0851BB71E11A098FEB28CF59D8913BAB7F0FB48724F10842AD685EB254D3B9D900DF50
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID:
                              • String ID:
                              • API String ID:
                              • Opcode ID: 9ae701cf74909eae495ca93c48b3458e65e25e435aa206d769dba681d1e6a122
                              • Instruction ID: 78edcad4c5e94a3a0abd930781c59394f403b8de9234e4fa2d118f663cd3bff3
                              • Opcode Fuzzy Hash: 9ae701cf74909eae495ca93c48b3458e65e25e435aa206d769dba681d1e6a122
                              • Instruction Fuzzy Hash: E741C0B5C0521DAEDF20DF69CC89ABABBB9AF45310F1442D9E50DD3221DA359E849F20
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID:
                              • String ID:
                              • API String ID:
                              • Opcode ID: d558d006f42668ff0cb3938fe5626bc0e09627662ae6e14989234e2d35bd114b
                              • Instruction ID: 96bef1942a341036335d5fb9a3a54da147665991db56eb45f9139712fa6ee162
                              • Opcode Fuzzy Hash: d558d006f42668ff0cb3938fe5626bc0e09627662ae6e14989234e2d35bd114b
                              • Instruction Fuzzy Hash: 07F06275A00200EFA756CF8DC54CC997BFAFB85710F6545D5E4049B2A1D3B0DD44CB61
                              Memory Dump Source
                              • Source File: 00000004.00000003.1390003579.0000000001002000.00000040.00000001.01000000.00000008.sdmp, Offset: 01002000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_3_1002000_nUCp.jbxd
                              Similarity
                              • API ID:
                              • String ID:
                              • API String ID:
                              • Opcode ID: d558d006f42668ff0cb3938fe5626bc0e09627662ae6e14989234e2d35bd114b
                              • Instruction ID: 96bef1942a341036335d5fb9a3a54da147665991db56eb45f9139712fa6ee162
                              • Opcode Fuzzy Hash: d558d006f42668ff0cb3938fe5626bc0e09627662ae6e14989234e2d35bd114b
                              • Instruction Fuzzy Hash: 07F06275A00200EFA756CF8DC54CC997BFAFB85710F6545D5E4049B2A1D3B0DD44CB61

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 160 ff72d1-ff72fc call ff7e99 163 ff7302-ff7305 160->163 164 ff7670-ff7675 call ff91a7 160->164 163->164 165 ff730b-ff7314 163->165 167 ff731a-ff731e 165->167 168 ff7411-ff7417 165->168 167->168 170 ff7324-ff732b 167->170 171 ff741f-ff742d 168->171 172 ff732d-ff7334 170->172 173 ff7343-ff7348 170->173 174 ff75d9-ff75dc 171->174 175 ff7433-ff7437 171->175 172->173 176 ff7336-ff733d 172->176 173->168 177 ff734e-ff7356 call ff6913 173->177 178 ff75ff-ff7608 call ff6913 174->178 179 ff75de-ff75e1 174->179 175->174 180 ff743d-ff7444 175->180 176->168 176->173 194 ff735c-ff7375 call ff6913 * 2 177->194 195 ff760a-ff760e 177->195 178->164 178->195 179->164 182 ff75e7-ff75fc call ff7676 179->182 183 ff745c-ff7462 180->183 184 ff7446-ff744d 180->184 182->178 189 ff7579-ff757d 183->189 190 ff7468-ff748f call ff6cc4 183->190 184->183 188 ff744f-ff7456 184->188 188->174 188->183 192 ff757f-ff7588 call ff65a0 189->192 193 ff7589-ff7595 189->193 190->189 202 ff7495-ff7498 190->202 192->193 193->178 200 ff7597-ff75a1 193->200 194->164 219 ff737b-ff7381 194->219 204 ff75af-ff75b1 200->204 205 ff75a3-ff75a5 200->205 207 ff749b-ff74b0 202->207 209 ff75c8-ff75d5 call ff7d59 204->209 210 ff75b3-ff75c6 call ff6913 * 2 204->210 205->178 208 ff75a7-ff75ab 205->208 212 ff755a-ff756d 207->212 213 ff74b6-ff74b9 207->213 208->178 215 ff75ad 208->215 227 ff75d7 209->227 228 ff7634-ff7649 call ff6913 * 2 209->228 234 ff760f call ff90eb 210->234 212->207 220 ff7573-ff7576 212->220 213->212 221 ff74bf-ff74c7 213->221 215->210 224 ff73ad-ff73b5 call ff6913 219->224 225 ff7383-ff7387 219->225 220->189 221->212 226 ff74cd-ff74e1 221->226 244 ff7419-ff741c 224->244 245 ff73b7-ff73d7 call ff6913 * 2 call ff7d59 224->245 225->224 230 ff7389-ff7390 225->230 231 ff74e4-ff74f5 226->231 227->178 257 ff764e-ff766b call ff6eb7 call ff7c59 call ff7e16 call ff7bd0 228->257 258 ff764b 228->258 235 ff73a4-ff73a7 230->235 236 ff7392-ff7399 230->236 237 ff751b-ff7528 231->237 238 ff74f7-ff7508 call ff77ac 231->238 248 ff7614-ff762f call ff65a0 call ff7960 call ff7f46 234->248 235->164 235->224 236->235 242 ff739b-ff73a2 236->242 237->231 247 ff752a 237->247 254 ff752c-ff7554 call ff7251 238->254 255 ff750a-ff7513 238->255 242->224 242->235 244->171 245->244 274 ff73d9-ff73de 245->274 252 ff7557 247->252 248->228 252->212 254->252 255->238 260 ff7515-ff7518 255->260 257->164 258->257 260->237 274->234 276 ff73e4-ff73f7 call ff79b5 274->276 276->248 281 ff73fd-ff7409 276->281 281->234 282 ff740f 281->282 282->276
                              APIs
                              • type_info::operator==.LIBVCRUNTIME ref: 00FF73F0
                              • ___TypeMatch.LIBVCRUNTIME ref: 00FF74FE
                              • CatchIt.LIBVCRUNTIME ref: 00FF754F
                              • _UnwindNestedFrames.LIBCMT ref: 00FF7650
                              • CallUnexpected.LIBVCRUNTIME ref: 00FF766B
                              Strings
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID: CallCatchFramesMatchNestedTypeUnexpectedUnwindtype_info::operator==
                              • String ID: csm$csm$csm
                              • API String ID: 4119006552-393685449
                              • Opcode ID: 34c7de161f2aafce6c2ab9f816e1bb6e67a4addf4ea01dc0590e4867c4aec9e5
                              • Instruction ID: 0ca4e27995472594d3c623937b97b6b155f3ede59a2ca7476e2a2cec863b2328
                              • Opcode Fuzzy Hash: 34c7de161f2aafce6c2ab9f816e1bb6e67a4addf4ea01dc0590e4867c4aec9e5
                              • Instruction Fuzzy Hash: 7BB14B71C0830DEFCF25EFA4C8819BEBB75EF04320B184559EA11AB222D775DA51EB91

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 283 ff63d0-ff6421 call 1001400 call ff6390 call ff68c7 290 ff647d-ff6480 283->290 291 ff6423-ff6435 283->291 292 ff6482-ff648f call ff68b0 290->292 293 ff64a0-ff64a9 290->293 291->293 294 ff6437-ff644e 291->294 298 ff6494-ff649d call ff6390 292->298 296 ff6464 294->296 297 ff6450-ff645e call ff6850 294->297 300 ff6467-ff646c 296->300 305 ff6474-ff647b 297->305 306 ff6460 297->306 298->293 300->294 303 ff646e-ff6470 300->303 303->293 307 ff6472 303->307 305->298 308 ff64aa-ff64b3 306->308 309 ff6462 306->309 307->298 310 ff64ed-ff64fd call ff6890 308->310 311 ff64b5-ff64bc 308->311 309->300 316 ff64ff-ff650e call ff68b0 310->316 317 ff6511-ff652d call ff6390 call ff6870 310->317 311->310 313 ff64be-ff64cd call 10011e0 311->313 321 ff64cf-ff64e7 313->321 322 ff64ea 313->322 316->317 321->322 322->310
                              APIs
                              • _ValidateLocalCookies.LIBCMT ref: 00FF6407
                              • ___except_validate_context_record.LIBVCRUNTIME ref: 00FF640F
                              • _ValidateLocalCookies.LIBCMT ref: 00FF6498
                              • __IsNonwritableInCurrentImage.LIBCMT ref: 00FF64C3
                              • _ValidateLocalCookies.LIBCMT ref: 00FF6518
                              Strings
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID: CookiesLocalValidate$CurrentImageNonwritable___except_validate_context_record
                              • String ID: csm
                              • API String ID: 1170836740-1018135373
                              • Opcode ID: 3881458301176a1638306b3db4ccb5df2853c16a2221144f71ec0113876002b9
                              • Instruction ID: 2062c4a61cc50b7536b9d918bd9b77fb3ff805f9d28de87da0803bdb7df4b1a7
                              • Opcode Fuzzy Hash: 3881458301176a1638306b3db4ccb5df2853c16a2221144f71ec0113876002b9
                              • Instruction Fuzzy Hash: DD419834E0020DAFCF10EF68C844AAE7BB5AF45328F148159EA14DB366DB35EA15DB91

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 329 ff6921-ff6928 330 ff692d-ff6948 GetLastError call ff6c04 329->330 331 ff692a-ff692c 329->331 334 ff694a-ff694c 330->334 335 ff6961-ff6963 330->335 336 ff694e-ff695f call ff6c3f 334->336 337 ff69a7-ff69b2 SetLastError 334->337 335->337 336->335 340 ff6965-ff6975 call ff91eb 336->340 343 ff6989-ff6999 call ff6c3f 340->343 344 ff6977-ff6987 call ff6c3f 340->344 350 ff699f-ff69a6 call ff9127 343->350 344->343 349 ff699b-ff699d 344->349 349->350 350->337
                              APIs
                              • GetLastError.KERNEL32(?,?,00FF6918,00FF674C,00FF578C), ref: 00FF692F
                              • ___vcrt_FlsGetValue.LIBVCRUNTIME ref: 00FF693D
                              • ___vcrt_FlsSetValue.LIBVCRUNTIME ref: 00FF6956
                              • SetLastError.KERNEL32(00000000,00FF6918,00FF674C,00FF578C), ref: 00FF69A8
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID: ErrorLastValue___vcrt_
                              • String ID:
                              • API String ID: 3852720340-0
                              • Opcode ID: b0bf639148806c2d30b7f4d62c6e706b620e42eb4217ec6f67f92bc267cae292
                              • Instruction ID: baf1844478457b2d0b6e1f6178c6e084c0680f453715258d23ea12d5f8c4d159
                              • Opcode Fuzzy Hash: b0bf639148806c2d30b7f4d62c6e706b620e42eb4217ec6f67f92bc267cae292
                              • Instruction Fuzzy Hash: 9D01D83390831E5DAA352A74AC9AA3737A5DF057797200329F3A0D60F5EFAE4C00F250

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 353 ffa6eb-ffa6f6 354 ffa6f8-ffa702 call ffa7d4 353->354 355 ffa707-ffa70d 353->355 363 ffa7aa-ffa7ac 354->363 357 ffa70f-ffa715 355->357 358 ffa734-ffa749 call ffb2b9 355->358 360 ffa728-ffa732 357->360 361 ffa717-ffa722 call ffa7ad 357->361 368 ffa74b-ffa75f GetLastError call ff9d37 call ff9d91 358->368 369 ffa761-ffa768 358->369 365 ffa7a9 360->365 361->360 361->365 365->363 368->365 370 ffa76a-ffa774 call ffa7ad 369->370 371 ffa776-ffa78a call ffa542 369->371 370->371 380 ffa7a8 370->380 381 ffa78c-ffa7a0 GetLastError call ff9d37 call ff9d91 371->381 382 ffa7a2-ffa7a6 371->382 380->365 381->380 382->380
                              Strings
                              • C:\Users\Public\Documents\nUCp.exe, xrefs: 00FFA707
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID:
                              • String ID: C:\Users\Public\Documents\nUCp.exe
                              • API String ID: 0-3310568506
                              • Opcode ID: 4461d9afc881cc6a9def0350c308c469d12b03cdee77d21ab1d302f3580b7714
                              • Instruction ID: dcef9ddec9449bd705666be8f903d3b1ae8bdef86094fc8a48fbe7709432781b
                              • Opcode Fuzzy Hash: 4461d9afc881cc6a9def0350c308c469d12b03cdee77d21ab1d302f3580b7714
                              • Instruction Fuzzy Hash: 222180B2A0420DBF9B20BF61CC80E3BB7B9AF003657108564FA59D7171E735EC10A7A2
                              APIs
                              • GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,00000000,BCC996EE,?,?,00000000,010014CF,000000FF,?,00FF896C,00FF8A50,?,00FF8940,00000000), ref: 00FF89C5
                              • GetProcAddress.KERNEL32(00000000,CorExitProcess), ref: 00FF89D7
                              • FreeLibrary.KERNEL32(00000000,?,?,00000000,010014CF,000000FF,?,00FF896C,00FF8A50,?,00FF8940,00000000), ref: 00FF89F9
                              Strings
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID: AddressFreeHandleLibraryModuleProc
                              • String ID: CorExitProcess$mscoree.dll
                              • API String ID: 4061214504-1276376045
                              • Opcode ID: 80603db29609d1a9b29da3033407151157e5c41365a960b195f847b8f08437ca
                              • Instruction ID: 2350687c3af8708d284e7ab10b9babf8f8d322a15ca0b453867a0f7c9fc78f48
                              • Opcode Fuzzy Hash: 80603db29609d1a9b29da3033407151157e5c41365a960b195f847b8f08437ca
                              • Instruction Fuzzy Hash: 4E01DB32940619AFDB369F40CC05BFE77B9FB04B20F110629F951A2294DFBD9900CB81
                              APIs
                              • RtlEncodePointer.NTDLL(00000000), ref: 00FF769B
                              • CatchIt.LIBVCRUNTIME ref: 00FF7781
                              Strings
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID: CatchEncodePointer
                              • String ID: MOC$RCC
                              • API String ID: 1435073870-2084237596
                              • Opcode ID: ff4731059164505084fa9e04eff848436c44a7fbe193bc90b46163bfd901843a
                              • Instruction ID: 97a2eea93dc1d6e5a62a791b5912cbbdd21d2c0d481110654c6620845cb62384
                              • Opcode Fuzzy Hash: ff4731059164505084fa9e04eff848436c44a7fbe193bc90b46163bfd901843a
                              • Instruction Fuzzy Hash: BF414A72D0020DAFDF15EF98CD81AAEBBB5FF48314F248199FA04A7261D3359950EB54
                              APIs
                              • LoadLibraryExW.KERNEL32(00000000,00000000,00000800,?,00FF6AF4,00000000,?,01019C78,?,?,?,00FF6C97,00000004,InitializeCriticalSectionEx,01012CC0,InitializeCriticalSectionEx), ref: 00FF6B50
                              • GetLastError.KERNEL32(?,00FF6AF4,00000000,?,01019C78,?,?,?,00FF6C97,00000004,InitializeCriticalSectionEx,01012CC0,InitializeCriticalSectionEx,00000000,?,00FF6A17), ref: 00FF6B5A
                              • LoadLibraryExW.KERNEL32(00000000,00000000,00000000), ref: 00FF6B82
                              Strings
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID: LibraryLoad$ErrorLast
                              • String ID: api-ms-
                              • API String ID: 3177248105-2084034818
                              • Opcode ID: f686aaf8d97a8bd3950034a17c8d9db87b009190ace500ca9660210c7fd95ad0
                              • Instruction ID: 87d09fc9389cf59ce2e75df496931e95d6d5768c30a09b80d5b7b87d3a4b4e5d
                              • Opcode Fuzzy Hash: f686aaf8d97a8bd3950034a17c8d9db87b009190ace500ca9660210c7fd95ad0
                              • Instruction Fuzzy Hash: DAE0483064020CFBDF311A71DC06F693A66AF50B65F204120FB4DE91E5DBABD851DB55
                              APIs
                              • GetConsoleOutputCP.KERNEL32(BCC996EE,00000000,00000000,?), ref: 00FFDFE4
                                • Part of subcall function 00FFB2B9: WideCharToMultiByte.KERNEL32(?,00000000,00000000,00000000,?,-00000008,?,00000000,-00000008,-00000008,00000000,?,00FFDC5F,?,00000000,-00000008), ref: 00FFB31A
                              • WriteFile.KERNEL32(?,?,00000000,?,00000000), ref: 00FFE236
                              • WriteFile.KERNEL32(?,?,00000001,?,00000000), ref: 00FFE27C
                              • GetLastError.KERNEL32 ref: 00FFE31F
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID: FileWrite$ByteCharConsoleErrorLastMultiOutputWide
                              • String ID:
                              • API String ID: 2112829910-0
                              • Opcode ID: b014a41c4f5c5021b9ee5cfe351465b473755a57aad72ee21c0e935c6ca4f343
                              • Instruction ID: 5b883cfcdf2e92373c7fbe9d95c9f72131cd84328818247b23d91d255ab5f2f7
                              • Opcode Fuzzy Hash: b014a41c4f5c5021b9ee5cfe351465b473755a57aad72ee21c0e935c6ca4f343
                              • Instruction Fuzzy Hash: 43D17A75D0024C9FCB15CFE8D884AEDBBB9FF09314F28412AE656EB361E634A941DB50
                              APIs
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID: AdjustPointer
                              • String ID:
                              • API String ID: 1740715915-0
                              • Opcode ID: 6f840fcc41fced50166943a766ea3f0a664295baf81747821dfe8a633abfa5f8
                              • Instruction ID: b9d3b3fd020018af8242d6050e78b0ed7dcd99c6bea6789ae6b46768427289aa
                              • Opcode Fuzzy Hash: 6f840fcc41fced50166943a766ea3f0a664295baf81747821dfe8a633abfa5f8
                              • Instruction Fuzzy Hash: 5C51C67290870E9FEB25AF54D841B7AF7A5EF40311F14416DEA01872B1EB35EC88E790
                              APIs
                                • Part of subcall function 00FFB2B9: WideCharToMultiByte.KERNEL32(?,00000000,00000000,00000000,?,-00000008,?,00000000,-00000008,-00000008,00000000,?,00FFDC5F,?,00000000,-00000008), ref: 00FFB31A
                              • GetLastError.KERNEL32 ref: 00FF9F69
                              • __dosmaperr.LIBCMT ref: 00FF9F70
                              • GetLastError.KERNEL32(?,?,?,?), ref: 00FF9FAA
                              • __dosmaperr.LIBCMT ref: 00FF9FB1
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID: ErrorLast__dosmaperr$ByteCharMultiWide
                              • String ID:
                              • API String ID: 1913693674-0
                              • Opcode ID: 2be96590f06b7bcc302291d3e6221aa596be749b14db9ce47dc30d489f008665
                              • Instruction ID: b0f2f84569474231cc21b2d8c1b3aa5dd6caf6b41f588b05c30d0dfa9b354b3c
                              • Opcode Fuzzy Hash: 2be96590f06b7bcc302291d3e6221aa596be749b14db9ce47dc30d489f008665
                              • Instruction Fuzzy Hash: F421C571A0820DAFDB20AF61DC80A7BB7ADEF403747148518FA59D71B0D7B5ED00A761
                              APIs
                              • GetEnvironmentStringsW.KERNEL32 ref: 00FFB364
                                • Part of subcall function 00FFB2B9: WideCharToMultiByte.KERNEL32(?,00000000,00000000,00000000,?,-00000008,?,00000000,-00000008,-00000008,00000000,?,00FFDC5F,?,00000000,-00000008), ref: 00FFB31A
                              • FreeEnvironmentStringsW.KERNEL32(00000000), ref: 00FFB39C
                              • FreeEnvironmentStringsW.KERNEL32(00000000), ref: 00FFB3BC
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID: EnvironmentStrings$Free$ByteCharMultiWide
                              • String ID:
                              • API String ID: 158306478-0
                              • Opcode ID: 7badfdb3a893dd6120853ba3452a25e2d173d04a4bba47b04c6875c1cd1cedc7
                              • Instruction ID: 5fc2c356682896a96a08d3ee3bfbd8b2627bbdd99a23417ded5c8d952f748a3e
                              • Opcode Fuzzy Hash: 7badfdb3a893dd6120853ba3452a25e2d173d04a4bba47b04c6875c1cd1cedc7
                              • Instruction Fuzzy Hash: 8511C0B690961DBFA62567B2DCCAD7F796CCE943A53210024FB01D2121EF69DD40A2B0
                              APIs
                              • WriteConsoleW.KERNEL32(00000000,?,00000000,00000000,00000000,?,00FFEF14,00000000,00000001,00000000,?,?,00FFE373,?,00000000,00000000), ref: 00FFF76D
                              • GetLastError.KERNEL32(?,00FFEF14,00000000,00000001,00000000,?,?,00FFE373,?,00000000,00000000,?,?,?,00FFE916,00000000), ref: 00FFF779
                                • Part of subcall function 00FFF73F: CloseHandle.KERNEL32(FFFFFFFE,00FFF789,?,00FFEF14,00000000,00000001,00000000,?,?,00FFE373,?,00000000,00000000,?,?), ref: 00FFF74F
                              • ___initconout.LIBCMT ref: 00FFF789
                                • Part of subcall function 00FFF701: CreateFileW.KERNEL32(CONOUT$,40000000,00000003,00000000,00000003,00000000,00000000,00FFF730,00FFEF01,?,?,00FFE373,?,00000000,00000000,?), ref: 00FFF714
                              • WriteConsoleW.KERNEL32(00000000,?,00000000,00000000,?,00FFEF14,00000000,00000001,00000000,?,?,00FFE373,?,00000000,00000000,?), ref: 00FFF79E
                              Memory Dump Source
                              • Source File: 00000004.00000002.1394153462.0000000000FA1000.00000040.00000001.01000000.00000008.sdmp, Offset: 00FA0000, based on PE: true
                              • Associated: 00000004.00000002.1394133696.0000000000FA0000.00000002.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001012000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.0000000001019000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394153462.000000000101E000.00000040.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394273419.000000000101F000.00000080.00000001.01000000.00000008.sdmpDownload File
                              • Associated: 00000004.00000002.1394293120.0000000001021000.00000004.00000001.01000000.00000008.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_4_2_fa0000_nUCp.jbxd
                              Yara matches
                              Similarity
                              • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast___initconout
                              • String ID:
                              • API String ID: 2744216297-0
                              • Opcode ID: 8541028e429f01dfcb74282b741f594dc257a9697d05203bd3b08228e6f797d0
                              • Instruction ID: 78ad32c5c5f56608bb13b40cd36dc59fb46a59454bfd89454d80b42acebc6f64
                              • Opcode Fuzzy Hash: 8541028e429f01dfcb74282b741f594dc257a9697d05203bd3b08228e6f797d0
                              • Instruction Fuzzy Hash: A5F0923651115DBBCF226E969C08AAA7E66FF087A1B254160FA5896125C63A8820EB90
                              APIs
                              • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000004,00000000,?,?), ref: 027F0326
                                • Part of subcall function 027F00A4: VirtualAlloc.KERNELBASE(00000000,00001012,00001000,00000004), ref: 027F00CD
                                • Part of subcall function 027F00A4: VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 027F0279
                              • VirtualAlloc.KERNELBASE(00000000,00400000,00001000,00000004), ref: 027F0378
                              • VirtualProtect.KERNELBASE(0000002C,?,00000040,?), ref: 027F03E7
                              • VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 027F0407
                              • MapViewOfFile.KERNELBASE(?,00000004,00000000,00000000,00000000), ref: 027F042E
                              • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000004), ref: 027F0456
                              • CloseHandle.KERNELBASE(?), ref: 027F0471
                              Strings
                              Memory Dump Source
                              • Source File: 00000005.00000003.1393395826.00000000027F0000.00000040.00000001.00020000.00000000.sdmp, Offset: 027F0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_5_3_27f0000_OpenWith.jbxd
                              Similarity
                              • API ID: Virtual$Alloc$Free$CloseFileHandleProtectView
                              • String ID: ,
                              • API String ID: 3867569247-3772416878
                              • Opcode ID: 34919759cab89c45596a3336aca0d90db3a2564f30e7825e5c793611e7351f71
                              • Instruction ID: b34c73bc54d7ac411398f63fffae95a47066e4c7f03fd1f9e840d829b4d5b000
                              • Opcode Fuzzy Hash: 34919759cab89c45596a3336aca0d90db3a2564f30e7825e5c793611e7351f71
                              • Instruction Fuzzy Hash: 00612BB5904209EFCB20DFA5C884AEEBBB9FF08354F14841AEA59A7345D730E950CF60
                              APIs
                              • VirtualAlloc.KERNELBASE(00000000,00001012,00001000,00000004), ref: 027F00CD
                              • VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 027F0279
                              Memory Dump Source
                              • Source File: 00000005.00000003.1393395826.00000000027F0000.00000040.00000001.00020000.00000000.sdmp, Offset: 027F0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_5_3_27f0000_OpenWith.jbxd
                              Similarity
                              • API ID: Virtual$AllocFree
                              • String ID:
                              • API String ID: 2087232378-0
                              • Opcode ID: 7dc8e79fde86babc96161718fc4e5f80a5398d7d893a888eaa0e52eee754c683
                              • Instruction ID: 78410cf56a4d9559bf57af57d6237d4957f91479115ee9e85c25f1fbebd08e9e
                              • Opcode Fuzzy Hash: 7dc8e79fde86babc96161718fc4e5f80a5398d7d893a888eaa0e52eee754c683
                              • Instruction Fuzzy Hash: 83718C75A08249DFDB81CF98C981BEEBBF0AB09314F244095E565FB346C334AA91CF65

                              Execution Graph

                              Execution Coverage:34.5%
                              Dynamic/Decrypted Code Coverage:100%
                              Signature Coverage:71.4%
                              Total number of Nodes:28
                              Total number of Limit Nodes:0
                              execution_graph 412 11f791b1cd0 414 11f791b1cf5 412->414 413 11f791b1f7d 414->413 423 11f791b15ac 414->423 416 11f791b1f74 CloseHandle 416->413 417 11f791b1f64 NtAcceptConnectPort 417->416 418 11f791b1e16 418->416 418->417 420 11f791b1ea9 418->420 426 11f791b0ac8 418->426 420->420 432 11f791b1a90 NtAcceptConnectPort 420->432 425 11f791b15e0 NtAcceptConnectPort 423->425 425->418 427 11f791b0c4b 426->427 428 11f791b0ae8 426->428 427->420 428->427 429 11f791b0bd1 NtAcceptConnectPort 428->429 429->427 430 11f791b0c04 429->430 430->427 431 11f791b0c1c NtAcceptConnectPort 430->431 431->427 433 11f791b1bf0 432->433 434 11f791b1ae3 432->434 433->417 438 11f791b185c 434->438 436 11f791b1afc 437 11f791b1ba2 NtAcceptConnectPort 436->437 437->433 440 11f791b1875 438->440 439 11f791b1935 439->436 440->439 441 11f791b191c GetProcessMitigationPolicy 440->441 441->439 442 11f791b19a0 443 11f791b19b3 442->443 444 11f791b19e7 443->444 445 11f791b19d2 VirtualFree 443->445 445->444

                              Callgraph

                              APIs
                              Strings
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptConnectPort$DuplicateHandlecalloc
                              • String ID: ,$H$H
                              • API String ID: 2577638757-438696205
                              • Opcode ID: 9fb62eb4d8959293fc2d40b19de36242d3d29fe68d1ba52932dcd9bec1ad6912
                              • Instruction ID: 3ffbdbc5c579fa841f8e3df00f17c76a51c3a6b80bd0bfdbb1d675c33461be55
                              • Opcode Fuzzy Hash: 9fb62eb4d8959293fc2d40b19de36242d3d29fe68d1ba52932dcd9bec1ad6912
                              • Instruction Fuzzy Hash: 9D02867061CA899BD768DF68D8856EBB3E1FB98300F50453FD58FC3291DA34E5818B86
                              APIs
                              Strings
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptConnectPort$freemalloc
                              • String ID: $0$@
                              • API String ID: 4227078157-2347541974
                              • Opcode ID: d8fdb236a247b9205c502de8d0d979f89367b2180e7993cbf521bb03780d7e1e
                              • Instruction ID: dbb3cf437e2625758fe0c3f000cf7c4b76bc98e3c11f15aa3c9b6e7810b1794b
                              • Opcode Fuzzy Hash: d8fdb236a247b9205c502de8d0d979f89367b2180e7993cbf521bb03780d7e1e
                              • Instruction Fuzzy Hash: 18516A706287889ED764DF28D8857ABB7E4FB89700F10452FE58EC2285DB74E4858B83
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1502016342.0000011F7ABB0000.00000040.00000001.00020000.00000000.sdmp, Offset: 0000011F7ABB0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_11f7abb0000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptConnectPort$FreeHeap
                              • String ID:
                              • API String ID: 2519882481-0
                              • Opcode ID: 06103e6240192ff0ea4d22a768af3a34bd3b5889dbd62609acb6a2f682bb8b02
                              • Instruction ID: a939ed62db6b0ea9f35b8757ce70c974b02c234cac4ce97fb66be38c4e818340
                              • Opcode Fuzzy Hash: 06103e6240192ff0ea4d22a768af3a34bd3b5889dbd62609acb6a2f682bb8b02
                              • Instruction Fuzzy Hash: B3C19730218B458FDB5CDF5CC485BE9B7E1FB94310F09492DE58AC7692DB34E84A8782
                              APIs
                              Strings
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID: $0$@
                              • API String ID: 1658770261-2347541974
                              • Opcode ID: e038bc6975502a75aa15522c9d2aad796b46013016ac9629b0cf3dc02c1d6b17
                              • Instruction ID: 5acf2ce1a00452d0d71f91028b77d20a412d637bff2b9f36328b755e68458a14
                              • Opcode Fuzzy Hash: e038bc6975502a75aa15522c9d2aad796b46013016ac9629b0cf3dc02c1d6b17
                              • Instruction Fuzzy Hash: 8F515A7060CB898FE765DF68C484BABB7E4FB98300F10452EE48EC3290DB75D4848B46
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: NamedPipe$BindCallbackCompletionConnectCreate
                              • String ID:
                              • API String ID: 2502124517-0
                              • Opcode ID: 584620923d8bee05c4cd2b55fbc688861300e251001a2660cae9de72a1f183dd
                              • Instruction ID: 0b0874ae4464720e32789add6f459a1494c7b15a47e43f4f15a73cec4917f6ec
                              • Opcode Fuzzy Hash: 584620923d8bee05c4cd2b55fbc688861300e251001a2660cae9de72a1f183dd
                              • Instruction Fuzzy Hash: 8C3182706086898FD794DF38D8D879B77E1FB94710F10462AD45BC62D0DF78D8858B41
                              Strings
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID:
                              • String ID: 0
                              • API String ID: 0-4108050209
                              • Opcode ID: d4dd2c9ec2e40b847152b417cb6d645fdeafd31ca8a11a7a04321dd5438b40c0
                              • Instruction ID: 9b503857611d58185f82e5fda68cf07d25dd5f1f870f53cbbd544b9141e7f850
                              • Opcode Fuzzy Hash: d4dd2c9ec2e40b847152b417cb6d645fdeafd31ca8a11a7a04321dd5438b40c0
                              • Instruction Fuzzy Hash: 8821A471E0CA8A5FD754DF689884BAB72E1FB88356F51093FF44AC7290D638D8C48745
                              Strings
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID:
                              • String ID: 0
                              • API String ID: 0-4108050209
                              • Opcode ID: 47ebd45c6b9b16ee77b28bcb10b07460bf5cba96d3288197dd2caf634787b8b3
                              • Instruction ID: a04745d6e2bb81a45eaca10dc21680df385ed9ae626c2ecb567f79737873a380
                              • Opcode Fuzzy Hash: 47ebd45c6b9b16ee77b28bcb10b07460bf5cba96d3288197dd2caf634787b8b3
                              • Instruction Fuzzy Hash: E121D571B0C98A5FE7509FA884C86AB72F0EB98321F50053FE50EC7250D728D9C48785
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: CloseHandleSuspendThread
                              • String ID:
                              • API String ID: 1038686644-0
                              • Opcode ID: ee8ed1484b309d5b480d9ed41d064abcb8b4e034361352156597246fbc6f772d
                              • Instruction ID: 44b8a68d5014e9f5f409607ec761f75384be10c9c4e0b1754f7d955124b53171
                              • Opcode Fuzzy Hash: ee8ed1484b309d5b480d9ed41d064abcb8b4e034361352156597246fbc6f772d
                              • Instruction Fuzzy Hash: 4C91C570A0CA564BEB689B28D8955BB73E1FF45310B14427ED05FC7595CE2CE882CB8D

                              Control-flow Graph

                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000002.1767089124.0000011F791B0000.00000040.00000001.00020000.00000000.sdmp, Offset: 0000011F791B0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_2_11f791b0000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptCloseConnectHandlePort
                              • String ID:
                              • API String ID: 3811980168-0
                              • Opcode ID: 2998f17752da19f3229414bc30af807452c20e21bc577cde4fa90f5802e493a5
                              • Instruction ID: 895ff40cea4c9149b7d826828385c0cba2e41e61f97bcc181cefc0c2c58d6d19
                              • Opcode Fuzzy Hash: 2998f17752da19f3229414bc30af807452c20e21bc577cde4fa90f5802e493a5
                              • Instruction Fuzzy Hash: 8E910830508E088FDB69EF1CD485BE573E2FB84320F15566EE58BC32D6EA74A8578781

                              Control-flow Graph

                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000002.1767089124.0000011F791B0000.00000040.00000001.00020000.00000000.sdmp, Offset: 0000011F791B0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_2_11f791b0000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: 82f3aeb1d2454658223fb6d5b21d23051085e6a8eeabdc877af9343281df37cc
                              • Instruction ID: 5ab83dec6172703e21c96476f2960d0d5afb13bec947623dadd2f5674ad2dff9
                              • Opcode Fuzzy Hash: 82f3aeb1d2454658223fb6d5b21d23051085e6a8eeabdc877af9343281df37cc
                              • Instruction Fuzzy Hash: D7417A30A18A140AE32CE62C9896AFDB7E2F7C5319F30557EE1E6C21D6FA79C5438641

                              Control-flow Graph

                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000002.1767089124.0000011F791B0000.00000040.00000001.00020000.00000000.sdmp, Offset: 0000011F791B0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_2_11f791b0000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptConnectPort$MitigationPolicyProcess
                              • String ID:
                              • API String ID: 2923266908-0
                              • Opcode ID: d10bc7eecf76d0dca438e32bd9e6ca23ea1b11bfffb6ce02bc94d4770511dc9b
                              • Instruction ID: 19c3b74c59ea9b8d3de8d90880aa198791e4f2c80273cb3a83461fdfc136bf55
                              • Opcode Fuzzy Hash: d10bc7eecf76d0dca438e32bd9e6ca23ea1b11bfffb6ce02bc94d4770511dc9b
                              • Instruction Fuzzy Hash: 1441F230208B488FDB48DF2C98897D57BD1FB59320F0443AEE95ACB2C7EA74C9168795
                              APIs
                              • socket.WS2_32(?,?,?,?,?,?,?,?,0000006B,0000006A,-00000002,00007DF46E5041A9), ref: 00007DF46E5040B5
                                • Part of subcall function 00007DF46E503C98: ioctlsocket.WS2_32 ref: 00007DF46E503CC4
                              • bind.WS2_32(?,?,?,?,?,?,?,?,0000006B,0000006A,-00000002,00007DF46E5041A9), ref: 00007DF46E50413A
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: bindioctlsocketsocket
                              • String ID:
                              • API String ID: 3555158474-0
                              • Opcode ID: 1cbeedcb49cdd83f56073e3a9aa9cf65c2d138516cd5c7d59cce1983b39e0131
                              • Instruction ID: fd9c335d12a26932ccc1f5c5e316f0169a2de4fc010eb9b2fd451e4eadb6d53e
                              • Opcode Fuzzy Hash: 1cbeedcb49cdd83f56073e3a9aa9cf65c2d138516cd5c7d59cce1983b39e0131
                              • Instruction Fuzzy Hash: DC21E7707089444FFB58AFB8D89D6A733E1EF65325F10067AE82FC72D5DE289C028655
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: 9166209b5f367574360b80d64ced2ea26e8fa752ef609ccd6263efb912702e76
                              • Instruction ID: 8cec44719ce3514eb7056f4c4315051f91ab8f35b256038689f393023aff8aa0
                              • Opcode Fuzzy Hash: 9166209b5f367574360b80d64ced2ea26e8fa752ef609ccd6263efb912702e76
                              • Instruction Fuzzy Hash: 3721427051CA498FDB55EF18D858BA673F1FBA9341F00452EE44AC36A0DBB5E884CF46
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: 98531d878e0ad7d3d6690ce9736b63ba0a61470b6d8d195234036ffb9fe9491b
                              • Instruction ID: 7df9d67d6537fa3398fe89baef33bf2bad5421c6148961676f29436bdaef4941
                              • Opcode Fuzzy Hash: 98531d878e0ad7d3d6690ce9736b63ba0a61470b6d8d195234036ffb9fe9491b
                              • Instruction Fuzzy Hash: E321427051CA488FDB49EB68D8447A673F1FBAD341F00452AE44AC36A0DBB4E984CF41
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: Recv
                              • String ID:
                              • API String ID: 4192927123-0
                              • Opcode ID: 653fe3a6da9e8edf6d7f9aad963387fd79a7ca64ce6bed9a03fbf4fad2203229
                              • Instruction ID: b123227a855e43134559729e84af883372abe2c23463a6e24b55cfba61930ea4
                              • Opcode Fuzzy Hash: 653fe3a6da9e8edf6d7f9aad963387fd79a7ca64ce6bed9a03fbf4fad2203229
                              • Instruction Fuzzy Hash: 21A1A1B0A18A854FFBA4DF5884A46EBB3F0FF65314F50012AE45FC6581D738E9528B89
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: 1a40425d81a0dda3cd82788b19327da5a379df3b5c3bd351d49e58af76a5eeec
                              • Instruction ID: 7442170e2f034437c0a15e60f21d26dd644fdf8eafe4d1a544ab16eea08d70ec
                              • Opcode Fuzzy Hash: 1a40425d81a0dda3cd82788b19327da5a379df3b5c3bd351d49e58af76a5eeec
                              • Instruction Fuzzy Hash: 8E81B9B0A1CB9A9BE7659B6894546EB73E1FF94300F50463BE44FCB180DB68F8808685
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: 5c97c20283281d0f686864c64b2abe35391f7ab31688f0fa8af160c1736108da
                              • Instruction ID: 09b5ec28dde5edd38c3eb68c1fc5b03bd0dd516c329e0c41b6f491459befb4e4
                              • Opcode Fuzzy Hash: 5c97c20283281d0f686864c64b2abe35391f7ab31688f0fa8af160c1736108da
                              • Instruction Fuzzy Hash: 11310771B0C95A6FEB185F2898855BF73E1EB89310F20463FE94FC3291DA18FC424A85
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: CryptDataUnprotect
                              • String ID:
                              • API String ID: 834300711-0
                              • Opcode ID: a07a12428c7964199d363ccabf4b149c9f1c56c6408fd6f078d364f4c66a6574
                              • Instruction ID: 8ff80adc9b7312b1c3f7c89109f602c40866fcb6c924e804544ed4cd4ad568e8
                              • Opcode Fuzzy Hash: a07a12428c7964199d363ccabf4b149c9f1c56c6408fd6f078d364f4c66a6574
                              • Instruction Fuzzy Hash: 5131843071CA884FD748DB68D88966BB7E2FBC9701F40452EE48BC3251DE74D8428B46

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 115 11f791b15ac-11f791b15de 116 11f791b15e0-11f791b15e3 115->116 117 11f791b15e5-11f791b15e7 115->117 118 11f791b160b-11f791b1659 NtAcceptConnectPort 116->118 119 11f791b15e9-11f791b15f5 117->119 120 11f791b15f7-11f791b15f9 117->120 119->118 121 11f791b1609 120->121 122 11f791b15fb-11f791b1607 120->122 121->118 122->118
                              APIs
                              • NtAcceptConnectPort.NTDLL(?,?,?,?,?,?,?,?,00000000,0000011F791B1E16), ref: 0000011F791B1640
                              Memory Dump Source
                              • Source File: 00000006.00000002.1767089124.0000011F791B0000.00000040.00000001.00020000.00000000.sdmp, Offset: 0000011F791B0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_2_11f791b0000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: 835a411c94ef729b3118f684f14c42465dca72cdcacd8c0bc7bbe2bb8e6fff18
                              • Instruction ID: 38c3a17bec567ad860a36ed4b3a8df9f89c55f8f08838f1ed613b8cbc1008f15
                              • Opcode Fuzzy Hash: 835a411c94ef729b3118f684f14c42465dca72cdcacd8c0bc7bbe2bb8e6fff18
                              • Instruction Fuzzy Hash: F621A271908B088FDB58DF58C4C96AAB7F2FBA9305F054A3EE44AC7260E770D485CB41
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: af3340e2b301fb20eba4bd36f70d30fdbe005acca17dd1e0c445e9428843075b
                              • Instruction ID: f6e5938f180091c4ea86836059d3c9f5f1c25166fda9e33b7af2151bad2fc176
                              • Opcode Fuzzy Hash: af3340e2b301fb20eba4bd36f70d30fdbe005acca17dd1e0c445e9428843075b
                              • Instruction Fuzzy Hash: 6DF0D070A1CB858FDBA4EF2CD4C5B9A77E1FB98304F50451AE44CC3245DB34D8808B46
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: d99824a7b56689602d55d9b975c23b4966fb1dfc1a28fa016acf5b8b83f0fdf8
                              • Instruction ID: 0a596f6c199b980d23d45c8919a1780a82aeea3f3974d463a1fc5e544ea43cc1
                              • Opcode Fuzzy Hash: d99824a7b56689602d55d9b975c23b4966fb1dfc1a28fa016acf5b8b83f0fdf8
                              • Instruction Fuzzy Hash: FBF0627491C7C59FDBA0EB688480B9ABBF0BBAA350F544A1EE8CCC3211D735D5848B43
                              APIs
                              • NtAcceptConnectPort.NTDLL(?,?,?,?,?,?,00000000,?,?,00000000,00007DF46E4C341C), ref: 00007DF46E4DAF8A
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: 1d9a6f3c19fc3a1664a9a6811ff4ba6c27299ee4e4794d390710366357d59dbc
                              • Instruction ID: f212d3faf48436b4de562207cfe933c9885834a1b0001015f6c9032b1fbdf94e
                              • Opcode Fuzzy Hash: 1d9a6f3c19fc3a1664a9a6811ff4ba6c27299ee4e4794d390710366357d59dbc
                              • Instruction Fuzzy Hash: ACE065716186458FDB04DFA4C8C18AAB3E0FB99304F004E7AE84AC6164D264D598C682
                              APIs
                              • GetSystemInfo.KERNELBASE(?,00007DF46E54B7C7,?,?,?,?,00000000,00000000), ref: 00007DF46E539F21
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: InfoSystem
                              • String ID:
                              • API String ID: 31276548-0
                              • Opcode ID: d72fac8d1d1b7f96bb5fe0759d88f2d5c6e0343dfc4f10e03c2c9322f33a3d86
                              • Instruction ID: 737f44ebb2d36a7216e06f3402bd3c2b08489e429ea18cad04de1f6eacb20879
                              • Opcode Fuzzy Hash: d72fac8d1d1b7f96bb5fe0759d88f2d5c6e0343dfc4f10e03c2c9322f33a3d86
                              • Instruction Fuzzy Hash: 46E04F319188594BF30EF770DCA58E732B2EBA4304F914632D907820A2ED2C6689C685
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: eb8f498348e5c7f372421b27a3827434041340d731fc3728b954386bc4ea4cc4
                              • Instruction ID: 27778a561208bbebf8af535f0ddca8279f3871f8314095e19f1f066976e3cab1
                              • Opcode Fuzzy Hash: eb8f498348e5c7f372421b27a3827434041340d731fc3728b954386bc4ea4cc4
                              • Instruction Fuzzy Hash: AED05E20A68A8A4BD650A738894024737E2FFD5304F924615E44EC2200D22CE44192C6
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: a9327488733b823840a3f29582a089392b2a1446868cb63a967a810240f58cb8
                              • Instruction ID: 32d0884f89e0e95e131e6c56e8306abb13746e2eafce3b1bf57949e19e7d7774
                              • Opcode Fuzzy Hash: a9327488733b823840a3f29582a089392b2a1446868cb63a967a810240f58cb8
                              • Instruction Fuzzy Hash: 75D05E30A68A8A4BD610A728980065637E2FFD4304F944615D849C2240D23CE481928E
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: 4927af5c10e17f27f2edd3b7dd4d43612d79bd47543f67f71f12626d98bff908
                              • Instruction ID: d5fd22b3c365fd3504884b6c8cb26af50217f817cd5760ede116dec9cd89762e
                              • Opcode Fuzzy Hash: 4927af5c10e17f27f2edd3b7dd4d43612d79bd47543f67f71f12626d98bff908
                              • Instruction Fuzzy Hash: F3D05E30E68ACA4BDA10A728890024A36E2FF95308F904615D849C2250D23CE4419386
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: 953671860da08bf31fab518e05a010f803d920f951da2702e38e3d0cf3acdea6
                              • Instruction ID: 9256bda067b7148905de3ef84c07e57b0adc807d1617d5571155c64219bc123c
                              • Opcode Fuzzy Hash: 953671860da08bf31fab518e05a010f803d920f951da2702e38e3d0cf3acdea6
                              • Instruction Fuzzy Hash: 78C08C80A6980BAAE90867BAAC8439A20E0AF48300F800152E40EC2180E40CE4D4639A
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: 333093483b5b65ac6ab85e83ccc52a142bbc301cae1d85d61a22b47e66de8b6c
                              • Instruction ID: f0b1f204326a3f2b6769ae8f37f545fb7a90ec619bf4418344e5f1262faa951d
                              • Opcode Fuzzy Hash: 333093483b5b65ac6ab85e83ccc52a142bbc301cae1d85d61a22b47e66de8b6c
                              • Instruction Fuzzy Hash: 51C08C60A2C80B2BE91463B94C8068620E0AF4C724F820012E80AC21C0E40CE5E0B396
                              APIs
                              Strings
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: ProtectVirtual
                              • String ID: rE\
                              • API String ID: 544645111-988334199
                              • Opcode ID: dc7abe3753608a406b2e8c4677f2e3e348cb1d8b9abc271147da51083885c1c3
                              • Instruction ID: e909b3514cff23d89ef083f9628d896adcee88126fc40670a955e40f7bf38656
                              • Opcode Fuzzy Hash: dc7abe3753608a406b2e8c4677f2e3e348cb1d8b9abc271147da51083885c1c3
                              • Instruction Fuzzy Hash: 9121B0717189484BEB44F768E8D1AAB72E6FBD8700F00443AE44FC3286DE68ED4587C2
                              APIs
                              Strings
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: ProtectVirtual
                              • String ID:
                              • API String ID: 544645111-3916222277
                              • Opcode ID: 45ee73fde44b844a7982fd6fa2bb9a274e67d6e904138dbe31d6ae3e461be495
                              • Instruction ID: a574add08845b0e8ab68770047363f98fa52f0f1f7809c25f2c7dcdd3122c581
                              • Opcode Fuzzy Hash: 45ee73fde44b844a7982fd6fa2bb9a274e67d6e904138dbe31d6ae3e461be495
                              • Instruction Fuzzy Hash: B011E7B160889B4BEB15E729E8587F7B3F1EB84710F544276E44FC3191DA1CE891C685
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: Completion$CreateFileModesNotificationPortioctlsocket
                              • String ID:
                              • API String ID: 1455841399-0
                              • Opcode ID: b0ef64daf23010be4df91d754ff29401ba7eeb6e21b37df906d22bfb74ec9eab
                              • Instruction ID: 48e998854ca4da141dba24ee74b779eb069f9202537a03b658d4e78cef982708
                              • Opcode Fuzzy Hash: b0ef64daf23010be4df91d754ff29401ba7eeb6e21b37df906d22bfb74ec9eab
                              • Instruction Fuzzy Hash: 2631D67170C9944BFBA89FA8DC99AB733E5FF55354F50007AF80FC6182DA29EC418689
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: InitializeUninitializefree
                              • String ID:
                              • API String ID: 1169324116-0
                              • Opcode ID: 300bfe15e1352cda4c3c9a5eb26de8ea91f06f6889c64728d4398b9a5c111e42
                              • Instruction ID: 6fbf0285c29f6789b8b2057879b8c9aec40fa5f44b1c9331514f27a031adb5a6
                              • Opcode Fuzzy Hash: 300bfe15e1352cda4c3c9a5eb26de8ea91f06f6889c64728d4398b9a5c111e42
                              • Instruction Fuzzy Hash: 07214C70609A098FDF84EF38D849AAA77E0FF94315F04462AE84FD3151DB39E941CB94
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: free$callocmalloc
                              • String ID:
                              • API String ID: 1437353635-0
                              • Opcode ID: 6cebd9367394abf21773eb1584d65681aa51e4210b0eb886ea29ebe4f46530e1
                              • Instruction ID: d7d0ee06531932b389e39fff20b632d8b8f75f6248cc82f7095cb1c242766914
                              • Opcode Fuzzy Hash: 6cebd9367394abf21773eb1584d65681aa51e4210b0eb886ea29ebe4f46530e1
                              • Instruction Fuzzy Hash: E0423D70618E498FEB55EF38D8896EBB7E1FB58700F10462AD04FC7291EB34A585CB85
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: malloc$free
                              • String ID:
                              • API String ID: 1480856625-0
                              • Opcode ID: f833b09acc7dcda6218a08ced81fc052c99920b07a41f041528abf3627ace0e1
                              • Instruction ID: 9db68d9123f7e8e0a22c71c32da3b262036b50b849663c4e0b4ee83014e76623
                              • Opcode Fuzzy Hash: f833b09acc7dcda6218a08ced81fc052c99920b07a41f041528abf3627ace0e1
                              • Instruction Fuzzy Hash: B631A070608A0A9BAB58EF24DC498ABB3F4FF50750B01462AD81BC7591FF64F89687C5
                              APIs
                              Strings
                              Memory Dump Source
                              • Source File: 00000006.00000003.1502016342.0000011F7ABB0000.00000040.00000001.00020000.00000000.sdmp, Offset: 0000011F7ABB0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_11f7abb0000_OpenWith.jbxd
                              Similarity
                              • API ID: FreeHeap
                              • String ID: l
                              • API String ID: 3298025750-2517025534
                              • Opcode ID: 945787e355e9cefb289f3126088299a2a592093c218b6f331fdd883cb8990c47
                              • Instruction ID: f17c56b97b81f423b90780d65746fe7624644298064fed736bb30e0cff8d49f6
                              • Opcode Fuzzy Hash: 945787e355e9cefb289f3126088299a2a592093c218b6f331fdd883cb8990c47
                              • Instruction Fuzzy Hash: A3A10331518A580AE72DAA2C88916FA77D1FB95300F1D0A7EE5DBC39C3ED34D94F8681
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: CreateFile$AcceptConnectMappingPortcalloc
                              • String ID:
                              • API String ID: 2835849967-0
                              • Opcode ID: d1b445dc56701135788b0dc920e68535db059dd4faca11d9a453a424e093dfee
                              • Instruction ID: a780bfdde682d9568ffa982ff55727aae413464a90c8111dca6af1beec9d32c0
                              • Opcode Fuzzy Hash: d1b445dc56701135788b0dc920e68535db059dd4faca11d9a453a424e093dfee
                              • Instruction Fuzzy Hash: 4DD15F7191C7898BE765DF28D4856EBB7E0FB94700F04462EE48FC3291DF34A5458B86
                              APIs
                              Strings
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: malloc
                              • String ID: X
                              • API String ID: 2803490479-3081909835
                              • Opcode ID: 9fe5fd8fd3d476687bc9124c984f097206d03f3ab6c64bd830142eb49153f5ac
                              • Instruction ID: 324f300cdf6eacd3fb33885ab2491e8b12ebabf70cd893db1e5d785dccff794b
                              • Opcode Fuzzy Hash: 9fe5fd8fd3d476687bc9124c984f097206d03f3ab6c64bd830142eb49153f5ac
                              • Instruction Fuzzy Hash: 1C71B3B0919B088FE768DF6CC4852B677E4FB49310B10063FD89BC7692D734B8428B85
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: File$CreateReadmalloc
                              • String ID:
                              • API String ID: 3950102678-0
                              • Opcode ID: b879bc7b5dc6143657be184a8553957d82cf9a437ba6bdf4bbb2c4680e42a6eb
                              • Instruction ID: 2ff49cca8b3ace95513e374c1ce3e0ffac3b84a942258031b1acda4da739e5c2
                              • Opcode Fuzzy Hash: b879bc7b5dc6143657be184a8553957d82cf9a437ba6bdf4bbb2c4680e42a6eb
                              • Instruction Fuzzy Hash: CF719870A0CB594FE7599F2894C57ABB2E1FB98301F50053FE58FC3292DA38D885CA46
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: AllocInfoSystemVirtual
                              • String ID:
                              • API String ID: 3440192736-0
                              • Opcode ID: 10974d638571623cb466fc5259723849182c6a649d453933aa228a33d07da908
                              • Instruction ID: 20bd2031ec1ca39aaf5e2531ea83a8891d84b7f2a8686d04ba845f13d68c6344
                              • Opcode Fuzzy Hash: 10974d638571623cb466fc5259723849182c6a649d453933aa228a33d07da908
                              • Instruction Fuzzy Hash: ED51D37061CE5E4FEB55AB7D98487BB72E1FB98300F04013AD44EC7595EE68E8C18789
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: File$CreateRead
                              • String ID:
                              • API String ID: 3388366904-0
                              • Opcode ID: 73db5555d885fd7ea61d85234132b183eb459049274d5711c35081ec0b7aef7a
                              • Instruction ID: 7e7bcd7290743a0d1f36a9541ff54a39184c6f1abf8602ccdc43d31be947867f
                              • Opcode Fuzzy Hash: 73db5555d885fd7ea61d85234132b183eb459049274d5711c35081ec0b7aef7a
                              • Instruction Fuzzy Hash: 2241E6B170C6494FD748EF28988566B73E5FB98B05F14462EE94FC3250EE35D8418786
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: File$CreateRead
                              • String ID:
                              • API String ID: 3388366904-0
                              • Opcode ID: 6dcf9cfff2eacf5cd94369649f002897bcffdea66228e64647734ab7a70026dd
                              • Instruction ID: 250177be1f20c7a1194f267b73ecf8e6b2b8840b651ab9b7c207919b9c123498
                              • Opcode Fuzzy Hash: 6dcf9cfff2eacf5cd94369649f002897bcffdea66228e64647734ab7a70026dd
                              • Instruction Fuzzy Hash: 232108B070C7455FE7649F6D98862BB73D4EB89710F10023FE88FC2342DA75AC464A86
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: ProtectVirtual
                              • String ID:
                              • API String ID: 544645111-0
                              • Opcode ID: e54d32ce24f4b710544f648fa16c64d8d7f0589b34fc61474f65512f49413183
                              • Instruction ID: 9f66a14e27e44028a172e678bb1a7b9980d75590897e115507e7fc930bcfeaef
                              • Opcode Fuzzy Hash: e54d32ce24f4b710544f648fa16c64d8d7f0589b34fc61474f65512f49413183
                              • Instruction Fuzzy Hash: 2831F72171CA864BD7149B7C9C987A63BD1FB5A310F1502A6E88EC72C5CB589842C389
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: callocfree
                              • String ID:
                              • API String ID: 306872129-0
                              • Opcode ID: 2b200ceb4e4cc9f035faf7b6c1b247c7413155f6bad845cc72cf0ce4a6dd00dc
                              • Instruction ID: a56776dfc3694b822a3087bf4087edf29085afb246e341137e737adf283d86fa
                              • Opcode Fuzzy Hash: 2b200ceb4e4cc9f035faf7b6c1b247c7413155f6bad845cc72cf0ce4a6dd00dc
                              • Instruction Fuzzy Hash: DDD1617161CA894BE765EF6884A56EF73E1FF98300F00062BE54FC3182DA79F5858686
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: malloc$free
                              • String ID:
                              • API String ID: 1480856625-0
                              • Opcode ID: 352f2f2cecbb3e27f866ef48949e4e4dcfd5ee98b9eced5f0af6e5ea8a5601e0
                              • Instruction ID: 65a0b5be48702d3b40f08b8e49ec6850abd57a13b574101a04cecd9b716ed64c
                              • Opcode Fuzzy Hash: 352f2f2cecbb3e27f866ef48949e4e4dcfd5ee98b9eced5f0af6e5ea8a5601e0
                              • Instruction Fuzzy Hash: 8F71A771A1C9854BD739A73898956EFB2E1FBD5301F10466FE08FC2183ED38B5868689
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptConnectPortfreemalloc
                              • String ID:
                              • API String ID: 3413200017-0
                              • Opcode ID: 694a03a6a0a341675988201f7685504af8169e7f1b53cb1e5f9007a100a90dea
                              • Instruction ID: c22a93d73c8e0b7c05a5f0f7e051db56702dd702abc5526ad50a695103b40dfc
                              • Opcode Fuzzy Hash: 694a03a6a0a341675988201f7685504af8169e7f1b53cb1e5f9007a100a90dea
                              • Instruction Fuzzy Hash: D0415FB0508A488FDB54EF29D8856E677E1FF58711F00056BE84ECB251DF34E885CB82
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: malloc
                              • String ID:
                              • API String ID: 2803490479-0
                              • Opcode ID: 31b51a1252b2397096177e19cb7010b666d546ef653b70412147a1dab026b8b6
                              • Instruction ID: 0e7eec1e5eba582b14762ab0429ee7078cdd5c16a93d7e35acf7984bc1a01476
                              • Opcode Fuzzy Hash: 31b51a1252b2397096177e19cb7010b666d546ef653b70412147a1dab026b8b6
                              • Instruction Fuzzy Hash: 0D41A270608D0E9FDB94EF2CD888AA677F1FBA8311714466BD41AC3660DB74E8D48BC0
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: free
                              • String ID:
                              • API String ID: 1294909896-0
                              • Opcode ID: 472e16019ba601094a4c2923f039f601fa415deb3ae2891c44a4e6fa2e872d25
                              • Instruction ID: b718468b24ecc55863f3e72cff04cbe04c26251a5023b3c92ad377beb57d43db
                              • Opcode Fuzzy Hash: 472e16019ba601094a4c2923f039f601fa415deb3ae2891c44a4e6fa2e872d25
                              • Instruction Fuzzy Hash: BB214970A098584FFF94EB5CC0E8DA677E2FF983107651261E91FC719AD625DC80D784
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: AcceptConnectPortcallocfreemalloc
                              • String ID:
                              • API String ID: 2445003351-0
                              • Opcode ID: 1c81860f17a6367f43a2a94f10a5d32e0a9fa92ddff0a1d18b0803ced88c0a31
                              • Instruction ID: fdab9524905a78a3fc9f5e0397252365672babbaf8520dbbfca2bd2e0142e469
                              • Opcode Fuzzy Hash: 1c81860f17a6367f43a2a94f10a5d32e0a9fa92ddff0a1d18b0803ced88c0a31
                              • Instruction Fuzzy Hash: F0F02831214D0C4FD748AB2C9C8C6B637E1EB94726714462BE00BC7260DD78DD40C780
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: calloc
                              • String ID:
                              • API String ID: 2635317215-0
                              • Opcode ID: 4c67779dd63165b43659fab8fd510d9b574d13d676e16a29e3859926c8de3004
                              • Instruction ID: 10905f04877b058baeb7421cfcb7e53c4366e8fa298194493479d4c159ee29dc
                              • Opcode Fuzzy Hash: 4c67779dd63165b43659fab8fd510d9b574d13d676e16a29e3859926c8de3004
                              • Instruction Fuzzy Hash: F672727051CA898BDB69EF28D495ADFB3E1FF94300F10466EE48F83296DE34E4858746
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: CreateFileMapping
                              • String ID:
                              • API String ID: 524692379-0
                              • Opcode ID: 090a60165b6d81dbbef6ccd1718067ffa9bcceaffdfa6db13320491a5d5642c1
                              • Instruction ID: cff1d0a5bc1abc4450b1e223cf614c94f53abe500ffe8c3a24a0f39a24f93065
                              • Opcode Fuzzy Hash: 090a60165b6d81dbbef6ccd1718067ffa9bcceaffdfa6db13320491a5d5642c1
                              • Instruction Fuzzy Hash: 01A14FB161CA898FDB54EF29C8849ABB7F1FB94700F404A6EE04FC7191DA34E585CB85
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: Open
                              • String ID:
                              • API String ID: 71445658-0
                              • Opcode ID: e8d5d7329d2320a05d82013e26ca3d8c66ee9948d03da3e8e50157f1609a8dd5
                              • Instruction ID: dafe9a70f2af5d53733a8a39329e7a2f02c122dd8888134e36f2e793cf0ed0e8
                              • Opcode Fuzzy Hash: e8d5d7329d2320a05d82013e26ca3d8c66ee9948d03da3e8e50157f1609a8dd5
                              • Instruction Fuzzy Hash: CA91BC7560DB899FE765EF64C488B9BB7E1FB98301F00492BE48AC3260DB34D544CB42
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: Send
                              • String ID:
                              • API String ID: 121738739-0
                              • Opcode ID: d8e018eafecf73722f3cfd2108c578dd3fd3213e6426fbbfe5b50f999653df9c
                              • Instruction ID: 524e37cb58aa473081c31b2145f2249bdc4e5b329c69dfd827a0dfc069f57b0c
                              • Opcode Fuzzy Hash: d8e018eafecf73722f3cfd2108c578dd3fd3213e6426fbbfe5b50f999653df9c
                              • Instruction Fuzzy Hash: E8819FB0508A498FEB98DF68C4987A6B7E0FF64314F00426AE40EC7691EB35E851CB85
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: InformationVolume
                              • String ID:
                              • API String ID: 2039140958-0
                              • Opcode ID: 458a1419ed12d8a3c2e86420f2914f8409b820493848f008ec8053e1bf8f0b77
                              • Instruction ID: 1edcf414c3a61005784d08d7996b0a7e3ad106885cb90b4acf90431d3f620853
                              • Opcode Fuzzy Hash: 458a1419ed12d8a3c2e86420f2914f8409b820493848f008ec8053e1bf8f0b77
                              • Instruction Fuzzy Hash: B2617EB150C7898BE765EF65D8956EBB7E1FB94300F000A2EE08FC3191DE39A545CB46
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: CreateProcess
                              • String ID:
                              • API String ID: 963392458-0
                              • Opcode ID: e9169745a3f5c8f3addee9eb58fc29d082d9d243fdbbd28d7b824531286ef21a
                              • Instruction ID: ddb4d43b26dd4f1d1907c5ee28a334cf60b24ab0972d5068b0be056682c14a77
                              • Opcode Fuzzy Hash: e9169745a3f5c8f3addee9eb58fc29d082d9d243fdbbd28d7b824531286ef21a
                              • Instruction Fuzzy Hash: 80516E70A0C7895BE765DB68D8457ABB3E5FFD5310F000A2FE48AC3191DB78E8418B46
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: Recv
                              • String ID:
                              • API String ID: 4192927123-0
                              • Opcode ID: 7916fdf4d3e942b440d7f5c412e90116e139ebed5d60f444feec34680a904e5a
                              • Instruction ID: 88f1ac002ee6621213b6f265a8f693aadbc32b6b705079b59871f3048a367797
                              • Opcode Fuzzy Hash: 7916fdf4d3e942b440d7f5c412e90116e139ebed5d60f444feec34680a904e5a
                              • Instruction Fuzzy Hash: 175148B0508A898FEBA4EF69C498B9777F0FF64314F50056AE44BC3561EB39E840CB45
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: calloc
                              • String ID:
                              • API String ID: 2635317215-0
                              • Opcode ID: 6627cfbe9fd8d1ed5517d68a071bfa190fd008ef314ddf0e2e91dc369a45b12d
                              • Instruction ID: 2f3af9619e1ffb0c7af9b43ced4e8f3c3371430a617383dbbc8804e35d680af3
                              • Opcode Fuzzy Hash: 6627cfbe9fd8d1ed5517d68a071bfa190fd008ef314ddf0e2e91dc369a45b12d
                              • Instruction Fuzzy Hash: 3CB1F87191CADC4FEB68AB6C84956EB73E1EB94300F50052FD59FC3182E929EC474689
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: getaddrinfo
                              • String ID:
                              • API String ID: 300660673-0
                              • Opcode ID: 6ecee242a2d9719518cb049206fbca905074d49784de06f99d83231cef7de4a6
                              • Instruction ID: 2f8e884a27c3a303e5fbc573a070a650e8bef1def67f30a8e1e0caa75b114c18
                              • Opcode Fuzzy Hash: 6ecee242a2d9719518cb049206fbca905074d49784de06f99d83231cef7de4a6
                              • Instruction Fuzzy Hash: 6C41BFB06189498BDB58EF39C8845EBB3E1FF98310B50436BE40FC7192DA38E985C785
                              APIs
                                • Part of subcall function 00007DF46E4C65E0: VirtualProtect.KERNELBASE ref: 00007DF46E4C6640
                                • Part of subcall function 00007DF46E4C65E0: VirtualProtect.KERNELBASE ref: 00007DF46E4C6669
                                • Part of subcall function 00007DF46E4C65E0: VirtualProtect.KERNELBASE ref: 00007DF46E4C6685
                                • Part of subcall function 00007DF46E4C65E0: VirtualProtect.KERNELBASE ref: 00007DF46E4C66B0
                              • TlsFree.KERNELBASE(?,?,?,?,?,?,?,00000000,?,?,00000000,00007DF46E4C341C), ref: 00007DF46E4C7CB7
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: ProtectVirtual$Free
                              • String ID:
                              • API String ID: 3841229516-0
                              • Opcode ID: 9454607179550a56fcb25c77309fc397396c8818e949c4bf6b88fbdfb1fa50f0
                              • Instruction ID: bd7afeb766278fb3e2be2f0239e3aff699450112bcf71c41e6553e9bf4862468
                              • Opcode Fuzzy Hash: 9454607179550a56fcb25c77309fc397396c8818e949c4bf6b88fbdfb1fa50f0
                              • Instruction Fuzzy Hash: B841A7B0B0CA4A4BDB54EB3994C95EF73E1EF49B00B044677E41BC72C6DA28F8858795
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: ErrorFunctionModeTable
                              • String ID:
                              • API String ID: 928017140-0
                              • Opcode ID: d9c23544fbb2a9f569b4c70e99ee3ada11af114710c16124923c5dd5b1b488fd
                              • Instruction ID: abb0626fddcae112241c764052ff352e1e43a7eab5428cd7fbb3ca4de723bcaa
                              • Opcode Fuzzy Hash: d9c23544fbb2a9f569b4c70e99ee3ada11af114710c16124923c5dd5b1b488fd
                              • Instruction Fuzzy Hash: EC31BFA171C89A4BEB54FB7A98866EB32E1EF44710B40067ED00FC31D2DD18EDC54249
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: setsockopt
                              • String ID:
                              • API String ID: 3981526788-0
                              • Opcode ID: 5ecb9aca37cfa74a852660f22e24977ddf5ffe3d9d8c212dab6545ea967c75f3
                              • Instruction ID: 59053acf83fa58f918b7a08ed2b51c5655fdbee812bf3e06f273e94e539a1494
                              • Opcode Fuzzy Hash: 5ecb9aca37cfa74a852660f22e24977ddf5ffe3d9d8c212dab6545ea967c75f3
                              • Instruction Fuzzy Hash: 6B31FCB0904A458FFBA8DF58C0987A277E5FF54325F1402AAE81ECB2E6D7749881CB44

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 92 11f791b185c-11f791b188c call 11f791b08a4 * 2 97 11f791b1892-11f791b1895 92->97 98 11f791b1940-11f791b1947 92->98 97->98 99 11f791b189b-11f791b18a5 97->99 99->98 100 11f791b18ab-11f791b18b0 99->100 100->98 101 11f791b18b6-11f791b18c3 100->101 101->98 102 11f791b18c5-11f791b18cd 101->102 102->98 103 11f791b18cf-11f791b18da 102->103 103->98 104 11f791b18dc-11f791b18e3 103->104 104->98 105 11f791b18e5-11f791b18e8 104->105 105->98 106 11f791b18ea-11f791b18f2 105->106 106->98 107 11f791b18f4-11f791b18f7 106->107 107->98 108 11f791b18f9-11f791b1902 107->108 108->98 109 11f791b1904-11f791b1908 108->109 109->98 110 11f791b190a-11f791b191a 109->110 110->98 112 11f791b191c-11f791b1933 GetProcessMitigationPolicy 110->112 112->98 113 11f791b1935-11f791b193a 112->113 113->98 114 11f791b193c-11f791b193d 113->114 114->98
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000002.1767089124.0000011F791B0000.00000040.00000001.00020000.00000000.sdmp, Offset: 0000011F791B0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_2_11f791b0000_OpenWith.jbxd
                              Similarity
                              • API ID: MitigationPolicyProcess
                              • String ID:
                              • API String ID: 1088084561-0
                              • Opcode ID: 04359cd7b97b11c476e8c0617afcaa098c35e265ec660168a6fbd24c0647ca60
                              • Instruction ID: 28fb2297dd0a2799e23a7d1fbbeeafb6c95a8fb07f05bf4172b2c6f6430906ed
                              • Opcode Fuzzy Hash: 04359cd7b97b11c476e8c0617afcaa098c35e265ec660168a6fbd24c0647ca60
                              • Instruction Fuzzy Hash: 89319E30240A4A4AFB7DD768A8847E173D7FB943B1F1B11BDC219CA1D1FAB1D8A28740
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: getaddrinfo
                              • String ID:
                              • API String ID: 300660673-0
                              • Opcode ID: 444279a65ed160c075670131e7138b44e5ba453f7519e9f4e47c8cdc32b69109
                              • Instruction ID: f90ac7677c201073310c4f314179f08b3d2e548284b46b48988ffa45460dfa2b
                              • Opcode Fuzzy Hash: 444279a65ed160c075670131e7138b44e5ba453f7519e9f4e47c8cdc32b69109
                              • Instruction Fuzzy Hash: CF21A1B060858A8BDF54EF2988845EFB7E2FFD8711B50836AD40FC7092C638E985C745
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: ResumeThread
                              • String ID:
                              • API String ID: 947044025-0
                              • Opcode ID: a1e79bfd5fdfa4d599be838d72d64bf9e685b5698f2b0b05ab8498b458f49234
                              • Instruction ID: de7ef6020a371f76cba1e16384a79bb179050f854d41ffaf02bb67f781f38b68
                              • Opcode Fuzzy Hash: a1e79bfd5fdfa4d599be838d72d64bf9e685b5698f2b0b05ab8498b458f49234
                              • Instruction Fuzzy Hash: 2601D631B1491A8FEB94AB79DC8867737E5FF893517040476E80EC7154DE39AC82C789
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: DestroyHeap
                              • String ID:
                              • API String ID: 2435110975-0
                              • Opcode ID: e8b38785987ebe4bf97a71b2e294a612045f12fa57e0274daf3e7e500e703184
                              • Instruction ID: f4cee7316d2dc079115e378cc56d94de77f11dc8331827bb02666d65c3f30ab8
                              • Opcode Fuzzy Hash: e8b38785987ebe4bf97a71b2e294a612045f12fa57e0274daf3e7e500e703184
                              • Instruction Fuzzy Hash: 4C016DB09086568FDB54AF79BC8616636F0EB98311740043BE10AC7960CE3858D0C744
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: CreateHeap
                              • String ID:
                              • API String ID: 10892065-0
                              • Opcode ID: f6a5c260a6ff26826b95901847e0f94daf167b208f970919ab6999429e88efbf
                              • Instruction ID: 1347751e46e37b76d45701fbab098c7f530ee6837ca6812f571139e8df74f0cb
                              • Opcode Fuzzy Hash: f6a5c260a6ff26826b95901847e0f94daf167b208f970919ab6999429e88efbf
                              • Instruction Fuzzy Hash: F9F0ECE1F1C24A4BE7246F765C851A771E6DB84311F14453BE90FC7185DC3D94C28648
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: setsockopt
                              • String ID:
                              • API String ID: 3981526788-0
                              • Opcode ID: ddedd6023ad442b8d2b2fe3290ed3783bcd232237776f9c3a295af58d00cf6c3
                              • Instruction ID: 11176a8c04ded030453a8764cf553eef639e5aee2bc9cdcb40ce212858800c19
                              • Opcode Fuzzy Hash: ddedd6023ad442b8d2b2fe3290ed3783bcd232237776f9c3a295af58d00cf6c3
                              • Instruction Fuzzy Hash: D2F082741046044FEB48EF5CC48876677E2FFE9315F10016AE90DC72E4DB359989C741
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: AddressCallerProc
                              • String ID:
                              • API String ID: 2663294120-0
                              • Opcode ID: c2543c20c0a7d110227d86949c13dfaa5e54e54e664fb098b1aa0bdcf88303a9
                              • Instruction ID: bd3f978ca7b108aa648b5753e422ee8bb3923bda8d1f03a01fb05c7475ae1eb2
                              • Opcode Fuzzy Hash: c2543c20c0a7d110227d86949c13dfaa5e54e54e664fb098b1aa0bdcf88303a9
                              • Instruction Fuzzy Hash: 0FE0C251B18C0A0B6B6862BF248CABB51D6CBDC13230402BBE41EC3295EC54CC850385
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: FilePointer
                              • String ID:
                              • API String ID: 973152223-0
                              • Opcode ID: 23f3765db31a0df280e37a6bc4f8137308a1fee0486dc2818908f898aea27d2f
                              • Instruction ID: c076b59af0e72806b2472201f695b54bc63e28b6ed3703abb36710452691a838
                              • Opcode Fuzzy Hash: 23f3765db31a0df280e37a6bc4f8137308a1fee0486dc2818908f898aea27d2f
                              • Instruction Fuzzy Hash: ADE0C232B150240BF72C6ABD2C8917A36DAC7CC572705423BF80AC3284ED7C8C4602D1
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: FunctionTable
                              • String ID:
                              • API String ID: 1252446317-0
                              • Opcode ID: 3b09555bf32cd7a482aca5e21dc4f37ab037edd0c1b9afc7390cc3b8e22e33b4
                              • Instruction ID: e8962ba890b837cef90ccfebdd91965c224765eebe277c316b9fcb70ac533a6e
                              • Opcode Fuzzy Hash: 3b09555bf32cd7a482aca5e21dc4f37ab037edd0c1b9afc7390cc3b8e22e33b4
                              • Instruction Fuzzy Hash: 8CE04F305509064BEBA8E72DC84D3913AE1FB58306F64426ED405C9691CB79D89BCF81
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: LibraryLoad
                              • String ID:
                              • API String ID: 1029625771-0
                              • Opcode ID: deadc42d593f6e2d9e8bf000e5cc548490ab76c2dd2841c06e942c08cce04583
                              • Instruction ID: f1103fc3ee2f0f2db8bcd6da909ee3440a417a953d48b6ed0b7e3a88edae3bac
                              • Opcode Fuzzy Hash: deadc42d593f6e2d9e8bf000e5cc548490ab76c2dd2841c06e942c08cce04583
                              • Instruction Fuzzy Hash: 4FD0A751724D0E1BEB48633F1C987A711D5EBCC225F54017BF40EC2285DD58CC950305
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: free
                              • String ID:
                              • API String ID: 1294909896-0
                              • Opcode ID: 903acddc3c2cbd21899d181af60d2020bd4c0d22b9f6ec9809e98e44769c02c6
                              • Instruction ID: 215d1ea1ba7791ac037c2277267c40358bb5a657460d214b267005249e55d3af
                              • Opcode Fuzzy Hash: 903acddc3c2cbd21899d181af60d2020bd4c0d22b9f6ec9809e98e44769c02c6
                              • Instruction Fuzzy Hash: 67414170618A498FDB94EF28C481AEBB3F1FF98710F50426AD44EC7196DA34F881CB85
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: malloc
                              • String ID:
                              • API String ID: 2803490479-0
                              • Opcode ID: c3b5330ba83a094f7bad87bbcfda8b7898b28b22e9f53235a9dbd9f71cfcc7c9
                              • Instruction ID: 5810ee4bdc7667b1657a44c8145813460f56e3ee6aff0995f26b627a7b39769f
                              • Opcode Fuzzy Hash: c3b5330ba83a094f7bad87bbcfda8b7898b28b22e9f53235a9dbd9f71cfcc7c9
                              • Instruction Fuzzy Hash: 40412A70A0449A4BEB68DF388CD44BB37F1EF85345714417BD86BCB186EA28E987C794
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: calloc
                              • String ID:
                              • API String ID: 2635317215-0
                              • Opcode ID: 1510f62e4c51649cb4b3fc6bb3479c9fee78b3cdc066acf53db6694c8fe85d1c
                              • Instruction ID: 2cae5f07fed359fff9410bfd23b0491d8adf07d9600076e627a283fcddae3c4d
                              • Opcode Fuzzy Hash: 1510f62e4c51649cb4b3fc6bb3479c9fee78b3cdc066acf53db6694c8fe85d1c
                              • Instruction Fuzzy Hash: 1F41EBB0908A188FDB91EF5894887D277E5FB68301F1842BBDC4DCF25ADB748885CB90
                              APIs
                              • free.MSVCRT(?,?,?,?,?,?,-00000002,00007DF46E4D59FD,?,?,?,?,?,?,-00000002,00007DF46E4D5A9F), ref: 00007DF46E589669
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: free
                              • String ID:
                              • API String ID: 1294909896-0
                              • Opcode ID: 3c3f3896645624ed2edffa25d0ed107847367446d48ff0b9b56c9f709a2f52a8
                              • Instruction ID: ef1b392146a887ba1f2a7f968b9230aa864ad68687b36503dc9a9b40b35248a1
                              • Opcode Fuzzy Hash: 3c3f3896645624ed2edffa25d0ed107847367446d48ff0b9b56c9f709a2f52a8
                              • Instruction Fuzzy Hash: 3531C0706158998FFF98EFA9C4B57E733E1FF94301F540479980FCA196CA28A842C715
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: free
                              • String ID:
                              • API String ID: 1294909896-0
                              • Opcode ID: 14d07331c19738ae6f5dcbbc3446d40274566deaf3c6ba6d90dddde88c6f0ea8
                              • Instruction ID: 5799f199e9d0ab065840188311d9da136d0454b4a67c7f321edae1d8b8889a26
                              • Opcode Fuzzy Hash: 14d07331c19738ae6f5dcbbc3446d40274566deaf3c6ba6d90dddde88c6f0ea8
                              • Instruction Fuzzy Hash: 2521E470A18B094FD748AF68D8895F677E4FB98711F00426FD44EC3262EA74E885CBC5
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: lstrcmpi
                              • String ID:
                              • API String ID: 1586166983-0
                              • Opcode ID: dd3043cd4fdbf6ce1bec2523c8a3e90b76413ae5d3024df9cc9149889a1f6f13
                              • Instruction ID: 960389c390e36a64727575624b4d19dcaa029abfdb0c5c1992fe7944db696564
                              • Opcode Fuzzy Hash: dd3043cd4fdbf6ce1bec2523c8a3e90b76413ae5d3024df9cc9149889a1f6f13
                              • Instruction Fuzzy Hash: 7911ECF0B0594A1BE75CAB3998493F736E1FF94B00B444376D80FC70A5EE689DC58248
                              APIs
                              • malloc.MSVCRT(?,?,?,?,-00000001,?,-00000001,00007DF46E4B65CE), ref: 00007DF46E4B6585
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: malloc
                              • String ID:
                              • API String ID: 2803490479-0
                              • Opcode ID: 051b47b6163c57a56397831363f2f208832c5eccc5cbea97d62df897e1ee0233
                              • Instruction ID: cb47e2569b52662ca798eb0b66b826e8126e15038a98f715a83ae4c55057456a
                              • Opcode Fuzzy Hash: 051b47b6163c57a56397831363f2f208832c5eccc5cbea97d62df897e1ee0233
                              • Instruction Fuzzy Hash: 6401A270A14A065BE3689F29D888263B3E1FB98311F04417AD409C3284DB38E8D0C780
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: FreeVirtual
                              • String ID:
                              • API String ID: 1263568516-0
                              • Opcode ID: 85f62002f11eda201487085593c698b0135f5f3e41b5990a1ae8dfcda2a01f33
                              • Instruction ID: ac15ac9916b90edf98469925bd93ab7d35c30781b4c9bde345377b1455a2b607
                              • Opcode Fuzzy Hash: 85f62002f11eda201487085593c698b0135f5f3e41b5990a1ae8dfcda2a01f33
                              • Instruction Fuzzy Hash: 32016270A18E4B4BEB58DF3C8C6526332E1FF58315754816AD00EC72E4FE29E8828709
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: free
                              • String ID:
                              • API String ID: 1294909896-0
                              • Opcode ID: 12b16b66d14aa5c191870bddd5a7e4309bad3884871b1f4995f58294878dabf5
                              • Instruction ID: c2439ae7ed2e5d484bd1bd82f6982f7863b2d6475fa26ba77236865813024642
                              • Opcode Fuzzy Hash: 12b16b66d14aa5c191870bddd5a7e4309bad3884871b1f4995f58294878dabf5
                              • Instruction Fuzzy Hash: 27F01DB0615E4B9FEB84EF29C4D876673E0FB68305F60447BE40AC2190D779D894C751

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 123 11f791b19a0-11f791b19bd 125 11f791b19c9-11f791b19d0 123->125 126 11f791b19bf-11f791b19c6 123->126 127 11f791b19e7-11f791b19f5 125->127 128 11f791b19d2-11f791b19e5 VirtualFree 125->128 126->125 128->127
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000002.1767089124.0000011F791B0000.00000040.00000001.00020000.00000000.sdmp, Offset: 0000011F791B0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_2_11f791b0000_OpenWith.jbxd
                              Similarity
                              • API ID: FreeVirtual
                              • String ID:
                              • API String ID: 1263568516-0
                              • Opcode ID: 68a2bebb63dec11ebeb4fbf40c1c95563ebbd08489d40e2effbc7ec76ba53b27
                              • Instruction ID: 25bc9f65c88d1e614c573aa9568271f157837e45393279cc3538588a968b3a82
                              • Opcode Fuzzy Hash: 68a2bebb63dec11ebeb4fbf40c1c95563ebbd08489d40e2effbc7ec76ba53b27
                              • Instruction Fuzzy Hash: E6F01731214A098FDF9CEF95D8D5EE133A5FB28301F0501B9CD0ACB19ADA61E885C791
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: free
                              • String ID:
                              • API String ID: 1294909896-0
                              • Opcode ID: e005b8aad8ae59e5c4306d33e7cf4f806ca0153c9240256dc9db618efce1777c
                              • Instruction ID: e358597af618c3c843f7e9ae40211c10e7e6438c299ef408932cbfe77ab4826d
                              • Opcode Fuzzy Hash: e005b8aad8ae59e5c4306d33e7cf4f806ca0153c9240256dc9db618efce1777c
                              • Instruction Fuzzy Hash: EAF0187451BA0E8BFF5CA7A598686AB37F1EF14306F04103FD80BD1590DA6E9464D721
                              APIs
                              • free.MSVCRT(?,?,?,?,?,?,?,00007DF46E5896DA,?,?,?,?,?,?,-00000002,00007DF46E4D59FD), ref: 00007DF46E5895F3
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: free
                              • String ID:
                              • API String ID: 1294909896-0
                              • Opcode ID: 93a629741bab06a182ed7c8d449849feef47e04a3418518c2bb9a01bc531160b
                              • Instruction ID: 499ab2cb5feaf4e6369759b561b4bc6c8bbd45a19cb77a1b3cc60e09e37863d5
                              • Opcode Fuzzy Hash: 93a629741bab06a182ed7c8d449849feef47e04a3418518c2bb9a01bc531160b
                              • Instruction Fuzzy Hash: 8EE012746168494BFF98FBA584B866772E1EF58205F50047A980FC62D2CA19DD42C745
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: malloc
                              • String ID:
                              • API String ID: 2803490479-0
                              • Opcode ID: 4c39f900df3972edeb9c523e4745635d2babc99cae264e1317ea5b764d4d565e
                              • Instruction ID: 1d8247767c5e82305b617c5d0bbce048d407ec682639171ebdd4ff234ea8cb02
                              • Opcode Fuzzy Hash: 4c39f900df3972edeb9c523e4745635d2babc99cae264e1317ea5b764d4d565e
                              • Instruction Fuzzy Hash: 71D05E50B15D0E1BAB58A37E1C8A17621D6D7D81227440637B80AC3254ED29DC858254
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: free
                              • String ID:
                              • API String ID: 1294909896-0
                              • Opcode ID: 6e328c12dc8307f618a414a7ee27d1f513c26b9c3dfb4301b0faf22b9c49d378
                              • Instruction ID: e4b7125b58109774fff9631daccca2105a362c42bc826e2bd333ff25323b33d6
                              • Opcode Fuzzy Hash: 6e328c12dc8307f618a414a7ee27d1f513c26b9c3dfb4301b0faf22b9c49d378
                              • Instruction Fuzzy Hash: 03D01331355C0C5F5684E65DDCC893433D5E7DC125314057FD40DC7255D5569C87C760
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: free
                              • String ID:
                              • API String ID: 1294909896-0
                              • Opcode ID: b7031c71d370f0c4b9d1add862bc0dfec61c612abdfff09cb5e9d61695c69b58
                              • Instruction ID: 6433c602a5855d0c4fb975f43202e5ac96cfd7dfefe46f2bec3d7b24f1505741
                              • Opcode Fuzzy Hash: b7031c71d370f0c4b9d1add862bc0dfec61c612abdfff09cb5e9d61695c69b58
                              • Instruction Fuzzy Hash: 04B0926499AD4B42AD0833760D9919A29A0AB14601BC501259806C0050E50E909A829A
                              APIs
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID: free
                              • String ID:
                              • API String ID: 1294909896-0
                              • Opcode ID: 551c0ffc82b28a3876ee79cfc9de3840c8837f1e4274ad0e5daf9a8a7b3ff23c
                              • Instruction ID: c741381c53317ed93acf1de60341ac84fd0f7a7fc63e4b4ec9554c8ce6e92c02
                              • Opcode Fuzzy Hash: 551c0ffc82b28a3876ee79cfc9de3840c8837f1e4274ad0e5daf9a8a7b3ff23c
                              • Instruction Fuzzy Hash: BCB01264E27C4F02ED4C33770E5906A36A0AF1C202FC40015E806C0C54F64CC4D5A34A
                              Memory Dump Source
                              • Source File: 00000006.00000002.1767089124.0000011F791B0000.00000040.00000001.00020000.00000000.sdmp, Offset: 0000011F791B0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_2_11f791b0000_OpenWith.jbxd
                              Similarity
                              • API ID:
                              • String ID:
                              • API String ID:
                              • Opcode ID: d522c07823fb8778296108337a3d1ec347010d1dae431256f70b68abef76ec51
                              • Instruction ID: 9c6f723353de5f7bfac1b68b00d860ec9f8fa9508ac40f659eae0282c9a534f1
                              • Opcode Fuzzy Hash: d522c07823fb8778296108337a3d1ec347010d1dae431256f70b68abef76ec51
                              • Instruction Fuzzy Hash: 26B01132E28A0082E3880E0AB8023B0F2B0C30B300F00B0322008F3220C828CC08028F
                              Memory Dump Source
                              • Source File: 00000006.00000003.1766636545.00007DF46E4B1000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF46E4B1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_6_3_7df46e4b1000_OpenWith.jbxd
                              Similarity
                              • API ID:
                              • String ID:
                              • API String ID:
                              • Opcode ID: 46f5df41ea43a57528ce76f95f617c5d60ae02f95908509022172248d9e28bd8
                              • Instruction ID: 317b8491c6c81d94af8fc2b3a06f72133790875556e8c436f9feff669d1d81d5
                              • Opcode Fuzzy Hash: 46f5df41ea43a57528ce76f95f617c5d60ae02f95908509022172248d9e28bd8
                              • Instruction Fuzzy Hash: FFB01130E28808C2C2280E0AF802330F2B0C30B300F00303A2000F3A20C8BACC82008F

                              Execution Graph

                              Execution Coverage:5.1%
                              Dynamic/Decrypted Code Coverage:15.9%
                              Signature Coverage:0%
                              Total number of Nodes:290
                              Total number of Limit Nodes:21
                              execution_graph 22453 21ce78e2628 22454 21ce78e265b 22453->22454 22456 21ce78e267c Thread32First 22454->22456 22460 21ce78e2734 22454->22460 22455 21ce78e288a 22459 21ce78e2681 22456->22459 22457 21ce78e276d SuspendThread 22457->22460 22458 21ce78e272b CloseHandle 22458->22460 22459->22458 22460->22455 22460->22457 22802 7df4b9901650 GetVolumeInformationW 22461 7df4b9913018 22462 7df4b991304b 22461->22462 22470 7df4b9913213 22462->22470 22471 7df4b9911708 22462->22471 22466 7df4b9913130 calloc 22468 7df4b9913085 22466->22468 22467 7df4b991318a 22469 7df4b99131e7 SendMessageA 22467->22469 22468->22466 22468->22467 22468->22470 22469->22470 22472 7df4b9911715 22471->22472 22473 7df4b991173b 22471->22473 22472->22473 22474 7df4b991171b RtlAddFunctionTable 22472->22474 22475 7df4b9911740 22473->22475 22474->22473 22476 7df4b9911760 VirtualProtect 22475->22476 22478 7df4b991176f 22475->22478 22476->22478 22477 7df4b991180d 22477->22468 22478->22477 22479 7df4b99117e9 VirtualProtect 22478->22479 22479->22478 22484 7df4b99022cc 22486 7df4b99022ee 22484->22486 22485 7df4b990276d 22486->22485 22494 7df4b9901290 22486->22494 22490 7df4b9902329 22490->22485 22491 7df4b9902347 calloc 22490->22491 22491->22485 22493 7df4b9902361 22491->22493 22492 7df4b9902754 SetTimer 22492->22485 22493->22492 22495 7df4b99012c3 22494->22495 22496 7df4b990129d 22494->22496 22498 7df4b99012c8 22495->22498 22496->22495 22497 7df4b99012a3 RtlAddFunctionTable 22496->22497 22497->22495 22499 7df4b99012e8 VirtualProtect 22498->22499 22501 7df4b99012f7 22498->22501 22499->22501 22500 7df4b9901395 22500->22490 22501->22500 22502 7df4b9901371 VirtualProtect 22501->22502 22502->22501 22792 21ce78edde4 GetSystemInfo VirtualAlloc 22503 21ce78e74a0 22507 21ce78e74d8 22503->22507 22504 21ce78e7712 free 22504->22507 22505 21ce78e7732 22506 21ce78e7573 VirtualFree 22506->22504 22507->22504 22507->22505 22507->22506 22508 21ce78f7da0 SetErrorMode 22509 21ce78f7db4 22508->22509 22510 21ce78fb216 socket 22509->22510 22511 21ce78fb25a getsockopt 22510->22511 22512 21ce78fb2a3 socket 22510->22512 22511->22512 22514 21ce78fb2c3 22512->22514 22515 7df4b9912f60 22516 7df4b9912f6d 22515->22516 22518 7df4b9912fdc 22515->22518 22517 7df4b9912fa3 SetWinEventHook 22516->22517 22516->22518 22517->22518 22793 21ce78e2ddc 6 API calls 22791 7df4b9902084 calloc NtQueryInformationProcess 22654 21ce78e2974 22655 21ce78e299a 22654->22655 22656 21ce78e29a2 VirtualProtect 22654->22656 22655->22656 22658 21ce78e29c7 22656->22658 22659 21ce78e29bd 22656->22659 22657 21ce78e2a09 VirtualProtect 22657->22659 22658->22657 22660 21ce78ebbb4 22661 21ce78ebbb9 22660->22661 22665 21ce78ebbe2 22660->22665 22666 21ce78e4e74 calloc 22661->22666 22663 21ce78ebbda 22667 21ce78eb9d8 22663->22667 22666->22663 22668 21ce78eb9f9 22667->22668 22669 21ce78ebad0 CreateWindowExW 22668->22669 22670 21ce78ebb2d 22668->22670 22669->22670 22670->22665 22671 21ce78ecdf4 22672 21ce78ece47 22671->22672 22679 21ce78eae7c 22672->22679 22674 21ce78ece6f CreateNamedPipeW 22675 21ce78eceb7 22674->22675 22677 21ce78ecef9 22674->22677 22676 21ce78eced0 BindIoCompletionCallback 22675->22676 22676->22677 22678 21ce78ecee8 ConnectNamedPipe 22676->22678 22678->22677 22680 21ce78eaeb8 22679->22680 22683 21ce78f2990 22680->22683 22682 21ce78eaec0 22682->22674 22684 21ce78f29a4 NtAcceptConnectPort 22683->22684 22685 21ce78f29be 22683->22685 22684->22685 22685->22682 22804 21ce78f0ab4 calloc 22480 21ce78e2904 22481 21ce78e2957 22480->22481 22482 21ce78e2916 22480->22482 22482->22481 22483 21ce78e2939 ResumeThread 22482->22483 22483->22482 22519 21ce78ebe7c 22520 21ce78ebea5 22519->22520 22521 21ce78ebeb5 22520->22521 22522 21ce78ebed3 LoadLibraryA 22520->22522 22522->22521 22523 21ce78e697c 22524 21ce78e6998 22523->22524 22525 21ce78e69a6 22524->22525 22526 21ce78e699d GetProcAddressForCaller 22524->22526 22526->22525 22790 21ce78e9a7c malloc 22527 21ce78e58d8 22530 21ce78e6c10 22527->22530 22529 21ce78e58ea 22531 21ce78e6c19 22530->22531 22538 21ce78e6cfc 22530->22538 22531->22538 22541 21ce78f2d24 22531->22541 22533 21ce78e6cae 22533->22538 22548 21ce78e3c84 22533->22548 22535 21ce78e6cba 22536 21ce78e6cd1 SetErrorMode 22535->22536 22537 21ce78e6cea 22536->22537 22540 21ce78e6d14 22536->22540 22537->22538 22552 21ce78e69b0 22537->22552 22538->22529 22540->22529 22570 21ce78e4998 22541->22570 22543 21ce78f3db2 22543->22533 22544 21ce78f3866 RtlFormatCurrentUserKeyPath 22546 21ce78f3872 22544->22546 22545 21ce78f2d71 22545->22543 22545->22544 22545->22546 22546->22543 22574 21ce78e55f0 6 API calls 22546->22574 22549 21ce78e3cb7 22548->22549 22550 21ce78e3c91 22548->22550 22549->22535 22550->22549 22551 21ce78e3c97 RtlAddFunctionTable 22550->22551 22551->22549 22553 21ce78e69b9 22552->22553 22569 21ce78e6a18 22552->22569 22575 21ce78e4e74 calloc 22553->22575 22555 21ce78e69d3 22556 21ce78e6a75 22555->22556 22558 21ce78e69e5 22555->22558 22601 21ce78f0bd0 15 API calls 22556->22601 22559 21ce78e69f9 22558->22559 22560 21ce78e6a41 22558->22560 22558->22569 22561 21ce78e6a34 22559->22561 22562 21ce78e69fe 22559->22562 22600 21ce78f11e8 12 API calls 22560->22600 22599 21ce78f0cf0 15 API calls 22561->22599 22565 21ce78e6a27 22562->22565 22566 21ce78e6a03 22562->22566 22598 21ce78f0e18 17 API calls 22565->22598 22566->22569 22576 21ce78ed594 22566->22576 22569->22538 22571 21ce78e49b0 22570->22571 22572 21ce78e49da 22571->22572 22573 21ce78e49b8 calloc 22571->22573 22572->22545 22573->22572 22574->22543 22575->22555 22577 21ce78ed5aa 22576->22577 22602 21ce78ea9c0 22577->22602 22579 21ce78ed5bd 22580 21ce78ed629 CloseHandle 22579->22580 22581 21ce78ed5c5 MapViewOfFile 22579->22581 22582 21ce78ed6db 22580->22582 22583 21ce78ed63b 22580->22583 22586 21ce78ed5ef 22581->22586 22582->22569 22583->22582 22605 21ce78e2b50 22583->22605 22585 21ce78ed64b 22585->22582 22609 21ce78edfc4 22585->22609 22591 21ce78ed614 22586->22591 22623 21ce78f026c malloc 22586->22623 22591->22580 22592 21ce78ed65d 22618 21ce78ed188 6 API calls 22592->22618 22594 21ce78ed662 22619 21ce78e7950 22594->22619 22596 21ce78ed697 22624 21ce78e2ba4 6 API calls 22596->22624 22598->22569 22599->22569 22600->22569 22601->22569 22603 21ce78ea9db malloc 22602->22603 22604 21ce78ea9f6 22602->22604 22603->22604 22604->22579 22606 21ce78e2b60 22605->22606 22607 21ce78e2b69 HeapCreate 22606->22607 22608 21ce78e2b82 22606->22608 22607->22608 22608->22585 22610 21ce78edfdc 22609->22610 22611 21ce78ee026 22610->22611 22625 21ce78e2c20 22610->22625 22613 21ce78ed658 22611->22613 22614 21ce78ee033 VirtualProtect 22611->22614 22617 21ce78edef8 GetSystemInfo VirtualAlloc 22613->22617 22629 21ce78e1000 22614->22629 22616 21ce78ee060 VirtualProtect 22616->22613 22617->22592 22618->22594 22620 21ce78e797b 22619->22620 22622 21ce78e7b21 22620->22622 22638 21ce78e778c 22620->22638 22622->22596 22623->22591 22624->22582 22626 21ce78e2c4e 22625->22626 22628 21ce78e2cb8 22626->22628 22631 21ce78e24c0 22626->22631 22628->22611 22630 21ce78e100c 22629->22630 22630->22616 22634 21ce78e22d0 GetSystemInfo 22631->22634 22635 21ce78e2301 22634->22635 22636 21ce78e23a0 VirtualAlloc 22635->22636 22637 21ce78e23cb 22635->22637 22636->22635 22636->22637 22637->22628 22639 21ce78e77b4 22638->22639 22646 21ce78f2c64 22639->22646 22641 21ce78e77dd 22643 21ce78e7829 22641->22643 22650 21ce78f29d4 22641->22650 22644 21ce78e786b GetVolumeInformationW 22643->22644 22645 21ce78e78bc 22643->22645 22644->22645 22645->22622 22647 21ce78f2c87 22646->22647 22649 21ce78f2c7f 22646->22649 22648 21ce78f2ce8 NtAcceptConnectPort 22647->22648 22647->22649 22648->22649 22649->22641 22651 21ce78f2a1d 22650->22651 22652 21ce78f2a73 NtAcceptConnectPort 22651->22652 22653 21ce78f2a27 22651->22653 22652->22653 22653->22643 22799 21ce78e6bd8 NtAcceptConnectPort 22795 21ce78ecd54 CreateNamedPipeW BindIoCompletionCallback ConnectNamedPipe NtAcceptConnectPort 22686 21ce78e6950 22687 21ce78e696a 22686->22687 22688 21ce78e6974 22687->22688 22689 21ce78e696f LoadLibraryA 22687->22689 22689->22688 22690 21ce78e5110 22703 21ce78f252c 22690->22703 22692 21ce78e5328 22693 21ce78e5169 22693->22692 22694 21ce78e531b 22693->22694 22706 21ce78f28b8 22693->22706 22715 21ce78f2418 22694->22715 22699 21ce78e52a6 22712 21ce78f28e8 22699->22712 22702 21ce78f28b8 NtAcceptConnectPort 22702->22699 22704 21ce78f2551 22703->22704 22705 21ce78f253c NtAcceptConnectPort 22703->22705 22704->22693 22705->22704 22707 21ce78f28c8 NtAcceptConnectPort 22706->22707 22708 21ce78e51f8 22706->22708 22707->22708 22708->22694 22709 21ce78f27b8 22708->22709 22710 21ce78e5244 22709->22710 22711 21ce78f27cb NtAcceptConnectPort 22709->22711 22710->22699 22710->22702 22711->22710 22713 21ce78f28f8 NtAcceptConnectPort 22712->22713 22714 21ce78f28fc 22712->22714 22713->22714 22714->22694 22716 21ce78f2428 NtAcceptConnectPort 22715->22716 22717 21ce78f242c 22715->22717 22716->22717 22717->22692 22797 21ce78e58d0 29 API calls 22718 21ce78eccd0 22719 21ce78ecd39 22718->22719 22720 21ce78ecce3 22718->22720 22724 21ce78ea76c 22720->22724 22722 21ce78eccf5 22723 21ce78ecd18 ReadFile 22722->22723 22723->22719 22725 21ce78ea78c 22724->22725 22726 21ce78ea7d3 22724->22726 22725->22726 22727 21ce78ea7f7 malloc 22725->22727 22726->22722 22727->22726 22805 21ce78f12d0 15 API calls 22728 7df4b9912ed0 22730 7df4b9912ee6 22728->22730 22731 7df4b9912f16 22730->22731 22732 7df4b9912704 NtQuerySystemInformation 22730->22732 22733 7df4b9912727 22732->22733 22734 7df4b991272d malloc 22732->22734 22733->22734 22735 7df4b991275f 22734->22735 22736 7df4b9912743 NtQuerySystemInformation 22734->22736 22735->22731 22736->22735 22737 21ce78eca8c 22738 21ce78ecaaa 22737->22738 22751 21ce78ecb24 22737->22751 22739 21ce78ecad0 22738->22739 22740 21ce78ecc4f 22738->22740 22738->22751 22741 21ce78ecc1e 22739->22741 22744 21ce78ecae7 22739->22744 22742 21ce78ea76c malloc 22740->22742 22743 21ce78ea76c malloc 22741->22743 22745 21ce78ecc32 22742->22745 22743->22745 22746 21ce78ecb1b 22744->22746 22747 21ce78ecbdd 22744->22747 22744->22751 22748 21ce78ecc83 ReadFile 22745->22748 22746->22751 22752 21ce78ec784 22746->22752 22763 21ce78ebbf0 22747->22763 22748->22751 22753 21ce78eca3f 22752->22753 22762 21ce78ec7be 22752->22762 22753->22751 22754 21ce78ec9ba free 22755 21ce78ec9c5 22754->22755 22755->22753 22777 21ce78ec25c 22755->22777 22757 21ce78ec9b2 22781 21ce78fdc78 free free 22757->22781 22760 21ce78ea9c0 malloc 22760->22762 22762->22753 22762->22754 22762->22755 22762->22757 22762->22760 22770 21ce78fe0c8 free free 22762->22770 22771 21ce78fd4ac 22762->22771 22764 21ce78ebc1e 22763->22764 22765 21ce78ebcec 22763->22765 22764->22765 22766 21ce78ebc41 OpenFileMappingW 22764->22766 22765->22751 22766->22765 22767 21ce78ebc5e MapViewOfFile 22766->22767 22768 21ce78ebce3 CloseHandle 22767->22768 22769 21ce78ebc7c 22767->22769 22768->22765 22769->22768 22770->22762 22774 21ce78fd4c5 22771->22774 22776 21ce78fd4be 22771->22776 22772 21ce78fd4fe free 22773 21ce78fd504 22772->22773 22773->22776 22782 21ce7924468 22773->22782 22774->22772 22774->22773 22774->22776 22776->22762 22778 21ce78ec2a1 22777->22778 22780 21ce78ec66e 22777->22780 22779 21ce78ec5ba VirtualAlloc 22778->22779 22778->22780 22779->22780 22780->22753 22781->22754 22783 21ce7924476 22782->22783 22785 21ce7924498 22782->22785 22784 21ce7924491 free 22783->22784 22783->22785 22784->22785 22785->22776 22786 21ce78f288c 22787 21ce78f28ab 22786->22787 22788 21ce78f289c NtAcceptConnectPort 22786->22788 22788->22787
                              APIs
                              Strings
                              Memory Dump Source
                              • Source File: 00000008.00000003.1706002611.00007DF4B9901000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4B9901000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_3_7df4b9901000_setup_wm.jbxd
                              Similarity
                              • API ID: MemoryVirtual$Read$Protect$Write$AllocateInformationProcessQuerycalloc
                              • String ID: H$H
                              • API String ID: 874015164-136785262
                              • Opcode ID: 8b723a4ddad616be20f9dda8abf44bc9042e1d61a48c0cd72079f3722cd3507a
                              • Instruction ID: 256a80f3cd8967d8d3951038bbb0583c94fed41a7a416c6787f45742f9a4e463
                              • Opcode Fuzzy Hash: 8b723a4ddad616be20f9dda8abf44bc9042e1d61a48c0cd72079f3722cd3507a
                              • Instruction Fuzzy Hash: 85B1B57060CB888FD764DF68D885A9BBBE5FBD5304F004A2EE58EC3251DB35E5058B86

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 0 21ce78f2d24-21ce78f2d80 call 21ce78e4998 3 21ce78f3dc7-21ce78f3ded call 21ce78f4500 0->3 4 21ce78f2d86-21ce78f2de7 call 21ce78e6da4 * 3 call 21ce78e32f8 call 21ce78e6da4 0->4 18 21ce78f3db4-21ce78f3db5 4->18 19 21ce78f2ded-21ce78f3700 4->19 22 21ce78f3db9-21ce78f3dc2 call 21ce78e49f4 18->22 20 21ce78f3706-21ce78f3711 19->20 21 21ce78f3855-21ce78f385d 19->21 20->21 25 21ce78f3717-21ce78f3725 20->25 23 21ce78f38d0-21ce78f38e1 21->23 24 21ce78f385f-21ce78f3864 21->24 22->3 27 21ce78f393a-21ce78f3940 23->27 28 21ce78f38e3-21ce78f38fb 23->28 24->23 29 21ce78f3866-21ce78f3870 RtlFormatCurrentUserKeyPath 24->29 30 21ce78f372b-21ce78f3733 25->30 31 21ce78f3850-21ce78f3851 25->31 34 21ce78f396b-21ce78f397e 27->34 35 21ce78f3942-21ce78f3943 27->35 28->27 43 21ce78f38fd-21ce78f3905 28->43 29->23 33 21ce78f3872-21ce78f3883 29->33 30->31 36 21ce78f3739-21ce78f3751 30->36 31->21 38 21ce78f3885-21ce78f3891 33->38 39 21ce78f389e-21ce78f38a6 33->39 34->18 54 21ce78f3984-21ce78f398f 34->54 40 21ce78f3945-21ce78f3964 35->40 41 21ce78f3757-21ce78f3758 36->41 42 21ce78f3844-21ce78f3848 36->42 56 21ce78f38c7-21ce78f38c8 38->56 57 21ce78f3893-21ce78f389c 38->57 44 21ce78f38a8-21ce78f38c4 call 21ce78e1000 39->44 40->40 45 21ce78f3966-21ce78f3967 40->45 46 21ce78f375b-21ce78f376b 41->46 48 21ce78f384a-21ce78f384b 42->48 49 21ce78f3917 43->49 50 21ce78f3907-21ce78f3915 43->50 44->56 45->34 53 21ce78f377d-21ce78f377f 46->53 48->31 49->27 55 21ce78f3919-21ce78f3934 49->55 50->27 59 21ce78f3781-21ce78f3786 53->59 60 21ce78f376d-21ce78f377b 53->60 54->18 61 21ce78f3995-21ce78f39a3 54->61 55->27 56->23 57->44 63 21ce78f3811-21ce78f3814 59->63 64 21ce78f378c 59->64 60->53 61->18 62 21ce78f39a9-21ce78f39b1 61->62 62->18 65 21ce78f39b7-21ce78f39d7 62->65 66 21ce78f3816-21ce78f381a 63->66 67 21ce78f3821-21ce78f3830 63->67 68 21ce78f378e-21ce78f3795 64->68 65->18 78 21ce78f39dd-21ce78f3a01 65->78 66->67 71 21ce78f381c-21ce78f381d 66->71 67->46 72 21ce78f3836-21ce78f3842 67->72 69 21ce78f3797-21ce78f37ab 68->69 70 21ce78f37af-21ce78f37db 68->70 69->68 73 21ce78f37ad 69->73 74 21ce78f3803-21ce78f3804 70->74 75 21ce78f37dd-21ce78f37f1 call 21ce78f452c 70->75 71->67 72->48 73->63 79 21ce78f3809-21ce78f380a 74->79 75->74 83 21ce78f37f3-21ce78f3801 75->83 81 21ce78f3a07-21ce78f3a1a 78->81 82 21ce78f3b20-21ce78f3b5b 78->82 79->63 84 21ce78f3a1c-21ce78f3a26 81->84 90 21ce78f3bb3-21ce78f3bc3 82->90 91 21ce78f3b5d-21ce78f3b5e 82->91 83->79 85 21ce78f3af1-21ce78f3b03 84->85 86 21ce78f3a2c-21ce78f3a30 84->86 85->84 88 21ce78f3b09-21ce78f3b1e 85->88 86->85 89 21ce78f3a36-21ce78f3a80 call 21ce78f4540 86->89 88->82 100 21ce78f3a94-21ce78f3a96 89->100 90->18 99 21ce78f3bc9-21ce78f3bdf 90->99 93 21ce78f3b60-21ce78f3b68 91->93 96 21ce78f3b6a-21ce78f3b6f 93->96 97 21ce78f3b95-21ce78f3ba9 93->97 96->97 101 21ce78f3b71-21ce78f3b7a 96->101 97->93 98 21ce78f3bab-21ce78f3bac 97->98 98->90 103 21ce78f3c55-21ce78f3c5b 99->103 104 21ce78f3be1-21ce78f3be2 99->104 105 21ce78f3a98-21ce78f3aae 100->105 106 21ce78f3a82-21ce78f3a92 100->106 102 21ce78f3b7d-21ce78f3b80 101->102 107 21ce78f3b89-21ce78f3b93 102->107 108 21ce78f3b82 102->108 109 21ce78f3cae-21ce78f3cb5 103->109 110 21ce78f3c5d-21ce78f3c61 103->110 111 21ce78f3be4-21ce78f3bef 104->111 112 21ce78f3ab0-21ce78f3ab8 105->112 113 21ce78f3aed 105->113 106->100 107->97 107->102 108->107 117 21ce78f3cbb-21ce78f3cdb call 21ce78e32f8 109->117 118 21ce78f3d62-21ce78f3d64 109->118 114 21ce78f3c68-21ce78f3c73 110->114 115 21ce78f3bf1-21ce78f3bfe 111->115 116 21ce78f3c00-21ce78f3c14 111->116 112->113 119 21ce78f3aba 112->119 113->85 123 21ce78f3c95-21ce78f3cac 114->123 124 21ce78f3c75-21ce78f3c81 114->124 115->116 138 21ce78f3c18-21ce78f3c27 115->138 116->103 125 21ce78f3c16 116->125 133 21ce78f3cf0-21ce78f3d04 call 21ce78e32f8 117->133 134 21ce78f3cdd-21ce78f3cee call 21ce78e35b4 117->134 121 21ce78f3d66-21ce78f3d70 118->121 122 21ce78f3d90-21ce78f3d99 118->122 120 21ce78f3abc-21ce78f3ad5 call 21ce78f452c 119->120 142 21ce78f3ad7-21ce78f3add 120->142 143 21ce78f3ae1-21ce78f3ae7 120->143 121->122 129 21ce78f3d72-21ce78f3d8c 121->129 122->22 130 21ce78f3d9b-21ce78f3db2 call 21ce78e6db4 call 21ce78e55f0 122->130 123->109 123->114 124->123 131 21ce78f3c83-21ce78f3c8a 124->131 125->111 129->122 130->22 131->123 137 21ce78f3c8c-21ce78f3c93 131->137 133->118 153 21ce78f3d06-21ce78f3d17 call 21ce78e35b4 133->153 134->133 152 21ce78f3d19-21ce78f3d2f call 21ce78f2310 134->152 137->123 139 21ce78f3c29-21ce78f3c46 138->139 140 21ce78f3c48 138->140 148 21ce78f3c4d-21ce78f3c4f 139->148 140->148 142->120 147 21ce78f3adf 142->147 143->113 147->113 148->103 148->122 152->118 159 21ce78f3d31-21ce78f3d41 152->159 153->118 153->152 159->118 161 21ce78f3d43-21ce78f3d5c 159->161 161->118
                              APIs
                              Strings
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: CurrentFormatPathUsercalloc
                              • String ID: ;$dW$;$dW$MZ$MZ$N$t$;Ln
                              • API String ID: 4207655178-84560671
                              • Opcode ID: 1512b8534d4c685afcc9061355cc33150ae67fa718ee72ec55426bd84ba67b64
                              • Instruction ID: 8e6a3e953c453fe3505c33ab2a98f87142a0c517e682a1256c078aaebf54cd63
                              • Opcode Fuzzy Hash: 1512b8534d4c685afcc9061355cc33150ae67fa718ee72ec55426bd84ba67b64
                              • Instruction Fuzzy Hash: 6FA29DB4518B888FD3B5DF1888897EAB7E4FBA9701F500A2FD58EC3251DB749541CB82
                              APIs
                              Strings
                              Memory Dump Source
                              • Source File: 00000008.00000003.1706002611.00007DF4B9901000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4B9901000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_3_7df4b9901000_setup_wm.jbxd
                              Similarity
                              • API ID: Close$CreateFunctionHandleInformationOpenProcessProtectQueryResumeTableThreadValueVirtualVolumecallocfree
                              • String ID: -
                              • API String ID: 167522227-2547889144
                              • Opcode ID: 105c85825427e7c8ed203293b96c467a96f9bba36c05be2648f83f100e5bc7da
                              • Instruction ID: 34ac16c3cda9e006cd5c9f452bbee0a9480ab0c23c08e280177039d6bf499c1f
                              • Opcode Fuzzy Hash: 105c85825427e7c8ed203293b96c467a96f9bba36c05be2648f83f100e5bc7da
                              • Instruction Fuzzy Hash: 6991CA3060CA4A9FE7A4EBB4D45566B77F1FF94305F00852AE55BC3292DF78E8018781
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000003.1706264667.0000021CE7A00000.00000040.00001000.00020000.00000000.sdmp, Offset: 0000021CE7A00000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_3_21ce7a00000_setup_wm.jbxd
                              Similarity
                              • API ID: Free$Heap$Virtual
                              • String ID:
                              • API String ID: 2808376930-0
                              • Opcode ID: 0239afe9e4586817184aca5c5cd0e1f03da4a7935eb0d1bd2fc8b19bf1b4dd3b
                              • Instruction ID: 55569fea427c64fdc229d26740e2af8ae0a4a13bfb66999664d4484e52adb80d
                              • Opcode Fuzzy Hash: 0239afe9e4586817184aca5c5cd0e1f03da4a7935eb0d1bd2fc8b19bf1b4dd3b
                              • Instruction Fuzzy Hash: EA224434648B444FDB6CDA5CC88E6B9B7D2FB95300F24596DE9CBC3282DA34D846CB81

                              Control-flow Graph

                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: NamedPipe$BindCallbackCompletionConnectCreate
                              • String ID:
                              • API String ID: 2502124517-0
                              • Opcode ID: 1f39a579d535edce93b33f8ad890ac1eeea552d42be0d6d7d28d92d913c1a808
                              • Instruction ID: 5f03bfc95634c14ed31c6200fb50f60c7053f4cc6752adf76a1d497000f05cdf
                              • Opcode Fuzzy Hash: 1f39a579d535edce93b33f8ad890ac1eeea552d42be0d6d7d28d92d913c1a808
                              • Instruction Fuzzy Hash: 3731F330608A488FE7A4EF28D8D8B9A77E4FBA8310F104629E45BD31D1DF74C945CB81

                              Control-flow Graph

                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2585736667.00007DF4B9911000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4B9911000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_7df4b9911000_setup_wm.jbxd
                              Similarity
                              • API ID: InformationQuerySystem$malloc
                              • String ID:
                              • API String ID: 1603438391-0
                              • Opcode ID: eaf85d99e703aa885d9be82610ad3d8d03a394a4204a017367fdf17adc8f3dbe
                              • Instruction ID: ef64bc9660ec9a510cccdaaf5e7218a9e25e7b0d43d3d8c924f45f9493ceca8b
                              • Opcode Fuzzy Hash: eaf85d99e703aa885d9be82610ad3d8d03a394a4204a017367fdf17adc8f3dbe
                              • Instruction Fuzzy Hash: A9011D306199469BE789FF64DC68A6A77E5FB94305F440128A40BC22A0DF38E555CB42

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 268 21ce78f2c64-21ce78f2c7d 269 21ce78f2c87-21ce78f2c8a 268->269 270 21ce78f2c7f-21ce78f2c82 268->270 272 21ce78f2c96-21ce78f2cab 269->272 273 21ce78f2c8c-21ce78f2c91 269->273 271 21ce78f2d1a-21ce78f2d22 270->271 274 21ce78f2cb7-21ce78f2ce6 272->274 275 21ce78f2cad-21ce78f2cb1 272->275 273->271 276 21ce78f2ce8-21ce78f2cf4 NtAcceptConnectPort 274->276 277 21ce78f2cf6 274->277 275->274 278 21ce78f2cfb-21ce78f2cfd 276->278 277->278 279 21ce78f2d18 278->279 280 21ce78f2cff-21ce78f2d09 278->280 279->271 281 21ce78f2d0b-21ce78f2d0f 280->281 282 21ce78f2d11 280->282 283 21ce78f2d16 281->283 282->283 283->279
                              Strings
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID:
                              • String ID: 0
                              • API String ID: 0-4108050209
                              • Opcode ID: f6b0f352e34b93935ac2a1f97fa2b0892be8d0a68ee0d9962c8f94757f801c03
                              • Instruction ID: b4828e83b04500744265a7c7b7602158eee8cf68f408db905c22cd195b815467
                              • Opcode Fuzzy Hash: f6b0f352e34b93935ac2a1f97fa2b0892be8d0a68ee0d9962c8f94757f801c03
                              • Instruction Fuzzy Hash: EA21C075708A4C4FE768EF5888CD3AE76E0F7B8311F70053FEA4AD3250DA2489448781

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 285 7df4b99022cc-7df4b99022f0 call 7df4b9901000 288 7df4b990276d-7df4b990277f 285->288 289 7df4b99022f6-7df4b990230c call 7df4b99010c0 285->289 289->288 292 7df4b9902312-7df4b9902341 call 7df4b9901290 call 7df4b99012c8 call 7df4b99013a0 289->292 292->288 300 7df4b9902347-7df4b990235b calloc 292->300 300->288 301 7df4b9902361-7df4b9902408 call 7df4b9902780 call 7df4b99031de 300->301 312 7df4b990240e-7df4b9902417 301->312 313 7df4b990274d-7df4b9902768 SetTimer 301->313 312->313 314 7df4b990241d-7df4b9902434 312->314 313->288 314->313 317 7df4b990243a-7df4b9902463 call 7df4b9903090 314->317 321 7df4b9902469-7df4b990246a 317->321 322 7df4b9902744-7df4b9902745 317->322 323 7df4b990246d-7df4b9902470 321->323 322->313 324 7df4b9902737-7df4b9902740 323->324 325 7df4b9902476-7df4b9902479 323->325 324->322 326 7df4b990247f-7df4b9902492 325->326 327 7df4b990271c-7df4b9902731 325->327 330 7df4b99024ca-7df4b99024dd 326->330 331 7df4b9902494-7df4b9902497 326->331 327->323 327->324 335 7df4b99024df-7df4b99024e2 330->335 336 7df4b9902516-7df4b9902529 330->336 331->327 332 7df4b990249d-7df4b99024b9 331->332 332->327 337 7df4b99024bf-7df4b99024c5 332->337 335->327 338 7df4b99024e8-7df4b9902501 335->338 341 7df4b990255e-7df4b9902574 336->341 342 7df4b990252b-7df4b990252e 336->342 337->327 338->327 343 7df4b9902507-7df4b9902511 338->343 341->327 347 7df4b990257a-7df4b990257d 341->347 342->327 344 7df4b9902534-7df4b990254d 342->344 343->327 344->327 348 7df4b9902553-7df4b9902559 344->348 347->327 349 7df4b9902583-7df4b9902591 call 7df4b990309c 347->349 348->327 349->327 352 7df4b9902597-7df4b99025b7 349->352 352->327 354 7df4b99025bd-7df4b99025e0 call 7df4b99013e8 352->354 357 7df4b9902713-7df4b9902714 354->357 358 7df4b99025e6-7df4b99025ef 354->358 357->327 358->357 359 7df4b99025f5-7df4b99025f8 358->359 360 7df4b990268e-7df4b9902695 359->360 361 7df4b99025fe-7df4b9902601 359->361 360->359 362 7df4b990269b-7df4b990269e 360->362 363 7df4b9902687-7df4b990268c 361->363 364 7df4b9902607-7df4b9902631 361->364 362->357 365 7df4b99026a0-7df4b99026c5 362->365 363->360 364->363 368 7df4b9902633-7df4b990264c 364->368 365->357 369 7df4b99026c7-7df4b99026dd 365->369 368->363 371 7df4b990264e-7df4b9902684 368->371 369->357 373 7df4b99026df-7df4b9902710 369->373 371->363 373->357
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2585645214.00007DF4B9901000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4B9901000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_7df4b9901000_setup_wm.jbxd
                              Similarity
                              • API ID: FunctionProtectTableTimerVirtualcalloc
                              • String ID:
                              • API String ID: 2994753352-0
                              • Opcode ID: 907297c01f2e853a7e6e6be3efaf92a15819b9f7a160a726e89f0d05781fa5e1
                              • Instruction ID: dfd5b76e9ef5bdacf7cfc5447ccc54219895a0aae5f24c686f60136e89fe5320
                              • Opcode Fuzzy Hash: 907297c01f2e853a7e6e6be3efaf92a15819b9f7a160a726e89f0d05781fa5e1
                              • Instruction Fuzzy Hash: FCE1A230608A495FEB99EF68D8885AE77E5FF98304F14463EE05BC3292DB34E9458741

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 447 21ce78e2628-21ce78e2662 call 21ce7922c58 450 21ce78e2668-21ce78e267c call 21ce7922c52 Thread32First 447->450 451 21ce78e2734-21ce78e2737 447->451 457 21ce78e2681-21ce78e2686 450->457 453 21ce78e288a-21ce78e289d 451->453 454 21ce78e273d-21ce78e2745 451->454 454->453 456 21ce78e274b-21ce78e274c 454->456 458 21ce78e274e-21ce78e2767 456->458 459 21ce78e2712-21ce78e2725 call 21ce7922c4c 457->459 460 21ce78e268c-21ce78e2696 457->460 463 21ce78e287a-21ce78e2884 458->463 464 21ce78e276d-21ce78e2784 SuspendThread 458->464 459->457 468 21ce78e272b-21ce78e272e CloseHandle 459->468 460->459 467 21ce78e2698-21ce78e26a2 460->467 463->453 463->458 469 21ce78e2792-21ce78e2794 464->469 467->459 475 21ce78e26a4-21ce78e26aa 467->475 468->451 470 21ce78e279a-21ce78e279e 469->470 471 21ce78e286f-21ce78e2878 469->471 473 21ce78e27a0-21ce78e27aa 470->473 474 21ce78e27ac-21ce78e27ad 470->474 471->463 476 21ce78e27b0-21ce78e27b2 473->476 474->476 478 21ce78e26d2-21ce78e26d8 475->478 479 21ce78e26ac-21ce78e26ce 475->479 476->471 482 21ce78e27b8-21ce78e27ce 476->482 480 21ce78e26da-21ce78e26f4 478->480 481 21ce78e2701-21ce78e270e 478->481 479->468 485 21ce78e26d0 479->485 480->468 489 21ce78e26f6-21ce78e26fe 480->489 481->459 483 21ce78e27d0-21ce78e27e1 482->483 487 21ce78e27fa 483->487 488 21ce78e27e3-21ce78e27e6 483->488 485->481 492 21ce78e27fc-21ce78e2806 487->492 490 21ce78e27e8-21ce78e27f1 488->490 491 21ce78e27f3-21ce78e27f8 488->491 489->481 490->492 491->492 493 21ce78e2808-21ce78e280a 492->493 494 21ce78e285e-21ce78e2866 492->494 495 21ce78e28a9-21ce78e28ad 493->495 496 21ce78e2810-21ce78e281d 493->496 494->483 497 21ce78e286c-21ce78e286d 494->497 498 21ce78e28bb-21ce78e28c8 495->498 499 21ce78e28af-21ce78e28b9 495->499 500 21ce78e2839 496->500 501 21ce78e281f-21ce78e282a 496->501 497->471 505 21ce78e28ca-21ce78e28d6 498->505 506 21ce78e28e5-21ce78e28e9 498->506 499->498 502 21ce78e283b-21ce78e283e 499->502 500->502 503 21ce78e289e-21ce78e28a7 501->503 504 21ce78e282c-21ce78e2837 501->504 502->494 509 21ce78e2840-21ce78e2857 502->509 503->502 504->500 504->501 507 21ce78e28d8-21ce78e28e3 505->507 508 21ce78e28f7-21ce78e28ff 505->508 506->500 510 21ce78e28ef-21ce78e28f2 506->510 507->505 507->506 508->502 509->494 510->502
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: CloseHandleSuspendThread
                              • String ID:
                              • API String ID: 1038686644-0
                              • Opcode ID: ee0b4b29cbf429cf193f7da3647d56e0b1a845656fd74a12addcfb7ee39e090b
                              • Instruction ID: 25897055f271efbe47f8bcd0a2b01c456473577606368e2f9da1e5dda38d4355
                              • Opcode Fuzzy Hash: ee0b4b29cbf429cf193f7da3647d56e0b1a845656fd74a12addcfb7ee39e090b
                              • Instruction Fuzzy Hash: 9791CE34248F298BEB7CDB18DC992A973D1FB79310F24426DD54ADA181DB35D842CBC2
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: AllocVirtual
                              • String ID:
                              • API String ID: 4275171209-0
                              • Opcode ID: 1463b6e579e83794cd598155eb9e3160b38bf0e3bcb0f61670329aaf0c67c5a2
                              • Instruction ID: b530a6725cd324042ffbf1811e0162ffdd5a111c7c39f76238bdebd31ddd0ce2
                              • Opcode Fuzzy Hash: 1463b6e579e83794cd598155eb9e3160b38bf0e3bcb0f61670329aaf0c67c5a2
                              • Instruction Fuzzy Hash: D1F13830A586680EE73C9B2C9C8A2B977D1F7A5301F38027ED5DBD6283DA38D54687C1
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: f13696e1930880e2e19ebf6412232386b6a4ab7a0f564d2111b2459b68bcc0da
                              • Instruction ID: 932951d74b6adf611d082e4e53fa52740378401e65f840b3c4b2ac0588705d64
                              • Opcode Fuzzy Hash: f13696e1930880e2e19ebf6412232386b6a4ab7a0f564d2111b2459b68bcc0da
                              • Instruction Fuzzy Hash: AA81C738259B0D8BE77DDF19944A7AEB3D0FBB8310F704639E956D7190EA64D80186C2
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: d9381645012d00cf6e7f8dfe8da443d67e907387f0873f85681973196ff3555c
                              • Instruction ID: 8513f9e5f8203e0fede5ab71e316db94502e7cdaedeefe752e39dc9265d25033
                              • Opcode Fuzzy Hash: d9381645012d00cf6e7f8dfe8da443d67e907387f0873f85681973196ff3555c
                              • Instruction Fuzzy Hash: 4FF0DA74A28B488FDB64EF2CD489B9A77E0FBA9300F604519E84CC3245DB34D8448B86
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: 98d03459468cdcd74854b97b597847e55f0ea75636d4913b4c299d0c762e3800
                              • Instruction ID: 1842e35e186cee448ebb38d6ccaf33a4e6bddc5b65c4f8ea8d928e27ff3ca4d1
                              • Opcode Fuzzy Hash: 98d03459468cdcd74854b97b597847e55f0ea75636d4913b4c299d0c762e3800
                              • Instruction Fuzzy Hash: 36E09275208B088FDB08EF98CCC5DADB3E4E7E9300F504D3AE99AC7164D264D648CAD2
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: 27a0ab9b8b81d19b55a36d5b88940b5d877d47714e961321c564cf766a84aa8c
                              • Instruction ID: 70a96e08a9f535138150397e516dad485f165f63a03304334b02429c38630a29
                              • Opcode Fuzzy Hash: 27a0ab9b8b81d19b55a36d5b88940b5d877d47714e961321c564cf766a84aa8c
                              • Instruction Fuzzy Hash: ABD01238A58B498BD754AB2C89466097BE1B7E9318F644628E858D3314E238D4418686
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: bd75e34d41d0a0c218f00c4b384fa59cf13494ae4b0fc6bee219bc2a66024f0a
                              • Instruction ID: 7f5770d8b239baeda91caba43020563c7943f4d6398bee8909e1e9fb02a5a8a5
                              • Opcode Fuzzy Hash: bd75e34d41d0a0c218f00c4b384fa59cf13494ae4b0fc6bee219bc2a66024f0a
                              • Instruction Fuzzy Hash: 83D01238DA8B498BD624AB6888456497BE1BBE9314F644618E885D3314E338D4418786
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: 1d483c746a178fd7cebb358bd60c8d391381be698edd62c71eedc0381d53c554
                              • Instruction ID: 78294eb383402c04b15becfc21e4e76b6608c73156f3f449eb6e179b0b003821
                              • Opcode Fuzzy Hash: 1d483c746a178fd7cebb358bd60c8d391381be698edd62c71eedc0381d53c554
                              • Instruction Fuzzy Hash: A6D0A738A78B4D4FEA28B728894130937D1F7F5308FA046189848D3254D62DD40047C2
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: 2134b33d09b848e70ba1f23de37cfdd97cd4e92c7083e33fbb9b34bfa8345c36
                              • Instruction ID: 74795932b49b6684d6fd7fcdb4116b6392b87d016eaf4a0c687eabd4f7166a80
                              • Opcode Fuzzy Hash: 2134b33d09b848e70ba1f23de37cfdd97cd4e92c7083e33fbb9b34bfa8345c36
                              • Instruction Fuzzy Hash: ABC08C28A5590F0AE92DB2BA8C8674C2080A7BA340FD00020A918C2180F48CC8D043E6
                              APIs
                              • NtAcceptConnectPort.NTDLL(?,?,?,?,?,?,?,?,?,0000021CE78E531B), ref: 0000021CE78F28F8
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: AcceptConnectPort
                              • String ID:
                              • API String ID: 1658770261-0
                              • Opcode ID: 14fbc5d4ea2d13eb613c5f0cfb1986910ad3174e43fd425e2ce4bb45159b65c3
                              • Instruction ID: 11f9ae88f4ccccf877653134ecbe39232510294bcfc7fbf8187696dba8e73a39
                              • Opcode Fuzzy Hash: 14fbc5d4ea2d13eb613c5f0cfb1986910ad3174e43fd425e2ce4bb45159b65c3
                              • Instruction Fuzzy Hash: 68C08C28669E0E0AE92CA2B98C86B5C2280A369314F9000109825D2180E80CD5C043D2
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000003.1706002611.00007DF4B9901000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4B9901000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_3_7df4b9901000_setup_wm.jbxd
                              Similarity
                              • API ID: CloseInformationOpenQueryValueVolume
                              • String ID:
                              • API String ID: 4069062851-0
                              • Opcode ID: 3ebb744f0aebbecadcf06631c3d65907a1788fb7df7ced3004579ef494ef68f9
                              • Instruction ID: 18d55bb6c52e677a0b31d4054310c68b842634477fdd1706a9f0fa912edcd986
                              • Opcode Fuzzy Hash: 3ebb744f0aebbecadcf06631c3d65907a1788fb7df7ced3004579ef494ef68f9
                              • Instruction Fuzzy Hash: 80414D3161CA488BE755EB64C899BDBB7F1FB94305F004A2EE08BC7291EF78D5048B42

                              Control-flow Graph

                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: socket$ErrorModegetsockopt
                              • String ID:
                              • API String ID: 552242919-0
                              • Opcode ID: 3bad8950bc8ed42d49e75fcab8a12e6def80f6fb96da2e8da31b13afe45452c3
                              • Instruction ID: 199eb65380debec91ad5ac6a931cb14d3d83f1b75a946a9c1c5e1758a2b665a9
                              • Opcode Fuzzy Hash: 3bad8950bc8ed42d49e75fcab8a12e6def80f6fb96da2e8da31b13afe45452c3
                              • Instruction Fuzzy Hash: A44199346587498FE769EF38D89D6AA77E5FBA8300F50463DE047C32A1DB388515CB81

                              Control-flow Graph

                              APIs
                              Strings
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: ProtectVirtual
                              • String ID: rE\
                              • API String ID: 544645111-988334199
                              • Opcode ID: fd197d1d460a7a7097ebc69198cfe8898b84731961e3c45740b5833891c72836
                              • Instruction ID: e810997a5dcf3ff7d26791e7c76de9ff2014296c2f6eb402b544581b31bb5d1e
                              • Opcode Fuzzy Hash: fd197d1d460a7a7097ebc69198cfe8898b84731961e3c45740b5833891c72836
                              • Instruction Fuzzy Hash: 8411B235348E090BEB55FB5898D5BE972D6F7F8300F600539A50BC7286EF28DD458781

                              Control-flow Graph

                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: File$CloseHandleMappingOpenView
                              • String ID:
                              • API String ID: 2553196624-0
                              • Opcode ID: 8bb8605ac1c349b7ed951fd2da0efd1c73228fe5391c7a5f19e2fcd3618d3200
                              • Instruction ID: f91751d5b9091584533dc7ad72dd7d5623a374e52697d6a76f9ed686b4d61fb0
                              • Opcode Fuzzy Hash: 8bb8605ac1c349b7ed951fd2da0efd1c73228fe5391c7a5f19e2fcd3618d3200
                              • Instruction Fuzzy Hash: 75319535618A0C8FEB65FF24D88AAEAB7D4FBB4300F60453BA94BC7181DE34D5598781

                              Control-flow Graph

                              APIs
                              Strings
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: CreateWindow
                              • String ID: P
                              • API String ID: 716092398-3110715001
                              • Opcode ID: 3958d680dd61ed40200acf61cd907bfc270c34c5250da5fbb8d7e78c828db693
                              • Instruction ID: 2a8aa001363b1658d8292375844ccf1782790335196e81ef2f9641d51dea8438
                              • Opcode Fuzzy Hash: 3958d680dd61ed40200acf61cd907bfc270c34c5250da5fbb8d7e78c828db693
                              • Instruction Fuzzy Hash: E6511F70518B448FD7A5EF28E88A79ABBE4FBA9311F10462FE08EC2150DF349545CB83

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 376 7df4b9913018-7df4b991304d call 7df4b9911478 379 7df4b99132e0-7df4b9913302 call 7df4b99134f0 376->379 380 7df4b9913053-7df4b9913068 call 7df4b9911538 376->380 380->379 385 7df4b991306e-7df4b991309c call 7df4b9911708 call 7df4b9911740 call 7df4b9911818 380->385 385->379 393 7df4b99130a2-7df4b99130ca 385->393 393->379 395 7df4b99130d0-7df4b99130d8 393->395 396 7df4b991318a-7df4b991320a call 7df4b9913520 call 7df4b991368c call 7df4b9913686 call 7df4b9913680 SendMessageA 395->396 397 7df4b99130de-7df4b9913122 call 7df4b991365c * 2 395->397 422 7df4b9913213-7df4b9913219 396->422 410 7df4b9913185-7df4b9913188 397->410 410->396 412 7df4b9913124-7df4b9913128 410->412 414 7df4b991312a-7df4b991312e 412->414 415 7df4b9913130-7df4b9913146 calloc 412->415 414->415 417 7df4b9913182-7df4b9913183 414->417 415->417 418 7df4b9913148-7df4b9913163 call 7df4b9913510 415->418 417->410 423 7df4b9913165-7df4b991316f 418->423 424 7df4b9913171-7df4b9913175 418->424 425 7df4b99132dd-7df4b99132de 422->425 426 7df4b991321f-7df4b9913225 422->426 423->417 424->417 428 7df4b9913177-7df4b991317f 424->428 425->379 426->425 427 7df4b991322b-7df4b991323d 426->427 427->425 430 7df4b9913243-7df4b9913256 call 7df4b9913510 427->430 428->417 433 7df4b99132bf-7df4b99132d2 430->433 435 7df4b99132d4-7df4b99132d5 433->435 436 7df4b9913258-7df4b991325b 433->436 435->425 437 7df4b99132bd 436->437 438 7df4b991325d-7df4b9913280 call 7df4b991365c 436->438 437->433 442 7df4b991328a-7df4b99132b7 call 7df4b991365c 438->442 443 7df4b9913282-7df4b9913288 438->443 442->437 443->437
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2585736667.00007DF4B9911000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4B9911000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_7df4b9911000_setup_wm.jbxd
                              Similarity
                              • API ID: FunctionMessageProtectSendTableVirtualcalloc
                              • String ID:
                              • API String ID: 2453823186-0
                              • Opcode ID: 06791c2761ba3497e0c9077ab5921302019734c58a86a701aa2be8a22ea6a1e2
                              • Instruction ID: 03dcd1b0e930569cd68c8fc73360ca7d003245240c937f1e22aa8e2be23547dc
                              • Opcode Fuzzy Hash: 06791c2761ba3497e0c9077ab5921302019734c58a86a701aa2be8a22ea6a1e2
                              • Instruction Fuzzy Hash: B691973060CA596FEB98EF68D4965AA77F2FB54304B104A3ED04BC3292DE38E855C781

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 512 21ce78e22d0-21ce78e22ff GetSystemInfo 513 21ce78e2301-21ce78e230c 512->513 514 21ce78e230f-21ce78e2325 512->514 513->514 515 21ce78e232b-21ce78e232e 514->515 516 21ce78e234a-21ce78e2350 515->516 517 21ce78e2330-21ce78e2333 515->517 520 21ce78e23cb-21ce78e23ce 516->520 521 21ce78e2352-21ce78e2362 516->521 518 21ce78e2345-21ce78e2348 517->518 519 21ce78e2335-21ce78e2338 517->519 518->515 519->518 524 21ce78e233a-21ce78e233f 519->524 523 21ce78e245a 520->523 522 21ce78e2391-21ce78e2397 521->522 525 21ce78e2399 522->525 526 21ce78e2364-21ce78e237b 522->526 527 21ce78e2467-21ce78e247e 523->527 528 21ce78e245c-21ce78e245f 523->528 524->518 529 21ce78e24ad-21ce78e24bf 524->529 530 21ce78e239b-21ce78e239e 525->530 526->525 540 21ce78e237d-21ce78e2385 526->540 533 21ce78e2480-21ce78e249a 527->533 531 21ce78e2465 528->531 532 21ce78e23d3-21ce78e23f1 528->532 530->520 535 21ce78e23a0-21ce78e23c0 VirtualAlloc 530->535 531->529 537 21ce78e2433 532->537 538 21ce78e23f3-21ce78e240a 532->538 533->533 536 21ce78e249c-21ce78e24a7 533->536 535->527 541 21ce78e23c6-21ce78e23c9 535->541 536->529 539 21ce78e2435-21ce78e2438 537->539 538->537 545 21ce78e240c-21ce78e2414 538->545 539->529 542 21ce78e243a-21ce78e2458 539->542 540->530 543 21ce78e2387-21ce78e238f 540->543 541->520 541->521 542->523 543->522 543->525 545->539 546 21ce78e2416-21ce78e2431 545->546 546->537 546->538
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: AllocInfoSystemVirtual
                              • String ID:
                              • API String ID: 3440192736-0
                              • Opcode ID: 9420d4d47bb5eb7f06d7fea4bf54311970c83033f74d5905fb72208c54926d5e
                              • Instruction ID: f01dcb7b05c56c506b315a0eed78571f198051dd572548d1cdc744b41759e736
                              • Opcode Fuzzy Hash: 9420d4d47bb5eb7f06d7fea4bf54311970c83033f74d5905fb72208c54926d5e
                              • Instruction Fuzzy Hash: 9E51C134258F0D4FEB69AB6C984C3AA73D1F7B8305F244139E54AD72A5EB64C8818BC1

                              Control-flow Graph

                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: CloseFileHandleViewmalloc
                              • String ID:
                              • API String ID: 4055022194-0
                              • Opcode ID: f5e4ace49f8dbf4d208ab68c6c07d1c08f373a7b01313fe5be4b999b6ef0fbb6
                              • Instruction ID: 7ed281874622c27cda42ca4650b6a7cce011112a43e611b9c1c5026b0d3ff519
                              • Opcode Fuzzy Hash: f5e4ace49f8dbf4d208ab68c6c07d1c08f373a7b01313fe5be4b999b6ef0fbb6
                              • Instruction Fuzzy Hash: 0C41B434294F088FE765FF28DC986EA73A4FBB5301F105539950ADB195DF24D80587D1

                              Control-flow Graph

                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: ProtectVirtual
                              • String ID:
                              • API String ID: 544645111-0
                              • Opcode ID: 9af94119fb7637b7a971dd9e5dfe6689dbe62cc4b897151fb24c5dcbfab40a36
                              • Instruction ID: 7fbabf363ccf002679a1a47996f176cb0f973774f347d61a2b2f6f05b2608a6f
                              • Opcode Fuzzy Hash: 9af94119fb7637b7a971dd9e5dfe6689dbe62cc4b897151fb24c5dcbfab40a36
                              • Instruction Fuzzy Hash: B1312D30308B854BE7249B6C9C987953BC1F76B314F2502A5E989CB2C5D754C802C396
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2585736667.00007DF4B9911000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4B9911000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_7df4b9911000_setup_wm.jbxd
                              Similarity
                              • API ID: ProtectVirtual
                              • String ID:
                              • API String ID: 544645111-0
                              • Opcode ID: 555ee51bdfbe110a30625e9d65cd405c650e6e50b938efdbc78372c29de57681
                              • Instruction ID: 01f47346898e02e2b4a673d142677242ce1a6be669641a6a53356f8bcd400d09
                              • Opcode Fuzzy Hash: 555ee51bdfbe110a30625e9d65cd405c650e6e50b938efdbc78372c29de57681
                              • Instruction Fuzzy Hash: 8721023160866777EBA89BACD484677BBF9FF90308F14813BE45BC7386D668E811C245

                              Control-flow Graph

                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2585645214.00007DF4B9901000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4B9901000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_7df4b9901000_setup_wm.jbxd
                              Similarity
                              • API ID: ProtectVirtual
                              • String ID:
                              • API String ID: 544645111-0
                              • Opcode ID: aa55061d99e775b82e27cc6da46f8fa59da2ee6fc95db4891e67f0932caa2168
                              • Instruction ID: b6424143862c6e3c1cd02dbaafe35e2285d1494d45d73f809b03246be79377b9
                              • Opcode Fuzzy Hash: aa55061d99e775b82e27cc6da46f8fa59da2ee6fc95db4891e67f0932caa2168
                              • Instruction Fuzzy Hash: C221053160864657EBAC8BBCC440676BBF1FF94304F14813BE85BC7B86D768F8418264
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000003.1706002611.00007DF4B9901000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4B9901000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_3_7df4b9901000_setup_wm.jbxd
                              Similarity
                              • API ID: ProtectVirtual
                              • String ID:
                              • API String ID: 544645111-0
                              • Opcode ID: 89563af4fe1d572c43706a2c5b782feb3df9d02bfd1ff06021ce1d81ad062eb6
                              • Instruction ID: 8cbb3653b714b066a9d84e0fd6cdef105fcce13193c9241365cb338d6889283e
                              • Opcode Fuzzy Hash: 89563af4fe1d572c43706a2c5b782feb3df9d02bfd1ff06021ce1d81ad062eb6
                              • Instruction Fuzzy Hash: 7121F33160864657DBA88BBCC440676BBF1FF90304F14813BE85BC7B86D668F8418265
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: FreeVirtualfree
                              • String ID:
                              • API String ID: 2434286298-0
                              • Opcode ID: ef59572018a9deb8cc9717970e2f4ccce5bc515e763955c946e33fff9a11c9f9
                              • Instruction ID: 27a91ff1c512e43f5a0698ad8f2c17753f8ed47569f6fd5b810e4f839491046b
                              • Opcode Fuzzy Hash: ef59572018a9deb8cc9717970e2f4ccce5bc515e763955c946e33fff9a11c9f9
                              • Instruction Fuzzy Hash: C0917134258B088FEB59EF18D889AEA73E1FB74300F504569E58ACB196DF30E955CBC1
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000003.1706002611.00007DF4B9901000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4B9901000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_3_7df4b9901000_setup_wm.jbxd
                              Similarity
                              • API ID: FileMappingOpen
                              • String ID:
                              • API String ID: 1680863896-0
                              • Opcode ID: a4d7378eb0dc183d45dac9fde789c38604b4b9a60361aa9a1ccba498305d516d
                              • Instruction ID: 47df0a3013b3154a76542f88afcb85072d975e978b00a80249741e215fd42ed4
                              • Opcode Fuzzy Hash: a4d7378eb0dc183d45dac9fde789c38604b4b9a60361aa9a1ccba498305d516d
                              • Instruction Fuzzy Hash: 5371757061C7854FD775DB79D4867ABBBE1FB94300F004A2EE59FC2252EA34A5058782
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: FileRead
                              • String ID:
                              • API String ID: 2738559852-0
                              • Opcode ID: e26a3d902f64fdb1e6a29b1ddfd8af137ced715061d327bbcfc87f3b72d7e64f
                              • Instruction ID: bd81533e4a947f7abd2d95fabd2e5a9e12631127e0249ee9afcd739f7db5602b
                              • Opcode Fuzzy Hash: e26a3d902f64fdb1e6a29b1ddfd8af137ced715061d327bbcfc87f3b72d7e64f
                              • Instruction Fuzzy Hash: CA71C235648B088FE779EB18DC89AA573E1FBB4710F20162DD68BD7192DB20F94687C1
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: ErrorMode
                              • String ID:
                              • API String ID: 2340568224-0
                              • Opcode ID: c27442c9625b69612e30a0c621dafdc38b3cd1b2ea33eefe8ec2cdf5f7c33623
                              • Instruction ID: 547d24df049a81450443404895e61895d36f83690085a45db7fafa63f1d3e439
                              • Opcode Fuzzy Hash: c27442c9625b69612e30a0c621dafdc38b3cd1b2ea33eefe8ec2cdf5f7c33623
                              • Instruction Fuzzy Hash: A041C738354B084BEB79F7389C997EA32D2E7B4310F600639A946EB1C6DF25D94187C1
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: InformationVolume
                              • String ID:
                              • API String ID: 2039140958-0
                              • Opcode ID: c6fe4b8a49b1c432d16a5d1b2244a4336856686fe2f0bc0d983b446ba2d85ae3
                              • Instruction ID: a9b8cd20af64975e3d7b022b848cedf85ee26bd39a80bd225909a63b0cb5a79d
                              • Opcode Fuzzy Hash: c6fe4b8a49b1c432d16a5d1b2244a4336856686fe2f0bc0d983b446ba2d85ae3
                              • Instruction Fuzzy Hash: 3A4160751187488BE769EF24C899BDBB3E1FBB4300F104A2EE18AD7191EF759505CB82
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: FileRead
                              • String ID:
                              • API String ID: 2738559852-0
                              • Opcode ID: 2f464fde3477c0bba4832f44d3340180ae7d23497e5ed422822a87f1e6a42210
                              • Instruction ID: bb7a84f6a70e592266d7e40f17e628c9385f1452e7f2659dd62d57961426dd2f
                              • Opcode Fuzzy Hash: 2f464fde3477c0bba4832f44d3340180ae7d23497e5ed422822a87f1e6a42210
                              • Instruction Fuzzy Hash: AF01C471704A0C8FE750FB19D8859A9B7E9FBE8310F50062AE94AD6140EF20EA558781
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: ResumeThread
                              • String ID:
                              • API String ID: 947044025-0
                              • Opcode ID: a3e65a005f3911c52a3a19618f507bf36bcbd5794d57615cb3bbd7cad2f75c67
                              • Instruction ID: 93fbed348495416d31c0e03f304514789bd129db66128aced5e8b17b16d61125
                              • Opcode Fuzzy Hash: a3e65a005f3911c52a3a19618f507bf36bcbd5794d57615cb3bbd7cad2f75c67
                              • Instruction Fuzzy Hash: 04012635754E098FEB68EB6DDC98A6533D1FB9A316B144075D80AC7144DA3A9C41CB81
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2585736667.00007DF4B9911000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4B9911000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_7df4b9911000_setup_wm.jbxd
                              Similarity
                              • API ID: EventHook
                              • String ID:
                              • API String ID: 3661607649-0
                              • Opcode ID: e6b188324f96a1e03f166e4287a2793acb406422b2b30f8b11d607c185f61fee
                              • Instruction ID: 526248aafb145dab66a769908235266506732315e41dfb149aa054cb388de3f5
                              • Opcode Fuzzy Hash: e6b188324f96a1e03f166e4287a2793acb406422b2b30f8b11d607c185f61fee
                              • Instruction Fuzzy Hash: 3D1165309189566FFB94EBA0D86A79B7AF0FF11318F500639D08BC22E2DB3DD4649741
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: LibraryLoad
                              • String ID:
                              • API String ID: 1029625771-0
                              • Opcode ID: 4d57d7d5982399080f90361c2699a999889f8feb933735bc5bb6e787f07df0d3
                              • Instruction ID: 18b8b5072a10f597fa5cea66ee83e96dd70d3da6da5f5d7cc1185b2f5c3c90bb
                              • Opcode Fuzzy Hash: 4d57d7d5982399080f90361c2699a999889f8feb933735bc5bb6e787f07df0d3
                              • Instruction Fuzzy Hash: 6301A434318B4D4FFB55EB38986A7A936D5EB74301F60057BA10AD7292EA28CD058781
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: CreateHeap
                              • String ID:
                              • API String ID: 10892065-0
                              • Opcode ID: eab2b32177be9564e25d5777707ea1ca30621b5695f0306aefe172fe800bc35c
                              • Instruction ID: 75acab24612675fe696574515e5beb6a04c7df79fe3bbe94e767733e4483531d
                              • Opcode Fuzzy Hash: eab2b32177be9564e25d5777707ea1ca30621b5695f0306aefe172fe800bc35c
                              • Instruction Fuzzy Hash: CFF0A735684F088FF738AE755C983962341F3F8212F34093AD645DA181DA3588414380
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: AddressCallerProc
                              • String ID:
                              • API String ID: 2663294120-0
                              • Opcode ID: c691d5039295ecc8b7e044fb40fc3c69618cf93c91779b6bda279d67736a12d8
                              • Instruction ID: f3a08863edaeeaed7d6779f15378958233bb72715abaa2847892482564b829ff
                              • Opcode Fuzzy Hash: c691d5039295ecc8b7e044fb40fc3c69618cf93c91779b6bda279d67736a12d8
                              • Instruction Fuzzy Hash: 5AE0C221704D190BAB7861AE288CAB611C6C7FC172714027BE51CC3299EE10CC410380
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2585736667.00007DF4B9911000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4B9911000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_7df4b9911000_setup_wm.jbxd
                              Similarity
                              • API ID: FunctionTable
                              • String ID:
                              • API String ID: 1252446317-0
                              • Opcode ID: 62df2a061ef9a83e40c3da8f8fbf33d98cfabe8aaf6c816d3fbd47a45bbcd3fe
                              • Instruction ID: 704d3d99bfc3cd373e1bcca7e68dc6f3318defd22abd6765c350f6123f1c9977
                              • Opcode Fuzzy Hash: 62df2a061ef9a83e40c3da8f8fbf33d98cfabe8aaf6c816d3fbd47a45bbcd3fe
                              • Instruction Fuzzy Hash: 2BE04F306509066BEBA8E61DC8497603AE0FB5830AF608269D405CA391CB3994ABCF42
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2585645214.00007DF4B9901000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4B9901000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_7df4b9901000_setup_wm.jbxd
                              Similarity
                              • API ID: FunctionTable
                              • String ID:
                              • API String ID: 1252446317-0
                              • Opcode ID: cff89ce48d21670ef986fb34dbe231ab83686b2b911df37c38ad495f9c0b2048
                              • Instruction ID: 60123d071eee8e860e920a54589b65e4253a81c0b0f2dad6104d49aa023580c2
                              • Opcode Fuzzy Hash: cff89ce48d21670ef986fb34dbe231ab83686b2b911df37c38ad495f9c0b2048
                              • Instruction Fuzzy Hash: 2DE04F309049065BEBA8D66DC8097503AE0FB5C30AF608669D509C9291CB39989BCF81
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000003.1706002611.00007DF4B9901000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4B9901000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_3_7df4b9901000_setup_wm.jbxd
                              Similarity
                              • API ID: FunctionTable
                              • String ID:
                              • API String ID: 1252446317-0
                              • Opcode ID: fc492990cf9c193ed0fed28dab1318ef1c2e9243cee28bd6a774944ac56baf31
                              • Instruction ID: 7740fd94aef7e1f3dc5c7d8fd20d357661017d8f4b0efa411c420e08befc9559
                              • Opcode Fuzzy Hash: fc492990cf9c193ed0fed28dab1318ef1c2e9243cee28bd6a774944ac56baf31
                              • Instruction Fuzzy Hash: 08E04F309049055BEBA8D66DC8097503AE0FB5830EF608669D509C9291CB79949BCF81
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: FunctionTable
                              • String ID:
                              • API String ID: 1252446317-0
                              • Opcode ID: a4029a93bfcd341c8676454adb8c6f5f12b6913b14ed0bccef0902b234b6dd47
                              • Instruction ID: a5541749bc9f28855cd368ac3a6138543f453b22dd469aa808e767e67a6d6a03
                              • Opcode Fuzzy Hash: a4029a93bfcd341c8676454adb8c6f5f12b6913b14ed0bccef0902b234b6dd47
                              • Instruction Fuzzy Hash: 1EE04F34140A055BEBA8DB1DC90D39036D0EBB831AF604268D504C9695CB3AC8DBCF81
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: LibraryLoad
                              • String ID:
                              • API String ID: 1029625771-0
                              • Opcode ID: deadc42d593f6e2d9e8bf000e5cc548490ab76c2dd2841c06e942c08cce04583
                              • Instruction ID: d492206c2a91b8dafaff30d80c8113f71ae012fc165048167e9400ad4e6ce8cc
                              • Opcode Fuzzy Hash: deadc42d593f6e2d9e8bf000e5cc548490ab76c2dd2841c06e942c08cce04583
                              • Instruction Fuzzy Hash: 45D0A720360E0D1BEA58633D1C9937551D5E7FC221F60027AB90AC2286DA58CC560380
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: freemalloc
                              • String ID:
                              • API String ID: 3061335427-0
                              • Opcode ID: 59198f789e8770a8feb484424aff911a50a4b1632d60f2ad6db9f6e5577744bf
                              • Instruction ID: d1c30e56214173caaebb7740d700404e5c0043a5d82261ee573c1dfdccd4f245
                              • Opcode Fuzzy Hash: 59198f789e8770a8feb484424aff911a50a4b1632d60f2ad6db9f6e5577744bf
                              • Instruction Fuzzy Hash: 1D915275558B484BD775FF14C89A6EAB3E1FBB8300F50093EE28AD7191EB30A54587C2
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: malloc
                              • String ID:
                              • API String ID: 2803490479-0
                              • Opcode ID: d2cb0783aaccdf533b8783a245833ea662784d452517a49626c29c14fb2d72e4
                              • Instruction ID: 789cbecd4813fe80b4da85199bf39e807f2ed3aacbb53f902303b748960e72bb
                              • Opcode Fuzzy Hash: d2cb0783aaccdf533b8783a245833ea662784d452517a49626c29c14fb2d72e4
                              • Instruction Fuzzy Hash: B0414B35218E0E8FDB94EF2CD88CAB5B7E1FB78711724466AD409C7664DB30E8858BC1
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: malloc
                              • String ID:
                              • API String ID: 2803490479-0
                              • Opcode ID: 79f048227ef8738a33d949dde2ae729533ca550820ee63163f1e85203fe644fa
                              • Instruction ID: ad138a98fa7f2c0724376ee1bf17cd8322003e61028c4aa683d9feb9be146154
                              • Opcode Fuzzy Hash: 79f048227ef8738a33d949dde2ae729533ca550820ee63163f1e85203fe644fa
                              • Instruction Fuzzy Hash: F521AE31214E0C8FDB59EF1CD88C7A173E5FBB831271442ABD809CB2A5DA24E9858B81
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: free
                              • String ID:
                              • API String ID: 1294909896-0
                              • Opcode ID: e53db298d0d7d8de9701e8a24c72cb59212fc55ca396913229799ff2ccd7724d
                              • Instruction ID: 6ddfe6c141a6c1f415c2b6939f657539f23cbd44ec59bfc7cb105a9972e3d96b
                              • Opcode Fuzzy Hash: e53db298d0d7d8de9701e8a24c72cb59212fc55ca396913229799ff2ccd7724d
                              • Instruction Fuzzy Hash: 4B114435240A1D8FEF79AF6998A93A533D0FB78315F2401BADA19DA195CB708C41C7E1
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: free
                              • String ID:
                              • API String ID: 1294909896-0
                              • Opcode ID: 5a17d2a82900e38e66e0587de357cfea25c88adc918405c2cab64094945da2f0
                              • Instruction ID: d138a85eefd45e2bd5a34f8d3b4fac49cad1d07abeffe2b45c211078a50a924f
                              • Opcode Fuzzy Hash: 5a17d2a82900e38e66e0587de357cfea25c88adc918405c2cab64094945da2f0
                              • Instruction Fuzzy Hash: DFF03074218E4A8FEF94EB6D94D8F6133E1FF68320F601264991AC71A5EB25DC82C780
                              APIs
                              Memory Dump Source
                              • Source File: 00000008.00000002.2584691781.0000021CE78E1000.00000020.00000001.00020000.00000000.sdmp, Offset: 0000021CE78E1000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_21ce78e1000_setup_wm.jbxd
                              Similarity
                              • API ID: calloc
                              • String ID:
                              • API String ID: 2635317215-0
                              • Opcode ID: f09fa07cc6f9e6f5b53de74bb20c91754370ab02738bba199ca246931610d18a
                              • Instruction ID: e0b94ebae03dfa7fc616b4404b45875b1258271ad5a92df10d4067b31b135671
                              • Opcode Fuzzy Hash: f09fa07cc6f9e6f5b53de74bb20c91754370ab02738bba199ca246931610d18a
                              • Instruction Fuzzy Hash: 28F08974650D094FF794AF2C9C9CB6535D4E769301F550076A50DD71A0DF78CC958741
                              APIs
                              Strings
                              Memory Dump Source
                              • Source File: 00000008.00000002.2585645214.00007DF4B9901000.00000020.00000001.00020000.00000000.sdmp, Offset: 00007DF4B9901000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_8_2_7df4b9901000_setup_wm.jbxd
                              Similarity
                              • API ID: InformationProcessQuery
                              • String ID: ($.$o
                              • API String ID: 1778838933-116743476
                              • Opcode ID: 4bc1349027c11bed1782b00e19f7c38053766996ee3beef85e27a3dd3919dec8
                              • Instruction ID: 74c53aa55963c857ba1533d99760be30ca634ef989d41c9968609b7fd2cf0a06
                              • Opcode Fuzzy Hash: 4bc1349027c11bed1782b00e19f7c38053766996ee3beef85e27a3dd3919dec8
                              • Instruction Fuzzy Hash: 2C818F3090C7D59EE3B59BB8C4183EBBBE1FF95304F145A2ED0EBC3292D62895458712

                              Control-flow Graph

                              APIs
                              Memory Dump Source
                              • Source File: 00000009.00000002.2584494739.0000022FAA4B0000.00000040.00000400.00020000.00000000.sdmp, Offset: 0000022FAA4B0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_9_2_22faa4b0000_dllhost.jbxd
                              Similarity
                              • API ID: Information$QuerySystemVolume
                              • String ID:
                              • API String ID: 2187445334-0
                              • Opcode ID: bbe3e2a7d344cf85ec3a4c395e4fae651ef179c001aa808880b53e11515cf003
                              • Instruction ID: 82e77dc104a69b28a81b8867702c85aadf0abc9af876767e0e6e88286637e210
                              • Opcode Fuzzy Hash: bbe3e2a7d344cf85ec3a4c395e4fae651ef179c001aa808880b53e11515cf003
                              • Instruction Fuzzy Hash: 5F918231214F095FEBA5EB74C9596E673F1FB68301F104A3AA85FC32A1EE3895498781

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 294 22faa4b2ac4-22faa4b2bb5 call 22faa4b3b44 call 22faa4b1030 call 22faa4b1914 call 22faa4b1488 call 22faa4b16a0 call 22faa4b1488 call 22faa4b11dc call 22faa4b1488 call 22faa4b11dc call 22faa4b1488 call 22faa4b11dc 318 22faa4b2dba-22faa4b2dd5 call 22faa4b1488 call 22faa4b17dc 294->318 319 22faa4b2bbb-22faa4b2bc3 call 22faa4e2736 294->319 327 22faa4b2dda-22faa4b2df6 318->327 322 22faa4b2bc8-22faa4b2bcd 319->322 324 22faa4b2bcf-22faa4b2bd2 322->324 325 22faa4b2bd4-22faa4b2bf0 322->325 324->325 328 22faa4b2c01-22faa4b2c03 324->328 325->328 339 22faa4b2bf2-22faa4b2bff call 22faa4e2736 325->339 336 22faa4b2df8-22faa4b2e38 call 22faa4b4a20 call 22faa4b5dc6 327->336 337 22faa4b2e3b-22faa4b2e50 call 22faa4b3cb0 327->337 329 22faa4b2c19-22faa4b2c1c 328->329 330 22faa4b2c05-22faa4b2c08 328->330 329->318 334 22faa4b2c22-22faa4b2c25 329->334 330->318 333 22faa4b2c0e-22faa4b2c17 330->333 333->329 338 22faa4b2c27-22faa4b2c2e 334->338 336->337 343 22faa4b2c32-22faa4b2c38 338->343 344 22faa4b2c30 338->344 339->328 343->338 348 22faa4b2c3a-22faa4b2c5b call 22faa4b1488 call 22faa4b17dc 343->348 344->343 356 22faa4b2c5d-22faa4b2c64 348->356 357 22faa4b2c6a-22faa4b2d9e call 22faa4b1914 call 22faa4b1488 call 22faa4b5dcc call 22faa4b1488 * 2 call 22faa4b5dcc call 22faa4b1488 * 2 call 22faa4b5dcc call 22faa4b1488 * 2 call 22faa4b5dcc call 22faa4b1488 * 2 call 22faa4b16a0 call 22faa4b1488 call 22faa4b5dcc call 22faa4b1488 356->357 358 22faa4b2da3-22faa4b2da9 356->358 357->358 358->356 360 22faa4b2daf-22faa4b2db8 358->360 360->327
                              Memory Dump Source
                              • Source File: 00000009.00000002.2584494739.0000022FAA4B0000.00000040.00000400.00020000.00000000.sdmp, Offset: 0000022FAA4B0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_9_2_22faa4b0000_dllhost.jbxd
                              Similarity
                              • API ID:
                              • String ID:
                              • API String ID:
                              • Opcode ID: 0f2ab5fabc2a0e36146663c7120b09b4177702f3456a2b2b11960e1abc9f1dee
                              • Instruction ID: 6a52c8f50f646be1d18ab75eed1ff0d62b651f8fe42b9d89e29de725d065ee50
                              • Opcode Fuzzy Hash: 0f2ab5fabc2a0e36146663c7120b09b4177702f3456a2b2b11960e1abc9f1dee
                              • Instruction Fuzzy Hash: E5B15531218B095BE796EB58C695ADB73F1FB94304F104639BC8FC71A6DE28E509CB81

                              Control-flow Graph

                              APIs
                              Memory Dump Source
                              • Source File: 00000009.00000002.2584494739.0000022FAA4B0000.00000040.00000400.00020000.00000000.sdmp, Offset: 0000022FAA4B0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_9_2_22faa4b0000_dllhost.jbxd
                              Similarity
                              • API ID: socket$ErrorModegetsockopt
                              • String ID:
                              • API String ID: 552242919-0
                              • Opcode ID: 2b6fb284fe353a32addd25f3df84090d0ecaa741c51bc7f7119ce81397f063fd
                              • Instruction ID: 1a18e1604d16b3193d73719260d10bae455a0b393811a2d03b56fc93ca4103e3
                              • Opcode Fuzzy Hash: 2b6fb284fe353a32addd25f3df84090d0ecaa741c51bc7f7119ce81397f063fd
                              • Instruction Fuzzy Hash: 54412130618B488FE794EF68D89869A77F1FB98300F50873AE45AC32E5DF398509CB41

                              Control-flow Graph

                              APIs
                              Memory Dump Source
                              • Source File: 00000009.00000002.2584494739.0000022FAA4B0000.00000040.00000400.00020000.00000000.sdmp, Offset: 0000022FAA4B0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_9_2_22faa4b0000_dllhost.jbxd
                              Similarity
                              • API ID: File$CreateMappingView
                              • String ID:
                              • API String ID: 3452162329-0
                              • Opcode ID: bece0600f44f861c643c7654aa2f2e3f03c84c914f92a664447b07396d3fe0fc
                              • Instruction ID: 153b05d9e7fe8d1ca7bc24365509ccf590fad85d5159d510860e81628f2a2ecf
                              • Opcode Fuzzy Hash: bece0600f44f861c643c7654aa2f2e3f03c84c914f92a664447b07396d3fe0fc
                              • Instruction Fuzzy Hash: F951703151CB889BD765EB65C5857EAB7F0FB94301F004A3FB89AC21A1DA349509CB92

                              Control-flow Graph

                              APIs
                              Memory Dump Source
                              • Source File: 00000009.00000002.2584494739.0000022FAA4B0000.00000040.00000400.00020000.00000000.sdmp, Offset: 0000022FAA4B0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_9_2_22faa4b0000_dllhost.jbxd
                              Similarity
                              • API ID: Completion$CreateFileModesNotificationPort
                              • String ID:
                              • API String ID: 3755109111-0
                              • Opcode ID: 84be1d14cb65808509a283a73e814be659c70036e97280a94885828e4d56e97e
                              • Instruction ID: bdfed706cbcbbbf15498ef239edb249a0379437b201d4bdbc91ee36b2619108e
                              • Opcode Fuzzy Hash: 84be1d14cb65808509a283a73e814be659c70036e97280a94885828e4d56e97e
                              • Instruction Fuzzy Hash: BD31C0303046195FFBE89BA89A8D36932F4F744315F900079FC2ECA2E2DB69CD458781

                              Control-flow Graph

                              APIs
                              Memory Dump Source
                              • Source File: 00000009.00000002.2584494739.0000022FAA4B0000.00000040.00000400.00020000.00000000.sdmp, Offset: 0000022FAA4B0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_9_2_22faa4b0000_dllhost.jbxd
                              Similarity
                              • API ID: InformationVolume
                              • String ID:
                              • API String ID: 2039140958-0
                              • Opcode ID: cbef5665e4e33130d77fabd6912371dd21022a2eb90503feaf05fbace3e60585
                              • Instruction ID: e7a69a64f5d309b6c29bf94f4179094ed097116b7e63c5b28e7c579fbfe03aff
                              • Opcode Fuzzy Hash: cbef5665e4e33130d77fabd6912371dd21022a2eb90503feaf05fbace3e60585
                              • Instruction Fuzzy Hash: 305101711187488BE7AAEB64C5987EBB7F0FB94304F504A3DE48AC21A1DF799509CB42

                              Control-flow Graph

                              APIs
                              Memory Dump Source
                              • Source File: 00000009.00000002.2584494739.0000022FAA4B0000.00000040.00000400.00020000.00000000.sdmp, Offset: 0000022FAA4B0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_9_2_22faa4b0000_dllhost.jbxd
                              Similarity
                              • API ID: socket
                              • String ID:
                              • API String ID: 98920635-0
                              • Opcode ID: 164deb1e36558be1443e0572fd883e2d2b2af36008d1889a4b6708111c61d883
                              • Instruction ID: 54952a3fc07bc58e9b69d54b5f7777ca2e7d9f2c73ef17cf973e801f4e136c4c
                              • Opcode Fuzzy Hash: 164deb1e36558be1443e0572fd883e2d2b2af36008d1889a4b6708111c61d883
                              • Instruction Fuzzy Hash: 592192303046045FEBD8ABB8998D76533F1EB58325F204679FC3EC72E6EB288C458691

                              Control-flow Graph

                              APIs
                              Memory Dump Source
                              • Source File: 00000009.00000002.2584494739.0000022FAA4B0000.00000040.00000400.00020000.00000000.sdmp, Offset: 0000022FAA4B0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_9_2_22faa4b0000_dllhost.jbxd
                              Similarity
                              • API ID: ErrorMode
                              • String ID:
                              • API String ID: 2340568224-0
                              • Opcode ID: 147b7861b8d55a5ae4162ffc4259640c3a28b81395385b0f304c643425426fcc
                              • Instruction ID: 555513282ad920f66b321a784454b5d8a620c5a7a18bc07358629b2bd1f74456
                              • Opcode Fuzzy Hash: 147b7861b8d55a5ae4162ffc4259640c3a28b81395385b0f304c643425426fcc
                              • Instruction Fuzzy Hash: 10011E20314B092AEBD9B6A8CB593B922F6EB95310F440139BC0ED21E2DE1CDA098641

                              Control-flow Graph

                              APIs
                              Memory Dump Source
                              • Source File: 00000009.00000002.2584494739.0000022FAA4B0000.00000040.00000400.00020000.00000000.sdmp, Offset: 0000022FAA4B0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_9_2_22faa4b0000_dllhost.jbxd
                              Similarity
                              • API ID: AddressCallerProc
                              • String ID:
                              • API String ID: 2663294120-0
                              • Opcode ID: be8164fcd6bb8b439b0c6dd95cb79210c8cf986f476e4ea7066077b0df3d1665
                              • Instruction ID: 572301d06be12458d479bb85f6c8b2b9010ca51005ae3d1ed1e36297d74c8ad8
                              • Opcode Fuzzy Hash: be8164fcd6bb8b439b0c6dd95cb79210c8cf986f476e4ea7066077b0df3d1665
                              • Instruction Fuzzy Hash: 2EE02B11704D0D1BABE861FE658C77651E6C7DC272B04027BFC1DC32A5ED14CC890390

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 223 22faa4b2874-22faa4b2891 call 22faa4b1994 226 22faa4b2898-22faa4b289e 223->226 227 22faa4b2893-22faa4b2896 LoadLibraryA 223->227 227->226
                              APIs
                              Memory Dump Source
                              • Source File: 00000009.00000002.2584494739.0000022FAA4B0000.00000040.00000400.00020000.00000000.sdmp, Offset: 0000022FAA4B0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_9_2_22faa4b0000_dllhost.jbxd
                              Similarity
                              • API ID: LibraryLoad
                              • String ID:
                              • API String ID: 1029625771-0
                              • Opcode ID: deadc42d593f6e2d9e8bf000e5cc548490ab76c2dd2841c06e942c08cce04583
                              • Instruction ID: 1998da428ac4c3fea1a03041c6f35ed7993c3b39afe8a3965d80fa8b6333250b
                              • Opcode Fuzzy Hash: deadc42d593f6e2d9e8bf000e5cc548490ab76c2dd2841c06e942c08cce04583
                              • Instruction Fuzzy Hash: 8AD0A710320E0E2FEB88637D5E9837511E5E7EC225F50153ABC0DC2281D95CCC594300

                              Control-flow Graph

                              APIs
                              Memory Dump Source
                              • Source File: 00000009.00000002.2584494739.0000022FAA4B0000.00000040.00000400.00020000.00000000.sdmp, Offset: 0000022FAA4B0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_9_2_22faa4b0000_dllhost.jbxd
                              Similarity
                              • API ID: free
                              • String ID:
                              • API String ID: 1294909896-0
                              • Opcode ID: 842a0fcfbae77ddf7c9ef53a2fdb97499bdab63288fbf5ca7410195d085d151d
                              • Instruction ID: 0e0c529dd38dd41caf0022dfd7080651218ae287ea4fe0fbd7c161b3ce0a567d
                              • Opcode Fuzzy Hash: 842a0fcfbae77ddf7c9ef53a2fdb97499bdab63288fbf5ca7410195d085d151d
                              • Instruction Fuzzy Hash: A5319E30215A099FEFD8EB59D6A976833B2FB94301F5440B8AC0ECA2A6CF289855C750

                              Control-flow Graph

                              APIs
                              Memory Dump Source
                              • Source File: 00000009.00000002.2584494739.0000022FAA4B0000.00000040.00000400.00020000.00000000.sdmp, Offset: 0000022FAA4B0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_9_2_22faa4b0000_dllhost.jbxd
                              Similarity
                              • API ID: free
                              • String ID:
                              • API String ID: 1294909896-0
                              • Opcode ID: 7a297f1986504495161170ee7aee10f4abf84ff64ce9de3e5e03136cde0e8aee
                              • Instruction ID: 2e0f96db2c11f2d2f545335ab62987a747293de5ccca0bdc39338596fa1a2664
                              • Opcode Fuzzy Hash: 7a297f1986504495161170ee7aee10f4abf84ff64ce9de3e5e03136cde0e8aee
                              • Instruction Fuzzy Hash: 96219370214A099FEB98EF5CC598B6477F1FB58305F5440B9AC09CB2A7CB75D846CB40

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 282 22faa4c48f8-22faa4c48fb 283 22faa4c48fd-22faa4c490c 282->283 284 22faa4c4940 282->284 285 22faa4c490e-22faa4c491f call 22faa4bac54 free 283->285 286 22faa4c4925-22faa4c493f 283->286 285->286 286->284
                              APIs
                              • free.MSVCRT(?,?,?,?,?,?,00000008,0000022FAA4BFD09,?,?,?,?,?,?,?,0000022FAA4B7FA9), ref: 0000022FAA4C491F
                              Memory Dump Source
                              • Source File: 00000009.00000002.2584494739.0000022FAA4B0000.00000040.00000400.00020000.00000000.sdmp, Offset: 0000022FAA4B0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_9_2_22faa4b0000_dllhost.jbxd
                              Similarity
                              • API ID: free
                              • String ID:
                              • API String ID: 1294909896-0
                              • Opcode ID: 7dd69658861cf162b6e8f5607d2afe179510db48a5e0ef57d5537ff1bbbeb537
                              • Instruction ID: 118f48fa5430595a83da77979339f80fd7de74448980e4ae9fff39089551a728
                              • Opcode Fuzzy Hash: 7dd69658861cf162b6e8f5607d2afe179510db48a5e0ef57d5537ff1bbbeb537
                              • Instruction Fuzzy Hash: 1DF03930121A094BEF98DF99C2D8B6572B0FB88301F5480A9AC18CA299C778C895C740

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 289 22faa4b3cb0-22faa4b3cc1 290 22faa4b3cdf-22faa4b3ce3 289->290 291 22faa4b3cc3-22faa4b3cc8 289->291 291->290 292 22faa4b3cca-22faa4b3cd4 291->292 292->290 293 22faa4b3cd6-22faa4b3cd9 free 292->293 293->290
                              APIs
                              Memory Dump Source
                              • Source File: 00000009.00000002.2584494739.0000022FAA4B0000.00000040.00000400.00020000.00000000.sdmp, Offset: 0000022FAA4B0000, based on PE: false
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_9_2_22faa4b0000_dllhost.jbxd
                              Similarity
                              • API ID: free
                              • String ID:
                              • API String ID: 1294909896-0
                              • Opcode ID: 8cb90f487aa88aaeb899a82658a4f96ee9d6a5816eee242e74479443c5ca5ecc
                              • Instruction ID: c3d77fae0b079c8cf0d4851da9afd5ae55ce292f58c29bc273d7448f8705978e
                              • Opcode Fuzzy Hash: 8cb90f487aa88aaeb899a82658a4f96ee9d6a5816eee242e74479443c5ca5ecc
                              • Instruction Fuzzy Hash: 7FE0E631211E199EEB95ABB5CA5C75032F0F758304F980574E805C35E0E66CF845F741